Skip to content

Every assessment connects conclusions to official sources.

Legal

Data Processing Agreement

The terms under which Lexapt processes personal data on behalf of its customers.

Last updated 2026-09-27

Roles

For personal data you upload or generate in the platform (account users, contacts, product-related personal data), you act as controller and Lexapt acts as processor, processing data only on your documented instructions and as needed to provide the service.

Subprocessors

We engage subprocessors for hosting, email delivery and payments. Each is bound by written data-protection terms. A current subprocessor list is available on request; we notify customers of material changes before they take effect.

Security measures

Encryption in transit and at rest, role-based access controls, audit logging of access to customer data, and private access-controlled document storage. See the security page for the measures we describe publicly.

International transfers

Where data is transferred across borders, we use appropriate safeguards such as standard contractual clauses. Contact us for details of transfer mechanisms applicable to your workspace.

Data subject requests and breach notification

We assist you in responding to data-subject requests and will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information needed to meet your own notification duties.

Return and deletion

On termination of your subscription you may export your data; we delete customer personal data within 90 days of termination unless retention is required by law.

Questions about this document? Contact us.