Leximise legal

Data Processing Agreement

A public overview of the processor commitments offered to Leximise customers.

Last updated: 20 August 2026

1. Status of this page

This page is a public DPA overview, not an executed agreement. The binding DPA must identify the customer, services, processing details, security measures and approved sub-processors and must be incorporated into or signed with the service agreement.

2. Roles and scope

Where Leximise processes personal data on a customer's documented instructions, the customer is controller and Leximise is processor. The subject matter is provision of the subscribed compliance and/or training services for the subscription term.

3. Processing details

  • Data subjects may include customer users, employees, learners, auditors, consultants and invited collaborators.
  • Data may include identity, contact, organisation, role, training, certificate, activity, assessment and evidence-related personal data.
  • Purposes include hosting, access management, training delivery, reporting, support, security, backup and authorised integrations.

4. Documented instructions and confidentiality

Leximise processes customer personal data only on documented instructions, including instructions inherent in use of the configured service, unless Union or Member State law requires otherwise. Authorised personnel are bound by confidentiality.

5. Security measures

The executed DPA should attach current technical and organisational measures covering identity and access management, least privilege, encryption, logging, backup, secure development, vulnerability management, incident response, business continuity, personnel controls and periodic review.

6. Sub-processors

Leximise may appoint vetted sub-processors under written terms that provide equivalent data-protection obligations. The executed DPA must specify the notice and objection process and link to a maintained sub-processor list.

7. International transfers

Restricted transfers use an applicable adequacy decision, Standard Contractual Clauses or another lawful mechanism, plus supplementary measures where required.

8. Assistance and incidents

Taking account of the nature of processing and available information, Leximise provides reasonable assistance with data-subject requests, security obligations, DPIAs and supervisory-authority consultations. Leximise notifies the customer without undue delay after becoming aware of a personal data breach affecting customer data and provides available relevant information.

9. Return, deletion and audit

At the customer's choice, personal data is returned or deleted after service termination, unless law requires retention, subject to documented backup cycles. Leximise provides information needed to demonstrate Article 28 compliance and supports proportionate audits under agreed confidentiality, scope and frequency terms.

10. Obtain the executable DPA

To review and sign the current DPA, including its processing schedule, security annex and sub-processor list, contact [email protected]. Do not represent this webpage as a signed DPA.