Compliance workflows with traceable AI support.
From GDPR requests to contract and vendor review: Smart Legal Pro provides a clear, auditable workflow with exports and escalation paths.
Start for free
- Law by country
- GDPR-compliant
- No AI training
- PII masking
- Lawyer handover
- Seven languages
Anyone responsible for compliance assesses a new tool first for what is wrong with it. Where does the data sit, who can see it, how long is it kept, and what happens when someone requests access or demands deletion.
This page answers that without selling. The application and database are in the EU, transfers are encrypted, every table is access-restricted row by row, personal data is masked before it reaches the AI provider, and content is not used to train models. Each of these statements is set out in full in an actual legal document, linked below.
Equally important is what we do not claim. There is no ISO or SOC 2 certification, no two-factor login for end users and no end-to-end encryption at document level. That is stated explicitly below — so you do not have to discover it during your own assessment.
What is in place operationally
Four building blocks that separate an AI chat from an auditable workflow.
GDPR and contract context in one place
Documents, legal questions and follow-up communication stay together instead of tool silos.
Retests when facts change
New information can be incorporated traceably and reassessed.
Auditable exports
Results as structured evidence for internal sign-off and external audits.
Security and roles model
EU hosting, RLS, PII masking and clear responsibility boundaries for production use.
- Legal questions without a document
- Chat with follow-ups in the matter
- Analysis, exports, lawyer handover
- Writing assistant & templates
We do not promise certifications we do not hold.
Access and deletion as a feature, not a mailbox process
Subject access under Articles 15 and 20 GDPR runs inside the account itself: a structured file spanning every area, with no ticket and no waiting time. If an area cannot be read out completely, that is flagged in the file rather than silently omitted. Account deletion can likewise be triggered by the user — with a window in which it can be withdrawn.
- Profile, documents, analyses, letters and chats in one structured file
- Credit and payment records as evidence of the contractual relationship
- Log entries relating to the account itself
- An explicit flag if any area could not be read out in full
Limits
What we do not claim
Four points that experience shows come up first in a security review — and where the answer is no.
No ISO 27001 or SOC 2 certification
The platform is not certified and holds no attestation. The technical and organisational measures are described in the data processing agreement and can be checked there — a certificate does not replace that, and we do not claim one.
No two-factor login for end users
A second authentication step currently exists only for platform administrators, not for regular accounts. If your approval requires it, that is a blocker today — and you should know it before rollout, not after.
No end-to-end encryption at document level
Data is encrypted in transit and at rest, and access is restricted row by row. There is no true end-to-end encryption in which the operator would technically be unable to read anything.
No availability commitment in percent
We make no binding SLA commitment. Our terms of service state a non-binding availability "target" of 99.0% annual average as a best-effort figure (no entitlement, no penalty clause) — recovery and data-loss objectives and the retention of backups are governed by the data processing agreement; we make no binding availability guarantee beyond that.
Retention and deletion
The periods set out in the privacy policy — merely collected here so you do not have to look for them.
- Retention of audit log entries
- 12 months
- See the privacy policy, section on retention.
- Server and security logs, IP truncated
- 14 days
- See the privacy policy, section on retention.
- Window until final account deletion
- 30 days
- Withdrawable within the window. Statutory retention duties for payment records remain unaffected.
Frequent questions from security reviews
The source documents
All of it is readable without an account — deliberately before the decision, not after.

Start free
Lexi shows the fastest path: structured assessment first, then a clean handover to vetted lawyers when needed.