LexFlow← Back to dashboard
πŸ“„ Legal document

Privacy Policy

Last updated: May 29, 2026

GDPR compliant (Regulation EU 2016/679)

Contents

  1. 1. Data controller
  2. 2. Data collected
  3. 3. Purpose and legal basis
  4. 4. Data retention
  5. 5. Third parties and sub-processors
  6. 6. International transfers
  7. 7. Your rights (GDPR)
  8. 8. Cookies
  9. 9. Security
  10. 10. Contact and DPO

1Data controller

The data controller for your personal data is LexFlow, a legal contract platform for European freelancers, operated in accordance with the laws of the European Union.

Contact email: privacy@lexflow.eu

Platform: https://lexflow.eu

2Data collected

We collect the following personal data:

CategoryDataSource
IdentityFull name, email addressProvided by user at registration
ContractsParty names, values, project description, country, contract typeProvided when creating contracts
PaymentSubscription history, plan status (we do not store card data)Processed by Stripe
TechnicalIP address, browser, operating system, pages visitedAutomatic β€” cookies and access logs
E-signatureRecipient client email and nameProvided by user when sending contracts

3Purpose and legal basis

PurposeLegal basis (GDPR Art. 6)
Provision of the LexFlow service (contract generation)Performance of contract β€” Art. 6(1)(b)
Subscription management and billingPerformance of contract β€” Art. 6(1)(b)
E-signature and automatic remindersPerformance of contract β€” Art. 6(1)(b)
Service communications (transactional emails)Legitimate interest β€” Art. 6(1)(f)
Compliance with legal obligationsLegal obligation β€” Art. 6(1)(c)
Analytics and product improvementConsent β€” Art. 6(1)(a)

4Data retention

CategoryRetention period
Account dataUntil account deletion + 30 days
Generated contractsWhile account is active; accessible after cancellation
Billing records7 years (EU tax obligation)
Technical access logs90 days
Electronic signature data5 years (legal evidence)

5Third parties and sub-processors

We share data only with the following sub-processors, all operating under GDPR agreements:

ServicePurposeData location
SupabaseDatabase and authenticationπŸ‡ͺπŸ‡Ί European Union (eu-west-1, Ireland)
VercelHosting and infrastructureπŸ‡ΊπŸ‡Έ USA β€” covered by SCCs
StripePayment processingπŸ‡ΊπŸ‡Έ/πŸ‡ͺπŸ‡Ί USA + EU β€” covered by SCCs
YousignElectronic signatureπŸ‡«πŸ‡· France (European company)
ResendTransactional email deliveryπŸ‡ΊπŸ‡Έ USA β€” covered by SCCs

We do not sell, rent or share personal data for third-party commercial purposes.

6International transfers

Your primary account and contract data is stored on Supabase servers in the eu-west-1 region (Ireland), within the European Union.

For services with servers in the USA (Vercel, Stripe, Resend), we ensure adequate protection through Standard Contractual Clauses (SCCs) approved by the European Commission, pursuant to Article 46 of the GDPR.

7Your rights (GDPR)

Under the GDPR, you have the following rights:

  • βœ“Access β€” Request a copy of all data we hold about you
  • βœ“Rectification β€” Correct inaccurate or incomplete data
  • βœ“Erasure β€” Request deletion of your data ("right to be forgotten")
  • βœ“Restriction β€” Restrict processing of your data in certain circumstances
  • βœ“Portability β€” Receive your data in a structured, machine-readable format
  • βœ“Objection β€” Object to processing based on legitimate interest
  • βœ“Withdrawal of consent β€” Withdraw consent at any time without affecting prior processing

To exercise any right, contact: privacy@lexflow.eu. We will respond within 30 days.

You also have the right to lodge a complaint with your national supervisory authority (e.g. CNIL in France, BfDI in Germany, ICO in Ireland, AEPD in Spain).

8Cookies

CookiePurposeDuration
sb-* (Supabase)Authentication session β€” essentialSession / 1 week
lexflow_cookie_consentStore cookie preference β€” essentialPermanent (localStorage)
Analytics (future)Product improvement β€” consent only30 days

You can manage your cookie preferences at any time via the banner that appears on your first visit.

9Security

We implement appropriate technical and organisational measures to protect your data:

  • βœ“Data transmission via HTTPS/TLS
  • βœ“Row Level Security (RLS) in the database β€” each user accesses only their own data
  • βœ“API keys stored as encrypted environment variables
  • βœ“Authentication via Supabase Auth with secure sessions
  • βœ“Database servers in the EU with no direct public access

10Contact and DPO

For privacy questions, exercising rights or complaints, contact our data protection officer:

πŸ“§
Privacy emailprivacy@lexflow.eu

This policy may be updated periodically. Users will be notified by email in the event of material changes.

LexFlowGDPR Compliant Β· Servers in EU
Privacy PolicyTerms of ServicePricing

Β© 2026 LexFlow. All rights reserved.