Your data is safe.

LEXA was designed so that you can upload and process even the most sensitive legal documents securely — without compromising between data protection and efficiency.

In legal work, data security is not optional. Client data, trade secrets and litigation strategies are among the most sensitive kinds of information. That is why LEXA places data protection at the center, not only as a legal obligation, but as one of its core value propositions.


🇪🇺 EU data processing, GDPR-compliant

LEXA handles all data in accordance with European Union data protection rules. This is not merely a legal statement — it is a fundamental design principle of the system.

What does this mean in practice?

  • Your data is stored exclusively in European data centers
  • We do not transfer any data to third parties for marketing purposes
  • Our data processing processes fully comply with GDPR requirements
  • Under our Zero Data Retention (ZDR) agreement with OpenAI, the text of legal questions is not stored after AI processing — meaning that questions relating to client matters cannot appear in other users’ answers and cannot be reconstructed even in the event of a data leak

Why is this important? General AI tools — such as consumer versions of ChatGPT or Claude — may, by default, store and use question content to train models. LEXA excludes this through the ZDR agreement: the content of legal questions will not become part of anyone else’s AI answer.


🛡️ Full control over your data

In LEXA, you decide what happens to your documents.

Document upload and sensitive-data filtering:

  • If you wish, we filter sensitive personal data from uploaded documents, including names, identifiers, dates, locations and contact data
  • Only the document text is processed to answer the legal question
  • You can delete uploaded documents from the system at any time by deleting the chat into which they were uploaded

Why does this matter in legal work?

During contract analysis, the client’s name, identification numbers and other personal data may appear in the document. Sensitive-data filtering allows the legal analysis to be carried out without unnecessary processing of these data, in line with professional confidentiality obligations.


🔐 Industry-grade security

Your data is stored encrypted and protected by infrastructure systems that meet strict international standards.

Our database infrastructure is provided by Neon, a cloud provider designed specifically for security and compliance. Neon holds the following independent, third-party audited certifications:

  • ISO/IEC 27001 – Information security management system
  • ISO/IEC 27701 – Privacy information management system
  • SOC 2 Type II – Audited certification for security, availability and confidentiality

These certifications are verified by independent auditors — it is not enough to claim security; it must be proven. We chose Neon as an infrastructure partner because the security guarantees it provides meet the expectations of the legal profession.

Encryption:

  • We store data encrypted according to standards used by government and banking sectors. In the event of a data leak, data can only be read with a separate “decryption key” stored apart from the data, providing an extra layer of security.
  • Data transmission happens through encrypted channels (HTTPS/TLS). Data is encrypted in transit as well, so it cannot be stolen “on the way”.

📊 Comparison with general AI tools

AspectLEXAChatGPT (consumer)Claude (consumer)
Zero Data Retention (AI side)✅ Yes❌ Not by default❌ Not by default
Use of data for model training✅ Excluded (ZDR)⚠️ Yes by default⚠️ Yes by default
EU data processing✅ Yes⚠️ Partial (US infrastructure)⚠️ Partial (US infrastructure)
GDPR-compliant✅ Yes⚠️ Partial⚠️ Partial
Optimized for national law✅ Yes❌ No❌ No
Sensitive-data filtering from documents✅ Yes❌ No❌ No
Document deletion option✅ Yes⚠️ Limited⚠️ Limited

💼 Why is this especially important for legal professionals?

Because of the nature of the legal profession, professional secrecy and the protection of client data are fundamental obligations. National confidentiality rules for attorneys, as well as general GDPR requirements, mean that every data processing decision carries legal responsibility.

LEXA was designed with this in mind:

  • We do not transfer client data to third parties
  • During AI processing, question content is not stored (ZDR)
  • Infrastructure partners comply with EU data protection requirements

LEXA does not merely comply with data protection requirements — we built these principles into the architecture of the system, so you can focus on legal work instead of data protection risks.