Skip to main content
Try Lexiel for freeTry now →
Verified GDPR compliance

Legal AI your security department will approve

Automatic personal data anonymization, banking-grade encryption, zero-retention and full traceability. Designed for corporate legal departments.

How we protect personal data

1

Your query

D. Juan García, con DNI 12345678-A, domiciliado en C/ Mayor 42, Madrid...
2

What the AI sees

[NAME_001], con DNI [DNI_001], domiciliado en [ADDRESS_001]...
3

Your result

The claim by D. Juan García has merit under art. 1101 CC...

Verified enterprise security

Automatic anonymization of 14 PII types

GDPR Art. 32(1)(a)

DNI, NIE, CIF, IBAN, phones, emails, names, addresses, license plates, companies, courts, case numbers, SS accounts, passports. All replaced with placeholders before sending to AI.

AES-256-GCM encryption at rest, TLS in transit

GDPR Art. 32(1)(a)

Credentials encrypted with AES-256-GCM (256-bit key, 12-byte IV, 16-byte auth tag). All communications over HTTPS/TLS.

Zero-retention: your data never trains AI models

DPA + SCC

We use Anthropic (Claude) and Google (Gemini) APIs with contractual zero-retention policy. Data is not stored or used for model training.

Audit logging of every AI interaction

EU AI Act Art. 12

Every query, document analysis and brief generation is logged with timestamp, model used, tokens, latency and RAG sources. 2-year retention.

GDPR rights implemented: access, rectification, erasure

GDPR Arts. 15-22

Right to erasure with permanent conversation deletion. PDF/CSV portability. Explicit consent for AI processing with anonymization.

DPIA documented per Art. 35 GDPR

GDPR Art. 35

Data Protection Impact Assessment with risk analysis, mitigation measures, and periodic review. Legal basis: Art. 6(1)(b) contract + Art. 6(1)(a) consent.

Need 100% local processing?

For companies requiring that absolutely no data leaves their infrastructure, we offer Docu.expert: local AI with Ollama, no external API connections, everything on your company servers.

Compliance checklist for your security team

Pre-treatment anonymization by AI (pseudonymization Art. 32(1)(a) GDPR)
AES-256-GCM encryption at rest and TLS 1.3 in transit
Contractual zero-retention with AI providers (Anthropic, Google)
Complete audit logging of AI interactions (EU AI Act Art. 12)
Documented and updated DPIA (Art. 35 GDPR)
Data subject rights implemented (Arts. 15-22 GDPR)
Explicit consent for AI processing (Art. 6(1)(a) GDPR)
System prompt with personal data minimization directives
Multi-tenant isolation (org-scoped data, no cross-leakage)
On-premise alternative available (Docu.expert + Ollama)