1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) for the processing of personal data in connection with the LexVault software platform (web application and Client App, collectively referred to below as "LexVault" or the "Platform") is:
Frick & Pauls GbR
Mierendorffstr. 38, 63225 Langen, Germany
Email: hello@evolunex.de · Website: lexvault-law.com / evolunex.de
2. Key Information: Two Roles at LexVault
LexVault is software for law firms and notarial offices. From a data protection perspective, two levels must be distinguished:
Own processing by us: To the extent that we process personal data for the provision of the Platform, contract administration with law firms, billing, support and operation of our websites, we act as controller within the meaning of Art. 4(7) GDPR.
Processing on behalf of the law firm: Content that a law firm or its clients upload to LexVault (including files, documents, deadlines, messages and documents transmitted via the Client App, collectively referred to below as "Matter Data") is processed by us exclusively as a processor within the meaning of Art. 28 GDPR. The respective law firm is the controller for Matter Data. The basis for this processing is the data processing agreement concluded with the law firm. For information and to exercise data subject rights in relation to Matter Data, please contact the law firm handling your matter.
3. Hosting and Infrastructure
LexVault is operated exclusively on servers in Germany, currently by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. No transfer of personal data to third countries outside the European Union (EU) or the European Economic Area (EEA) takes place for the operation of the Platform. We have entered into data processing agreements pursuant to Art. 28 GDPR with our hosting service providers.
When the Platform is accessed, the web server processes technically necessary data (IP address, date and time of access, resource accessed, volume of data transferred, browser type and version, operating system, referrer URL) in server log files. Processing is carried out to ensure stable and secure operation on the basis of Art. 6(1)(f) GDPR (legitimate interest in stability and security). Log files are deleted no later than 30 days after collection unless they are required for a longer period to investigate security incidents.
4. Registration and User Accounts
A user account is required to use LexVault. During registration, we process in particular: name, law firm or organisation, business email address, telephone number (optional), role/permissions and access credentials (password in encrypted form, not in plain text). The legal basis is Art. 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract); for user accounts created by a law firm for its employees, the data processing agreement with the law firm also applies.
For account security, we log security-related events (e.g. logins and logouts, failed login attempts) on the basis of Art. 6(1)(f) GDPR.
5. Client App
Through the LexVault Client App, clients of a law firm can photograph or upload documents and transmit them to their law firm in encrypted form; the processing status is displayed in the App. All content transmitted via the App constitutes Matter Data within the meaning of Section 2; we process such data exclusively on behalf of and in accordance with the instructions of the respective law firm. The law firm is the controller.
For the provision of the App itself, we process, as controller, the data required for registration and operation (Section 4) as well as technical log data (Section 3). Data is transmitted using transport encryption; documents are stored in encrypted form.
6. AI Features
LexVault includes AI-assisted features, in particular for the analysis and full-text search of documents, the identification and processing of deadlines, the creation of brief summaries and the answering of case-related questions based on Matter Data stored in LexVault. The AI features are intended solely to support the respective law firm and do not make independent legal decisions.
To provide the AI features, LexVault uses services provided by OpenAI, in particular the OpenAI API. The provider for customers in the European Economic Area is OpenAI Ireland Ltd., Dublin, Ireland. To the extent necessary to process a request, content relevant to the respective AI request is transmitted to OpenAI and processed there for the purpose of providing the service. OpenAI is used as a processor or subprocessor within the framework of the contractually agreed data processing arrangements.
Under the terms applicable to the OpenAI API, inputs submitted via the API and generated outputs are not used by default to train or improve OpenAI models. Processing is carried out on the basis of the data processing relationship with the respective law firm pursuant to Art. 28 GDPR. Where the technical provision of the service involves processing outside the European Union or the European Economic Area, such processing takes place only in compliance with the requirements of Arts. 44 et seq. GDPR and on the basis of appropriate safeguards, in particular the Standard Contractual Clauses approved by the European Commission, where required.
7. Contract Administration, Billing and Payment
For the performance of the contract with the law firm, we process master and billing data (company name, address, contact person, VAT identification number, bank details or payment data, invoice and payment history) on the basis of Art. 6(1)(b) GDPR and to comply with statutory retention obligations pursuant to Art. 6(1)(c) GDPR in conjunction with Section 147 of the German Fiscal Code (AO) and Section 257 of the German Commercial Code (HGB).
Payments are processed via the payment service provider Stripe (Stripe Payments Europe, Ltd., Ireland). Stripe processes payment data partly under its own responsibility as a controller; transfers to third countries may take place on the basis of appropriate safeguards (EU Standard Contractual Clauses). Further information is available at stripe.com/privacy.
8. Contact and Support
When you contact us by email, contact form or through support channels, we process the information you provide in order to handle your request (Art. 6(1)(b) GDPR; otherwise Art. 6(1)(f) GDPR). Support access to customer environments takes place only after authorisation by the law firm and is logged.
9. Cookies and Local Storage
LexVault uses technically necessary cookies and comparable storage technologies that are required in particular for login, session management and security. To the extent that these technologies are necessary to provide functions expressly requested by the user, they are used on the basis of Section 25(2) No. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG). Where applicable, the associated processing of personal data is based on Art. 6(1)(b) or (f) GDPR.
In addition, we use Google Ads, an advertising service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. In connection with Google Ads, technologies may in particular be used to measure the effectiveness of our advertisements and to attribute website visits to advertisements previously clicked by users. This may include the processing of information about the browser and device used, IP address, pages accessed, time of access, interactions with our website and information about Google advertisements previously clicked.
Where cookies or comparable technologies are stored on or read from the user's device for these purposes, or where personal data is processed for advertising and measurement purposes, this takes place only after the user has given prior consent. The legal basis for storing or accessing information on the user's device is Section 25(1) TDDDG; the legal basis for the associated processing of personal data is Art. 6(1)(a) GDPR. Consent may be withdrawn at any time with effect for the future via the cookie or privacy settings.
We may use Google Ads in particular to measure the success of our advertising campaigns and, where expressly permitted by the user and used by us, for personalised advertising or remarketing. Consent granted is communicated to Google via our consent management system. Google provides, among other things, its Consent Mode, which takes account of the user's consent status for advertising-related storage, the transmission of advertising data and personalised advertising. Google requires corresponding consent signals from users in the EEA for the relevant measurement and personalisation functions.
The recipient of the data is in particular Google Ireland Limited. In connection with the provision of these services, processing by other companies of the Google group outside the European Union or the European Economic Area cannot be completely excluded. Google provides the mechanisms required under applicable data protection law for such international data transfers. Further information on data processing by Google is available in Google's privacy policy.
10. Recipients and Processors
We disclose personal data only where this is necessary for the performance of a contract, required by law or based on consent. The service providers we use (in particular hosting, email delivery and payment processing providers) are carefully selected and, insofar as they process data on our behalf, are contractually bound in accordance with Art. 28 GDPR. We provide law firms with an up-to-date list of subprocessors for Matter Data as part of the data processing agreement.
11. Retention Periods
We retain personal data only for as long as necessary for the respective purposes or for as long as statutory retention obligations apply. Matter Data is stored for the duration of the contract with the law firm and, at the end of the contract, is returned to the law firm at its option and subsequently deleted; details are governed by the data processing agreement. Accounting-related records are retained in accordance with the retention periods under German commercial and tax law (generally 8 or 10 years).
12. Data Security
We implement technical and organisational measures pursuant to Art. 32 GDPR to ensure the security of processing. These measures include, in particular, transport encryption (TLS), encrypted storage of documents, role-based access controls, logging of access and changes, regular backups, system hardening and updates, and restriction of access to personnel who require it. The measures are reviewed regularly and adapted to the state of the art.
13. Your Rights as a Data Subject
Where we act as controller, you have the following rights:
- Access to the personal data processed (Art. 15 GDPR),
- Rectification of inaccurate data (Art. 16 GDPR),
- Erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR),
- Data portability (Art. 20 GDPR),
- Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR),
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR).
To exercise your rights, an informal request to the contact details stated above is sufficient. You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR); the supervisory authority responsible for us is the Hessian Commissioner for Data Protection and Freedom of Information (Hessischer Beauftragter für Datenschutz und Informationsfreiheit), Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany. If your request concerns Matter Data, we will forward it to the responsible law firm or refer you to that law firm.
14. No Automated Decision-Making
Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place. AI features are used solely for support purposes; decisions are made by users of the law firm.
15. Changes to this Privacy Policy
We amend this Privacy Policy if the legal framework, the Platform or our data processing activities change. The version published on the Platform at the relevant time applies.