1. Purpose
This Data Processing Agreement (hereinafter "DPA") supplements the Lexiel AI Terms of Service and applies to the processing of personal data that Lexiel performs on behalf of the professional user (the "Data Controller") in the context of providing the service.
This DPA is entered into in compliance with Article 28 of Regulation (EU) 2016/679 (GDPR) and Article 33 of Organic Law 3/2018 (LOPDGDD).
2. Definitions
- Controller: The lawyer or law firm using Lexiel who determines the purposes of processing their clients' data.
- Processor: Lexiel AI, which processes data on behalf of the Controller.
- Personal Data: Any information that identifies or may identify a natural person, including data contained in legal documents uploaded to the platform.
- Sub-processor: Third parties processing data on behalf of Lexiel (see section 6).
3. Purpose and Duration of Processing
Lexiel processes personal data exclusively for:
- Analyzing legal documents uploaded by the Controller
- Processing legal queries via AI
- Verifying legal citations and references
- Generating legal briefs and documents
The duration of processing coincides with the subscription term. Upon termination, data is deleted in accordance with the Terms of Service (maximum 90 days after cancellation).
4. Lexiel's Obligations as Processor
Lexiel undertakes to:
a) Process data only according to the Controller's documented instructions b) Ensure that authorized persons have committed to confidentiality c) Implement appropriate technical and organizational measures (Art. 32 GDPR):
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Role-based access control (RBAC)
- Data isolation per organization (multi-tenant with segregation)
- Access logs and periodic audits d) Not engage another processor without the Controller's prior authorization e) Assist the Controller in fulfilling obligations (data subject rights, DPIA, breach notification) f) Delete or return data upon termination of the service g) Make available to the Controller all information necessary to demonstrate compliance
5. Security Breach Notification
In the event of a security breach affecting personal data processed on behalf of the Controller:
- Lexiel will notify the Controller without undue delay and within 48 hours of detection
- The notification will include: nature of the breach, data affected, measures taken, recommendations
- Lexiel will cooperate with the Controller to enable compliance with notification obligations to the AEPD (72 hours) and data subjects (Art. 33-34 GDPR)
6. Sub-processors
Lexiel uses the following sub-processors:
| Sub-processor | Purpose | Location | Safeguards |
|---|---|---|---|
| Hetzner Online GmbH | Infrastructure (dedicated server) | EU (Germany) | Self-hosted infrastructure |
| codelabs.studio | PostgreSQL database (VPS) | EU | Self-hosted infrastructure |
| Anthropic | AI processing (Claude) | USA | SCCs (Decision 2021/914) |
| Google (Gemini API) | AI processing and embeddings | USA | SCCs (Decision 2021/914) |
| Groq | AI processing and audio transcription | USA | SCCs (Decision 2021/914) |
| Cerebras | AI processing (fallback) | USA | SCCs (Decision 2021/914) |
| OpenRouter | AI model routing (fallback) | USA | SCCs (Decision 2021/914) |
| Hume AI | Conversational voice for the mobile app assistant (user audio) | USA | SCCs (Decision 2021/914) |
| Signaturit | Electronic signature of documents (briefs, contracts, signer data) | EU (Spain) | eIDAS qualified trust service provider |
| Cloudflare R2 | Document storage | EU | Adequacy decisions |
| Stripe | Payment processing | USA/EU | SCCs, SOC 2 certification |
| Mailcow (mail.codelabs.studio) | Transactional emails (self-hosted SMTP, primary provider) | EU (Germany) | Self-hosted infrastructure |
| Resend | Transactional emails (fallback provider) | USA | SCCs |
The Controller expressly authorizes the listed sub-processors. Lexiel will inform the Controller 30 days in advance before engaging new sub-processors, granting the Controller the opportunity to object.
7. International Transfers
Data transfers outside the EEA are carried out exclusively under:
- Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914)
- Adequacy decisions where applicable
8. Audit Rights
The Controller has the right to verify compliance with this DPA through:
- Requesting information about technical and organizational measures
- On-site or remote audit, with 30 days' notice (maximum once per year, unless justified)
- Review of certifications and third-party audit results
9. Amendments
This DPA may be updated to reflect regulatory changes or changes to sub-processors. Material changes will be notified 30 days in advance.
10. Contact
For any questions regarding this DPA:
- Email: hola@lexiel.ai
- Address: Paseo Federico García Lorca, 6, 3º E, 29130 Alhaurín de la Torre (Málaga), Spain