Legal

Privacy Notice

Last updated: 8/6/2026

1. Who we are

This Privacy Notice explains how LexHarvi ("LexHarvi", "we", "us", or "our") handles personal data in connection with LexHarvi One (the "Service"). LexHarvi is the data controller for personal data processed via the Service, except where we act as processor on behalf of a customer organisation (for example, in respect of governance data uploaded by that organisation).

2. Data we collect

  • Account data: name, email, hashed password, role.
  • Workspace content: company records, director and shareholder details, filings, minutes, documents, and other governance data you upload.
  • Communications: support messages, feedback, and AI chat history you save to your workspace.
  • Usage and telemetry: log entries, actions taken, feature usage, and error reports.
  • Device data: IP address, browser, device identifiers, and approximate location derived from IP.

3. How we use personal data

  • To create and secure your account and provide the Service.
  • To operate governance features (registers, filings, meetings, AI assistance).
  • To detect, investigate, and prevent fraud, abuse, and security incidents.
  • To provide customer support and respond to your requests.
  • To improve the Service, including product analytics and quality monitoring.
  • To send service and administrative notices, and — where permitted — product updates.
  • To comply with legal, regulatory, and tax obligations.

4. Legal bases

Where GDPR or equivalent laws apply, we rely on: performance of a contract (to provide the Service), legitimate interests (to secure and improve the Service and communicate with customers), consent (for optional marketing or non-essential cookies), and legal obligation (for tax, accounting, and regulatory compliance).

5. Sharing

We share personal data only with:

  • Service providers / subprocessors that host the Service, provide infrastructure, analytics, email delivery, error monitoring, and customer support tooling.
  • Paddle.com, our Merchant of Record, which processes payments, subscription management, tax compliance, and invoicing. Paddle's processing is governed by its own privacy notice.
  • AI model providers used by the AI Company Secretary and AI Risk Briefing, solely to generate responses to prompts you submit.
  • Professional advisers (legal, accounting) where necessary.
  • Public authorities where required by law.

We do not sell personal data.

6. International transfers

Personal data may be transferred to countries outside your own. Where we transfer personal data outside the UK/EEA, we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses.

7. Retention

We keep personal data for as long as needed to provide the Service and comply with legal obligations. Workspace content is retained while your account is active and for a reasonable period after termination to allow export, after which it is deleted or anonymised. Audit logs may be retained longer to meet record-keeping requirements.

8. Your rights

Depending on your jurisdiction, you may have rights to access, rectify, erase, restrict, port, or object to the processing of your personal data, and to withdraw consent. Under GDPR you also have the right to lodge a complaint with your supervisory authority. We aim to respond to verified requests within one month.

9. Security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit, role-based access controls, and row-level security in our database. No system is completely secure; you should also protect your account credentials.

10. Cookies

We use strictly necessary cookies to keep you signed in and to remember preferences. If we introduce analytics or marketing cookies we will present a cookie notice and let you manage your preferences.

11. Contact

For privacy questions or to exercise your rights, contact us via our contact page.