Data Protection & GDPR
Last updated: 2026-08-18
Roles under GDPR
For customer data processed in the platform, the customer is the data controller and Lexabit is the data processor. The contracting Lexabit entity is Lexabit AB (Sweden) or its Danish entity Lexabit ApS, depending on which entity the customer's agreement is with; the processing described in this Trust Center is the same in either case. A Data Processing Agreement is Planned: bilateral data-processing terms are currently handled directly with each customer during onboarding, rather than through a standard published template.
Data we process
| Category | Examples | Source |
|---|---|---|
| Account & user data | Login credentials, session and authentication metadata | Created at sign-up / sign-in |
| Client & case records | Client and case records the customer creates in the platform | Entered by the customer |
| Bank account & transaction data | Account and transaction data from connected bank accounts | Retrieved under an authorized PSD2 consent through regulated open-banking providers (currently Enable Banking) |
| Company & registry data | Public company information plus registered role holders (directors, board members — name, date of birth, address) and beneficial owners | Public national business registries via Lexabit's self-hosted data registry |
| Audit logs | Integration activity and login metadata | Recorded by the platform's logging infrastructure |
Data residency
Lexabit is hosted entirely on DigitalOcean in Amsterdam — the application server, database, and CDN all run in the Amsterdam region, with object storage in the DO Spaces AMS3 region. All customer data therefore resides within the EU (Netherlands). Both MySQL and MongoDB are self-hosted on the same server. The self-hosted MongoDB registry — on the same Amsterdam infrastructure — holds this public-registry dataset; it does not contain the customer's own client, case, or user data.
Retention & deletion
Data is retained for as long as the customer's account remains active and used to deliver the platform's features. A formalized retention schedule is Planned. Requests for data deletion or erasure are handled operationally by contacting the security contact below.
Data-subject rights
Data subjects can access and correct their personal data through the application's normal features (for example, account and profile settings). Requests for data export or erasure beyond what the application supports are handled by contacting security@lexabit.com.
Sub-processors
Lexabit uses a small number of sub-processors to deliver the platform, including hosting and outbound email , and lists operational service providers where customer personal data may incidentally appear. Open-banking and company-data providers are used under a different model — see Sub-processors & Service Providers and Banking & Data Providers for details.