Back to Lexoreg

Privacy Policy

Last updated: April 24, 2026

1. Introduction

This Privacy Policy explains how Lexoreg ("Lexoreg", "we", "us") collects, uses, stores, and protects personal data when you use the Lexoreg platform ("Service").

Lexoreg is the data controller for personal data collected through account registration and platform usage. For customer-uploaded data (SBOMs, product information), Lexoreg acts as a data processor on behalf of the customer (data controller).

Data Controller: Lexoreg, Espoo, Finland — hello@lexoreg.io

2. Personal Data We Collect

2.1 Account Data (provided by you)

DataPurposeLegal Basis
NameAccount identification, communicationContract performance
Email addressAuthentication, notifications, supportContract performance
Password (hashed)AuthenticationContract performance
Organization nameMulti-tenant account setupContract performance
IP addressSecurity, rate limiting, audit trailLegitimate interest

2.2 Usage Data (collected automatically)

DataPurposeLegal Basis
Browser type and versionService optimizationLegitimate interest
Pages visitedProduct improvementLegitimate interest
Session timestampsSecurity monitoringLegitimate interest
API request logsDebugging, rate limitingLegitimate interest

2.3 Customer-Uploaded Data

Data you upload (product information, SBOMs, vulnerability records, ENISA reports, compliance checks) is processed strictly as a data processor on your behalf. We process this data solely to provide the Service.

3. How We Use Personal Data

We use personal data to:

  • Provide and maintain the Service
  • Authenticate users and manage accounts
  • Send transactional emails (vulnerability alerts, ENISA deadline reminders, password reset)
  • Process payments and manage subscriptions
  • Provide customer support
  • Monitor and improve Service performance and security
  • Comply with legal obligations

We do NOT use personal data for: advertising, selling to third parties, profiling, automated decision-making, or training AI/ML models.

4. Data Storage and Security

4.1 Where Data Is Stored

ServiceProviderLocationPurpose
DatabaseNeon (PostgreSQL)EU (Frankfurt)All application data
File storageCloudflare R2EUSBOM files
RedisRailwayEURate limiting, session cache
EmailResendUS (with EU processing)Transactional emails
API hostingRailwayEUApplication hosting
Web hostingVercelEUFrontend hosting

All primary data storage is within the European Economic Area (EEA).

4.2 Security Measures

  • All data encrypted in transit (TLS 1.2+)
  • Database encrypted at rest
  • Passwords hashed with bcrypt
  • API keys hashed with Argon2id
  • Audit trail hash-chained for tamper detection
  • Role-based access control (RBAC)
  • Rate limiting on authentication endpoints

5. Data Retention

Data TypeRetention PeriodReason
Account dataDuration of account + 30 daysService provision
Audit trail5 years after creationCRA compliance evidence requirement
SBOM filesDuration of account + 30 daysService provision
ENISA reports5 years after creationRegulatory evidence
Session logs90 daysSecurity monitoring
Payment records7 yearsFinnish tax law (Accounting Act)
Expired trial data90 days after trial expiryGrace period for reactivation

6. Data Sharing

6.1 Sub-Processors

Sub-ProcessorPurposeLocation
Neon Inc.Database hostingEU
Railway Corp.API hosting, RedisEU
Vercel Inc.Frontend hostingEU
Cloudflare Inc.DNS, file storage (R2)EU
Resend Inc.Email deliveryUS

6.2 Legal Requirements

We may disclose personal data if required by Finnish law, EU regulation, or court order. We will notify you of such disclosures unless prohibited by law.

6.3 Business Transfer

In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the acquiring entity. We will notify you before your data becomes subject to a different privacy policy.

7. Your Rights (GDPR)

Under the EU General Data Protection Regulation, you have the right to:

RightDescription
AccessRequest a copy of your personal data
RectificationCorrect inaccurate personal data
ErasureRequest deletion of your personal data
RestrictionRequest restriction of processing
PortabilityReceive your data in a structured, machine-readable format
ObjectionObject to processing based on legitimate interest
Withdraw consentWithdraw consent at any time where consent is the legal basis

To exercise any of these rights, contact us at hello@lexoreg.io. We will respond within 30 days.

Note on audit trail: Due to the immutable, hash-chained nature of the audit trail (required for CRA compliance evidence), individual entries cannot be deleted. Instead, we apply pseudonymisation to redact personal identifiers while preserving the integrity of the audit chain.

8. Cookies

Lexoreg uses only essential cookies required for the Service to function:

CookiePurposeDuration
Session cookieAuthenticationSession (expires on logout or after idle period)

We do NOT use: tracking cookies, analytics cookies, advertising cookies, or social media cookies. No cookie consent banner is required because we only use strictly necessary cookies.

9. International Transfers

Primary data processing occurs within the EEA. Where sub-processors operate outside the EEA (Resend), data transfers are protected by EU Standard Contractual Clauses (SCCs) as approved by the European Commission.

10. Children's Data

Lexoreg is not directed at individuals under the age of 18. We do not knowingly collect personal data from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email at least 30 days before taking effect.

12. Contact and Complaints

Data Controller:
Lexoreg
Email: hello@lexoreg.io
Espoo, Finland

Supervisory Authority:
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Finnish Data Protection Ombudsman:

Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
Website: tietosuoja.fi
Email: tietosuoja@om.fi
Address: Lintulahdenkuja 4, 00530 Helsinki, Finland