Last updated 30 August 2026

Privacy Policy

This policy explains how IT Union SRL handles personal data when you use LexAgenda. It is written for practical transparency (GDPR Art. 13 essentials) and is not legal advice for your firm. LexAgenda does not run your firm’s compliance program. See also the GDPR overview and DPA pages.

1. Controller

IT Union SRL CUI: RO35358991 Str. 1 Decembrie 1918, nr. 24 Craiova, Romania legal@lexagenda.ro

2. Data we process

Account details (name, email), organization and membership data, case and client records you enter, uploaded files, usage and security logs, billing-related identifiers when you subscribe, analytics and diagnostic events when those tools are configured, and support messages you send us (email or in-app chat when enabled).

3. Why we process data

To provide and operate the product, keep accounts secure, sync with services you use (such as Portal JUST), store case files, send operational emails (invitations, password reset, reminders), process subscriptions, diagnose errors, understand product usage (when analytics are enabled), and improve reliability. We do not sell personal data.

4. Legal bases

Depending on the processing, we rely on: • performance of a contract (Art. 6(1)(b)) — providing LexAgenda accounts, organizations, and subscribed features; • legitimate interests (Art. 6(1)(f)) — securing the service, preventing abuse, improving reliability, and (when configured) product analytics and error monitoring in a B2B context, balanced against your rights; • legal obligation (Art. 6(1)(c)) — e.g. tax and accounting records related to invoices; • consent (Art. 6(1)(a)) — where we ask for it (e.g. optional marketing emails), which you may withdraw at any time. When your firm stores client or case personal data in LexAgenda, your firm is typically the controller for that data and determines its own legal bases; we process it as processor — see the DPA page.

5. Recipients / service providers

We use selected providers to run LexAgenda. Depending on configuration, recipients may include: • application hosting, database and egress to the courts portal — EU-based VPS provider; • object/file storage for case files — Cloudflare R2; • transactional email delivery — Resend; • payment processing when you subscribe — Stripe; • bot/abuse protection (CAPTCHA) on authentication, the public demo and the public case lookup — Cloudflare Turnstile; • product analytics — PostHog, processed in the EU. In the browser it loads only if you accept in the cookie banner. Separately, a few product events from inside your account (firm created, trial started, subscribed) are recorded without cookies, on legitimate interest, so we know whether the product works; • error/performance monitoring, when configured — Sentry; • ad measurement, when we run campaigns and only with your agreement — Google Ads (Consent Mode: without agreement the signal carries no identifiers); • SMS / WhatsApp alerts, if you enable that add-on — Twilio; • optional in-app support chat, when enabled — Crisp; • invoicing and e-Factura, depending on what you connect — Oblio, SmartBill, or ANAF (SPV) directly. Portal JUST (portal.just.ro) is a public official source we query for court data; it is not our subprocessor for your firm’s client files, but sync features depend on its availability and accuracy. Providers process data only as needed to deliver their service. The list above is the current one; we will tell you before adding a new provider that processes personal data. For processor vs controller roles on client/case data, see the DPA page.

6. Retention

We keep personal data only as long as needed for the purposes above: • account and organization data — while the account/organization is active, then for a limited period needed for security, dispute handling, and legal obligations; • case, client, and file data you store — for as long as your organization retains it in LexAgenda (your firm controls deletion/export within the product), subject to backup cycles; • billing and invoice records — as required by tax and accounting rules; • logs, analytics, and error reports — for short operational windows unless a longer period is needed to investigate incidents. Exact periods can vary by record type; contact legal@lexagenda.ro for questions about a specific dataset.

7. Cookies

We use essential cookies for session and security (including bot/abuse protection when configured), preference storage (language, theme, cookie-notice dismissal), and — when enabled — product analytics and error/performance monitoring. See the Cookie Policy for details. Optional chat tools may set their own cookies when enabled.

8. Your rights

Under the GDPR you may request access, correction, deletion, restriction, portability, or objection, and withdraw consent where processing is consent-based. You have the right to lodge a complaint with a supervisory authority (in Romania: ANSPDCP). To exercise these rights, contact legal@lexagenda.ro. See the GDPR overview page. If your request concerns client or case data stored by a customer firm, we will direct you to that firm as controller where appropriate.

9. Contact

IT Union SRL CUI: RO35358991 Privacy: legal@lexagenda.ro Support: support@lexagenda.ro General: office@lexagenda.ro