БГ
Log in

Privacy Policy

Lex Alert / Лекс Алерт

Version 1 · Effective 22 February 2026 to 26 September 2026 · Current version

1. Introduction

This Privacy Policy describes how Lex Alert (the “Platform”) collects, uses, stores and protects users’ personal data when they use the service available at:

https://lexalert.bg

The Platform is an online system that automatically monitors publications in the State Gazette (Държавен вестник) and sends personalised notifications.

This policy is based on:

  • Regulation (EU) 2016/679 (GDPR)
  • the Bulgarian Personal Data Protection Act
  • the ePrivacy rules on cookies
  • the Google API Services User Data Policy

2. Data controller

Data controller:

  • Controller: Lex Alert - a platform operated by a natural person within the meaning of Article 4(7) GDPR
  • Email: [email protected]

GDPR contact: [email protected]

(hereinafter the “Controller”)

3. Types of personal data

3.1 Account and identification data

On registration we process:

  • email address
  • name (optional)
  • encrypted password (bcrypt hash)

Sign-in with Google OAuth

If you choose to sign in with Google, we receive:

  • email address
  • name
  • profile picture
  • Google user ID

This data is used for authentication only.

The Platform uses only the basic OAuth scopes (email, profile).

The data is:

  • not sold
  • not used for advertising
  • not used for profiling
  • not used for credit scoring

3.2 Billing and payment data

Payments are processed by Stripe, Inc.

We process only:

  • the customer ID in Stripe
  • the subscription plan
  • the payment status
  • the billing cycle

The Platform does not store bank card details.

3.3 User-generated data

The Platform stores:

  • notification rules (keywords, institutions and settings)
  • notification preferences
  • consent to marketing emails
  • bookmarked publications
  • read status
  • webhook URL and webhook secret (Professional plan)

Webhook notifications contain only public data from the State Gazette, not personal data of other users.

3.4 Technical and automatically collected data

When you use the service, the following may be processed:

  • IP address (audit logs)
  • session ID
  • JWT authentication tokens
  • actions in the system, for security purposes

The following data is stored only locally in the browser and is not sent to the server:

  • authentication session token (localStorage)
  • language preference (localStorage)
  • light/dark theme (localStorage)
  • completion of onboarding and the product tour (localStorage)
  • filters, pagination and navigation state (sessionStorage - cleared when the tab is closed)

3.5 Analytics data (home page only)

Analytics are used only on the public home page, not in the user dashboard.

Services used:

  • Google Analytics 4 by Google LLC (via Google Tag Manager)
  • Microsoft Clarity by Microsoft Corporation

They are activated only after explicit consent through the cookie banner, using Google Consent Mode v2.

All analytics cookies are disabled by default.

3.6 Data we do NOT collect

The Platform does not collect:

  • health data
  • biometric data
  • GPS or location data
  • phone numbers
  • data about children
  • special categories of personal data under Article 9 GDPR

Minimum age of use: 18 years.

4. Purposes and legal bases

PurposeLegal basis
Registration and sign-inArt. 6(1)(b) GDPR – contract
Delivering notificationsArt. 6(1)(b) GDPR
Managing subscriptionsArt. 6(1)(b) GDPR
Webhook deliveryArt. 6(1)(b) GDPR
Security and auditArt. 6(1)(f) GDPR – legitimate interest
AnalyticsArt. 6(1)(a) GDPR – consent
Marketing emailsArt. 6(1)(a) GDPR – consent
Legal obligationsArt. 6(1)(c) GDPR

5. Cookies

5.1 Necessary cookies and local storage

Used to:

  • store your cookie consent
NamePurposeDuration
cc_cookiecookie consent1 year

5.2 Analytics cookies (optional)

ServiceCookiesDuration
Google Analytics_ga, ga*up to 2 years
Microsoft Clarity_clck, _clsksession

No advertising cookies are used.

6. Data recipients (processors)

ProviderPurposeLocation
Supabase, Inc.hosting and databaseAWS eu-central-1 (Germany)
Stripe, Inc.paymentsEU/USA
Resend (Loops, Inc.)transactional emailsUSA
Google LLCOAuth + analyticsEU/USA
Microsoft CorporationClarityEU/USA
Anthropic, PBCAI processing of public textsUSA

Anthropic, PBC receives only public government publications, not personal data.

The Platform:

  • does not sell personal data
  • does not share data with advertising networks
  • does not use data brokers

7. International transfers

For transfers outside the EEA we rely on:

  • Standard Contractual Clauses (SCCs)
  • additional technical measures
  • encryption in transit and at rest

8. Retention periods

DataRetention
Account datauntil deletion
Audit logsdeleted automatically
Billing recordsas required by law
Analytics dataas set by Google LLC / Microsoft Corporation

9. Security

We apply technical and organisational measures, including:

  • HTTPS/TLS encryption
  • encryption at rest
  • Row Level Security (RLS)
  • bcrypt password hashing
  • HMAC-SHA256 webhook signing
  • CORS protection
  • Content Security Policy
  • session management and token rotation
  • masking of sensitive data in logs

10. Data subject rights

Users have the right to:

  • access (Art. 15 GDPR)
  • rectification (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction (Art. 18 GDPR)
  • portability (Art. 20 GDPR)
  • object (Art. 21 GDPR)
  • withdraw consent (Art. 7 GDPR)

Some of these are available directly in the account settings.

Requests: [email protected]

11. Automated decision-making

The Platform does not carry out profiling or automated decision-making under Article 22 GDPR.

12. Children’s data

The service is a professional tool and is not intended for persons under 18.

13. Google OAuth compliance

The Platform complies with the Google API Services User Data Policy:

  • uses only the basic OAuth scopes
  • uses the data only for sign-in
  • does not use it for advertising
  • does not sell it
  • does not share it beyond what authentication requires

14. Complaints

Users can lodge a complaint with:

Commission for Personal Data Protection (КЗЛД) https://www.cpdp.bg

15. Changes to this policy

This policy may be updated when the service or the law changes.

16. Contact

  • [email protected]
  • [email protected]

Language

This is an English translation of the Bulgarian original. If the two differ, the Bulgarian version prevails.

Terms of service Privacy policy Cookies

© 2026 Lex Alert · [email protected] ·