Privacy Policy
LexVera provides a source-grounded legal AI workspace for research, drafting, document analysis, document chat, and firm knowledge workflows. This policy explains how we handle personal data and professional content when you visit our website or use the LexVera service.
This policy explains LexVera's standard privacy approach. A signed customer agreement or data processing agreement may include additional terms for a particular organisation.
Professional content is protected
Legal queries, uploaded documents, matter context, generated outputs, and related metadata are handled as customer content.
Customers control matter data
For most product use, the law firm or organisation decides what matter data is submitted and why.
AI workflows are purpose-limited
We process content to provide requested workflows, secure the service, support users, and meet legal obligations.
Rights requests are supported
Access, deletion, correction, export, restriction, and objection requests can be sent to [email protected].
1. Who this policy applies to
This policy applies to website visitors, account holders, trial users, customer administrators, invited users, support contacts, and people whose personal data appears in documents, prompts, matter context, research queries, or generated outputs submitted by an authorised user.
2. Our role and the customer's role
LexVera B.V. provides the LexVera service. For website operation, account administration, security, billing, product communications, support, and our own legal obligations, LexVera may act as controller. For most product workflows, the customer or law firm is the controller of client files, matter data, uploaded documents, legal research content, and user instructions. LexVera generally acts as processor or service provider for that customer.
Privacy questions can be sent to [email protected]. LexVera's data protection contact can be reached at [email protected]. A signed customer agreement, order form, or data processing agreement may identify the contracting entity, customer contacts, processing instructions, sub-processor terms, and service-specific safeguards for a particular organisation.
3. Data we process
Depending on how LexVera is used, we may process:
- Account and identity data: name, email address, organisation, role, language preference, account status, invitation details, and authentication settings.
- Security and access data: login events, session metadata, IP address, user agent, audit events, rate-limit events, and security diagnostics.
- Professional content: legal research queries, prompts, messages, generated responses, citations, user annotations, matter context, drafting instructions, document questions, and precedent-search inputs.
- Uploaded documents and derived data: file names, document metadata, extracted text, document classifications, search indexes, embeddings, summaries, storage references, and ownership or access metadata.
- Organisation and matter data: team settings, role assignments, matter access settings, ethical-wall records, document collections, retention settings, and administrator actions.
- Operational data: service logs, performance metrics, error diagnostics, backup metadata, provider usage metadata, and support correspondence.
- Commercial data: subscription status, invoices, usage tier, payment metadata, and customer communications where billing is enabled.
- Website data: basic request logs and messages sent through email links or contact channels. The public landing site does not require advertising trackers.
We receive data directly from users, from customer administrators or other authorised users, from documents and matter materials submitted to LexVera, and from systems that record security, audit, billing, or operational events. Some account, authentication, and security data is required to provide the service; without it, account access, requested workflows, support, billing, or security controls may not be available.
4. Why we process data
We process data to provide, secure, maintain, and improve LexVera. This includes:
- Creating accounts, authenticating users, managing sessions, and enforcing account security.
- Providing legal research, drafting, quick advice, document analysis, document chat, meeting preparation, and precedent-search workflows.
- Uploading, storing, extracting, indexing, retrieving, displaying, exporting, and deleting documents and derived data.
- Enforcing access controls, tenant separation, role assignments, ethical walls, audit logging, and abuse prevention.
- Maintaining service reliability, backups, incident response, diagnostics, support, billing, and legal compliance.
- Improving retrieval quality, safety, and product reliability using aggregated, minimised, or customer-approved data where appropriate.
5. Legal bases
Where GDPR or similar laws apply, legal bases may include contract performance, legitimate interests, consent, legal obligations, and the establishment, exercise, or defence of legal claims. The exact basis depends on the relationship, the customer instructions, and the processing activity.
Where processing relies on consent, consent may be withdrawn at any time without affecting processing that occurred before withdrawal. Where processing relies on legitimate interests, LexVera balances the interest pursued against the rights and freedoms of affected individuals.
6. AI and third-party processing
Some workflows may use carefully selected AI, OCR, embedding, search, email, storage, hosting, security, observability, or support providers. When a user runs a workflow, relevant prompts, retrieved source excerpts, document text, metadata, or generated outputs may be processed by those providers where necessary to provide the requested service.
We aim to minimise the data sent, use secure transport, apply contractual safeguards, and keep professional review and source verification central to the workflow. Customers handling highly sensitive or privileged materials should ensure their policies, client instructions, provider settings, and customer agreements permit the intended processing.
LexVera is designed for human professional review. The service is not intended to make solely automated decisions that produce legal or similarly significant effects for individuals. Customers remain responsible for deciding whether and how AI-assisted outputs are used in a matter.
7. Documents, embeddings, and search data
Uploaded documents may be stored, extracted, indexed, searched, summarized, or converted into embeddings so users can analyse and retrieve content. Embeddings and extracted text can still be sensitive because they are derived from professional content. We treat them as protected customer data and apply access, retention, and deletion controls according to the service configuration and applicable agreement.
8. Security controls
LexVera is designed with layered security controls, including encrypted transport, account authentication, multi-factor authentication support, role-based access control, organisation separation, ethical-wall enforcement, audit logging, input validation, rate limiting, backups, monitoring, and restricted service access. No technical measure is perfect, so we continue to review and improve safeguards as the product and threat landscape evolve.
9. Retention and deletion
Retention depends on the customer agreement, account status, matter requirements, legal obligations, backup schedules, and selected retention settings. Some data may be retained for security, audit, legal, accounting, dispute-resolution, or professional-record reasons. Deletion may cover original documents, extracted text, search data, generated exports, and account data, subject to legal holds, audit requirements, and backup handling.
10. Cookies and local storage
The LexVera application uses authentication and session mechanisms necessary to keep users signed in and protect accounts. Browser storage may also be used to support product functionality. The public landing site is static and does not require advertising cookies. If optional analytics or marketing cookies are introduced, LexVera will use consent controls where required.
11. International transfers
LexVera is intended for European legal workflows, but some providers or support processes may involve processing outside the EEA. Where required, we rely on appropriate safeguards such as EU Standard Contractual Clauses, data processing agreements, regional processing options, or equivalent mechanisms. Information about applicable safeguards may be requested via [email protected].
12. Your rights
Depending on your jurisdiction and role, you may have rights to be informed, access personal data, receive a copy, correct inaccurate data, delete data, restrict processing, object to processing, receive portable data, withdraw consent where consent is the basis, and avoid solely automated decisions where the law provides that right. If your data was submitted by a customer, we may need to refer the request to that customer as controller or consult that customer before acting. To exercise rights, contact [email protected]. We may need to verify identity and authority before responding.
You may also lodge a complaint with a competent data protection authority. For LexVera B.V. in the Netherlands, this is the Autoriteit Persoonsgegevens. You may also contact the authority in your own EU or EEA member state where applicable.
13. Confidentiality and professional obligations
Legal professionals remain responsible for determining whether particular client materials may be submitted to LexVera and whether AI-assisted workflows are appropriate for a matter. Customer policies, bar rules, client instructions, court rules, and matter-specific restrictions may require stricter controls than the default service configuration.
14. Changes to this policy
We may update this policy as LexVera, applicable law, providers, or operational practices change. Material changes will be reflected on this page and, where appropriate, communicated through the product or customer channels.
15. Contact
Privacy requests:
[email protected]
Data protection contact:
[email protected]
Security reports:
[email protected]
General contact:
[email protected]