Privacy
Who We Are
Outlex AI LDA is a Portuguese limited liability company (VAT no. 518861660) providing AI-powered legal assistance with optional human legal review.
We are committed to protecting users' personal data and ensuring privacy when using Outlex. This Privacy Policy informs you on how we process data and your rights under applicable law.
Data Protection Officer
privacy@outlex.aiSupervisory Authority (Portugal)
CNPD
Av. D. Carlos I, 134, 1º, 1200-651 Lisboa
+351 213 928 400 | geral@cnpd.pt
Scope & Definitions
This Policy informs users how we collect, store, process, use, and manage information when using the Service. Your data will be processed according to GDPR standards and is limited to information collected by Outlex.
Personal data: Information relating to an identified or identifiable natural person
Processing: Operations carried out on personal data (collection, organization, use, transmission, etc.)
Data Controller: Entity that determines purposes and means of processing personal data (Outlex for account/billing)
Data Processor: Entity that processes personal data on behalf of the controller (Outlex for Customer Data)
Our Role Under GDPR
Data Controller
Data Controller: For Website, Account, and Marketing data
Data Processor
Data Processor: For Customer Data you upload (documents, contracts, prompts, chats). Governed by our Data Processing Addendum (DPA)
Categories of Data We Process
Account & Business Data: Name, work email, company, role, billing contacts, subscription tier
Usage/Technical Data: Device/OS info, IP, timestamps, event logs, telemetry, cookie IDs
Customer Data: Documents, contract text, comments, AI prompts/outputs, tags, metadata
Support Data: Tickets, severity, recordings (with consent)
Payment Data: Handled by PSP; we store tokens/last4 only
Marketing & Communication Data: Preferences, campaign interactions, waitlist forms, event sign-ups
Special categories: As Controller, we do NOT seek special category data. As Processor, categories are determined by you; we apply heightened safeguards.
Purposes & Legal Bases
Provide and secure the Service
Contract/legitimate interests for fraud/security
Improve and develop features/AI quality
Legitimate interests. Customer Data not used for foundation model training by default
Support & incident response
Contract/legitimate interests
Compliance & protection of rights
Legal obligations/legitimate interests
Marketing Communications
You may withdraw consent or opt out at any time.
Cookies & Tracking
We use essential cookies and, with your consent, analytics/marketing cookies. You can manage choices anytime in our Cookie Banner and browser settings. See our Cookie Policy for more details.
Sharing & Disclosures
Sub-processors: Cloud, monitoring, analytics, email, payments, LLM providers under DPAs. Live list at outlex.ai/subprocessors with 30-day notice
Human legal reviewers/partners: Expressly engaged by you, bound by confidentiality and access logging
Others: Affiliates (internal operations), Authorities (when legally required), Successors (business transfer with notice)
We do NOT sell personal data
International Transfers
Where data leaves the EEA, we rely on:
EU-US Data Privacy Framework (DPF) for certified US providers for certified US providers
EU Standard Contractual Clauses (SCCs 2021/914) with supplementary measures with supplementary measures
For UK transfers: UK IDTA or UK Addendum to EU SCCs
Security
Encryption at rest/in transit
Network segregation & role-based access
SSO/SAML (on eligible plans)
Least-privilege & vulnerability management
Off-site backups & routine penetration testing
Request our Security Summary & Pentest Letter under NDA. We disable provider-side retention/training where available with LLM providers.
AI & Human-in-the-Loop
Customer Data is NOT used to train foundation models by default. You can allow limited anonymised/aggregated learning signals via an org-level toggle (disable anytime).
Human review is opt-in and bound by strict access logging and NDAs.
We track EU AI Act milestones with staged obligations through 2025-2027.
We do NOT make decisions based solely on automated processing that produce legal or similarly significant effects.
Retention Periods
Account Data
Duration of relationship + 7 years (legal/tax)
Customer Data
Until deletion request or 90 days post-termination
Logs & Telemetry
Typically 12-24 months, anonymised thereafter
Marketing Data
Until consent withdrawn or 3 years of inactivity
Your Rights (GDPR/UK)
Access — obtain a copy of your data
Rectification — correct inaccurate data
Erasure — request deletion
Restriction — limit processing
Portability — receive data in structured format
Objection — object to processing
To exercise your rights, contact privacy@outlex.ai. We respond within 30 days.
Contact Us
Privacy inquiries
privacy@outlex.aiGeneral inquiries
hello@outlex.aiRegistered Address: Outlex AI LDA, Rua Gomes Freire 11, 1150-176 Lisbon, Portugal