LexCall.aiLexCall.ai

LexCall.ai

Data Processing Agreement

Last updated: September 16, 2026 · GDPR Article 28

This agreement forms an integral part of the Terms of Service. It is accepted by the firm when creating its account and applies to all processing of personal data carried out by LexCall.ai on its behalf.

1. Parties and roles

Controller: the law firm, lawyer or legal professional holding the account ("the Firm"). It determines the purposes and means of processing the calls received on its line.

Processor: Lifeora, company number BE 0843.008.489, Rue Lieutenant Liedel 44, 1070 Anderlecht, Belgium, publisher of LexCall.ai ("LexCall"). LexCall processes data solely on behalf of and on the instructions of the Firm.

2. Subject matter, nature and purpose

LexCall provides a voice agent that answers phone calls made to the Firm, collects the reason for the call, qualifies the request, books appointments and sends a summary to the Firm. Processing includes: receiving and transcribing calls, automated analysis of the content to produce a summary and qualification, notifications (email, confirmation SMS to the caller), appointment booking in the Firm's calendar, temporary storage in the dashboard.

3. Categories of data and data subjects

  • Callers (clients, prospects, third parties): phone number, name, email if provided, call content (transcript, summary, reason, urgency, legal area), appointments.
  • Firm members: identity, contact details, configuration data, billing data.

Call content may include information covered by professional secrecy and, occasionally, special categories of data (GDPR Article 9, e.g. criminal proceedings or family situations). The Firm remains responsible for the lawfulness of this processing; LexCall applies the enhanced security measures described in Section 6.

4. Duration

This agreement applies for the whole duration of the use of the service and until the data is deleted in accordance with Section 10.

5. LexCall's obligations

  • Process data only on the Firm's documented instructions, including regarding transfers outside the EU, unless required by law (in which case LexCall informs the Firm unless legally prohibited).
  • Ensure that persons authorised to process the data are bound by confidentiality. The voice agent gives no legal advice and discloses no information about ongoing matters.
  • Implement the security measures in Section 6.
  • Comply with Section 7 when engaging sub-processors.
  • Assist the Firm in responding to data subject requests (Section 9).
  • Assist the Firm with security, breach notification and impact assessment obligations, taking into account the nature of processing and the information available to LexCall.
  • Delete or return the data at the end of the service (Section 10).
  • Make available the information necessary to demonstrate compliance and allow audits (Section 11).
  • Immediately inform the Firm if, in LexCall's opinion, an instruction infringes the GDPR.

6. Security measures (GDPR Article 32)

  • Encryption at rest (AES-256-GCM, dedicated keys managed outside the database) of transcripts, summaries, caller names and emails, notes, structured call data, the Firm's address, user phone numbers and calendar access tokens.
  • Encryption in transit (TLS) for all exchanges, including with sub-processors; signed webhooks.
  • Strict tenant isolation: every request is checked against the data owner; logged and limited administrator access.
  • Audit log of sensitive operations (administrator access, deletions, contact detail changes).
  • Automatic deletion: transcripts after 12 months, audio recordings after 90 days, handled questions after 6 months; deletion at the voice provider after 90 days.
  • Personal data scrubbed from technical logs and error monitoring.
  • Encrypted database backups; periodic dependency and security patch reviews.

7. Sub-processors

The Firm gives LexCall general authorisation to engage the sub-processors listed below. LexCall informs the Firm by email of any addition or replacement at least 30 days before it takes effect; the Firm may object by terminating the service free of charge before that date. LexCall imposes on each sub-processor obligations equivalent to this agreement and remains fully liable to the Firm.

Sub-processorLocationPurposeSafeguards
ElevenLabs, Inc.United StatesVoice agent (speech synthesis and recognition, call handling)Standard Contractual Clauses (SCC); retention limited to 90 days
Twilio, Inc.United States / EUTelephony (numbers, call routing, SMS)SCC / Data Privacy Framework
Anthropic, PBCUnited StatesTranscript analysis and summariesSCC; no retention after processing
Google LLCUnited States / EUCalendar (when enabled by the firm), authentication, analytics (with consent)SCC / Data Privacy Framework
Stripe, Inc.United States / EUBilling and paymentsSCC / Data Privacy Framework
Resend, Inc.United StatesTransactional email deliverySCC
Vercel, Inc.United States / EU (functions run in Paris)Web application hostingSCC / Data Privacy Framework
Railway Corp.United StatesApplication server and database hosting (encrypted)SCC
Functional Software, Inc. (Sentry)United States / EUTechnical error monitoring (personal data scrubbed)SCC / Data Privacy Framework

8. Transfers outside the European Union

Some sub-processors are established in the United States. Transfers rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) and, where applicable, on EU-US Data Privacy Framework certification, supplemented by the encryption described in Section 6.

9. Data subject rights

The Firm can handle most requests itself from its dashboard: viewing and exporting calls, correcting contact records, deleting a call or a contact, deleting the whole account. When a caller's request reaches LexCall directly, LexCall forwards it to the Firm without delay and does not respond on its own initiative unless instructed otherwise by the Firm.

10. End of processing

When the account is closed, all data of the Firm and its callers is permanently deleted within 30 days, except where retention is legally required (billing data). The Firm can export its data from the dashboard before closing.

11. Data breaches and audits

LexCall notifies the Firm of any personal data breach affecting it without undue delay and at the latest 48 hours after becoming aware of it, with the information needed for any notification to the supervisory authority. Once a year, with 30 days' notice, the Firm may request the information necessary to verify compliance with this agreement, or have an audit carried out at its own expense by an independent third party bound by confidentiality.

12. Liability and governing law

Each party is liable for damage resulting from its own breach of the GDPR. This agreement is governed by Belgian law; the courts of Brussels have jurisdiction. Questions about this agreement: raisamine11@gmail.com.

LexCall.ai — Lifeora, BCE 0843.008.489 · raisamine11@gmail.com