lang="en"
Skip to main content
Data Protection

Privacy

Last Updated: December 30, 2025Effective Date: August 14, 2025

Who We Are

Outlex AI LDA is a Portuguese limited liability company (VAT no. 518861660) providing AI-powered legal assistance with optional human legal review.

We are committed to protecting users' personal data and ensuring privacy when using Outlex. This Privacy Policy informs you on how we process data and your rights under applicable law.

Data Protection Officer

privacy@outlex.ai

Supervisory Authority (Portugal)

CNPD
Av. D. Carlos I, 134, 1º, 1200-651 Lisboa
+351 213 928 400 | geral@cnpd.pt

Scope & Definitions

This Policy informs users how we collect, store, process, use, and manage information when using the Service. Your data will be processed according to GDPR standards and is limited to information collected by Outlex.

Personal data: Information relating to an identified or identifiable natural person

Processing: Operations carried out on personal data (collection, organization, use, transmission, etc.)

Data Controller: Entity that determines purposes and means of processing personal data (Outlex for account/billing)

Data Processor: Entity that processes personal data on behalf of the controller (Outlex for Customer Data)

Our Role Under GDPR

Data Controller

Data Controller: For Website, Account, and Marketing data

Data Processor

Data Processor: For Customer Data you upload (documents, contracts, prompts, chats). Governed by our Data Processing Addendum (DPA)

Categories of Data We Process

Account & Business Data: Name, work email, company, role, billing contacts, subscription tier

Usage/Technical Data: Device/OS info, IP, timestamps, event logs, telemetry, cookie IDs

Customer Data: Documents, contract text, comments, AI prompts/outputs, tags, metadata

Support Data: Tickets, severity, recordings (with consent)

Payment Data: Handled by PSP; we store tokens/last4 only

Marketing & Communication Data: Preferences, campaign interactions, waitlist forms, event sign-ups

Special categories: As Controller, we do NOT seek special category data. As Processor, categories are determined by you; we apply heightened safeguards.

Purposes & Legal Bases

Provide and secure the Service

Contract/legitimate interests for fraud/security

Improve and develop features/AI quality

Legitimate interests. Customer Data not used for foundation model training by default

Support & incident response

Contract/legitimate interests

Compliance & protection of rights

Legal obligations/legitimate interests

Marketing Communications

B2C: B2C: Prior consent required for email/SMS marketing
B2B: B2B: Permissible with opt-out and clear unsubscribe

You may withdraw consent or opt out at any time.

Cookies & Tracking

We use essential cookies and, with your consent, analytics/marketing cookies. You can manage choices anytime in our Cookie Banner and browser settings. See our Cookie Policy for more details.

Sharing & Disclosures

Sub-processors: Cloud, monitoring, analytics, email, payments, LLM providers under DPAs. Live list at outlex.ai/subprocessors with 30-day notice

Human legal reviewers/partners: Expressly engaged by you, bound by confidentiality and access logging

Others: Affiliates (internal operations), Authorities (when legally required), Successors (business transfer with notice)

We do NOT sell personal data

International Transfers

Where data leaves the EEA, we rely on:

EU-US Data Privacy Framework (DPF) for certified US providers for certified US providers

EU Standard Contractual Clauses (SCCs 2021/914) with supplementary measures with supplementary measures

For UK transfers: UK IDTA or UK Addendum to EU SCCs

Security

Encryption at rest/in transit

Network segregation & role-based access

SSO/SAML (on eligible plans)

Least-privilege & vulnerability management

Off-site backups & routine penetration testing

Request our Security Summary & Pentest Letter under NDA. We disable provider-side retention/training where available with LLM providers.

AI & Human-in-the-Loop

Customer Data is NOT used to train foundation models by default. You can allow limited anonymised/aggregated learning signals via an org-level toggle (disable anytime).

Human review is opt-in and bound by strict access logging and NDAs.

We track EU AI Act milestones with staged obligations through 2025-2027.

We do NOT make decisions based solely on automated processing that produce legal or similarly significant effects.

Retention Periods

Account Data

Duration of relationship + 7 years (legal/tax)

Customer Data

Until deletion request or 90 days post-termination

Logs & Telemetry

Typically 12-24 months, anonymised thereafter

Marketing Data

Until consent withdrawn or 3 years of inactivity

Your Rights (GDPR/UK)

Accessobtain a copy of your data

Rectificationcorrect inaccurate data

Erasurerequest deletion

Restrictionlimit processing

Portabilityreceive data in structured format

Objectionobject to processing

To exercise your rights, contact privacy@outlex.ai. We respond within 30 days.

Contact Us

Privacy inquiries

privacy@outlex.ai

General inquiries

hello@outlex.ai

Registered Address: Outlex AI LDA, Rua Gomes Freire 11, 1150-176 Lisbon, Portugal