GDPR COMPLIANCE
Last Updated
August 5, 2026
1. Our Commitment
Legalica OÜ is established in Estonia, and the General Data Protection Regulation (EU) 2016/679 ("GDPR") is the baseline standard for everything we process — for all users worldwide, not only those in the EU. This page summarizes how we comply. The binding document is the Master Privacy & Data Governance Policy, which incorporates our Data Processing Addendum (DPA), Cookie Policy and retention schedules.
2. Who Is Responsible for Your Data
| Field | Detail |
|---|---|
| Data Controller | Legalica OÜ |
| Legal form | Private limited company (osaühing), Republic of Estonia |
| Registered office | Ahtri tn 12, 10151 Tallinn, Estonia (temporary address, pending completion of company formation) |
| Registration number | ************* |
| VAT number | ************* |
| Data protection contact | privacy@legalica.app |
Lead supervisory authority: Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate), Tatari 39, 10134 Tallinn, Estonia — info@aki.ee / aki.ee. You may also complain to the supervisory authority of your place of habitual residence.
3. Controller and Processor Roles
- Legalica as Controller: account management, billing relationship, security, service communication, and anonymized analytics.
- Legalica as Processor (Art. 28): when we process User Input, uploaded documents and AI Output on behalf of a Workspace Owner (typically a law firm or company). In that case the Workspace Owner is the Controller and our Data Processing Addendum governs — including documented-instructions processing, confidentiality, subprocessor governance with 14-day change notice, audit rights, breach notification within 36 hours, and deletion or return of data on termination.
- Creem (Merchant of Record): processes buyer payment data as an independent controller under its own privacy notice. Legalica never stores full card numbers.
4. Lawful Bases and Key Principles
- Processing is grounded in GDPR Art. 6: contract performance (accounts, AI responses, billing), legitimate interest (security, fraud prevention, anonymized improvement), consent (non-essential cookies, marketing), and legal obligation (tax and accounting records).
- We do not intentionally collect special-category data (Art. 9) or criminal-conviction data (Art. 10). Such data may appear only if you include it in User Input; you are responsible for your lawful basis.
- No sale of personal data. No advertising profiling. No use of Customer Data to train AI models — contractually prohibited across the entire AI Cascade.
- No automated decision-making producing legal or similarly significant effects within the meaning of Art. 22. AI Output is decision support subject to mandatory human review.
5. Your Rights and How to Exercise Them
| Right | GDPR Article | How to Exercise |
|---|---|---|
| Access | Art. 15 | Email privacy@legalica.app |
| Rectification | Art. 16 | Account settings or privacy@legalica.app |
| Erasure | Art. 17 | privacy@legalica.app or account deletion |
| Restriction of processing | Art. 18 | privacy@legalica.app |
| Data portability | Art. 20 | privacy@legalica.app (structured, machine-readable export) |
| Objection | Art. 21 | privacy@legalica.app |
| Withdraw consent | Art. 7(3) | Cookie/consent settings or privacy@legalica.app |
| Lodge a complaint | Art. 77 | Andmekaitse Inspektsioon (aki.ee) or your local supervisory authority |
We respond within one month (GDPR Art. 12(3)) (extendable to 60 for complex requests, with notice). Identity verification is required before processing a request. Exercising your rights is free of charge, subject to Art. 12(5).
6. International Transfers
- Primary storage and processing: EU (Google Cloud europe-west3, Frankfurt).
- US endpoints (certain processing and Groq fallback): SCC 2021/914 and the EU-US Data Privacy Framework.
- China fallback (Moonshot AI / Kimi): no adequacy decision; contractual safeguards and zero-retention apply; residual risks and the EU-only routing option are described in the Subprocessor List, Section 4.
- A Transfer Impact Assessment summary is available on request at privacy@legalica.app.
7. Security and Breach Handling
Technical and organizational measures are described in detail in the Privacy Policy §11.3 and on the Security Details page: TLS 1.3 in transit, AES-256 at rest, least-privilege access, MFA, audit logging, and DDoS mitigation via Google Cloud Armor.
In the event of a personal data breach: we notify the competent supervisory authority within 72 hours where required (Art. 33), inform affected data subjects without undue delay where required (Art. 34), and notify Controllers within 36 hours under the DPA.
8. DPIA, DPO and Accountability
- DPIA (Art. 35): a Data Protection Impact Assessment covering large-scale AI processing and KYC tooling is being finalized ahead of full production launch and will thereafter be maintained and updated before material changes. A summary will be available on request.
- Data protection contact: privacy@legalica.app. Should a formal Data Protection Officer (Art. 37) be appointed, their details will be published here and registered with Andmekaitse Inspektsioon.
- Records of processing (Art. 30): being compiled as part of the launch compliance documentation and will be available to supervisory authorities.
- Subprocessors: the live register is at /trust/subprocessors with 14-day advance change notice.
9. Related Documents
- Master Privacy & Data Governance Policy (incl. DPA, Cookie Policy, retention)
- Subprocessor List
- Security Details
- Terms of Service