Skip to main content
Try Lexiel for freeTry now →

Data Protection

Last updated: 28 February 2026

1. Data Subject Rights

In accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and Spain's Organic Law 3/2018 on Personal Data Protection (LOPDGDD), we inform you of your rights:

Right of Access (Art. 15 GDPR)

You have the right to obtain confirmation of whether we are processing your personal data and, if so, access to it and the following information: processing purposes, data categories, recipients, retention period, and data origin.

Right to Rectification (Art. 16 GDPR)

You have the right to have inaccurate personal data rectified and incomplete data completed.

Right to Erasure (Art. 17 GDPR)

You have the right to have your personal data deleted when: it is no longer necessary for the purposes collected, you withdraw consent, you object to processing, or it has been processed unlawfully.

Right to Restriction (Art. 18 GDPR)

You may request restriction of processing when: you contest data accuracy, processing is unlawful, Lexiel no longer needs the data but you need it for claims, or you have exercised the right to object.

Right to Portability (Art. 20 GDPR)

You have the right to receive your personal data in a structured, commonly used, machine-readable format (JSON/CSV), and to transmit it to another controller.

Right to Object (Art. 21 GDPR)

You may object to processing of your data based on legitimate interest or direct marketing purposes.

Right Against Automated Decisions (Art. 22 GDPR)

You have the right not to be subject to decisions based solely on automated processing that produce legal effects or significantly affect you. Lexiel's analyses are support tools that always require human oversight.

2. Procedure to Exercise Your Rights

How to request

Send an email to hola@lexiel.ai indicating:

  1. Your full name and registration email
  2. The right you wish to exercise
  3. A description of your request
  4. Copy of your ID document (to verify your identity)

Response times

  • General deadline: 1 month from receipt of request
  • Extension: Up to 2 additional months in complex cases (we will inform you in the first month)
  • Cost: Free, except for manifestly unfounded or excessive requests

Automatic data export

From your Lexiel settings panel, you can:

  • Download all your data in JSON format
  • Delete your account and all associated data
  • View your consent history

3. Data Protection Officer

Given the current nature and volume of data processed, Lexiel AI is not required to designate a Data Protection Officer (DPO). However, you may direct any data protection queries to: hola@lexiel.ai

4. Complaint to the AEPD

If you are not satisfied with our response or believe your rights have been violated, you may file a complaint with the Spanish Data Protection Agency:

5. Security Measures

Lexiel AI implements the following technical and organizational measures:

  • Encryption: TLS 1.3 in transit, AES-256 at rest
  • Access: Multi-factor authentication, role-based access control
  • Infrastructure: Servers in the European Union (Railway EU, PostgreSQL VPS EU)
  • Audits: Periodic security reviews
  • Breach notification: In case of a security breach, we will notify the AEPD within 72 hours and affected individuals without undue delay (Art. 33-34 GDPR)

6. Lexiel's Commitment

  • Servers in the European Union: Your information is processed and stored on European infrastructure.
  • Your data is NEVER used to train models: Neither ours nor third parties'.
  • Automatic anonymization: Before processing documents, we offer automatic removal of personal data.
  • EU AI Act alignment: We comply with the transparency, human oversight, and documentation requirements of Regulation (EU) 2024/1689.

Weekly legal updates

Legislative changes, relevant case law, and Lexiel news. No spam. Unsubscribe anytime.

GDPR compliant. We never share your email with third parties.