‍LEXEMIN PROFESSIONAL SERVICES LLC
Terms of Use for Client Portal(s)


Effective Date: October 9, 2026  |  Version 1.0


1. Structure and definitions

These Terms, together with the documents listed below, form the agreement between Lexemin Professional Services LLC ("Lexemin", “lps.”, “lps llc”, “we”, “us”, “our”) and the client organisation named in the Order Form ("Client").

The agreement comprises, in descending order of precedence where they conflict:

  1. the Order Form

  2. Annex A, the Data Processing Agreement

  3. these Terms

  4. Annex B, the Sub-processor List

  5. the Acceptable Use Policy

  6. the LexHR End User Terms, which govern the relationship between Lexemin and individual users

The LexHR Privacy Notice is informational and does not vary the agreement.

Definitions.

  • Authorized User means an individual the Client permits to access LexHR, including the Client's employees, workers, contractors and administrators.

  • Client Data means all data the Client or its Authorized Users submit to LexHR, including personal data relating to the Client's workforce.

  • LexHR means the hosted human resources platform made available by Lexemin, including its interfaces, documentation and any configured modules.

  • Order Form means the ordering document or contractual agreement or Master Services Agreement, signed by both parties specifying the subscription tier, user count, term, fees and hosting region.

  • Hosting Region means the United Kingdom or European Union region, or the United States region, as specified in the Order Form.

  • Data protection law means, as applicable, the UK GDPR and Data Protection Act 2018, the EU GDPR, and US federal and state privacy legislation.

2. Licence and Client obligations

2.1 Licence. Lexemin grants the Client a non-exclusive, non-transferable right for the Client and its Authorised Users to access and use LexHR during the term, for the Client's internal business purposes, up to the user count in the Order Form.

2.2 Restrictions. The Client shall not, and shall not permit any person to: resell, sublicense or make LexHR available to any third party except Authorised Users; copy, modify, reverse engineer or create derivative works of the platform; access it to build a competing product; or circumvent any access control, usage limit or security measure.

2.3 Account security. The Client is responsible for the acts and omissions of its Authorised Users, for configuring roles and permissions appropriately, for promptly deactivating users who leave, and for notifying Lexemin without delay of any suspected unauthorised access.

2.4 Accuracy and lawfulness of Client Data. The Client warrants that it has the right to submit the Client Data to LexHR; that its processing instructions to Lexemin comply with data protection law; and that it has identified a lawful basis under Article 6 UK GDPR and, for special category data, a condition under Article 9 and Schedule 1 DPA 2018, together with an appropriate policy document where Schedule 1 requires one.

2.5 Transparency to the Client's own workforce. The Client is responsible for informing its workforce how their personal data is processed in LexHR, including the identity of Lexemin as processor, the Hosting Region and the possibility of cross-region administrative access. Lexemin will make available information reasonably required for that purpose.

2.6 Prohibited data. The Client shall not submit to LexHR any data of a category excluded in the Order Form, nor any payment card data, nor any special category or criminal offence data for which it has not confirmed a lawful condition.

2.7 AI-assisted features. Any AI-assisted feature is disabled unless the Client enables it in writing. By enabling it the Client instructs Lexemin to submit the relevant Client Data to the AI sub-processors listed in Annex B and confirms its lawful basis extends to that processing.

2.8 Acceptable Use Policy. The Client and its Authorised Users shall comply with the Acceptable Use Policy, which Lexemin may update on 30 days' notice.

3. Fees, availability and support

3.1 Fees. Fees are those in the Order Form, payable in the currency stated, within 30 days of invoice. Fees exclude VAT, sales tax and other applicable taxes, which the Client pays in addition.

3.2 User count. Where the Client exceeds the licensed user count, Lexemin may invoice the excess at the per-user rate in the Order Form, pro-rated for the remainder of the term.

3.3 Late payment. Lexemin may charge interest on overdue sums and, on 14 days' written notice, suspend access until payment is made. Suspension does not affect the Client's right to export its data under Clause 5.

3.4 Fee changes. Lexemin may change fees on renewal, on at least 60 days' written notice before the end of the current term.

3.5 Availability. Lexemin will use commercially reasonable efforts to make LexHR available 99.5% of the time each calendar month, excluding scheduled maintenance notified at least 48 hours in advance, emergency maintenance, and any unavailability caused by the Client, its users, or events beyond Lexemin's reasonable control.

3.6 Support. Support is available by email to the address in the Order Form during Lexemin's business hours in the United Kingdom and the United States. Target response times are:

Severity

Definition

Target first response

P1

Platform unavailable or data inaccessible for all users

2 business hours

P2

Major function unavailable, no workaround

4 business hours

P3

Function impaired, workaround available

1 business day

P4

Question, minor issue or enhancement request

3 business days

3.7 Single-jurisdiction support. Where the Client has elected to restrict Lexemin's administrative access to one jurisdiction under the LexHR Privacy Notice, the targets above apply only during that jurisdiction's business hours.

3.8 Service credits. Where monthly availability falls below 99.5%, the Client may claim a service credit, requested in writing within 30 days of the end of the affected month, calculated as 5% of that month's fees for each full percentage point below the target, capped at 25% of that month's fees. Service credits are the Client's sole remedy for failure to meet the availability target.

4. Intellectual property, confidentiality and liability

4.1 Lexemin IP. Lexemin and its licensors own all rights in LexHR, including its software, interfaces, documentation and branding. Nothing in this agreement transfers any of those rights to the Client.

4.2 Client Data. The Client and its licensors own all rights in the Client Data. The Client grants Lexemin a licence to host, copy, transmit and display the Client Data solely to provide LexHR and to perform its obligations under this agreement.

4.3 Aggregated data. Lexemin may generate aggregated and de-identified statistical data from use of the platform to operate, secure and improve it. Such data contains no personal data and does not identify the Client or any individual, and Lexemin shall not disclose it in a form that could.

4.4 Feedback. Lexemin may use suggestions the Client provides about LexHR without restriction or obligation.

4.5 Confidentiality. Each party shall keep the other's confidential information confidential, use it only for this agreement, and disclose it only to personnel and advisers who need it and are bound by equivalent obligations. The obligation does not apply to information that is public through no breach, was already known without obligation, is independently developed, or must be disclosed by law, in which case the disclosing party shall give notice where lawful.

4.6 Warranties. Lexemin warrants that it will provide LexHR with reasonable skill and care and in accordance with this agreement, and that it has the right to grant the licence in Clause 2.1. Each party warrants it has authority to enter into this agreement.

4.7 Disclaimer. Except as expressly stated, LexHR is provided "as is". Lexemin does not warrant that the platform will be uninterrupted or error-free, nor that it will meet requirements Lexemin has not agreed in writing. LexHR is a record-keeping and workflow tool. It does not provide legal, tax, payroll or employment advice, and its outputs are not a substitute for professional advice. The Client remains responsible for its own compliance with employment, tax and data protection law.

4.8 Liability not excluded. Neither party excludes liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot lawfully be excluded.

4.9 Excluded losses. Subject to Clause 4.8, neither party is liable for loss of profit, revenue, anticipated savings, business, goodwill or reputation, or for any indirect or consequential loss.

4.10 Liability cap. Subject to Clauses 4.8 and 4.11, each party's total liability arising out of this agreement is limited to the fees paid or payable by the Client in the 12 months preceding the event giving rise to the claim.

4.11 Data protection liability. The cap in Clause 4.10 does not apply to a party's liability arising from its own breach of data protection law or of Annex A. The parties should agree a separate, higher cap for such claims in the Order Form.

Drafting note. Clause 4.11 is deliberately left open. A single low cap covering data protection breaches is commonly rejected in HR SaaS negotiations and may be unenforceable as a limitation on statutory liability. Set a figure, typically a multiple of annual fees, before issuing.

5. Term, termination and data exit

5.1 Term. The agreement begins on the start date in the Order Form and continues for the initial term stated, renewing automatically for successive periods of the same length unless either party gives written notice of non-renewal at least 60 days before the end of the current term.

5.2 Termination for cause. Either party may terminate immediately on written notice if the other commits a material breach that is not remedied within 30 days of notice, or becomes insolvent, enters administration or ceases to trade.

5.3 Termination by the Client for data protection reasons. The Client may terminate without penalty where it objects on reasonable data protection grounds to a new sub-processor under Clause 5 of the LexHR Privacy Notice and Lexemin is unable to offer a reasonable alternative, or where a change in law renders Lexemin's transfer mechanism unavailable and no replacement is implemented within 60 days.

5.4 Suspension. Lexemin may suspend access, in whole or in part, where required by law, where continued access presents a material security risk, or for non-payment under Clause 3.3. Lexemin will give as much notice as is reasonably practicable and will restore access once the cause is resolved.

5.5 Export window. For 30 days after termination or expiry, the Client may export the Client Data from LexHR in a structured, commonly used, machine-readable format. Lexemin will provide reasonable assistance with export at its then-current professional services rates, except where termination is for Lexemin's material breach, in which case assistance is provided at no charge.

5.6 Deletion. After the export window closes, Lexemin deletes the Client Data from active systems within 30 days and from backups within 90 days, and will certify deletion in writing on request. Lexemin may retain data only where law requires, for the period required, subject to continuing confidentiality and security obligations.

5.7 Survival. Clauses 4.1 to 4.11, this Clause 5.7, Clause 6 and Annex A survive termination to the extent necessary.

6. General

6.1 Governing law and jurisdiction. The governing law depends on the Client's place of establishment, as recorded in the Order Form:

Client establishment

Governing law

Exclusive jurisdiction

United Kingdom, European Union, or elsewhere outside North America

England and Wales

Courts of England and Wales

United States, Canada or Mexico

State of Georgia, excluding its conflict of laws rules

State and federal courts in Fulton County, Georgia

The United Nations Convention on Contracts for the International Sale of Goods does not apply.

6.2 Changes to these Terms. Lexemin may amend these Terms on 30 days' written notice. Where an amendment materially reduces the Client's rights, the Client may terminate without penalty before the amendment takes effect. Fees and the Order Form are not varied by this clause.

6.3 Entire agreement. This agreement is the entire agreement between the parties on its subject matter and supersedes prior discussions. Neither party relies on any statement not set out in it, save for fraudulent misrepresentation.

6.4 Assignment. Neither party may assign the agreement without the other's written consent, not to be unreasonably withheld, except that either may assign to a successor in connection with a merger, acquisition or sale of substantially all assets on written notice.

6.5 Subcontracting. Lexemin may subcontract its obligations but remains responsible for its subcontractors' performance. Sub-processing of personal data is governed by Annex A.

6.6 Notices. Notices must be in writing and sent to the addresses in the Order Form, with notices to Lexemin copied to info@lexemin.com and, for data protection matters, data-services@lexemin.com.

6.7 Force majeure. Neither party is liable for failure to perform caused by events beyond its reasonable control, provided it notifies the other and resumes performance as soon as practicable. This does not excuse payment obligations.

6.8 No partnership. Nothing creates a partnership, joint venture, agency or employment relationship.

6.9 Third party rights. Except for Lexemin's licensors under Clause 4.1, no person who is not a party may enforce any term, and the Contracts (Rights of Third Parties) Act 1999 does not apply.

6.10 Severance. If any provision is held unenforceable, the remainder continues in force and the provision is modified to the minimum extent necessary to make it enforceable.

6.11 Counterparts. The Order Form may be signed in counterparts, including electronically.

Annex A — Data Processing Agreement

This Annex forms part of the LexHR Platform Terms of Service and applies where Lexemin processes personal data on behalf of the Client. Terms defined in the Terms have the same meaning here.

A1. Roles. The Client is the controller and Lexemin is the processor in respect of Client Data. Where the Client is itself a processor for a third party, Lexemin is a sub-processor and references to the Client's instructions mean instructions originating from that third party controller.

A2. Instructions. Lexemin shall process Client Data only on the Client's documented instructions, which comprise the Terms, this Annex, the Order Form, the Client's configuration of the platform, and any further written instruction the parties agree. Lexemin shall inform the Client if, in its opinion, an instruction infringes data protection law. Where Lexemin is required by law to process Client Data otherwise, it shall inform the Client before doing so unless that law prohibits it.

A3. Confidentiality. Lexemin shall ensure that all personnel authorised to process Client Data are subject to a binding duty of confidentiality and have received appropriate data protection training.

A4. Security. Lexemin shall implement the technical and organisational measures described in Clause 6 of the LexHR Privacy Notice, which the parties agree are appropriate under Article 32 UK GDPR having regard to the state of the art, costs, and the risks presented by the processing.

A5. Sub-processors. The Client grants general written authorisation for Lexemin to engage the sub-processors listed in Annex B. Lexemin shall give the Client at least 30 days' written notice before adding or replacing a sub-processor, during which the Client may object on reasonable data protection grounds. Where the parties cannot agree a resolution, the Client may terminate under Clause 5.3. Lexemin shall impose data protection obligations on each sub-processor no less protective than those in this Annex and remains fully liable for its sub-processors' performance.

A6. Data subject rights. Taking into account the nature of the processing, Lexemin shall assist the Client by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligations to respond to data subject requests. LexHR provides self-service functionality for access, correction, export and deletion. Where Lexemin receives a request directly from a data subject, it shall not respond substantively and shall forward the request to the Client without undue delay.

A7. Assistance with compliance. Lexemin shall assist the Client, taking into account the nature of processing and the information available to it, with its obligations under Articles 32 to 36 UK GDPR, including security, breach notification, data protection impact assessments and prior consultation.

A8. Breach notification. Lexemin shall notify the Client without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Client Data, and shall provide the information reasonably required for the Client to meet its own obligations, supplementing it as further detail becomes available.

A9. Deletion or return. On termination, Lexemin shall delete or return Client Data in accordance with Clauses 5.5 and 5.6 of the Terms.

A10. Audit. Lexemin shall make available to the Client the information necessary to demonstrate compliance with Article 28 UK GDPR, and shall allow for and contribute to audits, including inspections, conducted by the Client or an auditor it mandates. The Client shall give at least 30 days' notice, conduct no more than one audit in any 12-month period except following a personal data breach or at a regulator's direction, conduct audits during business hours without unreasonable disruption, and bear its own costs. Lexemin may satisfy an audit request in whole or in part by providing a current third-party audit report or security certification.

A11. International transfers. Transfers are governed by Clause 4 of the LexHR Privacy Notice. Where the UK Addendum or EU Standard Contractual Clauses apply, they are incorporated into this Annex, with the Client as data exporter and Lexemin as data importer, and the details in Appendix 1 completing their annexes. Where those clauses conflict with this Annex, the clauses prevail.

A12. Processing details (Appendix 1).

Item

Detail

Subject matter

Provision of the LexHR human resources platform

Duration

The term of the agreement, plus the export and deletion periods in Clause 5

Nature and purpose

Hosting, storage, retrieval, organisation, and automated calculation of workforce records as configured by the Client

Types of personal data

As listed in Clause 2 of the LexHR Privacy Notice

Special categories

Health and occupational health, disability, maternity and parental records, equality monitoring, trade union membership, where the Client records them

Categories of data subject

The Client's employees, workers, contractors, job applicants where configured, and the emergency contacts and dependants they nominate

Frequency of transfer

Continuous, for the duration of the agreement

Competent supervisory authority

The Information Commissioner's Office, or the lead authority of the Client's EU establishment

Annex B — Sub-processor list

The table below must be completed with Lexemin's actual vendors before issue. The rows show the shape required: every sub-processor needs a named entity, the purpose it serves, the country of processing and the transfer mechanism relied on.

Sub-processor

Purpose

Country of processing

Transfer mechanism

[Cloud hosting provider]

Hosting and storage of Client Data, UK/EU region

United Kingdom or Ireland

N/A for UK region

[Cloud hosting provider]

Hosting and storage of Client Data, US region

United States

UK IDTA, or DPF where certified

[Email and notification provider]

Transactional email and in-platform notifications

[to confirm]

[to confirm]

[Backup and disaster recovery provider]

Encrypted backup storage

[to confirm]

[to confirm]

[Error monitoring and telemetry provider]

Platform performance and error reporting

[to confirm]

[to confirm]

[Payroll provider, if integrated]

Payroll calculation and disbursement

[to confirm]

[to confirm]

Anthropic PBC

AI-assisted features, where the Client has enabled them

United States

UK IDTA, or DPF where certified

OpenAI, LLC

AI-assisted features, where the Client has enabled them

United States

UK IDTA, or DPF where certified

Lexemin Professional Services LLC, with personnel in the United Kingdom and the United States, is not a sub-processor. Its cross-region access is described in Clause 4 of the LexHR Privacy Notice.

The current version of this list is published at www.lexemin.com and notified under Clause A5.

This Addendum forms part of the Lexemin Professional Services LLC Privacy Notice and Cookie Policy.