Legal
Data Processing Agreement
The terms under which Lexapt processes personal data on behalf of its customers.
Roles
For personal data you upload or generate in the platform (account users, contacts, product-related personal data), you act as controller and Lexapt acts as processor, processing data only on your documented instructions and as needed to provide the service.
Subprocessors
We engage subprocessors for hosting, email delivery and payments. Each is bound by written data-protection terms. A current subprocessor list is available on request; we notify customers of material changes before they take effect.
Security measures
Encryption in transit and at rest, role-based access controls, audit logging of access to customer data, and private access-controlled document storage. See the security page for the measures we describe publicly.
International transfers
Where data is transferred across borders, we use appropriate safeguards such as standard contractual clauses. Contact us for details of transfer mechanisms applicable to your workspace.
Data subject requests and breach notification
We assist you in responding to data-subject requests and will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information needed to meet your own notification duties.
Return and deletion
On termination of your subscription you may export your data; we delete customer personal data within 90 days of termination unless retention is required by law.
Questions about this document? Contact us.