LexCall.ai
Data Processing Agreement
Last updated: September 16, 2026 · GDPR Article 28
This agreement forms an integral part of the Terms of Service. It is accepted by the firm when creating its account and applies to all processing of personal data carried out by LexCall.ai on its behalf.
1. Parties and roles
Controller: the law firm, lawyer or legal professional holding the account ("the Firm"). It determines the purposes and means of processing the calls received on its line.
Processor: Lifeora, company number BE 0843.008.489, Rue Lieutenant Liedel 44, 1070 Anderlecht, Belgium, publisher of LexCall.ai ("LexCall"). LexCall processes data solely on behalf of and on the instructions of the Firm.
2. Subject matter, nature and purpose
LexCall provides a voice agent that answers phone calls made to the Firm, collects the reason for the call, qualifies the request, books appointments and sends a summary to the Firm. Processing includes: receiving and transcribing calls, automated analysis of the content to produce a summary and qualification, notifications (email, confirmation SMS to the caller), appointment booking in the Firm's calendar, temporary storage in the dashboard.
3. Categories of data and data subjects
- Callers (clients, prospects, third parties): phone number, name, email if provided, call content (transcript, summary, reason, urgency, legal area), appointments.
- Firm members: identity, contact details, configuration data, billing data.
Call content may include information covered by professional secrecy and, occasionally, special categories of data (GDPR Article 9, e.g. criminal proceedings or family situations). The Firm remains responsible for the lawfulness of this processing; LexCall applies the enhanced security measures described in Section 6.
4. Duration
This agreement applies for the whole duration of the use of the service and until the data is deleted in accordance with Section 10.
5. LexCall's obligations
- Process data only on the Firm's documented instructions, including regarding transfers outside the EU, unless required by law (in which case LexCall informs the Firm unless legally prohibited).
- Ensure that persons authorised to process the data are bound by confidentiality. The voice agent gives no legal advice and discloses no information about ongoing matters.
- Implement the security measures in Section 6.
- Comply with Section 7 when engaging sub-processors.
- Assist the Firm in responding to data subject requests (Section 9).
- Assist the Firm with security, breach notification and impact assessment obligations, taking into account the nature of processing and the information available to LexCall.
- Delete or return the data at the end of the service (Section 10).
- Make available the information necessary to demonstrate compliance and allow audits (Section 11).
- Immediately inform the Firm if, in LexCall's opinion, an instruction infringes the GDPR.
6. Security measures (GDPR Article 32)
- Encryption at rest (AES-256-GCM, dedicated keys managed outside the database) of transcripts, summaries, caller names and emails, notes, structured call data, the Firm's address, user phone numbers and calendar access tokens.
- Encryption in transit (TLS) for all exchanges, including with sub-processors; signed webhooks.
- Strict tenant isolation: every request is checked against the data owner; logged and limited administrator access.
- Audit log of sensitive operations (administrator access, deletions, contact detail changes).
- Automatic deletion: transcripts after 12 months, audio recordings after 90 days, handled questions after 6 months; deletion at the voice provider after 90 days.
- Personal data scrubbed from technical logs and error monitoring.
- Encrypted database backups; periodic dependency and security patch reviews.
7. Sub-processors
The Firm gives LexCall general authorisation to engage the sub-processors listed below. LexCall informs the Firm by email of any addition or replacement at least 30 days before it takes effect; the Firm may object by terminating the service free of charge before that date. LexCall imposes on each sub-processor obligations equivalent to this agreement and remains fully liable to the Firm.
| Sub-processor | Location | Purpose | Safeguards |
|---|---|---|---|
| ElevenLabs, Inc. | United States | Voice agent (speech synthesis and recognition, call handling) | Standard Contractual Clauses (SCC); retention limited to 90 days |
| Twilio, Inc. | United States / EU | Telephony (numbers, call routing, SMS) | SCC / Data Privacy Framework |
| Anthropic, PBC | United States | Transcript analysis and summaries | SCC; no retention after processing |
| Google LLC | United States / EU | Calendar (when enabled by the firm), authentication, analytics (with consent) | SCC / Data Privacy Framework |
| Stripe, Inc. | United States / EU | Billing and payments | SCC / Data Privacy Framework |
| Resend, Inc. | United States | Transactional email delivery | SCC |
| Vercel, Inc. | United States / EU (functions run in Paris) | Web application hosting | SCC / Data Privacy Framework |
| Railway Corp. | United States | Application server and database hosting (encrypted) | SCC |
| Functional Software, Inc. (Sentry) | United States / EU | Technical error monitoring (personal data scrubbed) | SCC / Data Privacy Framework |
8. Transfers outside the European Union
Some sub-processors are established in the United States. Transfers rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) and, where applicable, on EU-US Data Privacy Framework certification, supplemented by the encryption described in Section 6.
9. Data subject rights
The Firm can handle most requests itself from its dashboard: viewing and exporting calls, correcting contact records, deleting a call or a contact, deleting the whole account. When a caller's request reaches LexCall directly, LexCall forwards it to the Firm without delay and does not respond on its own initiative unless instructed otherwise by the Firm.
10. End of processing
When the account is closed, all data of the Firm and its callers is permanently deleted within 30 days, except where retention is legally required (billing data). The Firm can export its data from the dashboard before closing.
11. Data breaches and audits
LexCall notifies the Firm of any personal data breach affecting it without undue delay and at the latest 48 hours after becoming aware of it, with the information needed for any notification to the supervisory authority. Once a year, with 30 days' notice, the Firm may request the information necessary to verify compliance with this agreement, or have an audit carried out at its own expense by an independent third party bound by confidentiality.
12. Liability and governing law
Each party is liable for damage resulting from its own breach of the GDPR. This agreement is governed by Belgian law; the courts of Brussels have jurisdiction. Questions about this agreement: raisamine11@gmail.com.