Legal
Privacy Policy & Terms of Use
Privacy Policy
1. Data Controller under the GDPR
LexDuvia UG (haftungsbeschränkt)
Sprengerstraße 7, 31134 Hildesheim
Email: support@lexduvia.de
A Data Protection Officer has not been appointed; the statutory thresholds under § 38 (1) of the Federal Data Protection Act (BDSG) are not met.
2. Categories of processed data
When you use the platform, the following categories of personal data within the meaning of Art. 4 No. 1 GDPR are processed:
- Account data: name, email address, password hash (bcrypt)
- Content data: the cases and legal analyses (Gutachten) you submit and the resulting analysis output
- Usage data: analysis history, quiz results, learning progress, feedback
- Billing and payment data for paid plans (handled by the payment service provider)
- Metadata: IP address, user agent, timestamps and request logs required to run the service
3. Purposes and legal bases
Processing takes place on the following legal bases under Art. 6 (1) GDPR; the assigned purposes are exhaustive:
- Art. 6 (1) lit. b GDPR — Performance of the user contract: providing the account, running the analysis of your Gutachten, generating practice questions.
- Art. 6 (1) lit. a GDPR — Consent: transmission of your content to the AI model used (Amazon Bedrock / Anthropic Claude). Consent can be withdrawn at any time with effect for the future (Art. 7 (3) GDPR).
- Art. 6 (1) lit. f GDPR — Legitimate interests: IT security, abuse prevention, reliable operation (logging, rate limiting). Our interest prevails because the data is stored only briefly and is not used for profiling.
- Art. 6 (1) lit. c GDPR — Compliance with legal obligations: retention and record-keeping duties, in particular under §§ 147 AO (German Fiscal Code) and 257 HGB (German Commercial Code).
4. Data processors (Art. 28 GDPR)
For the technical operation of the platform we use the following data processors. Data processing agreements under Art. 28 GDPR are in place with every provider listed:
Hetzner
Hetzner Online GmbH, Germany
Server infrastructure (Nuremberg data center) and S3-compatible object storage for profile pictures and uploads (Falkenstein data center) — both locations in Germany. Hetzner acts solely as a technical infrastructure provider and is bound by our instructions. Hetzner does not review, analyze or otherwise make use of the stored data. Privacy policy →
Neon
Neon, Inc., USA
Managed PostgreSQL service storing all persisted platform data (account, content and usage data). Data is stored exclusively in the EU region AWS Europe Central 1 (Frankfurt); no processing or replication outside the EU takes place. Privacy Policy →
Amazon Bedrock
Amazon Web Services EMEA SARL, Luxembourg
AI-assisted analysis of your Gutachten with Anthropic Claude. Uploaded texts are processed via the EU inference profile and remain within the AWS EU regions (Frankfurt, Stockholm, Milan, Spain, Ireland, Paris). Texts are not used to train AI models. Privacy notice →
Scaleway (Transactional Email)
Scaleway SAS, France
Delivery of transactional emails (e.g. password reset, verification). Scaleway processes the email address and the message contents for this purpose. Privacy Policy →
Authentication runs exclusively on our own infrastructure. Credentials are not transmitted to any external identity provider.
Third-country transfer: Neon, Inc. and the AWS parent company are based in the USA. Actual data processing, however, takes place exclusively within the EU. The transfer mechanism relied on is the EU Standard Contractual Clauses (Implementing Decision 2021/914) under Art. 46 (2) lit. c GDPR, supplemented by the additional safeguards documented in the respective DPA.
5. Cookies and local storage
Only strictly necessary session cookies from our own authentication system are set. The legal basis is § 25 (2) No. 2 TDDDG (German Telecommunications Digital Services Data Protection Act). No third-party tracking, marketing or analytics cookies are used; consent under § 25 (1) TDDDG is therefore not required.
6. Retention periods
Personal data is stored only for as long as required for the purposes stated above or as mandated by statutory retention periods:
- Account and content data: until you delete your account; deletion then takes place within 30 days unless retention obligations apply.
- Invoices and payment records: 10 years (§ 147 (3) AO, § 257 (4) HGB).
- Server and security logs: at most 30 days, then automatically deleted or anonymized.
7. Automated processing (Art. 22 GDPR)
The AI-assisted analysis of Gutachten is purely a learning aid. There is no automated decision-making that produces legal effects or similarly significantly affects the data subject within the meaning of Art. 22 (1) GDPR. The results serve only your own self-assessment; no profiling or evaluation towards third parties (e.g. examination offices) takes place.
8. Rights of data subjects
You have the following rights vis-à-vis the controller:
- Right of access to the data processed (Art. 15 GDPR)
- Right to rectification of inaccurate or incomplete data (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability in a structured, commonly used format (Art. 20 GDPR)
- Right to object to processing based on legitimate interests (Art. 21 GDPR)
- Right to withdraw consent with effect for the future (Art. 7 (3) GDPR)
An informal message to support@lexduvia.de is sufficient to exercise these rights. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority for us is the State Commissioner for Data Protection of Lower Saxony.
Terms of Use
1. Scope
These Terms of Use govern the use of the LexDuvia platform operated by LexDuvia UG (haftungsbeschränkt). By registering and using the platform you agree to these terms.
2. Description of service
LexDuvia provides an AI-assisted analysis platform for legal Gutachten (case analyses). Users can upload Gutachten and receive automated feedback on structure, argumentation and style. Based on the analysis, practice questions can also be generated.
3. No legal advice
LexDuvia is a learning tool and explicitly does not provide legal advice within the meaning of the German Legal Services Act (RDG). The AI-generated analyses and practice questions serve solely as learning support. For legal advice, please consult a qualified lawyer.
4. Notice on AI use
The analysis of your Gutachten is performed by AI models from Anthropic (Claude), operated via Amazon Bedrock in the EU. AI-generated content can contain errors. LexDuvia makes no warranty as to the correctness, completeness or timeliness of the generated analyses and practice questions. The results do not replace expert review by qualified instructors.
5. User obligations
- You may only upload content for which you hold the necessary rights
- You must not use the platform for unlawful purposes
- You are responsible for keeping your credentials secure
- Multiple accounts per user are not permitted
6. Availability
We strive for uninterrupted availability of the platform but cannot guarantee it. Maintenance, technical issues or force majeure can cause temporary restrictions. There is no entitlement to continuous availability.
7. Limitation of liability
LexDuvia is liable only for damages caused by intentional or grossly negligent conduct. Liability for slight negligence is excluded unless essential contractual obligations are affected. In particular, we accept no liability for examination outcomes achieved on the basis of our analyses.
8. Termination & account deletion
You can delete your account at any time. Upon deletion, all stored data (Gutachten, analyses, quiz results) is irrevocably removed. We reserve the right to suspend accounts that violate these Terms of Use.
9. Changes to the terms
We reserve the right to amend these Terms of Use. We will notify you by email of any material changes. Continued use of the platform after changes take effect constitutes acceptance.
10. Applicable law
The law of the Federal Republic of Germany applies. The place of jurisdiction, to the extent permitted by law, is the registered office of LexDuvia UG (haftungsbeschränkt).
Last updated: March 2026