Last updated 1 August 2026

GDPR & data protection

A short overview of how LexAgenda approaches personal data under the GDPR. Details: Privacy Policy; processor terms: DPA page. Not legal advice — we do not ensure your firm’s compliance program.

Controller

For LexAgenda as a product (accounts, billing, support), the controller is IT Union SRL. IT Union SRL CUI: RO35358991 Str. 1 Decembrie 1918, nr. 24 Craiova, Romania legal@lexagenda.ro When your firm stores client or case personal data in LexAgenda, your firm is typically the controller and IT Union SRL acts as processor — see the DPA page. You remain responsible for your own controller obligations.

Why we process data

We process personal data to provide the software (accounts, case/calendar tools, Just sync, reminders, file storage where enabled), keep the service secure, send operational emails, process subscriptions, and — when configured — run analytics and error monitoring. We do not sell personal data. More detail is in the Privacy Policy.

Legal bases

Typical bases: contract performance; legitimate interests for security and reliability (and B2B analytics/error monitoring when configured); legal obligation for billing/tax records; consent for optional marketing. Your firm sets its own bases for client/case data it controls.

Providers and official sources

Typical categories: hosting/infrastructure; file storage; transactional email; payments when enabled; CAPTCHA when configured; analytics and error monitoring when configured; optional in-app chat when enabled. Portal JUST (portal.just.ro) is an official public source used for sync — not our subprocessor for your client files; availability and data quality are outside our control (Terms §5). Named subprocessors: on request at legal@lexagenda.ro.

Retention (high level)

Account/org data while active (plus limited post-closure needs); case/client/file data while your organization keeps it in the product; billing per tax rules; logs/analytics for short operational windows unless investigation requires longer. See Privacy Policy.

Your rights

Subject to applicable law: access, correction, erasure where applicable, restriction, portability, objection, withdrawal of consent where consent-based, and complaint to a supervisory authority (in Romania: ANSPDCP). Contact legal@lexagenda.ro. Requests about a customer firm’s client/case data go to that firm as controller.

Privacy contact

Privacy and data-protection requests: legal@lexagenda.ro Support: support@lexagenda.ro General: office@lexagenda.ro

Disclaimer

This page is a non-binding overview. It does not create contractual obligations beyond the Terms, Privacy Policy, or a signed DPA, and it is not professional legal advice. We do not claim ISO/SOC or similar certifications unless confirmed separately in writing.