Legal
Privacy Policy
How Lexnus processes personal data for Users, External Parties and Lexnus Counterparties in connection with the Lexnus Platform.
Welcome to Lexnus' Privacy Policy for users of our Contract Control Automation Platform. You are most likely reading this because you use the Platform on behalf of one of our Customers as a User, our Customer has submitted your personal data to the Platform, or because you have a business relationship with Lexnus.
At the end of this policy, we have set up a table which will give you an overview of the processing activities you may be affected by.
Should you have any questions regarding this policy, privacy, GDPR or how we handle your data, please don't hesitate to reach out to us at legal@lexnus.com.
1. About Lexnus
Lexnus is a Swedish company built on the experience and knowledge gained through years of working closely with legal teams at Precisely. Through that work, we identified a growing gap: as contracting becomes more decentralised and AI makes it easier than ever to create and work with contracts, legal teams need a way to ensure that their standards are consistently followed without having to review every contract themselves. Lexnus was created to address that need.
The Lexnus Platform enables organisations to define their legal standards and apply them across their contracts, helping businesses work more independently while Legal stays in control. As our Platform processes contracts and other information that may contain personal and confidential data, privacy, security and responsible handling of data are fundamental to how Lexnus is designed and operated. The Platform is developed in-house with these principles at its core.
Contact information:
Lexnus by Precisely AB
Address: Nellickevägen 26, 412 63 Gothenburg, Sweden.
Business registration number: 556963-5286 (Sweden)
Email: legal@lexnus.com
2. Applicability
This policy covers Lexnus' Platform, and applies to individuals whose personal data may be processed in connection with the Platform or our relationship with you.
For the purpose of this policy, a "Customer" is an organisation that has entered into an agreement with Lexnus to use the Platform. This policy may apply to you if you use the Platform on behalf of a Customer (a "User"), if you are an individual whose personal data is processed through the Platform in connection with a Customer's use of the Platform (an "External Party"), or if Lexnus processes your personal data in connection with our own relationship with you or the organisation you represent (a "Lexnus Counterparty").
3. Roles – Controller and Processor
The General Data Protection Regulation ("GDPR") is a comprehensive EU regulation on data protection and privacy, which came into effect in May 2018. It sets out the rules and responsibilities of organizations processing personal data – with the purpose of ensuring the privacy of individuals (typically "Data Subjects").
The GDPR defines two main roles in terms of responsibility for data processing; Data Processors ("Processors") and Data Controllers ("Controllers"). Additionally, a Processor may have other processors of their own; commonly referred to as Subprocessors.
Lexnus acts both as a Controller and Processor in different scenarios, as described below. Lexnus will treat all data with utmost care and security, irrespective of whether we are Controllers or Processors of the data.
3.1 When is Lexnus the Processor?
If you are a User of the Platform, the Customer who has given you access to Lexnus is generally the Controller and Lexnus is the Processor. This is because the Customer determines the purposes for using the Platform and how it will be used.
If you are an External Party, the relevant Customer is generally the Controller and Lexnus is the Processor. The Customer determines what personal data is submitted to the Platform and for what purposes it is processed.
Naturally, Lexnus uses suppliers to provide and maintain the Platform. Where these suppliers process personal data on our behalf when we act as Processor, they are our Subprocessors.
3.2 When is Lexnus the Controller?
If you are a Lexnus Counterparty, Lexnus is generally the Controller of your personal data. This means that we determine why and how your personal data is processed in connection with our relationship with you or the organisation you represent.
Lexnus may also act as Controller for certain processing relating to the operation of our own services, for example account administration, billing, security and communication where Lexnus determines the purposes and means of the processing.
4. Processed Personal Data
4.1 Users
Lexnus will process certain information about Users of the Platform, such as name, email address and IP address. This information might be provided or updated directly by you or by the Customer, for example through a user management solution.
4.2 External Parties
Our Customers may submit contracts, documents and other information to the Platform that contain personal data about you. Depending on the type of document and how the Customer uses the Platform, this may for example include your name, email address, phone number, workplace or company, job title or other personal information contained in a contract or document.
If you are invited to interact with the Platform, for example to electronically sign a document, additional information may also be processed in order to provide that functionality (such as your personal ID number).
It is important to remember that our Customer is generally the Controller in these situations. This means that the Customer is responsible for determining what personal data is submitted to the Platform and the purpose for processing it. If you have questions about why your personal data has been submitted to Lexnus, you should therefore first reach out to the relevant Customer.
4.3 Lexnus Counterparties
We always try to limit the personal information we process about our Counterparties to what is necessary for our relationship with you. What information we process will depend on the nature of that relationship.
For example, we may process your name, email address, phone number, company, job title and other information necessary for us to manage our relationship with you or the organisation you represent.
5. Purpose(s) for the processing
5.1 Users
Lexnus, as the Processor, processes personal information relating to your user account for the purpose of providing access to the Platform and allowing you to use the functions available in it. We also process this information in order to fulfil our obligations towards the Customer.
The personal information relating to your User account may be provided directly by you or by the Customer, for example when the Customer creates or manages User accounts through Active Directory (AD), Single Sign-On (SSO) or another user management solution.
If you reach out to Lexnus regarding a support request, we may process personal data for the purpose of responding to your inquiry.
5.2 External Parties
Lexnus, as the Processor, may process personal information about External Parties in order to provide the Platform and allow our Customers to use its functions.
Our Customers are responsible for determining the purpose for processing this data as they are the Controllers. Lexnus enters into a Data Processing Agreement ("DPA") with our Customer, which sets out how we process personal data on their behalf.
If you reach out to Lexnus regarding a support request, we may process personal data for the purpose of responding to your inquiries.
5.3 Lexnus Counterparties
When Lexnus is the Controller, we process personal data about our Counterparties in order to manage our relationship with you or the organisation you represent. This may for example include entering into and performing the obligations stipulated in the contract.
If you reach out to Lexnus through the chat available in the Platform, we also process personal data for the purpose of responding to your inquiries.
6. Where information is stored
6.1 Users, External Parties and Lexnus Counterparties
Information submitted to the Lexnus Platform is stored and processed within the Platform using our infrastructure providers. The Platform is hosted through Clever Cloud, with hosting, database and object storage services located in Paris, France. For redundancy and disaster recovery purposes, contract files are replicated through OVHcloud in Frankfurt, Germany and are stored as sealed ciphertext.
Our Customers may also choose to make information available to third-party services through integrations with the Platform, including optional services and external AI services connected through our MCP connector. Where a Customer enables such an integration, information may be processed or stored by the relevant third-party provider in accordance with the Customer's configuration and arrangements with that provider. Please contact the relevant Customer for further information about third-party services they have chosen to connect to Lexnus.
7. How long information is stored
7.1 Users
Lexnus will store information about you, your User account and your organisation for as long as your account remains active and the relevant Customer has an active organisation in the Platform. We will delete this information in accordance with the Customer's instructions and when our relationship with the Customer ends, unless we are required to retain certain information for legal, regulatory or legitimate business purposes.
Information retained in our backups may remain for a limited period in accordance with our ordinary backup and disaster recovery procedures and will be deleted in accordance with our applicable retention procedures.
7.2 External Parties
It is the responsibility of our Customer, as Controller, to determine how long they store information in the Platform. Lexnus will delete such personal data in accordance with the Customer's instructions and when our relationship with the Customer ends, subject to applicable retention requirements and our ordinary backup and disaster recovery procedures.
7.3 Lexnus Counterparties
Lexnus has set retention periods for data we store about our Counterparties. In general, we only store information as long as we need it, and will delete it once it is not necessary for us to keep.
8. How information is protected
Lexnus has taken several measures to protect your data, and ensure GDPR compliance. You can be sure that we take great pride in being able to provide a secure service.
A few of Lexnus' security measures worth mentioning:
- Data is stored in Europe with providers internationally well known to provide high security standards
- Encryption both in transit and at rest
- European personnel (Sweden)
- European e-signing provider
- Access rights according to the principle of least privilege
- Data Processing Agreements in place with both subprocessors and customers (see our Data Processing Addendum)
- Standard Contractual Clauses ("SCCs") with our Subprocessors and vendors in place where deemed necessary
Additional measures available for Customers to enhance security:
- Possibility to use Single Sign-On and Active Directory for user management
You are always welcome to reach out to us should you have any questions.
9. Third-party transfers
Our essential sub-processors, which will handle personal information, have been mentioned above and also specified in the table below.
All our essential data processing is located within the EU or with internationally well known and trusted providers. We have chosen these providers since they have state of the art security on top of our own high internal security standards.
Please see the table "Processing activities overview" below for more information.
10. Your rights
You have several rights regarding processing of your personal data, in accordance with GDPR. Which rights apply may depend on the circumstances and whether Lexnus or one of our Customers is the Controller of your personal data. Where one of our Customers is the Controller, we will cooperate with the Customer as necessary to help them respond to your request.
Depending on the circumstances, your rights may include:
- Request information from us at all times regarding data we store about you, as well as origin, recipients or categories of recipients, to whom these data are passed on and the purpose of the storage.
- Request correction or erasure of your personal data, restriction of processing and, where applicable, exercise your right to data portability (article 20 of the GDPR).
- Lodge a complaint with a competent data protection supervisory authority.
- If you have given your consent to the use of your data, you can rescind your consent at any time.
Please send all requests for information, disclosure or revocation of data processing by email to privacy@lexnus.com.
11. Processing activities overview
The purpose of this table is to provide you with an overview of the different processing activities in and in connection with the Lexnus Platform.
11.1 Essential
These activities occur for all Customers as part of providing the Platform.
| Type | Data Subject | Purpose | Personal data | Storage / Processing | Comment |
|---|---|---|---|---|---|
| Access, hosting and usage of the Platform | Users; External Parties | Providing User accounts and enabling access to and use of the Platform | Name; Email address; IP address; Workplace/company; Platform activity and other information submitted through the Platform | The Platform is hosted through Clever Cloud in Paris, France, including application hosting, PostgreSQL database and object storage. | Other Personal Data may be submitted in contracts, documents or other information in the Platform. The type and extent of such Personal Data depends on the Customer's use of the Platform. |
| Contract storage and replication | Users; External Parties; Lexnus Counterparties | Storage, redundancy and disaster recovery of contracts and documents submitted to the Platform | Personal Data contained in contracts and related documents | Contract files are replicated through OVHcloud in Frankfurt, Germany for redundancy and disaster recovery. | Contract files replicated to OVHcloud are stored as sealed ciphertext. |
| AI-enabled contract processing | Users; External Parties; Lexnus Counterparties | Analysing and otherwise processing contracts and contract information to provide the Platform's AI-enabled functionality | Contract text and any Personal Data contained in the contract text submitted for processing | Mistral AI is Lexnus' default AI/LLM provider and processes contract text. | Personal Data is not provided to the AI provider for the purpose of training or improving its general-purpose or provider-owned AI models. |
| Transactional emails | Users; External Parties; Lexnus Counterparties | Sending transactional emails and Platform notifications | Name; Email address; Notification content | Transactional emails are processed through Sweego. Sweego processes data in France / the Netherlands. | The information processed depends on the relevant notification or communication. |
| Monitoring and observability | Users; External Parties | Maintaining and monitoring the performance, reliability and operation of the Platform, including troubleshooting errors | Telemetry; Platform usage information; UI replay and other technical information | Processed through Better Stack for logs, traces, error monitoring, session replay and status services. | The information processed depends on the relevant Platform activity and technical event. |
11.2 Optional
These activities only occur where the Customer selects, activates or uses the relevant functionality.
| Type | Data Subject | Purpose | Personal data | Storage / Processing | Comment |
|---|---|---|---|---|---|
| Alternative AI provider: Anthropic* | Users; External Parties; Lexnus Counterparties | Providing AI-enabled functionality where the administrator of the Workspace selects Anthropic as its AI provider | Contract text and Personal Data contained in information submitted for AI processing | Personal Data is processed by Anthropic when the Customer selects Anthropic as its AI provider. | Activated at the Customer's choice. The Customer's use of the provider is subject to the Customer's own account, configuration and contractual arrangements with the provider. See "External AI services and MCP connections" below. |
| Alternative AI provider: OpenAI* | Users; External Parties; Lexnus Counterparties | Providing AI-enabled functionality where the administrator of the Workspace selects OpenAI as its AI provider | Contract text and Personal Data contained in information submitted for AI processing | Personal Data is processed by OpenAI when the Customer selects OpenAI as its AI provider. | Activated at the Customer's choice. The Customer's use of the provider is subject to the Customer's own account, configuration and contractual arrangements with the provider. See "External AI services and MCP connections" below. |
| Electronic signing: Scrive | Users; External Parties; Lexnus Counterparties | Enabling contracts and documents to be electronically signed | Documents sent for signature and Personal Data contained in or associated with those documents | Personal Data is processed by Scrive when a Customer sends a document for signature. | Scrive is only engaged when the Customer uses the electronic-signature functionality. |
| Slack integration | Users; External Parties | Enabling the Customer to connect Lexnus to its Slack workspace | Personal Data made available through the integration | Personal Data is processed through Slack when the Customer connects a Slack workspace through OAuth. | The Customer chooses whether to connect its Slack workspace. The information processed depends on how the Customer uses the integration. |
* External AI services and MCP connections
Customers may choose to connect Lexnus to third-party artificial intelligence platforms, applications or services ("External AI Services"), including by providing their own API key within the Platform or through a Model Context Protocol ("MCP") connector or similar integration.
Where a Customer enables an External AI Service, the Customer instructs Lexnus to make Personal Data available to that service in accordance with the Customer's actions, configuration and use of the Platform. Such External AI Services are selected and controlled by the Customer and are not subprocessors engaged by Lexnus.
The subsequent processing, storage, use and protection of Personal Data by an External AI Service is subject to the Customer's own account, configuration and contractual arrangements with the relevant provider. The Customer is responsible for ensuring that its use of the External AI Service, including the transfer of Personal Data to that service, complies with applicable data protection requirements.
For the avoidance of doubt, Lexnus' commitments regarding the use of Personal Data by AI subprocessors engaged by Lexnus, including restrictions on the use of Personal Data for model training or improvement, do not apply to External AI Services selected and controlled by the Customer.