Last updated 30 July 2026

Privacy Policy

This policy explains how IT Union SRL handles personal data when you use LexAgenda. It is written for practical transparency (GDPR Art. 13 essentials) and is not a substitute for legal advice tailored to your firm. See also the GDPR overview and DPA pages.

1. Controller

IT Union SRL CUI: RO35358991 Str. 1 Decembrie 1918, nr. 24 Craiova, Romania legal@lexagenda.ro

2. Data we process

Account details (name, email), organization and membership data, case and client records you enter, uploaded files, usage and security logs, billing-related identifiers when you subscribe, analytics and diagnostic events when those tools are configured, and support messages you send us (email or in-app chat when enabled).

3. Why we process data

To provide and operate the product, keep accounts secure, sync with services you use (such as Portal JUST), store case files, send operational emails (invitations, password reset, reminders), process subscriptions, diagnose errors, understand product usage (when analytics are enabled), and improve reliability. We do not sell personal data.

4. Legal bases

Depending on the processing, we rely on: • performance of a contract (Art. 6(1)(b)) — providing LexAgenda accounts, organizations, and subscribed features; • legitimate interests (Art. 6(1)(f)) — securing the service, preventing abuse, improving reliability, and (when configured) product analytics and error monitoring in a B2B context, balanced against your rights; • legal obligation (Art. 6(1)(c)) — e.g. tax and accounting records related to invoices; • consent (Art. 6(1)(a)) — where we ask for it (e.g. optional marketing emails), which you may withdraw at any time. When your firm stores client or case personal data in LexAgenda, your firm is typically the controller for that data and determines its own legal bases; we process it as processor — see the DPA page.

5. Recipients / service providers

We use selected providers to run LexAgenda. Depending on configuration, recipients may include providers in these categories: • application hosting and infrastructure (including database hosting); • object/file storage for case files; • transactional email delivery; • payment processing when you subscribe; • bot/abuse protection (CAPTCHA) on authentication flows when configured; • product analytics when configured (we prefer EU/EEA processing where available); • error/performance monitoring when configured; • optional in-app support chat when enabled for your deployment. Portal JUST / portalquery.just.ro is a public official source we query for court data; it is not our subprocessor for your firm’s client files, but sync features depend on its availability and accuracy. Providers process data only as needed to deliver their service. A current list of subprocessors is available on request to B2B DPA customers at legal@lexagenda.ro. For processor vs controller roles on client/case data, see the DPA page.

6. Retention

We keep personal data only as long as needed for the purposes above: • account and organization data — while the account/organization is active, then for a limited period needed for security, dispute handling, and legal obligations; • case, client, and file data you store — for as long as your organization retains it in LexAgenda (your firm controls deletion/export within the product), subject to backup cycles; • billing and invoice records — as required by tax and accounting rules; • logs, analytics, and error reports — for short operational windows unless a longer period is needed to investigate incidents. Exact periods can vary by record type; contact legal@lexagenda.ro for questions about a specific dataset.

7. Cookies

We use essential cookies for session and security (including bot/abuse protection when configured), preference storage (language, theme, cookie-notice dismissal), and — when enabled — product analytics and error/performance monitoring. See the Cookie Policy for details. Optional chat tools may set their own cookies when enabled.

8. Your rights

Under the GDPR you may request access, correction, deletion, restriction, portability, or objection, and withdraw consent where processing is consent-based. Contact legal@lexagenda.ro. You may also lodge a complaint with a supervisory authority (in Romania, ANSPDCP). See the GDPR overview page. If your request concerns client or case data stored by a customer firm, we will direct you to that firm as controller where appropriate.

9. Contact

IT Union SRL CUI: RO35358991 Privacy: legal@lexagenda.ro Support: support@lexagenda.ro General: office@lexagenda.ro