Skip to content
返回首页

Privacy Policy

Effective August 14, 2026

1. Who processes your data

LexFlow is operated by amirich.org LLC. This document explains what data we collect, why, who we share it with, and how you can control it. It covers lex-flow.com, the lawyer application, the client portal and the mobile application.

2. Two distinct roles: your data and your clients' data

This distinction is fundamental and determines the scope of our obligations.

  • For your account data — name, email, billing details, sign-in history — we act as controller and determine the purposes of processing.
  • For your practice content — matters, documents, client data, correspondence — we act as processor and act solely on your instructions.
  • We do not use your practice content for our own purposes: we do not analyze it for marketing, sell it, disclose it to third parties, or train models on it.
  • You remain the controller of your clients' data and are responsible for the lawfulness of processing it, including obtaining consents where required.

3. What we collect

We collect exactly what the service needs to work.

  • Account data: name, email, hashed password, interface language, time zone, two-factor settings.
  • Practice content: matters, clients, documents and versions, deadlines, hearings, tasks, time entries, invoices and messages — everything you enter yourself.
  • Billing data: plan, subscription status, payment history. Card details are handled by Stripe; we neither receive nor store them.
  • Technical data: connection address, device and browser type, timestamps of actions, security logs.
  • Support requests and their contents.

4. Why we process it

Each purpose has a legal basis.

  • Performance of contract: providing the service, authentication, storing and displaying your data, accepting payment.
  • Legitimate interest: securing the service, preventing abuse, diagnosing failures, improving the product using aggregated metrics.
  • Legal compliance: tax and accounting records, responding to lawful requests from competent authorities.
  • Consent: product announcements unrelated to service operation. You can unsubscribe at any time; this does not affect mandatory notices.

5. Who we share data with

We do not sell data and do not share it for third-party advertising. We engage only the vendors the service cannot run without, and bind them to data protection obligations.

  • Hosting and storage — infrastructure provider in the European Union (Germany).
  • Payments — Stripe.
  • Email delivery — Resend.
  • Error tracking — Sentry. We send only a user identifier and technical error details; query strings are redacted and practice content is not transmitted.
  • Language models — only when you invoke an AI feature yourself, and only the excerpt needed to perform it.
  • Calendar — Google, if you enable synchronization.
  • Authorities — only upon a lawful and binding request; we will notify you unless prohibited by law.

6. How we protect data

Our measures are proportionate to the sensitivity of legal data.

  • Documents are encrypted at rest with AES-256-GCM; sensitive fields and third-party keys are stored encrypted.
  • Data in transit is protected by TLS.
  • Each firm's data is isolated: every query is scoped to a workspace the user has access to.
  • Passwords are stored as bcrypt hashes and cannot be recovered by us.
  • Two-factor authentication, an audit log and active session management are available.
  • Staff access to practice content is closed by default; the audit journal opens only for the owner, after re-entering the password, and for a limited time.

7. No system is perfectly secure

We are candid about this: the measures above substantially reduce risk but do not eliminate it. You are responsible for your part — a strong password, two-factor authentication enabled, control over who you invite into your workspace, and the devices you sign in from. If an incident affects your data we will notify you without undue delay and tell you what is known and what we are doing.

8. How long we keep data

We keep data for as long as your account is active.

  • After account deletion, practice content remains available for export for thirty days.
  • It is then deleted from production systems; backups are overwritten in the ordinary rotation cycle within the following ninety days.
  • Billing records are kept as long as tax and accounting law requires.
  • Security logs are kept for the limited period needed to investigate incidents.

9. Your rights

You can exercise these rights from the interface or by contacting us.

  • Access your data and export it in a machine-readable format.
  • Correct inaccurate information.
  • Delete your account and associated data.
  • Restrict processing or object to it where it rests on legitimate interest.
  • Withdraw consent to product announcements.
  • Lodge a complaint with the supervisory authority where you are located.

10. Where data is stored and international transfers

Primary storage is in the European Union (Germany). Certain vendors — the payment provider, error tracking and language models — process data in the United States. Such transfers rely on standard contractual clauses or another lawful mechanism.

11. Cookies

We use strictly necessary cookies: they hold your session and protect forms against request forgery. There are no advertising or tracking cookies in the application. The website uses traffic analytics, which you can disable in your browser.

12. Children

The service is intended for professional use and is not directed to anyone under eighteen. We do not knowingly collect their data. If such data reaches us, tell us and we will delete it.

13. Changes to this policy

For material changes we will notify you by email or in the interface at least thirty days before they take effect and update the date at the top of this document. Prior versions are available on request.

Contact us

For data protection questions write to [email protected]. The controller is amirich.org LLC. We respond within thirty days.