Privacy Policy

How Lex handles your data and your clients' data

Last updated: 29 April 2026 · Effective: 29 April 2026

Lex is built for Nigerian lawyers who carry a duty of confidentiality to their clients under the Rules of Professional Conduct and the Nigeria Data Protection Act 2023. This policy explains what we collect, where it goes, and how you keep control of it.

On this page
  1. 1. Who we are
  2. 2. Scope and roles
  3. 3. Data we process
  4. 4. How we use it
  5. 5. Lawful basis
  6. 6. Sub-processors
  7. 7. AI processing
  8. 8. Cross-border transfers
  9. 9. Retention
  10. 10. Security
  11. 11. Your rights
  12. 12. Your clients' data
  13. 13. Breach notification
  14. 14. Cookies and storage
  15. 15. Changes
  16. 16. Contact

1. Who we are

Lex is operated by Lex Technology, a Nigerian technology company building practice intelligence software for legal practitioners. References to "Lex", "we", "us", or "our" mean Lex Technology. References to "you" mean the lawyer, paralegal, or firm staff member who registers a Lex account, and where the context requires, your law firm.

You can reach us at hello@uselex.app. For data-protection enquiries specifically, write to privacy@uselex.app.

2. Scope and roles

Lex processes two distinct categories of personal data, and our role under the Nigeria Data Protection Act 2023 (NDPA) and equivalent foreign laws is different for each:

This split matters: you continue to owe your own clients the duty of confidentiality and the disclosures required of a data controller. Lex is the tool you use; it does not replace your obligations to your clients.

3. Data we process

3.1 Account and identity data

3.2 Practice and matter data

3.3 Communications data

3.4 Billing data

3.5 Technical data

4. How we use it

Section 25 of the NDPA requires a lawful basis for each act of processing. We rely on:

6. Sub-processors we share data with

Lex relies on the following sub-processors. Each handles a defined slice of data, under a contractual obligation to process it only on our instructions and to protect it with reasonable security measures:

Sub-processorWhat they doData they receiveLocation
SupabaseDatabase, authentication, file storage, edge runtimeAll application data, hashed credentials, uploaded filesUnited States
Anthropic (Claude)AI assistant, document analysis, proofreading, drafting, form-field detection, OCR for scanned PDFsYour queries, document text and images, matter context, transcript snippetsUnited States
OpenAIVector embeddings for library search; text-to-speech for the "Listen" featureLibrary document chunks; text you ask Lex to read aloudUnited States
AssemblyAIAudio transcription with speaker labelsAudio files you record in the recorderUnited States
Recall.aiMeeting bot that joins and records calls you dispatch it toMeeting URL, audio and transcript of the callUnited States
PaystackSubscription and one-off paymentsName, email, phone, firm, practice area, payment instrument metadataNigeria
ResendTransactional email (reminders, invites, alerts)Recipient email and the body of the messageUnited States
TermiiSMS delivery for reminders and notificationsRecipient phone number and the message textNigeria
TwilioWhatsApp delivery for reminders and notificationsRecipient WhatsApp number and the message textUnited States
Cloudflare PagesStatic asset hosting and global content deliveryPublic application files; visitor IPs at the edgeGlobal edge network
Google FontsWeb typeface deliveryVisitor IPs only (no user content)United States / Global

We keep an up-to-date list and notify you of material changes through the application before they take effect.

7. How we use AI providers

Lex's AI features are not magic — they are calls to large-language-model providers operated by third parties. We treat that as a meaningful disclosure obligation, not a footnote.

8. Cross-border transfers

As section 6 makes clear, several of our sub-processors are located outside Nigeria, principally in the United States. Section 41 of the NDPA permits transfers of personal data outside Nigeria where the recipient is subject to a law, binding corporate rule, contract, or other instrument that provides an adequate level of protection.

For each US sub-processor, we rely on contractual data-processing terms that bind them to security and confidentiality obligations comparable to the NDPA. Where you are based in a jurisdiction (such as the EU/UK) that imposes additional transfer requirements, we apply standard contractual clauses or equivalent mechanisms with the same providers.

By signing up to Lex, you authorise these cross-border transfers as necessary to deliver the service you have requested.

9. How long we keep data

10. Security

11. Your rights as a data subject

Under the NDPA you have the rights to:

To exercise any of these rights, email privacy@uselex.app. We will respond within thirty days. We may ask you to verify your identity before we act on a request.

12. Your clients' personal data

Important. When you put a client's name, contact, document, recording, or case fact into Lex, you remain the controller of that data. Lex is your processor. Your duties to the client under the Legal Practitioners Act, the Rules of Professional Conduct, and the NDPA continue to apply.

This means:

13. Breach notification

If we become aware of a personal-data breach affecting your account or your firm's data, we will notify you without undue delay and, where the breach is likely to result in a high risk to you or your clients, within seventy-two hours of becoming aware. Our notice will describe what happened, what data was affected, what we are doing about it, and what you should do.

We will also notify the NDPC where the law requires us to do so. Where you are the controller of affected client data, we will give you the information you need to discharge your own notification duties.

14. Cookies, local storage, and the service worker

15. Changes to this policy

If we change how Lex handles data in a material way, we will update this page, change the "Last updated" date at the top, and notify active users by email or in-product banner before the change takes effect. Minor clarifications and link updates may be made without notice.

16. Contact us

For privacy questions, complaints, or to exercise any of the rights described above:

If you remain unsatisfied after contacting us, you may lodge a complaint with the Nigeria Data Protection Commission at ndpc.gov.ng.