🔒 Privacy

Privacy Policy

Version 1.0 Last updated: April 2026 LexCap.io
DIFC DPL GDPR eIDAS

1. Who We Are

Privacy enquiries: privacy@lexcap.io

This policy reflects our commitment to data privacy across the jurisdictions we operate in, including GDPR where applicable.

2. What We Collect

3. AI Processing — Important Disclosure

Layla.ai is powered by Anthropic's Claude API. When you submit a message or upload a document, that content is transmitted to Anthropic's servers for processing.

4. How We Use Your Data

Legal basisPurposes
Performance of contractAccount management, Layla.ai processing, document storage, payments, consultant bookings, signing envelopes
Legitimate interestsSecurity monitoring, fraud detection, platform analytics, error monitoring
Legal obligationsRecord-keeping required by applicable law, responses to lawful requests
ConsentMarketing emails (withdraw anytime), non-essential cookies

5. Data Sharing & Processors

We share your data only with these processors, only as necessary:

ProcessorPurposeLocationDPA
AnthropicClaude API — Layla.ai processingUSAYes
SupabaseDatabase & file storageEU West (Ireland)Yes
StripePayment processingUSA / EUYes
ResendTransactional emailEUYes
PostHogProduct analyticsEUYes
SentryError monitoringUSAYes
We do not sell your personal data. We do not share your data with advertisers.

6. Data Retention

Data typeRetentionNotes
Account dataUntil deletion + 90 daysGrace period for export
Conversation history90 days rollingYou can delete any time
DocumentsUntil you delete themYou control deletion
Billing records7 yearsApplicable commercial law
Disclaimer acceptance7 yearsLegal compliance
Signing envelopes7 yearsLegal enforceability
Security logs12 monthsFraud prevention

7. Your Rights

Depending on your jurisdiction, you may have rights to: access your data, correct inaccuracies, request erasure, restrict processing, receive your data in portable format, object to processing, and withdraw consent.

Most data management is self-service via Settings → Data & Privacy in your account. To exercise any right, email privacy@lexcap.io. We will respond within 30 days.

8. Security

To report a security issue: security@lexcap.io

9. International Transfers

Your data may be transferred to the United States in connection with our processors (Anthropic, Stripe, Sentry). All transfers are subject to appropriate safeguards including standard contractual clauses. If you are in the UK, Canada, Australia, or another jurisdiction with specific transfer requirements, we apply equivalent safeguards. Contact privacy@lexcap.io for jurisdiction-specific information.

10. Cookies

CategoryConsent requiredExamples
EssentialNoSession auth, CSRF tokens, load balancing
AnalyticsYesPostHog — anonymised feature usage
PreferenceYesTheme, UI preferences
We do not use advertising cookies. We do not allow third-party advertising on the Platform.

11. Children

The Platform is not directed at anyone under 18. Contact privacy@lexcap.io if you believe we have inadvertently collected data from a minor.

12. Changes to This Policy

We will notify you of material changes by email at least 14 days before they take effect.

13. Complaints

If you believe we have not handled your data appropriately, you can complain to:

We would always prefer to resolve concerns directly — contact privacy@lexcap.io first.

Contact

Privacy matters: privacy@lexcap.io

Security issues: security@lexcap.io