Lexqura holds two very different kinds of information, and almost every question about privacy resolves once you separate them.
- Account data is about the people who use Lexqura: your name, work email, firm, role, billing details, and the logs our systems generate as you work. We decide why and how this is processed, so for account data we are the data controller.
- Client data is what your firm puts into its workspace: matters, documents, correspondence, notes, and the personal data of your own clients. You decide why and how that is processed. You are the controller. For client data we are your data processor, acting on your instructions.
That distinction runs through the rest of this policy. Where a rule differs between the two, we say so.
1. What we collect
Information you give us
- Account details: name, work email address, password hash, firm name and your role.
- Firm details: practice areas, jurisdiction, size, and your billing address.
- Payment details, handled by our payment processor. We see the last four digits and the card brand. We never see or store a full card number.
- Anything you send us in a support message, a demo request or a feedback form.
Information your firm uploads
- Matters, client records, documents, notes, time entries and invoices.
- Research questions you ask the assistant, and the drafts it produces for you.
This content frequently contains personal data about third parties, including your clients and opposing parties. We process it only to provide the service to you.
Information we generate
- Audit records: who did what, on which matter, and when. These exist so your firm can answer that question later, and they are deliberately hard to alter.
- Technical logs: IP address, device and browser type, timestamps, and error traces.
- Aggregate product usage, such as which features a workspace uses and how often. This is counted at the workspace level, not read at the matter level.
2. Why we process it
- To run the service. Authenticate you, store your matters, produce answers and drafts, send invoices.
- To keep it secure. Detect unauthorised access, investigate incidents, maintain the audit trail.
- To support you. Answer your questions and diagnose faults you report.
- To bill you. Take payment and meet our accounting and tax obligations.
- To improve the product. Using aggregate usage and error data, never by reading your matters.
- To tell you about the product. Service notices always; marketing email only if you asked for it, and every marketing email carries an unsubscribe link.
3. Our legal bases
Under the Ghana Data Protection Act, 2012 (Act 843)
Lexqura is established in Ghana and processes personal data there. We process account data because it is necessary for the performance of the contract with your firm, because we have a legitimate interest in securing and improving the service, and because we are required to by law in the case of accounting records. Where none of those apply, we ask for your consent, and you can withdraw it.
Act 843 also requires that data be processed lawfully and only for the purpose it was collected for, that it be accurate and kept no longer than necessary, and that it be protected by appropriate security safeguards. Those principles are the backbone of this policy.
Under the GDPR
Where the GDPR applies, because a user is in the European Economic Area or a firm is established there, our legal bases are Article 6(1)(b) for performance of the contract, Article 6(1)(f) for our legitimate interests in security, fraud prevention and product improvement, Article 6(1)(c) for legal obligations, and Article 6(1)(a) for consent where we rely on it.
For client data we act as a processor under Article 28. We will enter a data processing agreement with your firm on request. It commits us to process client data only on your documented instructions, to bind our staff to confidentiality, to help you answer data subject requests, and to notify you of a personal data breach without undue delay.
Where client data includes special category data, which in a legal practice it very often does, your firm is responsible for identifying the Article 9 condition that permits your processing. Ours is Article 9(2)(f) where the processing relates to legal claims.
4. Where your data is hosted
Production data is stored in the European Union, in Frankfurt, Germany. Backups stay in the same region. We chose an EU region because it gives every customer, wherever they practise, the protection of a strong and well tested data protection regime.
Where a sub-processor is outside the EEA, the transfer is covered by the European Commission’s Standard Contractual Clauses or an adequacy decision.
We plan additional regions as we expand, so that firms with jurisdiction-specific residency requirements can meet them. We will not move your data to a new region without telling you.
5. Who else processes your data
We use a small number of sub-processors. We do not sell personal data, and we do not share it with advertisers or data brokers. Each sub-processor is contractually bound to confidentiality and to security obligations at least as strict as ours. The categories are:
- Cloud hosting and managed database. Stores your workspace. EU region.
- AI model providers. Process the text of a research question, and the relevant retrieved passages, in order to produce an answer. Under our agreements this content is not retained for training.
- Payment processing. Takes card and mobile money payments and holds the card details we never see.
- Transactional email delivery. Sends invitations, password resets and invoices.
- Error monitoring and product analytics. Tells us when something breaks. Configured to scrub message bodies and document contents.
- Customer support tooling. Holds the tickets you raise with us.
A current list of named sub-processors is available on request, and we will give notice before adding a new one that processes client data.
6. AI processing, stated plainly
- We do not train models on your matters.Not our models, not a provider’s. Your content is not part of any training set.
- When you ask the assistant a question, your question and the passages retrieved from our legal corpus are sent to a model provider to generate the answer. Your matter documents are sent only when you explicitly attach them to the request.
- The corpus the assistant searches is public primary law: constitutions, statutes and procedural rules. It is not built from customer data.
- Answers and citations are stored in your workspace so you can return to them, and are deleted with it.
7. How long we keep things
- Client data. For as long as your workspace is active. After termination you have 30 days to export, then we delete it. Encrypted backups age out within a further 90 days.
- Account data. Deleted with the workspace, except where we must keep it for a legal reason.
- Billing and accounting records. Kept for the period Ghanaian tax law requires, currently six years.
- Technical logs. Up to 90 days.
- Audit records. Kept for the life of the workspace, because their value is that they cannot be quietly pruned.
8. Security
Data is encrypted in transit and at rest. Every record is scoped to a single firm at the database layer, so one workspace cannot query another. Access to production is limited to the people who need it, requires a second factor, and is logged. We review those logs.
No system is perfect. If a breach affects your personal data, we will notify you and the relevant supervisory authority within the time limits that apply, and we will tell you what happened rather than what sounds best.
9. Your rights
Under Act 843 and the GDPR you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we process it, port it to another provider, or withdraw consent where consent is our basis. You can also complain to a supervisory authority: the Data Protection Commission in Ghana, or your national authority in the EEA.
If you are a client of a firm that uses Lexqura, we hold your data on that firm’s behalf. Send your request to the firm. If it reaches us first, we will pass it on and help the firm answer it.
Write to privacy@lexqura.com. We respond within 30 days, and we do not charge for a first request.
10. Cookies
We use the cookies needed to keep you signed in and to keep the session secure. We use a small amount of first-party analytics to understand which parts of the product are used. We do not run third-party advertising cookies or cross-site trackers.
11. Children
Lexqura is a professional tool and is not directed at children. We do not knowingly collect personal data from anyone under 18 as a user of the service.
12. Changes to this policy
We will post any update here and change the date at the top. For a material change we will email account administrators at least 30 days before it takes effect.
13. Contact
For privacy questions, data subject requests, or a copy of our data processing agreement, write to privacy@lexqura.com. For anything else, the contact page will route you. Our Terms of Service sit alongside this policy.