1. Data Controller
The entity responsible for data collection and processing is:
LexLogik UG (haftungsbeschränkt) Mahlgasse 488339 Bad Waldsee
Germany
Managing Director: Jonas Maximilian RegulEmail: info@lexlogik.comVAT ID: DE460852323
2. Collection and Storage of Personal Data
When you visit our website, your browser automatically sends information to our server (log files).
- Data collected: IP address, date/time of access, file requested, referrer URL, browser type, and operating system.
- Purpose: Ensuring a smooth connection, system security, and administration.
- Legal Basis: Art. 6 (1) (f) UK GDPR (legitimate interest).
3. Cloudflare (Security & Performance)
We use services from Cloudflare, Inc. (USA/EU) to protect our infrastructure against DDoS attacks and optimize loading times.
- Important: Cloudflare is only used for the delivery of the web interface (frontend). Documents you upload for processing are transmitted directly to our servers in Germany and do not pass through Cloudflare's infrastructure.
- Legal Basis: Art. 6 (1) (f) UK GDPR. Cloudflare is certified under the Data Privacy Framework.
4. Stripe (Payment Processing)
For the billing of our "Counsel" and "Professional" plans, we use the payment service provider Stripe (Stripe Payments Europe Ltd., Ireland / Stripe Inc., USA).
- When you subscribe, your payment details are transmitted directly to Stripe. LexLogik does not store full credit card details.
- Legal Basis: Art. 6 (1) (b) UK GDPR (fulfillment of contract).
5. Self-hosted Analytics (Privacy-First)
We do not use Google Analytics or Meta Pixels. To statistically evaluate page views, we use a self-hosted analytics tool on our own servers in Germany.
- IP addresses are anonymized immediately.
- No data is shared with third parties.
- Legal Basis: Art. 6 (1) (f) UK GDPR (reach measurement without personal reference).
7. Disclosure of Data
Your content data (documents) will not be disclosed to third parties unless there is a legal obligation to do so. Only the necessary master data is transmitted to Stripe for payment processing.
8. Your Rights (Data Subject Rights)
Under the UK GDPR, you have the right to:
- Access (Art. 15), Rectification (Art. 16), and Erasure (Art. 17).
- Restriction of processing (Art. 18) and Data portability (Art. 20).
- Withdrawal of consent (Art. 7 (3)).
- Complaint: You have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO).
9. Data Security
We use 256-bit SSL encryption for all data transmissions. Our servers in Germany are subject to the strictest physical and digital access controls and are managed in accordance with ISO 27001 standards.
As of: April 2026