← Legal center

DocVex — Legal

GDPR Compliance

DocVex processes personal data in accordance with the EU General Data Protection Regulation. This page explains your rights, our roles and legal bases, and how to act on any of it.

Last updated: 18 July 2026

1. Our commitment

GDPR as a design constraint, not a checkbox.

DocVex is built in the EU, for professionals whose work depends on confidentiality. We treat the GDPR's principles — lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and accountability — as product requirements. The clearest expression of that is architectural: your project documents never leave your device unless you explicitly invoke a feature that processes them.

2. Controller & processor roles

Who is responsible for what.

DocVex as controller

For your account data (registration details, preferences, support communications, website enrollments), DocVex determines the purposes and means of processing and acts as the data controller. The Privacy Policy is the controller-side notice.

DocVex as processor

For personal data contained in the content your organization manages through DocVex — chat messages, project data, documents you submit to AI features — your organization is the controller and DocVex processes that data only on its instructions, as the processor. Those obligations are set out in the Data Processing Agreement.

3. Legal bases for processing

Article 6 GDPR, applied to DocVex.

  • Contract (Art. 6(1)(b)) — operating your account, projects, chat, notifications, connected mailboxes, and AI features you invoke.
  • Consent (Art. 6(1)(a)) — optional communications such as the Legal Newsfeed email briefing; connecting a Gmail/Outlook mailbox. Consent can be withdrawn at any time.
  • Legitimate interests (Art. 6(1)(f)) — securing the Service, preventing abuse, and diagnosing problems you report. We balance these interests against your rights and do not use this basis for profiling or advertising.
  • Legal obligation (Art. 6(1)(c)) — retaining or disclosing data where the law requires it.

4. Your rights as a data subject

Articles 15–22 GDPR.

  • Access (Art. 15) — obtain confirmation of what personal data we hold about you, and a copy of it.
  • Rectification (Art. 16) — have inaccurate data corrected; most account details can be edited directly in the app.
  • Erasure (Art. 17) — have your account and associated personal data deleted.
  • Restriction (Art. 18) — have processing paused while a dispute about the data is resolved.
  • Portability (Art. 20) — receive the data you provided in a structured, machine-readable format. Note that your project files are already fully portable: they are ordinary files in a folder you control.
  • Objection (Art. 21) — object to processing based on legitimate interests.
  • No automated decision-making (Art. 22) — DocVex makes no automated decisions with legal or similarly significant effects about you. AI features produce suggestions that you review; they do not decide anything about you.

5. Exercising your rights

Self-service first, email always available.

In the app

  • Account → Erase data — signs you out on all devices and clears locally cached data.
  • Account → Delete account — permanently deletes your account and associated personal data.
  • Profile details and preferences are editable directly in Account and Settings.

By email

For any other request — access copies, rectification we can't expose in the app, restriction, objection, portability — write to docvexteam@docvex.ro. We will verify your identity, respond within one month (extendable by two months for complex requests, with notice), and the process is free of charge except for manifestly unfounded or excessive requests.

If your personal data appears in another organization's DocVex project (for example, in a law firm's matter), that organization is the controller — we will refer your request to them and assist as their processor.

6. International transfers

Chapter V safeguards.

Our primary infrastructure runs in the European Union (Ireland). Where a sub-processor operates outside the EEA — notably AI processing in the United States — transfers rely on:

  • the European Commission's adequacy decision for the EU–US Data Privacy Framework, where the provider is certified; and
  • Standard Contractual Clauses (2021/914) with supplementary measures otherwise.

The current sub-processor list, including locations, is maintained in the Data Processing Agreement.

7. Data protection by design & by default

Article 25 in practice.

  • Local-first files — project documents never touch our servers in normal operation; there is nothing to breach, subpoena, or leak from our side.
  • Minimisation — we collect account data the Service needs, and AI features receive only the content you select, only when you invoke them.
  • Access control by default — row-level security enforces project membership at the database layer; roles and capabilities restrict actions within a project.
  • Encryption — in transit everywhere, at rest for stored data, with additional application-layer encryption for mailbox tokens.
  • User-controlled deletion — erase and delete actions are self-service in the app, not a support ticket.

8. Personal data breach notification

Articles 33–34.

If a personal data breach occurs, we will assess it without delay, notify the competent supervisory authority within 72 hours where the breach is likely to result in a risk to individuals, notify affected users without undue delay where the risk is high, and inform controller customers without undue delay so they can meet their own obligations. We document all breaches and remediation regardless of notification thresholds.

9. Supervisory authority

Your right to complain.

You may lodge a complaint with a supervisory authority at any time, in particular in the EU member state of your residence or workplace. For Romania, the authority is the ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, B-dul G-ral. Gheorghe Magheru 28-30, Bucharest (dataprotection.ro).

10. Contact

Data-protection questions.

For all GDPR matters, contact docvexteam@docvex.ro. We are not currently required to appoint a Data Protection Officer (Art. 37); if that changes, this page will name the DPO.

The operating legal entity's registered details will be added to this page upon incorporation. This document has not yet been reviewed by counsel and does not constitute legal advice.