Privacy Policy
Lex Alert / Лекс Алерт
Version 1 · Effective 22 February 2026 to 26 September 2026 · Current version
1. Introduction
This Privacy Policy describes how Lex Alert (the “Platform”) collects, uses, stores and protects users’ personal data when they use the service available at:
The Platform is an online system that automatically monitors publications in the State Gazette (Държавен вестник) and sends personalised notifications.
This policy is based on:
- Regulation (EU) 2016/679 (GDPR)
- the Bulgarian Personal Data Protection Act
- the ePrivacy rules on cookies
- the Google API Services User Data Policy
2. Data controller
Data controller:
- Controller: Lex Alert - a platform operated by a natural person within the meaning of Article 4(7) GDPR
- Email: [email protected]
GDPR contact: [email protected]
(hereinafter the “Controller”)
3. Types of personal data
3.1 Account and identification data
On registration we process:
- email address
- name (optional)
- encrypted password (bcrypt hash)
Sign-in with Google OAuth
If you choose to sign in with Google, we receive:
- email address
- name
- profile picture
- Google user ID
This data is used for authentication only.
The Platform uses only the basic OAuth scopes (email, profile).
The data is:
- not sold
- not used for advertising
- not used for profiling
- not used for credit scoring
3.2 Billing and payment data
Payments are processed by Stripe, Inc.
We process only:
- the customer ID in Stripe
- the subscription plan
- the payment status
- the billing cycle
The Platform does not store bank card details.
3.3 User-generated data
The Platform stores:
- notification rules (keywords, institutions and settings)
- notification preferences
- consent to marketing emails
- bookmarked publications
- read status
- webhook URL and webhook secret (Professional plan)
Webhook notifications contain only public data from the State Gazette, not personal data of other users.
3.4 Technical and automatically collected data
When you use the service, the following may be processed:
- IP address (audit logs)
- session ID
- JWT authentication tokens
- actions in the system, for security purposes
The following data is stored only locally in the browser and is not sent to the server:
- authentication session token (localStorage)
- language preference (localStorage)
- light/dark theme (localStorage)
- completion of onboarding and the product tour (localStorage)
- filters, pagination and navigation state (sessionStorage - cleared when the tab is closed)
3.5 Analytics data (home page only)
Analytics are used only on the public home page, not in the user dashboard.
Services used:
- Google Analytics 4 by Google LLC (via Google Tag Manager)
- Microsoft Clarity by Microsoft Corporation
They are activated only after explicit consent through the cookie banner, using Google Consent Mode v2.
All analytics cookies are disabled by default.
3.6 Data we do NOT collect
The Platform does not collect:
- health data
- biometric data
- GPS or location data
- phone numbers
- data about children
- special categories of personal data under Article 9 GDPR
Minimum age of use: 18 years.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Registration and sign-in | Art. 6(1)(b) GDPR – contract |
| Delivering notifications | Art. 6(1)(b) GDPR |
| Managing subscriptions | Art. 6(1)(b) GDPR |
| Webhook delivery | Art. 6(1)(b) GDPR |
| Security and audit | Art. 6(1)(f) GDPR – legitimate interest |
| Analytics | Art. 6(1)(a) GDPR – consent |
| Marketing emails | Art. 6(1)(a) GDPR – consent |
| Legal obligations | Art. 6(1)(c) GDPR |
5. Cookies
5.1 Necessary cookies and local storage
Used to:
- store your cookie consent
| Name | Purpose | Duration |
|---|---|---|
| cc_cookie | cookie consent | 1 year |
5.2 Analytics cookies (optional)
| Service | Cookies | Duration |
|---|---|---|
| Google Analytics | _ga, ga* | up to 2 years |
| Microsoft Clarity | _clck, _clsk | session |
No advertising cookies are used.
6. Data recipients (processors)
| Provider | Purpose | Location |
|---|---|---|
| Supabase, Inc. | hosting and database | AWS eu-central-1 (Germany) |
| Stripe, Inc. | payments | EU/USA |
| Resend (Loops, Inc.) | transactional emails | USA |
| Google LLC | OAuth + analytics | EU/USA |
| Microsoft Corporation | Clarity | EU/USA |
| Anthropic, PBC | AI processing of public texts | USA |
Anthropic, PBC receives only public government publications, not personal data.
The Platform:
- does not sell personal data
- does not share data with advertising networks
- does not use data brokers
7. International transfers
For transfers outside the EEA we rely on:
- Standard Contractual Clauses (SCCs)
- additional technical measures
- encryption in transit and at rest
8. Retention periods
| Data | Retention |
|---|---|
| Account data | until deletion |
| Audit logs | deleted automatically |
| Billing records | as required by law |
| Analytics data | as set by Google LLC / Microsoft Corporation |
9. Security
We apply technical and organisational measures, including:
- HTTPS/TLS encryption
- encryption at rest
- Row Level Security (RLS)
- bcrypt password hashing
- HMAC-SHA256 webhook signing
- CORS protection
- Content Security Policy
- session management and token rotation
- masking of sensitive data in logs
10. Data subject rights
Users have the right to:
- access (Art. 15 GDPR)
- rectification (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction (Art. 18 GDPR)
- portability (Art. 20 GDPR)
- object (Art. 21 GDPR)
- withdraw consent (Art. 7 GDPR)
Some of these are available directly in the account settings.
Requests: [email protected]
11. Automated decision-making
The Platform does not carry out profiling or automated decision-making under Article 22 GDPR.
12. Children’s data
The service is a professional tool and is not intended for persons under 18.
13. Google OAuth compliance
The Platform complies with the Google API Services User Data Policy:
- uses only the basic OAuth scopes
- uses the data only for sign-in
- does not use it for advertising
- does not sell it
- does not share it beyond what authentication requires
14. Complaints
Users can lodge a complaint with:
Commission for Personal Data Protection (КЗЛД) https://www.cpdp.bg
15. Changes to this policy
This policy may be updated when the service or the law changes.
16. Contact
Language
This is an English translation of the Bulgarian original. If the two differ, the Bulgarian version prevails.