Skip to main content

For compliance & privacy

Compliance workflows with traceable AI support.

From GDPR requests to contract and vendor review: Smart Legal Pro provides a clear, auditable workflow with exports and escalation paths.

Start for free

  • Law by country
  • GDPR-compliant
  • No AI training
  • PII masking
  • Lawyer handover
  • Seven languages

Anyone responsible for compliance assesses a new tool first for what is wrong with it. Where does the data sit, who can see it, how long is it kept, and what happens when someone requests access or demands deletion.

This page answers that without selling. The application and database are in the EU, transfers are encrypted, every table is access-restricted row by row, personal data is masked before it reaches the AI provider, and content is not used to train models. Each of these statements is set out in full in an actual legal document, linked below.

Equally important is what we do not claim. There is no ISO or SOC 2 certification, no two-factor login for end users and no end-to-end encryption at document level. That is stated explicitly below — so you do not have to discover it during your own assessment.

What is in place operationally

Four building blocks that separate an AI chat from an auditable workflow.

  1. GDPR and contract context in one place

    Documents, legal questions and follow-up communication stay together instead of tool silos.

  2. Retests when facts change

    New information can be incorporated traceably and reassessed.

  3. Auditable exports

    Results as structured evidence for internal sign-off and external audits.

  4. Security and roles model

    EU hosting, RLS, PII masking and clear responsibility boundaries for production use.

  • Legal questions without a document
  • Chat with follow-ups in the matter
  • Analysis, exports, lawyer handover
  • Writing assistant & templates
We do not promise certifications we do not hold.
From the help article "Is this secure?" — the same wording our users read.
Data subject rights

Access and deletion as a feature, not a mailbox process

Subject access under Articles 15 and 20 GDPR runs inside the account itself: a structured file spanning every area, with no ticket and no waiting time. If an area cannot be read out completely, that is flagged in the file rather than silently omitted. Account deletion can likewise be triggered by the user — with a window in which it can be withdrawn.

Security and data processing in detail
Subject access export (Art. 15 GDPR)Self-service
  • Profile, documents, analyses, letters and chats in one structured file
  • Credit and payment records as evidence of the contractual relationship
  • Log entries relating to the account itself
  • An explicit flag if any area could not be read out in full

Limits

What we do not claim

Four points that experience shows come up first in a security review — and where the answer is no.

  • No ISO 27001 or SOC 2 certification

    The platform is not certified and holds no attestation. The technical and organisational measures are described in the data processing agreement and can be checked there — a certificate does not replace that, and we do not claim one.

  • No two-factor login for end users

    A second authentication step currently exists only for platform administrators, not for regular accounts. If your approval requires it, that is a blocker today — and you should know it before rollout, not after.

  • No end-to-end encryption at document level

    Data is encrypted in transit and at rest, and access is restricted row by row. There is no true end-to-end encryption in which the operator would technically be unable to read anything.

  • No availability commitment in percent

    We make no binding SLA commitment. Our terms of service state a non-binding availability "target" of 99.0% annual average as a best-effort figure (no entitlement, no penalty clause) — recovery and data-loss objectives and the retention of backups are governed by the data processing agreement; we make no binding availability guarantee beyond that.

Retention and deletion

The periods set out in the privacy policy — merely collected here so you do not have to look for them.

Retention of audit log entries
12 months
See the privacy policy, section on retention.
Server and security logs, IP truncated
14 days
See the privacy policy, section on retention.
Window until final account deletion
30 days
Withdrawable within the window. Statutory retention duties for payment records remain unaffected.

Frequent questions from security reviews

Lexi, digitale Rechts-Assistenz

Start free

Lexi shows the fastest path: structured assessment first, then a clean handover to vetted lawyers when needed.

Request compliance demo

No credit card required · GDPR-compliant · Start for free

See pricing
Start free
No credit card
Get started