Privacy Policy
Lex Alert / Лекс Алерт
Version 2 · Effective 27 September 2026
1. Introduction
This Privacy Policy describes how Lex Alert (the “Platform”) collects, uses, stores and protects the personal data of users and of other persons when providing the service available at:
The Platform is an online system that automatically monitors publications in the State Gazette (Държавен вестник) and sends personalised notifications.
This policy is based on:
- Regulation (EU) 2016/679 (GDPR)
- the Bulgarian Personal Data Protection Act
- the ePrivacy rules on cookies
- the Google API Services User Data Policy
2. Data controller
Data controller:
- Controller: Lex Alert - a platform operated by a natural person within the meaning of Article 4(7) GDPR
- Email: [email protected]
GDPR contact: [email protected]
(hereinafter the “Controller”)
3. Types of personal data
3.1 Account and identification data
On registration we process:
- email address
- name (optional)
- encrypted password (bcrypt hash)
- the version of the Terms of Service you accepted and when
Sign-in with Google OAuth
If you choose to sign in with Google, we receive:
- email address
- name
- profile picture
- Google user ID
This data is used for authentication only. The Platform uses only the basic OAuth scopes (email, profile).
The data is:
- not sold
- not used for advertising
- not used for profiling
- not used for credit scoring
3.2 Billing and payment data
Payments are processed by Stripe. Stripe collects the card details and the billing name and address. The Platform does not store bank card details.
The Platform processes:
- the customer ID in Stripe
- the subscription plan, payment status and billing cycle
- the accepted version of the First Subscribers Program Terms, when it was accepted and the checkout ID
- the reason and comment given when cancelling a subscription (optional, free text)
- withdrawals from the contract and refunded amounts
3.3 User-generated data
The Platform stores:
- notification rules (keywords, institutions and settings)
- notification preferences
- consent to marketing emails
- bookmarked publications
- read status
- webhook URL and webhook secret (Professional plan)
- Telegram chat ID and bot token entered by the user (Telegram channel)
- the reason given when requesting Professional features during the trial (free text; emailed to the administrator)
Webhook and Telegram notifications contain only public data from the State Gazette, not personal data of other users.
3.4 Technical and automatically collected data
When you use the service, we process:
- session ID and JWT authentication tokens
- security logs: records of changes to data (including a copy of the changed record), kept for 14 days
- notification delivery logs (email, webhook, Telegram): request content, response and errors
- the IP address when subscribing to the newsletter - only temporarily, to limit the number of requests
The following data is stored only locally in the browser and is not sent to the server:
- authentication session token (localStorage)
- language preference and light/dark theme (localStorage)
- completion of onboarding and the product tour (localStorage)
- filters, pagination and navigation state (sessionStorage - cleared when the tab is closed)
3.5 New-issue newsletter
When you subscribe to the newsletter, we process your email address. A subscription from the public website becomes active only after you confirm it through a link in an email (double opt-in). When you unsubscribe, the address is kept, marked as unsubscribed, only so that it isn’t added again by mistake.
3.6 Analytics data (public website only)
Analytics are used only on the public website, not in the app.
Services used:
- Google Analytics 4 by Google LLC (via Google Tag Manager)
- Microsoft Clarity by Microsoft Corporation
They are activated only after explicit consent through the cookie banner, using Google Consent Mode v2. All analytics cookies are disabled by default.
3.7 Personal data in State Gazette publications
State Gazette publications sometimes contain names and other data of natural persons (e.g. appointments, court notices, decrees). The Platform collects these publications from the official public source, stores them in its archive, matches them against users’ rules, includes them in notifications and processes them with artificial intelligence (section 6) to extract structured data.
- Source: the State Gazette (dv.parliament.bg) - a public official source
- Purpose: monitoring publications and notifying users
- Legal basis: legitimate interest (Art. 6(1)(f) GDPR) - access to official legal information
- Retention: publications are kept as an archive of the public record
The persons whose data appears in publications are not notified individually, as this would involve disproportionate effort (Art. 14(5)(b) GDPR). They can exercise their rights under section 10, including the right to object, by writing to [email protected]. The Platform cannot change the official text published in the State Gazette.
3.8 Data we do NOT collect
The Platform does not collect:
- health data
- biometric data
- GPS or location data
- phone numbers
- data about children
- special categories of personal data under Article 9 GDPR, unless contained in a State Gazette publication (section 3.7)
Minimum age of use: 18 years.
3.9 Calls with users
You can book a call with us (optional) through a Cal.com booking page. When you book, we process your name, email address, the chosen time and your answers in the form. The call takes place in Google Meet.
The call is recorded, transcribed and summarised with Fathom only with your explicit consent, asked for at the start of the call. If you don’t agree, the call takes place without a recording. The recording and summary are not sent to anyone automatically and are used only to improve the service.
3.10 Source of sign-up and subscription
When you open the website or the app through a link in one of our emails, the link carries campaign parameters (utm_source, utm_medium, utm_campaign, utm_content). The app keeps them temporarily in the browser tab (sessionStorage) and stores them with your account when you sign up or subscribe. This tells us which of our messages were useful. No cookies are used and the data is not shared with advertising networks.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Registration and sign-in | Art. 6(1)(b) GDPR – contract |
| Delivering notifications (email, webhook, Telegram) | Art. 6(1)(b) GDPR |
| Managing subscriptions and payments | Art. 6(1)(b) GDPR |
| Withdrawals, complaints, accounting documents | Art. 6(1)(c) GDPR – legal obligation |
| Proof of accepted terms | Art. 6(1)(f) GDPR – legitimate interest |
| Security and audit | Art. 6(1)(f) GDPR – legitimate interest |
| State Gazette publications (section 3.7) | Art. 6(1)(f) GDPR – legitimate interest |
| New-issue newsletter | Art. 6(1)(a) GDPR – consent |
| Analytics | Art. 6(1)(a) GDPR – consent |
| Marketing emails | Art. 6(1)(a) GDPR – consent |
| Arranging and holding calls with users (section 3.9) | Art. 6(1)(f) GDPR – legitimate interest |
| Recording, transcribing and summarising a call (section 3.9) | Art. 6(1)(a) GDPR – consent |
| Source of sign-up and subscription (section 3.10) | Art. 6(1)(f) GDPR – legitimate interest |
5. Cookies
The public website uses one necessary cookie (for your cookie choice) and, only with consent, analytics cookies. The app does not use cookies. Details: Cookie Policy.
6. Data recipients (processors)
| Provider | Purpose | Location |
|---|---|---|
| Supabase, Inc. | hosting and database | AWS eu-central-1 (Germany) |
| Cloudflare, Inc. | hosting of the website and the app; forwarding of emails to contact@ and privacy@ | global network (EU/USA) |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | payments | EU/USA |
| Resend (Plus Five Five, Inc.) | transactional emails and the newsletter list | USA |
| Google LLC | Google sign-in, analytics, the mailbox for emails to contact@ and privacy@, calendar and Google Meet for the calls in section 3.9 | EU/USA |
| Cal.com, Inc. | booking page for calls (section 3.9) | USA |
| Fathom Video, Inc. | recording, transcribing and summarising calls, only with consent (section 3.9) | USA |
| Microsoft Corporation | Clarity (analytics) | EU/USA |
| Telegram | notification delivery, only if the user has set up a Telegram channel | outside the EU |
| Anthropic, PBC | AI processing of State Gazette publications | USA |
| INSAIT, Sofia University “St. Kliment Ohridski” (BgGPT) | backup provider for AI processing of publications | EU (Netherlands) |
Anthropic and INSAIT receive only the texts of State Gazette publications, not user data. Publications may contain the data of persons described in section 3.7.
The Platform:
- does not sell personal data
- does not share data with advertising networks
- does not use data brokers
7. International transfers
For transfers outside the EEA we rely on:
- the EU–US Data Privacy Framework (for certified providers)
- Standard Contractual Clauses (SCCs)
- additional technical measures, including encryption in transit and at rest
8. Retention periods
| Data | Retention |
|---|---|
| Account data, rules and settings | until the account is deleted |
| Notification history | while the account exists; visibility depends on the plan; deleted with the account |
| Accepted terms (version and time) | until the account is deleted |
| Notification delivery logs and webhook responses | 90 days |
| Security logs | 14 days |
| Operational copies for alerts and failed processing | 90 days |
| Data export file | until the download link expires (24 hours) |
| Customer and invoices in Stripe | 10 years (Bulgarian Accountancy Act); kept after the account is deleted |
| Newsletter | until you unsubscribe; the address then stays marked as unsubscribed |
| Emails to contact@ and privacy@ | as long as needed to reply and to protect our rights |
| Analytics data | as set by Google LLC / Microsoft Corporation |
| Call bookings | 12 months |
| Call recordings, transcripts and summaries | 6 months |
| Source of sign-up and subscription | until the account is deleted |
| State Gazette publications | as an archive of the public record |
9. Security
We apply technical and organisational measures, including:
- HTTPS/TLS encryption
- encryption at rest
- Row Level Security (RLS)
- bcrypt password hashing
- HMAC-SHA256 webhook signing
- CORS protection
- Content Security Policy
- session management and token rotation
- masking of sensitive data in logs
10. Data subject rights
You have the right to:
- access (Art. 15 GDPR)
- rectification (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction (Art. 18 GDPR)
- portability (Art. 20 GDPR)
- object (Art. 21 GDPR)
- withdraw consent (Art. 7 GDPR)
Data export and account deletion are available directly under Settings → Data & Privacy in the app.
Requests: [email protected]
11. Automated decision-making
The Platform does not carry out profiling or automated decision-making under Article 22 GDPR.
12. Children’s data
The service is a professional tool and is not intended for persons under 18.
13. Google OAuth compliance
The Platform complies with the Google API Services User Data Policy:
- uses only the basic OAuth scopes
- uses the data only for sign-in
- does not use it for advertising
- does not sell it
- does not share it beyond what authentication requires
14. Complaints
You can lodge a complaint with:
Commission for Personal Data Protection (КЗЛД) https://www.cpdp.bg
15. Changes to this policy
This policy may be updated when the service or the law changes. New versions are published at lexalert.bg/en/privacy with a number and date; previous versions remain available (e.g. version 1).
16. Contact
Language
This is an English translation of the Bulgarian original. If the two differ, the Bulgarian version prevails.