Last updated 30 July 2026

GDPR & data protection

A plain-language overview of how LexAgenda approaches personal data under the GDPR. Details live in the Privacy Policy; processor terms for firm data are covered on the DPA page. This overview is not legal advice for your firm’s compliance program.

Controller

For LexAgenda as a product (accounts, billing, support), the controller is IT Union SRL. IT Union SRL CUI: RO35358991 Str. 1 Decembrie 1918, nr. 24 Craiova, Romania legal@lexagenda.ro When your firm stores client or case personal data in LexAgenda, your firm is typically the controller for that data and LexAgenda (IT Union SRL) acts as processor — see the DPA page.

Why we process data

We process personal data to: • create and manage user accounts and organizations; • provide case management, calendar, Just sync, reminders, file storage, and related features; • keep the service secure and reliable; • send operational emails (e.g. invitations, password reset, reminders); • process subscriptions and meet billing obligations; • when configured, run product analytics and error/performance monitoring. We do not sell personal data. More detail is in the Privacy Policy.

Legal bases

Typical bases: contract performance for delivering the service; legitimate interests for security, reliability, and B2B product analytics/error monitoring when configured; legal obligation for billing/tax records; consent where we ask for optional marketing. Your firm sets its own bases for client/case data it controls.

Providers and official sources

Typical recipients fall into these categories: application hosting and infrastructure; object/file storage; transactional email delivery; payment processing when enabled; bot/abuse protection (CAPTCHA) on authentication when configured; product analytics and error/performance monitoring when configured; and optional in-app support chat when enabled. Portal JUST and related query services are official public sources used for sync; their availability and data quality are outside LexAgenda’s control — see Terms of Service §5. A current list of subprocessors is available on request to B2B DPA customers at legal@lexagenda.ro.

Retention (high level)

Account and org data while active (plus limited post-closure needs); case/client/file data for as long as your organization keeps it in the product; billing records per tax rules; logs/analytics/errors for short operational windows unless investigation requires longer. See the Privacy Policy for more.

Your rights

Subject to applicable law, you may request: • access to your personal data; • correction of inaccurate data; • erasure (“right to be forgotten”) where applicable; • restriction of processing; • data portability; • objection to certain processing; • withdrawal of consent where processing is consent-based. You may also lodge a complaint with a supervisory authority (in Romania: ANSPDCP). To exercise rights, contact legal@lexagenda.ro. Requests about a customer firm’s client/case data are handled with that firm as controller.

Privacy contact

Privacy and data-protection requests: legal@lexagenda.ro Support: support@lexagenda.ro General: office@lexagenda.ro

Disclaimer

This page is a non-binding overview. It does not create contractual obligations beyond those in the Terms, Privacy Policy, or a signed DPA, and it is not a substitute for professional legal advice.