DocVex — Legal
DocVex processes personal data in accordance with the EU General Data Protection Regulation. This page explains your rights, our roles and legal bases, and how to act on any of it.
Last updated: 18 July 2026
GDPR as a design constraint, not a checkbox.
DocVex is built in the EU, for professionals whose work depends on confidentiality. We treat the GDPR's principles — lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and accountability — as product requirements. The clearest expression of that is architectural: your project documents never leave your device unless you explicitly invoke a feature that processes them.
Who is responsible for what.
For your account data (registration details, preferences, support communications, website enrollments), DocVex determines the purposes and means of processing and acts as the data controller. The Privacy Policy is the controller-side notice.
For personal data contained in the content your organization manages through DocVex — chat messages, project data, documents you submit to AI features — your organization is the controller and DocVex processes that data only on its instructions, as the processor. Those obligations are set out in the Data Processing Agreement.
Article 6 GDPR, applied to DocVex.
Articles 15–22 GDPR.
Self-service first, email always available.
For any other request — access copies, rectification we can't expose in the app, restriction, objection, portability — write to docvexteam@docvex.ro. We will verify your identity, respond within one month (extendable by two months for complex requests, with notice), and the process is free of charge except for manifestly unfounded or excessive requests.
If your personal data appears in another organization's DocVex project (for example, in a law firm's matter), that organization is the controller — we will refer your request to them and assist as their processor.
Chapter V safeguards.
Our primary infrastructure runs in the European Union (Ireland). Where a sub-processor operates outside the EEA — notably AI processing in the United States — transfers rely on:
The current sub-processor list, including locations, is maintained in the Data Processing Agreement.
Article 25 in practice.
Articles 33–34.
If a personal data breach occurs, we will assess it without delay, notify the competent supervisory authority within 72 hours where the breach is likely to result in a risk to individuals, notify affected users without undue delay where the risk is high, and inform controller customers without undue delay so they can meet their own obligations. We document all breaches and remediation regardless of notification thresholds.
Your right to complain.
You may lodge a complaint with a supervisory authority at any time, in particular in the EU member state of your residence or workplace. For Romania, the authority is the ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, B-dul G-ral. Gheorghe Magheru 28-30, Bucharest (dataprotection.ro).
Data-protection questions.
For all GDPR matters, contact docvexteam@docvex.ro. We are not currently required to appoint a Data Protection Officer (Art. 37); if that changes, this page will name the DPO.
The operating legal entity's registered details will be added to this page upon incorporation. This document has not yet been reviewed by counsel and does not constitute legal advice.