Lyxter

Privacy Policy

Last updated: 28 July 2026

Lyxter ("we", "us") provides an AI diagnostic assistant for heavy-vehicle companies at app.lyxter.ai. This policy explains what personal data we process, why, and what rights you have. It is written to comply with the EU General Data Protection Regulation (GDPR).

1. Who is responsible

The data controller is Lyxter ApS (CVR 46627571), Bjergegade 58, 6870 Ølgod, Denmark. Contact: hello@lyxter.ai.

One category of data is different: the records your company keeps about its own customers - under Customers, or when Service records work for one of them - the names, contact details, and vehicle information you enter about those customers are your company's data, not ours. For that data Lyxter acts only as a processor, on your instructions, and your company is the controller - see section 6 for the data processing agreement.

2. What we collect

Cookies and local storage. We do not use advertising, analytics, or tracking cookies of any kind. Everything we store in your browser is strictly necessary for features you ask for, which is why Lyxter shows no cookie consent banner. The complete list:

Our pages load no third-party scripts; fonts are hosted by us. There is one third-party request, and only inside a chat: where an answer drew on a web source, your browser loads that source site's small icon from the site itself. It is described in section 4. Content served by our own providers (section 6), such as your uploaded photos, is not a third-party request: those providers act only on our instructions.

3. Why we process it (legal bases)

4. AI processing and the shared knowledge base

Your messages are processed by AI models (see subprocessors below) to generate answers. Lyxter learns from chats, but we never train the AI model itself on your data: your chats are not used to train or fine-tune any AI model.

What the system learns goes into a shared knowledge base of fault codes and repair guidance that improves answers for every company. It holds structured data only, never your raw conversation text:

Your own words, chat text, and images are never placed in the shared knowledge base, and neither is anything that identifies you, your colleagues, or your company.

Your company's own earlier chats, its own case records, and the chat search entries that find them (all described in section 2) are not part of this shared knowledge base and there is no route by which they can become part of it. They are used only in your own company's chats. What an earlier chat of yours said is also never treated as a checked answer: the AI is told plainly that nothing said in an earlier chat was reviewed, that it may have been wrong, and that it may never be used as the source of what a fault code means or of a torque, pressure, clearance, capacity or service interval. Recalling one also never stops the AI from looking a fault code up properly.

When Lyxter cannot answer from its own reviewed knowledge base, your company's manuals or the machine's own history, it may look the machine up on the public web. The search runs through the same AI provider that already answers your questions (listed in section 6), which searches the web on Lyxter's behalf using its own search partner. An entry learned from your own chats that Lyxter staff have not reviewed yet does not count as an answer here: it is still used in your own company's chats, and where Lyxter reads its review state it tells the AI the entry is unreviewed, but it does not hold the lookup back, so an unchecked note in your own account is not left standing as the meaning of a fault code. When your chat carries a fault code that no reviewed Lyxter source describes, this lookup normally runs automatically as the chat starts, or when the machine is first identified, before the AI writes anything, so that its answer rests on a source rather than on what it happens to remember. Nothing about what may be sent changes when it runs that way: it is the same wording, built the same way, described below. Your message is never sent. The search wording is built by the software itself, out of a fixed, short list of technical fields and nothing else: the machine brand (only when it is one of the brands Lyxter knows by name), the model and engine designation (only when they look like a designation, such as "WA380" or "TCD 7.8"), the model year from your fleet record, the fault code recorded on the case (only when it has the shape of a diagnostic code - and where the code was typed inside a longer line, only the part of that line that has the shape of a diagnostic code, taken word for word and never rewritten), a few plain English technical words naming the part or system, and one of four fixed phrases saying what kind of answer is wanted. Anything that fails one of those tests is left out, and the words naming the part are additionally checked in software for personal details and rejected if any are found.

So your message, a description of a symptom, your photos, your files, and anything naming you, your company, your customer, a place or a registration number are never sent to a search provider. The one thing that can overlap with what you wrote is an ordinary technical word: if you write that an injector is leaking, the word "injector" can be part of what is looked up. Lyxter states this precisely rather than promising more than the software checks.

This is enforced by how the search is made, not only by what is put into it. The lookup runs as a separate request whose entire content is that one built search wording: the part of the AI that does the searching is never given your conversation, your photos, your vehicle record or your customer record at all, so it cannot pass on something it was never shown. The search is normally restricted to a curated list of manufacturer, technical and workshop sites.

No account, no name and no address goes with the search, and it is not told who is asking: the request is made by Lyxter's own servers, so your device never contacts the search provider and your IP address is never sent to it. Lyxter treats what comes back as unverified: the answer itself does not name the site it drew on, because the app attaches the sources to the answer for you - a small chip under the reply that opens each source's site and page title. The chip appears when one of the sources found names the fault code in question; where an automatic lookup came back with none that does, no chip is shown at all, which is not a statement that nothing was looked up. The AI must never state a torque figure, a pressure, a clearance or a service interval on the strength of a web result.

That chip is the one place your own device does reach out: to show each source's site icon, your browser loads that icon from the source site itself, so those sites can see your IP address and browser type at that moment, the way they would if you opened the page. Nothing else goes with it - no account, no name, nothing from your chat, and the request deliberately carries no referrer, so the site is not told which app or page the icon was shown in. When an icon cannot be loaded, a plain letter is shown instead. Opening a source from the chip is an ordinary visit to that site, under that site's own privacy terms.

Manuals uploaded by your company are reviewed by Lyxter staff and then stay private to your company by default: the AI uses them only in your company's own chats. After approving a manual, staff may add a small number of short, AI-written technical lessons distilled from it to the shared knowledge base described above; each lesson is reviewed before the AI can use it, is written in the AI's own words rather than copied from the manual, and contains nothing identifying you or your company. A manual itself becomes part of the shared knowledge pool only if Lyxter staff explicitly decide to share it after review, for material that may lawfully be shared (see the Terms of Service).

5. Staff access and quality assurance

A small number of Lyxter staff can view customer chats and account data when needed to provide support, review the quality and safety of AI answers, and investigate problems. Staff access to customer data is read-only, and every access is recorded in an internal log: who looked at what, and when. While a learned knowledge entry is still waiting for that review it also shows those staff which user and which chat it came from - staff-only, logged like any other access, private to your company until the entry is approved, and cleared from the entry once it is approved and shared.

To test the AI before changes go live, we may turn a real diagnostic case into an internal test scenario. Before that happens, identifying details (names, company names, email addresses, phone numbers, number plates and similar) are removed, the cleaned text is reviewed by staff, and images are never included. Internal usage and cost figures are aggregated counts and contain no chat content.

6. Service providers

We use a small number of carefully selected service providers (processors) to run Lyxter. Where a provider processes data outside the EU/EEA, the transfer is protected by the EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.

CategoryPurposeLocation
Database and authenticationStoring accounts, chats, and documentsEU (Ireland)
Application hostingRunning the serviceEU
AI model providersGenerating answers, reading images, and - when the wider web lookup in section 4 is switched on for your account - searching the public web on Lyxter's behalfUSA
Payment processorSubscriptions and invoicingEU/USA
Email deliveryTransactional email (confirmations, invites, service reminders), and an invoice your company chooses to send to one of its own customers - which carries that customer's name and address and the priced lines of the workUSA
Customer relationship management (CRM)Managing customer and prospect accounts: company name, plan and billing status, the name and work email of the people on the account, and simple activity counts such as how many diagnoses a user has run and when they were last active. No chat content, no photos, no vehicle or service records.EU/USA
Network and DNS securityTraffic routing and protectionEU/global

The wider web lookup described in section 4 adds no new provider to this list. It runs through the AI model provider already named in it, which uses its own search partner to fetch the pages; that partner receives only the built technical search wording described in section 4, and never your message, your photos or anything naming you or your customer.

Business customers can request the named list of providers as part of a data processing agreement by writing to hello@lyxter.ai. If your company records customer data (section 2), that agreement is what makes the controller/processor relationship in section 1 formal - write to us before you enter your first customer record if you need it in place first.

7. How long we keep data

8. Your rights

You can ask us to access, correct, export, or delete your personal data, and to restrict or object to processing. Write to hello@lyxter.ai - we respond within 30 days.

Company owners can request deletion of their entire company account, including all user accounts, chats, vehicles, service history, and uploaded manuals. There are two ways to ask, and both file the same request: from inside the app, under Settings, Company, or on our public account deletion page, which works whether or not you still have the app installed. We confirm the request within 2 working days and complete the deletion within 30 days, and you can withdraw it until we do. That page lists exactly what is deleted and the little we have to keep (see section 7). One of those things is a minimal record of the deletion itself - the company name, the date, which staff member carried it out, reference ids and counts of what was removed - kept so the erasure can be accounted for afterwards.

Customer records are the exception: if you are a workshop's customer and want to access, correct, or delete what that workshop has recorded about you, ask the workshop directly. They are the controller for that data, not us (section 1); we only act on their instructions and will pass such a request on to them.

If you are unhappy with how we handle your data, you can complain to the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk).

9. Changes

We will update this policy as the service evolves and note the date above. Significant changes will be announced to account owners by email.

Terms of Service · Log in · lyxter.ai