1. Data Controller
The entity responsible for data collection and processing is:
LexLogik UG (haftungsbeschränkt)Mahlgasse 4
88339 Bad Waldsee
Germany
Managing Director: Jonas Maximilian RegulEmail: info@lexlogik.comVAT ID: DE460852323
2. Collection and Storage of Personal Data
When you access our website, your browser automatically sends information to our website server (log files).
- Information: IP address, date/time, accessed file, referrer URL, browser type/operating system.
- Purpose: Ensuring a smooth connection, system security, and administration.
- Legal Basis: Art. 6 (1) (f) GDPR (legitimate interest).
3. Cloudflare (Security & Performance)
We use services from Cloudflare, Inc. (USA/EU) to protect our infrastructure against bot attacks (DDoS) and to optimize website loading times.
- Important: Cloudflare is only used for the delivery of the web interface. Documents uploaded for processing are transmitted directly to our servers in Germany and do not pass through Cloudflare's infrastructure.
- Legal Basis: Art. 6 (1) (f) GDPR (IT infrastructure security).
- Cloudflare is certified under the EU-U.S. Data Privacy Framework.
4. Stripe (Payment Processing)
For the billing of "Counsel" and "Professional" plans, we use the payment service provider Stripe (Stripe Payments Europe Ltd., Ireland / Stripe Inc., USA).
- When you subscribe to a paid plan, your payment data (credit card, bank details) is transmitted directly to Stripe. LexLogik does not store full credit card information.
- Legal Basis: Art. 6 (1) (b) GDPR (performance of a contract).
- Stripe is certified under the EU-U.S. Data Privacy Framework.
5. Self-hosted Analytics (Data Privacy Focused)
We do not use Google Analytics or Meta Pixels. For statistical analysis of page views, we use a self-hosted analysis tool on our own servers in Germany.
- IP addresses are anonymized immediately.
- No data is passed on to third parties.
- Legal Basis: Art. 6 (1) (f) GDPR (reach measurement without personal reference).
7. Disclosure of Data
Your content data (documents) is never passed on to third parties unless there is a legal obligation. For payment processing, only the necessary master data is transmitted to Stripe.
8. Your Rights (Data Subject Rights)
Under the GDPR, you have the right to:
- Access (Art. 15), Rectification (Art. 16), Erasure (Art. 17).
- Restriction of processing (Art. 18) and Data portability (Art. 20).
- Withdrawal of consent (Art. 7 (3)).
- Lodge a complaint with a supervisory authority. In Ireland, this is the Data Protection Commission (DPC).
9. Data Security
We use 256-bit SSL encryption for all data transmissions. Our servers in Germany are subject to the strictest physical and digital access controls.
As of: April 2026