Privacy Policy

1. Data Controller Identification
The data controller responsible for processing personal data on https://openltx.com (the “Platform”) is DCX TRADE s.r.o., a company incorporated under the laws of the Czech Republic, with its registered office at Lidická 700/19, Veveří, 602 00 Brno, Czech Republic, Company Identification Number (IČ): 06368247, registered in the Commercial Register maintained by the Regional Court in Brno, File No. C 101692 (the “Operator”).

2. OpenLTX Platform Nature
OpenLTX is an independent community-driven knowledge hub and cloud platform focused on AI video generation technologies, workflows, documentation and experimentation. OpenLTX is not affiliated with, endorsed by, or operated by Lightricks or any other developer of LTX-related technologies.

3. Contact Information
For questions, requests or concerns regarding personal data processing, users may contact the Operator via email at info@openltx.com. For official communications from public authorities within the Czech Republic, the Operator uses its legally recognized Data Box communication channel.

4. Data Protection Officer
The Operator has not appointed a Data Protection Officer, as such appointment is not required under Article 37 GDPR. The Operator has designated a contact point for privacy-related matters.

5. Legal Basis for Processing
Personal data is processed in accordance with the General Data Protection Regulation (GDPR) and applicable Czech legislation. Processing may be based on contractual necessity, legitimate interests of the Operator, user consent, and legal obligations.

1. Account Registration and Management
When users create an account on the Platform, the Operator may process information such as email address, username, encrypted password data and account-related information. This data is used to create, maintain and secure user accounts.

2. Platform Services and AI Workflows
To provide access to OpenLTX features, including workflow execution, cloud environments and AI video generation tools, the Operator may process account information, technical information, usage records and related service metadata.

3. Cloud GPU Infrastructure Usage
When users launch or use cloud-based computing environments, technical information related to resource usage, sessions, configurations and operational activities may be processed to provide and maintain the service.

4. Payments and Transactions
If paid services are provided, the Operator may process transaction information, payment records and billing-related data necessary for payment processing, accounting and compliance with legal obligations.

5. Platform Security and Fraud Prevention
The Operator may process technical information, login activity, usage patterns and security-related data to protect the Platform, prevent abuse, detect unauthorized access and maintain system integrity.

6. Analytics and Improvement
Usage information, technical data and interaction statistics may be processed to analyze Platform performance, improve workflows, optimize user experience and develop new features.

7. Communication and Support
Personal data provided through emails, support requests or other communication channels may be processed to respond to inquiries, provide assistance and maintain service communication.

8. Categories of Personal Data
The Operator may process account information, contact information, technical data, device information, IP addresses, usage data, payment-related information and communication records.

1. Data Recipients
Personal data may be shared with trusted service providers necessary for operating the Platform, including hosting providers, cloud infrastructure providers, payment processors, analytics providers, email services and technical partners.

2. Third-Party Services
Some Platform functions may rely on third-party services. These providers process data according to their own privacy policies and applicable agreements. Where required, appropriate GDPR safeguards are applied.

3. Data Retention
Personal data is retained only for the period necessary to provide services, maintain accounts, comply with legal obligations, resolve disputes and protect the security of the Platform.

4. Data Security
The Operator applies reasonable technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration or disclosure.

5. User Rights Under GDPR
Users have rights including access, rectification, deletion, restriction of processing, data portability, objection to processing and withdrawal of consent where applicable.

6. Exercising Data Rights
Users may exercise their GDPR rights by contacting the Operator through the official contact email. The Operator may request identity verification to protect user data and prevent unauthorized requests.

7. Complaints
Users have the right to lodge a complaint with the competent data protection supervisory authority, including the Czech Office for Personal Data Protection, if they believe their rights have been violated.

8. Effective Date
This Privacy Policy is effective as of 29 July 2026. The Operator may update this Privacy Policy when necessary due to legal, technical or operational changes.