Privacy Policy

LexFlow Privacy Policy

Last updated: 13 September 2026. LexFlow handles client data under EU GDPR requirements. We protect the privacy of our customers and their clients using recognised standards as a point of reference.

1. Who we are

LexFlow is a legal practice management platform operated for Studio Legale X (Genoa, Italy) and deployed by AVibe Agency. This privacy policy explains what data we collect, why, and how it is protected.

2. Data we collect

3. How we use data

4. Data protection

All data is transmitted over TLS. Client matter data in the LexFlow CRM is stored with bank-grade 256-bit encryption, zero-knowledge document storage, and SOC2-aligned practices. Internal notes are never visible to clients.

We protect the privacy of our customers and their clients using recognised standards as a point of reference.

Certification status: ISO/IEC 27001 and ISO/IEC 27701 certification is in progress and not yet held. SOC 2 is an auditing framework we align our practices with, not a completed certification. These are reference points for how we build, not claims of completed certification.

5. Cookies & local storage

LexFlow does not use advertising trackers. We use localStorage only for your language and theme preferences. A cookie consent banner is shown on first visit; you may dismiss it at any time.

6. Your rights (GDPR)

You may request access, correction, or deletion of your personal data at any time by writing to info@lexflow.com. We respond within 30 days.

7. Contact

LexFlow · Studio Legale X · Genova, Italia
WhatsApp: +39 345 023 4084 · info@lexflow.com