Legis S.r.l.

Platform Privacy Notice

Last updated: 25 September 2026

Information under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003, as amended, for people who use the Legis platform and its AI assistant Lio.

This notice explains how Legis S.r.l. ("Legis") processes the personal data of people who use the Legis platform, available at app.uselegis.com, including the AI assistant Lio and the integrations with third-party services (the "Platform"). If you only visit the legis.eu website, see the website privacy notice.

Section 01

Data Controller

The controller of the processing described in this notice is:

Company
Legis S.r.l.
Registered office
Via Lorenzo il Magnifico 14, 50129 Florence (FI), Italy — VAT no. 07506890487
Email
PEC
Section 02

Who this notice covers and who decides on the data

The Platform is a professional service. It is used by the people to whom a Customer, meaning the company or professional firm that has signed the contract with Legis, has given access: the Customer's employees and collaborators, consultants working for it, and invited guests. It is not intended for anyone under 18.

When Legis decides

Legis decides how and why to process the data needed to let you use the Platform and to keep it secure: your account data, logins, usage data, error reports and support requests. For this data Legis is the controller, and this is the processing described in the following sections.

When the Customer decides

Everything the Customer and its users upload or create on the Platform (documents, registers, assessments, conversations with Lio, data about the Customer's employees, suppliers or clients, and emails and files read through integrations) is processed by Legis on behalf of the Customer, as a processor under Art. 28 GDPR, in accordance with the contract and the data processing agreement signed with it. The Customer is the controller of this data: information about its processing, and requests to exercise your rights, should be addressed to the Customer. Legis does not use this content for its own purposes.

Likewise, if you fill in a form you received through a link, such as a supplier qualification questionnaire, the controller is the organisation that sent it to you.

Section 03

What data we process

a) Account data

First and last name, email address, organisation, role and permissions, language and preferences. Your password is never stored in plain text. If you enable multi-factor authentication, we process the data needed for the second factor. If you sign in with Google or Microsoft, we receive your name, email address and an account identifier from them.

b) Login and security data

IP address, browser and device, date, time and outcome of logins, and the relevant actions carried out on the Platform (activity log). If Legis staff access your account to help you, that access is logged.

c) Usage data

Which pages and features you use and how you interact with the interface, so we can understand how the Platform is used and improve it. These statistics record which features you use, not what you write: they do not include the content of documents or conversations, interface text is masked before it is sent, and your IP address is anonymised. We do not record your screen or your sessions.

d) Error reports

When something goes wrong, the Platform sends a technical report containing your IP address, browser, account identifier and the technical context of the error, so that we can find and fix it.

e) Support requests

The content of the requests you send us from the Platform or by email, and our replies.

f) Contract data

If you are the person who signed the contract with Legis, we also process the data needed to manage it and to invoice.

Where the data comes from

Some data you provide yourself; other data we receive from the Customer that invites you (name, email address, role) or from Google or Microsoft, if you use them to sign in. Login, usage and error data are generated by your use of the Platform.

Section 04

Why we process data and on what legal basis

4.1 Letting you use the Platform

Purpose: to create and manage your account, authenticate you, manage invitations, roles and permissions, and provide the features you use.

Legal basis: performance of a contract (Art. 6(1)(b) GDPR) if you are the contracting party; otherwise the legitimate interest of Legis and of the Customer in providing the service the Customer has purchased for you (Art. 6(1)(f) GDPR).

Provision of data: required; without this data you cannot use the Platform.

4.2 Platform security

Purpose: to protect accounts and data, prevent misuse and unauthorised access, and reconstruct what happened in the event of an incident.

Legal basis: legitimate interest (Art. 6(1)(f) GDPR), including to meet the security obligation under Art. 32 GDPR.

4.3 Service communications and support

Purpose: to send you invitations, password reset emails, notifications and notices about maintenance or changes to the service, and to answer your support requests.

Legal basis: the same as in 4.1.

4.4 Usage statistics

Purpose: to understand which features are used and where users run into difficulties, in order to improve the Platform.

Legal basis: legitimate interest (Art. 6(1)(f) GDPR). You can object at any time by writing to [email protected].

4.5 Fixing errors

Purpose: to detect and fix Platform malfunctions.

Legal basis: legitimate interest (Art. 6(1)(f) GDPR).

4.6 Contract, invoicing and legal obligations

Purpose: to manage the contract and invoicing where you are the contracting party, to comply with legal obligations, and to establish, exercise or defend legal claims.

Legal basis: performance of a contract (Art. 6(1)(b)), legal obligation (Art. 6(1)(c)) or legitimate interest (Art. 6(1)(f) GDPR), as the case may be.

We do not use your data to send you advertising, we do not sell it, and we do not share it with third parties for their own commercial purposes.

Section 05

Lio and artificial intelligence

Lio is the Platform's AI assistant. To answer questions, analyse documents or draft text, Lio sends your request, together with the parts of the Customer's documents needed to answer it, to AI models provided by third parties. These providers act as sub-processors: they process the data only to return the result, under agreements that comply with Art. 28 GDPR.

Some of these providers are based in the European Union; others are outside the European Economic Area, in particular in the United States. In that case the transfer takes place with the safeguards described in section 09. The up-to-date list of providers can be requested at [email protected].

  • No training. Your data and the Customer's content are not used to train AI models, either by Legis or by its providers.
  • Voice dictation. If you dictate a message and your device cannot transcribe it on its own, the audio is sent to a transcription provider. Legis does not keep the audio: only the transcribed text remains.
  • Web searches. When Lio looks up public information online, only the search queries Lio writes and the addresses of the pages to read are sent to the search service, never the documents.
  • No automated decisions. Lio does not take decisions that produce legal effects on you or similarly significant effects (Art. 22 GDPR).

Lio's answers are generated automatically and may contain errors: always check them before relying on them.

Section 06

Google and Microsoft integrations

Signing in with Google or Microsoft

If you choose to sign in with your Google or Microsoft account, they verify your identity and share your name, email address and an account identifier with us. For the sign-in service, Google and Microsoft act as independent controllers under their own privacy notices.

Connecting your accounts

You can connect services such as Google Drive, Gmail and the Google Workspace admin console, or Microsoft Outlook, OneDrive, SharePoint and Calendar, to the Platform in order to import documents, let Lio consult emails and files when you ask it to, or collect security evidence. A connection is only made at your initiative, with the permissions you approve on the Google or Microsoft consent screen, and data is read only for the feature you requested. The access credentials for connected services are stored encrypted, and you can revoke a connection at any time, from the Platform or from your Google or Microsoft account settings. Content read in this way is processed on behalf of the Customer, as described in section 02.

Data received from Google

Legis's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, data obtained through Google Workspace APIs is not used to develop, improve or train generalised AI or machine learning models, and no person reads it unless you ask us to, it is necessary for security, or the law requires it.

Section 08

Who receives the data

Your data may be accessed by:

  • the Customer: your organisation's administrators can see your account, your permissions and the activity you carry out on the Platform, and so can the consultants the Customer entrusts with managing its workspaces;
  • authorised Legis staff, bound by confidentiality, only as far as needed to provide the service, support you and keep the Platform secure;
  • the providers that process data on behalf of Legis, listed in the table below;
  • Legis's advisers and professionals, such as lawyers and accountants, and public authorities where the law requires it.
Provider
Service and data location
Supabase
Database, authentication and file storage. Data in the EU (Frankfurt).
Amazon Web Services
Hosting of the Platform and of its AI services. Data in the EU (Frankfurt).
Cloudflare
Network, attack protection and DNS.
Aruba
Document editor server. Data in the EU.
Resend
Sending of service emails: invitations, password resets, notifications.
PostHog
Usage statistics. Data in the EU (Frankfurt).
Sentry
Error reports. Data in the EU (Frankfurt).
Google
Legis's email, including for support requests; Google sign-in and integrations, if you use them.
Microsoft
Microsoft sign-in and integrations, if you use them.
AI and web search providers
Processing of requests to Lio, reading and indexing of documents, voice transcription, web searches. In the EU and in the United States (section 05).
Administrative and commercial services
Management of the contract, invoicing and the relationship with the Customer.

The providers are appointed as processors under Art. 28 GDPR, except Google and Microsoft for the sign-in service, which act as independent controllers. The up-to-date list of processors can be requested at [email protected].

Section 09

Transfers outside the European Economic Area

The Platform and its databases are hosted in the European Union. However, some providers are based in the United States or may access the data from there: Resend for service emails, the US companies that host data in the EU (Supabase, Cloudflare, PostHog, Sentry, Google and Microsoft), and some AI providers. In these cases Legis ensures that the transfer complies with Chapter V GDPR, by means of:

  • an adequacy decision of the European Commission, including the EU-U.S. Data Privacy Framework for certified providers;
  • standard contractual clauses approved by the European Commission;
  • supplementary measures, where necessary.

You can ask about the safeguards in place by writing to [email protected].

Section 10

How long we keep data

Data
Retention period
Account
For as long as your account exists. When the contract with the Customer ends, the data can be exported for 30 days and is permanently deleted within 90 days of termination.
Backups
Daily backups are overwritten within 7 days.
Login records
12 months.
Server logs
30 days.
Activity log
For the duration of the contract with the Customer, as it is part of the Customer's workspace.
Usage statistics
12 months.
Error reports
Up to 90 days.
Support requests
24 months after the request is closed.
Google and Microsoft connections
Until you revoke the connection or close your account.
Dictation audio
Not kept.
Contract and invoices
10 years, as required by Italian law (Art. 2220 of the Civil Code).

At the end of these periods the data is deleted or anonymised. It may be kept longer only where needed to comply with a legal obligation or to defend a legal claim, and only for as long as necessary.

Section 11

How we protect data

We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR), including:

  • encryption of data in transit and at rest;
  • separation of each Customer's data at database level;
  • multi-factor authentication available to users;
  • access to data limited to the staff who need it, with support access logged;
  • daily backups;
  • infrastructure hosted in data centres in the European Union.

No measure removes risk entirely: in the event of a personal data breach, Legis acts as required by Articles 33 and 34 GDPR.

Section 12

Your rights

You can exercise the rights provided by Articles 15–22 GDPR at any time:

  • access to your data and a copy of it;
  • rectification of inaccurate or incomplete data;
  • erasure, in the cases provided by law;
  • restriction of processing;
  • portability of the data you provided to us;
  • objection to processing based on legitimate interest, including usage statistics.

To exercise them, write to [email protected] or, by certified email (PEC), to [email protected]. We reply within one month, which may be extended in the cases provided by Art. 12 GDPR.

For content processed on behalf of the Customer, contact the Customer, which is its controller. If your request reaches us, we forward it to the Customer without delay.

You also have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).

Section 13

Changes to this notice

We may update this notice when the Platform, our providers or the law change. The date at the top shows the version in force. If the changes are substantial, we will tell you on the Platform or by email before they apply.