Skip to main content

Data Protection & GDPR

Last updated: 2026-08-18

Roles under GDPR

For customer data processed in the platform, the customer is the data controller and Lexabit is the data processor. The contracting Lexabit entity is Lexabit AB (Sweden) or its Danish entity Lexabit ApS, depending on which entity the customer's agreement is with; the processing described in this Trust Center is the same in either case. A Data Processing Agreement is Planned: bilateral data-processing terms are currently handled directly with each customer during onboarding, rather than through a standard published template.

Data we process

CategoryExamplesSource
Account & user dataLogin credentials, session and authentication metadataCreated at sign-up / sign-in
Client & case recordsClient and case records the customer creates in the platformEntered by the customer
Bank account & transaction dataAccount and transaction data from connected bank accountsRetrieved under an authorized PSD2 consent through regulated open-banking providers (currently Enable Banking)
Company & registry dataPublic company information plus registered role holders (directors, board members — name, date of birth, address) and beneficial ownersPublic national business registries via Lexabit's self-hosted data registry
Audit logsIntegration activity and login metadataRecorded by the platform's logging infrastructure

Data residency

Lexabit is hosted entirely on DigitalOcean in Amsterdam — the application server, database, and CDN all run in the Amsterdam region, with object storage in the DO Spaces AMS3 region. All customer data therefore resides within the EU (Netherlands). Both MySQL and MongoDB are self-hosted on the same server. The self-hosted MongoDB registry — on the same Amsterdam infrastructure — holds this public-registry dataset; it does not contain the customer's own client, case, or user data.

Retention & deletion

Data is retained for as long as the customer's account remains active and used to deliver the platform's features. A formalized retention schedule is Planned. Requests for data deletion or erasure are handled operationally by contacting the security contact below.

Data-subject rights

Data subjects can access and correct their personal data through the application's normal features (for example, account and profile settings). Requests for data export or erasure beyond what the application supports are handled by contacting security@lexabit.com.

Sub-processors

Lexabit uses a small number of sub-processors to deliver the platform, including hosting and outbound email , and lists operational service providers where customer personal data may incidentally appear. Open-banking and company-data providers are used under a different model — see Sub-processors & Service Providers and Banking & Data Providers for details.