In 30 minutes we show you Legis on your real documents — your frameworks, your method.
Information under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003, as amended, for people who use the Legis platform and its AI assistant Lio.
This notice explains how Legis S.r.l. ("Legis") processes the personal data of people who use the Legis platform, available at app.uselegis.com, including the AI assistant Lio and the integrations with third-party services (the "Platform"). If you only visit the legis.eu website, see the website privacy notice.
The controller of the processing described in this notice is:
The Platform is a professional service. It is used by the people to whom a Customer, meaning the company or professional firm that has signed the contract with Legis, has given access: the Customer's employees and collaborators, consultants working for it, and invited guests. It is not intended for anyone under 18.
Legis decides how and why to process the data needed to let you use the Platform and to keep it secure: your account data, logins, usage data, error reports and support requests. For this data Legis is the controller, and this is the processing described in the following sections.
Everything the Customer and its users upload or create on the Platform (documents, registers, assessments, conversations with Lio, data about the Customer's employees, suppliers or clients, and emails and files read through integrations) is processed by Legis on behalf of the Customer, as a processor under Art. 28 GDPR, in accordance with the contract and the data processing agreement signed with it. The Customer is the controller of this data: information about its processing, and requests to exercise your rights, should be addressed to the Customer. Legis does not use this content for its own purposes.
Likewise, if you fill in a form you received through a link, such as a supplier qualification questionnaire, the controller is the organisation that sent it to you.
First and last name, email address, organisation, role and permissions, language and preferences. Your password is never stored in plain text. If you enable multi-factor authentication, we process the data needed for the second factor. If you sign in with Google or Microsoft, we receive your name, email address and an account identifier from them.
IP address, browser and device, date, time and outcome of logins, and the relevant actions carried out on the Platform (activity log). If Legis staff access your account to help you, that access is logged.
Which pages and features you use and how you interact with the interface, so we can understand how the Platform is used and improve it. These statistics record which features you use, not what you write: they do not include the content of documents or conversations, interface text is masked before it is sent, and your IP address is anonymised. We do not record your screen or your sessions.
When something goes wrong, the Platform sends a technical report containing your IP address, browser, account identifier and the technical context of the error, so that we can find and fix it.
The content of the requests you send us from the Platform or by email, and our replies.
If you are the person who signed the contract with Legis, we also process the data needed to manage it and to invoice.
Some data you provide yourself; other data we receive from the Customer that invites you (name, email address, role) or from Google or Microsoft, if you use them to sign in. Login, usage and error data are generated by your use of the Platform.
Purpose: to create and manage your account, authenticate you, manage invitations, roles and permissions, and provide the features you use.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR) if you are the contracting party; otherwise the legitimate interest of Legis and of the Customer in providing the service the Customer has purchased for you (Art. 6(1)(f) GDPR).
Provision of data: required; without this data you cannot use the Platform.
Purpose: to protect accounts and data, prevent misuse and unauthorised access, and reconstruct what happened in the event of an incident.
Legal basis: legitimate interest (Art. 6(1)(f) GDPR), including to meet the security obligation under Art. 32 GDPR.
Purpose: to send you invitations, password reset emails, notifications and notices about maintenance or changes to the service, and to answer your support requests.
Legal basis: the same as in 4.1.
Purpose: to understand which features are used and where users run into difficulties, in order to improve the Platform.
Legal basis: legitimate interest (Art. 6(1)(f) GDPR). You can object at any time by writing to [email protected].
Purpose: to detect and fix Platform malfunctions.
Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
Purpose: to manage the contract and invoicing where you are the contracting party, to comply with legal obligations, and to establish, exercise or defend legal claims.
Legal basis: performance of a contract (Art. 6(1)(b)), legal obligation (Art. 6(1)(c)) or legitimate interest (Art. 6(1)(f) GDPR), as the case may be.
We do not use your data to send you advertising, we do not sell it, and we do not share it with third parties for their own commercial purposes.
Lio is the Platform's AI assistant. To answer questions, analyse documents or draft text, Lio sends your request, together with the parts of the Customer's documents needed to answer it, to AI models provided by third parties. These providers act as sub-processors: they process the data only to return the result, under agreements that comply with Art. 28 GDPR.
Some of these providers are based in the European Union; others are outside the European Economic Area, in particular in the United States. In that case the transfer takes place with the safeguards described in section 09. The up-to-date list of providers can be requested at [email protected].
Lio's answers are generated automatically and may contain errors: always check them before relying on them.
If you choose to sign in with your Google or Microsoft account, they verify your identity and share your name, email address and an account identifier with us. For the sign-in service, Google and Microsoft act as independent controllers under their own privacy notices.
You can connect services such as Google Drive, Gmail and the Google Workspace admin console, or Microsoft Outlook, OneDrive, SharePoint and Calendar, to the Platform in order to import documents, let Lio consult emails and files when you ask it to, or collect security evidence. A connection is only made at your initiative, with the permissions you approve on the Google or Microsoft consent screen, and data is read only for the feature you requested. The access credentials for connected services are stored encrypted, and you can revoke a connection at any time, from the Platform or from your Google or Microsoft account settings. Content read in this way is processed on behalf of the Customer, as described in section 02.
Legis's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, data obtained through Google Workspace APIs is not used to develop, improve or train generalised AI or machine learning models, and no person reads it unless you ask us to, it is necessary for security, or the law requires it.
Your data may be accessed by:
The providers are appointed as processors under Art. 28 GDPR, except Google and Microsoft for the sign-in service, which act as independent controllers. The up-to-date list of processors can be requested at [email protected].
The Platform and its databases are hosted in the European Union. However, some providers are based in the United States or may access the data from there: Resend for service emails, the US companies that host data in the EU (Supabase, Cloudflare, PostHog, Sentry, Google and Microsoft), and some AI providers. In these cases Legis ensures that the transfer complies with Chapter V GDPR, by means of:
You can ask about the safeguards in place by writing to [email protected].
At the end of these periods the data is deleted or anonymised. It may be kept longer only where needed to comply with a legal obligation or to defend a legal claim, and only for as long as necessary.
We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR), including:
No measure removes risk entirely: in the event of a personal data breach, Legis acts as required by Articles 33 and 34 GDPR.
You can exercise the rights provided by Articles 15–22 GDPR at any time:
To exercise them, write to [email protected] or, by certified email (PEC), to [email protected]. We reply within one month, which may be extended in the cases provided by Art. 12 GDPR.
For content processed on behalf of the Customer, contact the Customer, which is its controller. If your request reaches us, we forward it to the Customer without delay.
You also have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).
We may update this notice when the Platform, our providers or the law change. The date at the top shows the version in force. If the changes are substantial, we will tell you on the Platform or by email before they apply.