LEXchat GmbH
Data protection matters to us. We process your personal data with great care and in accordance with the applicable statutory provisions.
This privacy policy is based on the revised Swiss Federal Act on Data Protection (FADP, in force since 1 September 2023) and its implementing ordinance (DPO). Where applicable in an individual case, it also takes the European General Data Protection Regulation (GDPR) into account.
It applies to this website (lexchat.ch) and to LEXchat Law, our offering for professional users in Switzerland — law firms, in-house legal departments, legal expenses insurers and comparable professional organisations (sec. 1.2 of the GTC). Section 13 additionally applies to the processing of client matter and case data in LEXchat Law.
This privacy policy discharges our statutory information duties. It is not part of the contract and does not create assurances going beyond the law; the contractual obligations follow from the GTC and the data processing agreement.
The controller for the processing of personal data within the meaning of the FADP is:
LEXchat GmbH
Obere Burghalde 22, 8225 Siblingen, Switzerland
E-mail: contact@lexchat.ch
We are available at this address for any data protection matter.
When you visit our website or open the platform, the following technical data is recorded:
We do not generate any persistent device identifier that would allow recognition across devices, and we do not read out any characteristics of your device beyond the list above.
When you use LEXchat Law, we process the sets of facts and the attached documents entered by the Customer in order to produce preliminary analyses from them. This content may contain sensitive personal data relating to the Customer's clients or to the individuals concerned.
The Customer using the service decides which client matter and case data is entered. It is the controller for that data; we process it exclusively on its behalf (see section 13).
For the signed-in portals we operate our own identity management based on Zitadel, which we run ourselves on our infrastructure in Switzerland (see section 5). No external identity provider is involved; your passwords and other authentication secrets do not leave our infrastructure. Your login name or e-mail address may, by contrast, be contained in the operational logs under section 7.
We store your e-mail address, a login name and — where you provide it — your name. Passwords are stored exclusively as a cryptographic hash. Session and token information is stored in your browser so that you remain signed in.
For contract formation, billing and payment processing we process in particular the company name, billing address, business identification number (UID), the plan selected, the number of users, the volume of use, the invoice amount, the payment status and transaction references. Card data is processed directly by our payment service provider and is never stored on our servers; we do not receive a full card number (see section 8).
If you contact us — by e-mail, via a form or as part of an access request — we process your contact details and the content of the correspondence, including any information you provide for troubleshooting. This also covers the details of contact persons at customers and prospective customers.
Usage and access logs arise for the purposes of operation, troubleshooting, traceability and prevention of abuse, in particular sign-in events, processing runs, error messages and information on the volume of use. Section 7 sets out which of this data is transmitted to our monitoring provider.
We document consents and approvals granted — in particular consent to being named as a reference and to logo use under section 21 of the GTC, and your consent to product and offer e-mails under section 8, in each case with the time and the version of the consent text — as well as your language and display preferences and the document versions incorporated at contract formation.
On the relationship between the FADP and the GDPR. The Swiss FADP does not require private controllers to have a legal basis for every processing operation in the manner of Art. 6 GDPR. We process personal data in compliance with the FADP processing principles (lawfulness, good faith, proportionality, purpose limitation, accuracy, security). Where a processing operation could constitute an infringement of personality, we rely where necessary on consent, on an overriding private or public interest, or on a statutory basis (Art. 30 et seq. FADP). Where the GDPR applies, we additionally state the legal basis under Art. 6 or Art. 9 GDPR.
We process your personal data for the following purposes:
No own purposes for client matter content. We do not use client matter or customer content for our own product, quality or training purposes. Pseudonymised customer content remains personal data; it is processed exclusively to perform the contract and within the documented instructions of the Customer.
The LEXchat Law application and database run on servers that we administer ourselves. The production platform is located in a data centre in Switzerland (Infomaniak Network SA, Geneva; residency CH.CH under the notation in section 12).
All persistent platform data of the production environment — matter files, sets of facts, user accounts and identity management — remains in Switzerland. No replication of production data to regions outside Switzerland takes place.
Encrypted backup copies of the production databases are held with a second Swiss provider independent of the platform (Akenes SA (Exoscale), Lausanne; data centre in Geneva; residency CH.CH). The backups are encrypted on our systems before transfer; the provider at no time has access to plaintext data or key material. Retention periods: section 14.
Three components run in Germany (Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen):
Further information: Hetzner privacy policy.
To answer your queries we use language models and embedding models from external providers. Which model is used depends on the portal and on the configuration selected. The following may be used:
The following applies to this processing:
We have concluded corresponding contractual arrangements (data processing agreements under Art. 9 FADP / Art. 28 GDPR) with all processors, ensuring an adequate level of data protection.
For each provider engaged we maintain an internal record of: the contracting party and the specific legal entity, the product and model, whether training is excluded contractually or required an opt-out, the retention period, the processing region, the sub-processors used, the basis for any transfer to the USA, and the date of the last review. Customers receive this information on request; for processing on their behalf it is additionally set out in Annex B to the data processing agreement.
To monitor service quality and for troubleshooting, we transmit structured log data to Grafana Labs (Raintank, Inc. dba Grafana Labs, New York, USA) via their Grafana Cloud platform; the data is stored in a data centre in the EU. The following may be transmitted:
The following applies to this processing:
The legal basis is our overriding legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR). Further information: Grafana Labs privacy policy.
Background. Earlier versions of this policy named input extracts (query text, truncated to a few hundred characters) and the login name here, because our logs did in fact contain both. We are aware that even a few hundred characters of a set of facts from a legal matter may contain information covered by professional secrecy. Both have since been removed: in normal operation, input content has been replaced by key figures, and the login name and matter file designation by technical identifiers. What remains is the diagnostic mode described above. Customers that do not want any content in the logs even for that purpose should contact contact@lexchat.ch.
Payment processing. Card payments and comparable transactions are handled by Stripe (Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin, Ireland). Card data is captured directly in Stripe's PCI-DSS certified payment form and is never stored on our servers. We receive the payment status, amount, product and a transaction reference. Further information: Stripe privacy policy. Where payment is made against invoice under section 12.1 of the GTC, no payment service provider is involved.
E-mail delivery. We send our e-mails via the SMTP service of Infomaniak (Infomaniak Network SA, Geneva, Switzerland — the same provider as in section 5). This concerns three kinds of message:
Your e-mail address and the content of the message concerned are transmitted in the process; we do not send any other marketing e-mails. The delivery service is therefore located in Switzerland.
On our public website we measure audience figures with Plausible Analytics (Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia). The analysis takes place on servers within the European Union (Germany).
Plausible works without cookies and without cross-device recognition. The following is recorded and evaluated exclusively in aggregated form:
The IP address itself is neither stored nor logged; no information is stored on or read from your device. No profiling takes place. Plausible receives the technical information required for audience measurement as a processor; the data is not used for advertising, cross-device tracking or the provider's own profiling purposes, and is not combined with your LEXchat account.
Loading of the measurement script. The measurement script is loaded from Plausible's servers when the page is opened. For technical reasons, the technical data described in section 3.1 — in particular the IP address, browser information and the time of access — is transmitted to Plausible in the process. We do not use any other external providers of scripts, fonts, libraries or content (content delivery networks) on our website; all other components of the page are served from our own servers (section 5).
The legal basis is our overriding legitimate interest in designing our offering to meet demand (Art. 6(1)(f) GDPR). Since no information is stored on or retrieved from your device, no consent is required for this. Further information: Plausible privacy.
No audience measurement takes place in the signed-in area of LEXchat Law.
We use exclusively technically necessary cookies and storage entries that are required to operate the platform. We do not use marketing, advertising or cross-device tracking cookies. Should we do so in future, we will obtain your consent beforehand.
In detail — category, provider, purpose, duration:
No cookies are set and no information is stored on or read from your device for audience measurement on the public website (section 9).
Your personal data is disclosed to third parties only in the following cases. We distinguish recipients by their role under data protection law:
We do not sell personal data to third parties.
The production platform itself is operated in Switzerland (section 5). For each recipient we set out below: the legal entity and its seat, the function, the categories of data transmitted, whether data is stored permanently or only processed transiently, the actual processing region, and the basis for the transfer. The seat of the entity and the processing region are two different pieces of information; where they diverge, both are stated. In addition, each entry states the residency as the code head office.processing location (head office = seat of the parent company; a contracting company in Ireland or Luxembourg does not change this), for example CH.CH, US.EU, US.US or DE.DE; for the platform operated in Switzerland and its backup copies (section 5) the code is CH.CH. The customer portal shows the same code with every choice of model and region.
We make the list of sub-processors of the recipients named available to Customers on request; for processing on their behalf it forms part of Annex B to the data processing agreement.
The USA has an adequate level of data protection recognised by the Swiss Federal Council only to the extent that the US recipient concerned is effectively certified under the Swiss–U.S. Data Privacy Framework and the category of data in question is covered by that certification. We verify the certification status of the specific recipient before onboarding, thereafter regularly, at least annually, and on an event-driven basis — in particular where the certification list or the provider's terms change.
Where reliance on the Swiss–U.S. Data Privacy Framework is not possible, we use appropriate safeguards, in particular standard data protection clauses adapted to Swiss data protection law under Art. 16 et seq. FADP or Art. 46 GDPR and, where necessary, supplementary protective measures. Where standard data protection clauses are used, we also assess the specific circumstances of the transfer.
Where a Customer — a law firm, an in-house legal department, a legal expenses insurer or a comparable professional organisation (sec. 1.2 of the GTC) — uses our AI-assisted case analysis for its own client matter or case work, the data of the individuals concerned is processed exclusively on that Customer's behalf. In that case the Customer using the service is the controller; we act as processor on the basis of a corresponding agreement.
Visibility within a shared customer account. Where LEXchat provides a Customer with a shared account for several authorised persons (law-firm account), the dossiers, facts, documents, analyses and research held in that account are visible to all authorised persons of that account; within such an account there is no restriction to individual users. This reflects how a law firm works: professional secrecy applies to everyone working there, and both substitution and conflict checking presuppose access to the mandate data. The Customer decides who is granted access to its account and with which role, and manages that access; material actions are logged per account. Details are governed by the data processing agreement (sec. 2.7 there).
If you come into contact with us as the client of a law firm through that firm's LEXchat access, the data protection notices of your firm apply to you primarily. The same applies mutatis mutandis if you are affected through the access of another Customer — for example an in-house legal department or a legal expenses insurer. Section 16 governs the exercise of your rights.
We store your data only for as long as is necessary for the respective purposes or required by law:
Deletion. If you request the deletion of your data, or delete a matter file or your account, we implement this in the production system without delay. Where statutory retention duties exist, the data concerned is blocked for the duration of the retention period and not processed further.
We take appropriate technical and organisational measures to protect your data against unauthorised access, loss and manipulation (encryption of transmission channels, encryption at rest of the database containing the client matter and case data, client-side encrypted backup copies locked against premature deletion, access restrictions, hardening of systems).
To the extent that we process as controller — in particular account, contract, billing, contact and website data — we assess a breach of data security under Art. 24 FADP and make the required notifications to the Federal Data Protection and Information Commissioner (FDPIC) and provide the required information to the individuals concerned.
To the extent that we process client matter or other customer data as processor, we inform the responsible Customer without delay, where possible within 24 hours of becoming aware, of a breach of data security and provide it with the information required for risk assessment and notification. In that case, notifications to authorities and information to the individuals concerned are as a rule made by the Customer, unless applicable law requires otherwise. The details are governed by sec. 8.5 of the GTC and sec. 9.3 of the data processing agreement.
For data that we process for our own purposes — in particular account, contract, billing, contact and website data — you may assert your rights directly against LEXchat:
For client matter data, case facts and matter file data we act exclusively as the processor of the Customer using the service. Such requests must as a rule be addressed to the Customer concerned. If we receive such a request, we forward it to that Customer without delay — where this is permissible and the responsible Customer can be identified — and process the data concerned only on that Customer's instructions. Without such an instruction we may neither provide access to, nor rectify or erase, that data; this is required by the rights of other parties to the proceedings and by the Customer's retention duties — and, where the Customer is a law firm, additionally by professional secrecy.
To exercise the rights described in the first paragraph, please contact us at contact@lexchat.ch. We may require proof of identity before providing access.
If you consider that the processing of your personal data infringes applicable data protection law, you may report a possible data protection infringement to the Federal Data Protection and Information Commissioner (FDPIC): www.edoeb.admin.ch. The FDPIC is a supervisory authority; it does not rule on civil claims.
Civil claims — in particular for rectification, erasure, injunctive relief or damages — must be asserted against the controller or before the competent court. Where the GDPR applies, there is additionally a right to lodge a complaint with the competent supervisory authority in the EU/EEA.
We reserve the right to amend this privacy policy at any time, in particular where our services or the legal framework change. The current version is available on our website; the version in force at the time of the processing is authoritative. For Customers, changes to the processors, AI providers or processing regions used are additionally governed by the data processing agreement.
v1.1 (Website) — 21 September 2026