Legal
Privacy notice
How UAB Lexoria collects, uses and protects personal data across this website, our sales and support relationships, and the administration of platform accounts.
Who we are
This notice explains how UAB Lexoria ("Lexoria", "we", "us") handles personal data when you visit this website, enquire about our services, or use the Lexoria platform as an individual user. Our registered office is Girulių g. 14, 3rd floor, LT-08312 Vilnius, Lithuania. Our company code is 305 428 116.
For questions about this notice or about how we handle personal data, contact our data protection contact at dpo@info-lex.lt or by post at the address above, marked for the attention of the Data Protection contact.
Two different roles. Where a customer organisation uses the Lexoria platform, the content they place in it — their client and matter records — is controlled by that organisation. For that content, the customer is the controller and Lexoria acts as a processor under our data processing agreement. This notice describes the processing for which Lexoria itself is the controller: our website, our sales and support relationships, and the administration of user accounts.
The data we process
Depending on how you interact with us, we process the following categories of personal data:
- Contact and enquiry data — name, organisation, email, telephone number, and the content of messages you send us.
- Account data — the name, work email and role of individual users provisioned on the platform, and authentication data such as hashed credentials and two-factor settings.
- Usage and technical data — records of how the service is used for security, troubleshooting and improvement, together with IP address, browser type and similar technical information.
- Support data — correspondence and records relating to support requests.
- Billing data — the information needed to invoice a customer and record payment. We do not store full card details; payment is handled by a payment processor.
We do not seek to collect special categories of personal data through this website or in the administration of accounts. Please do not send us such data in an enquiry.
How we collect it
We collect personal data directly from you when you contact us, request a demonstration, correspond with our team, or are set up as a user by your organisation. We also collect technical data automatically when you use the website or the platform, as described in the section on cookies below.
Where your organisation provisions you as a user, we receive your account data from that organisation.
Why we process it, and our lawful basis
We process personal data for the following purposes, relying on the lawful bases indicated:
- Responding to enquiries and providing demonstrations — on the basis of taking steps at your request prior to entering a contract, or our legitimate interest in responding to business enquiries.
- Providing and administering the platform — on the basis of performance of our contract with your organisation, and our legitimate interest in operating and securing the service.
- Support, security and service improvement — on the basis of our legitimate interests in providing a reliable, secure service, balanced against your interests and rights.
- Billing and record-keeping — on the basis of performance of a contract and compliance with our legal obligations, including accounting and tax law.
- Marketing communications — where you have asked to receive them, on the basis of your consent, which you may withdraw at any time.
Where we rely on legitimate interests, we have carried out a balancing assessment and will provide further information on request.
Who we share it with
We share personal data only where necessary, and subject to appropriate safeguards:
- Service providers (processors) acting on our instructions — including cloud infrastructure, transactional email, error monitoring, support tooling and payment processing. A current list of the categories of sub-processor used for the platform is maintained on our security page.
- Professional advisers such as auditors and lawyers, where necessary and subject to confidentiality.
- Authorities, where we are required to disclose information by law.
- A successor in the context of a merger, acquisition or reorganisation, subject to this notice.
We do not sell personal data, and we do not use customer content to train machine learning models.
International transfers
Lexoria hosts and processes data within the European Union. Where a service provider's support function could involve access to personal data from outside the European Economic Area, we put in place an appropriate transfer mechanism, such as the European Commission's standard contractual clauses, together with supplementary measures where required. You can ask us for further detail about the safeguards applying to a particular transfer.
How long we keep it
We keep personal data only for as long as necessary for the purpose for which it was collected, and to meet legal, accounting and reporting requirements.
- Enquiry data — retained for up to 24 months after the last contact, unless a relationship develops.
- Account data — retained for the duration of the customer relationship and deleted or returned in line with the data processing agreement after it ends.
- Billing records — retained for the period required by applicable accounting and tax law.
- Support correspondence — retained for up to 36 months.
When personal data is no longer required, we delete it or irreversibly anonymise it.
Your rights
Subject to the conditions in applicable data protection law, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have data erased in certain circumstances;
- restrict or object to certain processing;
- receive certain data in a portable format;
- withdraw consent at any time, where we rely on consent; and
- lodge a complaint with a supervisory authority.
To exercise any of these rights, contact dpo@info-lex.lt. We will respond within the period required by law. If your data is held in the platform under your organisation's control, we may direct your request to that organisation as the controller.
The supervisory authority in our jurisdiction is the State Data Protection Inspectorate of the Republic of Lithuania. You may also complain to the authority in your country of residence or work.
Cookies and similar technologies
This website uses only what is necessary to function and to load its appearance. It does not set advertising cookies and does not embed third-party analytics or social media trackers. Fonts and the styling framework are loaded from content delivery networks in order to display the site; those providers may process technical connection data as independent controllers for the purpose of delivering the requested resources.
The Lexoria platform uses strictly necessary cookies to keep you signed in and to maintain security. Where any non-essential cookies are introduced, we will ask for consent first.
Security
We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls, logging and a documented incident response process. Our information security management system is certified to ISO/IEC 27001:2022. Further detail is available on our security page.
Changes to this notice
We may update this notice from time to time. Where changes are material, we will take reasonable steps to bring them to your attention. The version below indicates when this notice was last updated.
Effective date: 1 June 2026. Version: 2026-06-01.