Skip to main content
Try Lexiel for freeTry now →

Data Processing Agreement (DPA)

Last updated: 5 August 2026

1. Purpose

This Data Processing Agreement (hereinafter "DPA") supplements the Lexiel AI Terms of Service and applies to the processing of personal data that Lexiel performs on behalf of the professional user (the "Data Controller") in the context of providing the service.

This DPA is entered into in compliance with Article 28 of Regulation (EU) 2016/679 (GDPR) and Article 33 of Organic Law 3/2018 (LOPDGDD).

2. Definitions

  • Controller: The lawyer or law firm using Lexiel who determines the purposes of processing their clients' data.
  • Processor: Lexiel AI, which processes data on behalf of the Controller.
  • Personal Data: Any information that identifies or may identify a natural person, including data contained in legal documents uploaded to the platform.
  • Sub-processor: Third parties processing data on behalf of Lexiel (see section 6).

3. Purpose and Duration of Processing

Lexiel processes personal data exclusively for:

  • Analyzing legal documents uploaded by the Controller
  • Processing legal queries via AI
  • Verifying legal citations and references
  • Generating legal briefs and documents

The duration of processing coincides with the subscription term. Upon termination, data is deleted in accordance with the Terms of Service (maximum 90 days after cancellation).

4. Lexiel's Obligations as Processor

Lexiel undertakes to:

a) Process data only according to the Controller's documented instructions b) Ensure that authorized persons have committed to confidentiality c) Implement appropriate technical and organizational measures (Art. 32 GDPR):

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Role-based access control (RBAC)
  • Data isolation per organization (multi-tenant with segregation)
  • Access logs and periodic audits d) Not engage another processor without the Controller's prior authorization e) Assist the Controller in fulfilling obligations (data subject rights, DPIA, breach notification) f) Delete or return data upon termination of the service g) Make available to the Controller all information necessary to demonstrate compliance

5. Security Breach Notification

In the event of a security breach affecting personal data processed on behalf of the Controller:

  1. Lexiel will notify the Controller without undue delay and within 48 hours of detection
  2. The notification will include: nature of the breach, data affected, measures taken, recommendations
  3. Lexiel will cooperate with the Controller to enable compliance with notification obligations to the AEPD (72 hours) and data subjects (Art. 33-34 GDPR)

6. Sub-processors

Lexiel uses the following sub-processors:

Sub-processorPurposeLocationSafeguards
Hetzner Online GmbHInfrastructure (dedicated server)EU (Germany)Self-hosted infrastructure
codelabs.studioPostgreSQL database (VPS)EUSelf-hosted infrastructure
AnthropicAI processing (Claude)USASCCs (Decision 2021/914)
Google (Gemini API)AI processing and embeddingsUSASCCs (Decision 2021/914)
GroqAI processing and audio transcriptionUSASCCs (Decision 2021/914)
CerebrasAI processing (fallback)USASCCs (Decision 2021/914)
OpenRouterAI model routing (fallback)USASCCs (Decision 2021/914)
Hume AIConversational voice for the mobile app assistant (user audio)USASCCs (Decision 2021/914)
SignaturitElectronic signature of documents (briefs, contracts, signer data)EU (Spain)eIDAS qualified trust service provider
Cloudflare R2Document storageEUAdequacy decisions
StripePayment processingUSA/EUSCCs, SOC 2 certification
Mailcow (mail.codelabs.studio)Transactional emails (self-hosted SMTP, primary provider)EU (Germany)Self-hosted infrastructure
ResendTransactional emails (fallback provider)USASCCs

The Controller expressly authorizes the listed sub-processors. Lexiel will inform the Controller 30 days in advance before engaging new sub-processors, granting the Controller the opportunity to object.

7. International Transfers

Data transfers outside the EEA are carried out exclusively under:

  • Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914)
  • Adequacy decisions where applicable

8. Audit Rights

The Controller has the right to verify compliance with this DPA through:

  • Requesting information about technical and organizational measures
  • On-site or remote audit, with 30 days' notice (maximum once per year, unless justified)
  • Review of certifications and third-party audit results

9. Amendments

This DPA may be updated to reflect regulatory changes or changes to sub-processors. Material changes will be notified 30 days in advance.

10. Contact

For any questions regarding this DPA:

  • Email: hola@lexiel.ai
  • Address: Paseo Federico García Lorca, 6, 3º E, 29130 Alhaurín de la Torre (Málaga), Spain

Weekly legal updates

Legislative changes, relevant case law, and Lexiel news. No spam. Unsubscribe anytime.

GDPR compliant. We never share your email with third parties.