Every section opens with an “In short” summary in plain language. The summaries are reading aids — if a summary and the full text ever disagree, the full text is what binds.
Who we are
LexAPI is run by Arieta Labs Ltd, a UK company, and hosted in the EU. For anything in this notice, email [email protected].
LexAPI is operated by Arieta Labs Ltd (“we”, “us”), a private limited company registered in England and Wales under company number 16629785, with its registered office at 128 City Road, London, EC1V 2NX, United Kingdom. We run lex-api.com — a REST API, MCP server and dashboard for European legal data — on infrastructure in the European Union.
For the personal data described in this notice, Arieta Labs Ltd is the data controller. You can reach us about anything privacy-related at [email protected].
What we collect
Your email, an optional name, a hashed password, billing status, and technical logs of your API usage — including IP addresses and, for semantic search, the query text.
Account data. When you register we store:
- Your email address and an optional display name
- Your password — stored only as a bcrypt hash, never in plain text
- Email-verification status and your marketing / digest email preferences
- If you enable two-factor authentication: your TOTP secret (encrypted at rest) and backup codes (stored as one-way hashes)
- A first-touch attribution note (for example a
?ref=or UTM tag, or the referring site) recording how you found us
Billing data. Payments are handled by Stripe. Your card details go directly to Stripe and never touch our servers. We store your plan, subscription status, invoicing reference and a credit ledger — an audit trail of every credit your account earns and spends.
Usage data. Every API request is logged with the endpoint, method, status code, response time, IP address and user agent. Semantic searches are additionally logged with the query text you sent, so we can meter credits, debug relevance and investigate abuse. If you register webhooks, we keep delivery logs (payloads sent and responses received from your endpoint).
Correspondence. If you email support or use the sales contact form, we receive what you send us (the form asks for name, email and company) and use it to reply.
What we don’t do
No data sales, no ad networks, no tracking cookies — and your search queries are processed on our own EU infrastructure, not sent to third-party AI providers.
- We do not sell, rent or trade personal data. To anyone. Ever.
- We do not run advertising networks or share data with ad-tech companies.
- We do not send your search queries to third-party AI providers. Semantic search runs on our own EU-hosted infrastructure (
semantic.lex-api.com). - We do not store passwords, two-factor secrets or backup codes in a readable form.
How we use your data
To run the service, meter your credits, bill you, keep the platform safe, and send you emails you asked for.
- Providing the service — authenticating you, serving API responses, running your webhooks and showing your dashboard
- Metering and billing — counting credits against your plan and processing subscription payments through Stripe
- Security and abuse prevention — rate limiting, bot protection at sign-up and sign-in (Cloudflare Turnstile), and investigating misuse using the request logs described above
- Transactional email — verification, password reset, billing and credit-usage notices, and security alerts
- Product email — updates and digests, only per your opt-in preferences; every message includes an unsubscribe link and you can change preferences in your dashboard at any time
- Aggregate analytics — understanding overall traffic and feature usage; see §5 for exactly what runs in your browser
Our legal bases under the GDPR are performance of contract (running the service), legitimate interests (security, abuse prevention, service improvement), consent (marketing email) and legal obligation (financial records).
Who we share data with
A short list of processors we need to run the service — Stripe, SendGrid, Cloudflare and our EU hosting provider. Nobody else, unless the law compels us.
| Processor | Purpose | What they see |
|---|---|---|
| Stripe | Payments & subscriptions | Name, email, card details (entered directly with Stripe), invoices |
| SendGrid (Twilio) | Transactional & product email | Email address, name, message content |
| Cloudflare | Turnstile bot protection on auth forms | IP address, browser signals during the challenge |
| Hetzner | Hosting (EU data centres) | Hosts our servers and database; all data listed in §2 |
Semantic search is processed by our own service at semantic.lex-api.com, on EU infrastructure we operate — it is not a third party.
Beyond that, we disclose personal data only if validly required by law (for example a court order), or — should LexAPI ever be part of a merger or acquisition — to a successor bound by this notice. We would tell you before that happened.
Where your data lives
Primary infrastructure is in the EU. Stripe, SendGrid and Cloudflare may process some data outside the EEA under approved transfer safeguards.
Our servers and database run in European Union data centres (Hetzner). That is where your account data, usage logs and credit ledger live.
Our operator, Arieta Labs Ltd, is in the United Kingdom. The UK holds a European Commission adequacy decision, so personal data moves between the EU and the UK with its protection intact.
Stripe, SendGrid and Cloudflare are global companies and may process some data outside the European Economic Area. Where they do, transfers rely on the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
How long we keep it
For the life of your account. Deleting your account erases everything at once — only Stripe’s invoices survive, because tax law says they must.
We keep your account data, usage logs, search logs and credit ledger for as long as your account exists. Usage and search logs are kept for the life of the account because they are our billing evidence and our abuse-investigation trail.
When your account is deleted (§9), all of it is erased together, immediately. Two things outlive deletion:
- Invoices and payment records held by Stripe — retained for the statutory financial-record periods that apply to us
- Anonymous operational metrics (for example service-uptime samples, which are pruned after ~92 days) that contain no personal data
Deletion & your rights
Delete your account yourself, from the dashboard, effective immediately and irreversibly. GDPR rights apply — and we extend them to everyone, wherever you live.
Self-service deletion. You can delete your account from your dashboard at any time. We re-verify your password (and two-factor code, if enabled), cancel any active subscription, and then permanently erase your account and everything attached to it — API keys, usage logs, search logs, webhooks and delivery history, credit ledger, tokens. There is no grace period and no recovery: deletion is immediate and irreversible.
Under the EU and UK GDPR you also have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate data
- Erasure — beyond self-service deletion, ask us to erase specific data
- Restriction and objection — limit or object to particular processing
- Portability — receive your data in a structured, machine-readable format
- Withdraw consent — for example, unsubscribe from product email at any time
Write to [email protected] and we will respond within 30 days. We apply these rights to all users, wherever you are — including equivalent rights under laws such as the California Consumer Privacy Act. You also have the right to lodge a complaint with a supervisory authority — ours is the UK Information Commissioner’s Office (ICO), and if you are in the EU you can equally complain to your local data protection authority.
Data processing for your business (DPA)
LexAPI mostly serves you public legal data, so there is usually little personal data processed on your behalf. If your compliance team needs a signed DPA, ask.
For your account data, we act as an independent controller under this notice. The content you retrieve through the API is published European Union law — public documents, not personal data you entrust to us.
Some usage can involve us processing data on your behalf — for example if your search queries or webhook configurations contain personal data you control. For customers whose compliance process requires a countersigned data processing agreement covering that processing, we offer one: contact [email protected].
Children
LexAPI is a professional tool for adults. Not for children.
The service is intended for professional use by people aged 18 or over. We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will delete it.
Changes to this notice
If we change something that matters, we’ll email you before it takes effect.
We will update this notice as the service evolves. For material changes — a new processor, a new category of data, a changed retention rule — we will notify you by email or by a prominent notice in the dashboard before the change takes effect. The “Last updated” date at the top always tells you when this text last changed.
Questions about this notice or our data practices: [email protected]. General support: [email protected]. See also our Terms of Service.
Anything unclear? We answer legal and privacy questions at [email protected] — usually within two business days.
Terms of Service