Last updated 30 July 2026
GDPR & data protection
A plain-language overview of how LexAgenda approaches personal data under the GDPR. Details live in the Privacy Policy; processor terms for firm data are covered on the DPA page. This overview is not legal advice for your firm’s compliance program.
Controller
For LexAgenda as a product (accounts, billing, support), the controller is IT Union SRL. IT Union SRL CUI: RO35358991 Str. 1 Decembrie 1918, nr. 24 Craiova, Romania legal@lexagenda.ro When your firm stores client or case personal data in LexAgenda, your firm is typically the controller for that data and LexAgenda (IT Union SRL) acts as processor — see the DPA page.
Why we process data
We process personal data to: • create and manage user accounts and organizations; • provide case management, calendar, Just sync, reminders, file storage, and related features; • keep the service secure and reliable; • send operational emails (e.g. invitations, password reset, reminders); • process subscriptions and meet billing obligations; • when configured, run product analytics and error/performance monitoring. We do not sell personal data. More detail is in the Privacy Policy.
Legal bases
Typical bases: contract performance for delivering the service; legitimate interests for security, reliability, and B2B product analytics/error monitoring when configured; legal obligation for billing/tax records; consent where we ask for optional marketing. Your firm sets its own bases for client/case data it controls.
Providers and official sources
Typical recipients fall into these categories: application hosting and infrastructure; object/file storage; transactional email delivery; payment processing when enabled; bot/abuse protection (CAPTCHA) on authentication when configured; product analytics and error/performance monitoring when configured; and optional in-app support chat when enabled. Portal JUST and related query services are official public sources used for sync; their availability and data quality are outside LexAgenda’s control — see Terms of Service §5. A current list of subprocessors is available on request to B2B DPA customers at legal@lexagenda.ro.
Retention (high level)
Account and org data while active (plus limited post-closure needs); case/client/file data for as long as your organization keeps it in the product; billing records per tax rules; logs/analytics/errors for short operational windows unless investigation requires longer. See the Privacy Policy for more.
Your rights
Subject to applicable law, you may request: • access to your personal data; • correction of inaccurate data; • erasure (“right to be forgotten”) where applicable; • restriction of processing; • data portability; • objection to certain processing; • withdrawal of consent where processing is consent-based. You may also lodge a complaint with a supervisory authority (in Romania: ANSPDCP). To exercise rights, contact legal@lexagenda.ro. Requests about a customer firm’s client/case data are handled with that firm as controller.
Privacy contact
Privacy and data-protection requests: legal@lexagenda.ro Support: support@lexagenda.ro General: office@lexagenda.ro
Disclaimer
This page is a non-binding overview. It does not create contractual obligations beyond those in the Terms, Privacy Policy, or a signed DPA, and it is not a substitute for professional legal advice.
Related