БГ
Log in

Privacy Policy

Lex Alert / Лекс Алерт

Version 2 · Effective 27 September 2026

1. Introduction

This Privacy Policy describes how Lex Alert (the “Platform”) collects, uses, stores and protects the personal data of users and of other persons when providing the service available at:

https://lexalert.bg

The Platform is an online system that automatically monitors publications in the State Gazette (Държавен вестник) and sends personalised notifications.

This policy is based on:

  • Regulation (EU) 2016/679 (GDPR)
  • the Bulgarian Personal Data Protection Act
  • the ePrivacy rules on cookies
  • the Google API Services User Data Policy

2. Data controller

Data controller:

  • Controller: Lex Alert - a platform operated by a natural person within the meaning of Article 4(7) GDPR
  • Email: [email protected]

GDPR contact: [email protected]

(hereinafter the “Controller”)

3. Types of personal data

3.1 Account and identification data

On registration we process:

  • email address
  • name (optional)
  • encrypted password (bcrypt hash)
  • the version of the Terms of Service you accepted and when

Sign-in with Google OAuth

If you choose to sign in with Google, we receive:

  • email address
  • name
  • profile picture
  • Google user ID

This data is used for authentication only. The Platform uses only the basic OAuth scopes (email, profile).

The data is:

  • not sold
  • not used for advertising
  • not used for profiling
  • not used for credit scoring

3.2 Billing and payment data

Payments are processed by Stripe. Stripe collects the card details and the billing name and address. The Platform does not store bank card details.

The Platform processes:

  • the customer ID in Stripe
  • the subscription plan, payment status and billing cycle
  • the accepted version of the First Subscribers Program Terms, when it was accepted and the checkout ID
  • the reason and comment given when cancelling a subscription (optional, free text)
  • withdrawals from the contract and refunded amounts

3.3 User-generated data

The Platform stores:

  • notification rules (keywords, institutions and settings)
  • notification preferences
  • consent to marketing emails
  • bookmarked publications
  • read status
  • webhook URL and webhook secret (Professional plan)
  • Telegram chat ID and bot token entered by the user (Telegram channel)
  • the reason given when requesting Professional features during the trial (free text; emailed to the administrator)

Webhook and Telegram notifications contain only public data from the State Gazette, not personal data of other users.

3.4 Technical and automatically collected data

When you use the service, we process:

  • session ID and JWT authentication tokens
  • security logs: records of changes to data (including a copy of the changed record), kept for 14 days
  • notification delivery logs (email, webhook, Telegram): request content, response and errors
  • the IP address when subscribing to the newsletter - only temporarily, to limit the number of requests

The following data is stored only locally in the browser and is not sent to the server:

  • authentication session token (localStorage)
  • language preference and light/dark theme (localStorage)
  • completion of onboarding and the product tour (localStorage)
  • filters, pagination and navigation state (sessionStorage - cleared when the tab is closed)

3.5 New-issue newsletter

When you subscribe to the newsletter, we process your email address. A subscription from the public website becomes active only after you confirm it through a link in an email (double opt-in). When you unsubscribe, the address is kept, marked as unsubscribed, only so that it isn’t added again by mistake.

3.6 Analytics data (public website only)

Analytics are used only on the public website, not in the app.

Services used:

  • Google Analytics 4 by Google LLC (via Google Tag Manager)
  • Microsoft Clarity by Microsoft Corporation

They are activated only after explicit consent through the cookie banner, using Google Consent Mode v2. All analytics cookies are disabled by default.

3.7 Personal data in State Gazette publications

State Gazette publications sometimes contain names and other data of natural persons (e.g. appointments, court notices, decrees). The Platform collects these publications from the official public source, stores them in its archive, matches them against users’ rules, includes them in notifications and processes them with artificial intelligence (section 6) to extract structured data.

  • Source: the State Gazette (dv.parliament.bg) - a public official source
  • Purpose: monitoring publications and notifying users
  • Legal basis: legitimate interest (Art. 6(1)(f) GDPR) - access to official legal information
  • Retention: publications are kept as an archive of the public record

The persons whose data appears in publications are not notified individually, as this would involve disproportionate effort (Art. 14(5)(b) GDPR). They can exercise their rights under section 10, including the right to object, by writing to [email protected]. The Platform cannot change the official text published in the State Gazette.

3.8 Data we do NOT collect

The Platform does not collect:

  • health data
  • biometric data
  • GPS or location data
  • phone numbers
  • data about children
  • special categories of personal data under Article 9 GDPR, unless contained in a State Gazette publication (section 3.7)

Minimum age of use: 18 years.

3.9 Calls with users

You can book a call with us (optional) through a Cal.com booking page. When you book, we process your name, email address, the chosen time and your answers in the form. The call takes place in Google Meet.

The call is recorded, transcribed and summarised with Fathom only with your explicit consent, asked for at the start of the call. If you don’t agree, the call takes place without a recording. The recording and summary are not sent to anyone automatically and are used only to improve the service.

3.10 Source of sign-up and subscription

When you open the website or the app through a link in one of our emails, the link carries campaign parameters (utm_source, utm_medium, utm_campaign, utm_content). The app keeps them temporarily in the browser tab (sessionStorage) and stores them with your account when you sign up or subscribe. This tells us which of our messages were useful. No cookies are used and the data is not shared with advertising networks.

4. Purposes and legal bases

PurposeLegal basis
Registration and sign-inArt. 6(1)(b) GDPR – contract
Delivering notifications (email, webhook, Telegram)Art. 6(1)(b) GDPR
Managing subscriptions and paymentsArt. 6(1)(b) GDPR
Withdrawals, complaints, accounting documentsArt. 6(1)(c) GDPR – legal obligation
Proof of accepted termsArt. 6(1)(f) GDPR – legitimate interest
Security and auditArt. 6(1)(f) GDPR – legitimate interest
State Gazette publications (section 3.7)Art. 6(1)(f) GDPR – legitimate interest
New-issue newsletterArt. 6(1)(a) GDPR – consent
AnalyticsArt. 6(1)(a) GDPR – consent
Marketing emailsArt. 6(1)(a) GDPR – consent
Arranging and holding calls with users (section 3.9)Art. 6(1)(f) GDPR – legitimate interest
Recording, transcribing and summarising a call (section 3.9)Art. 6(1)(a) GDPR – consent
Source of sign-up and subscription (section 3.10)Art. 6(1)(f) GDPR – legitimate interest

5. Cookies

The public website uses one necessary cookie (for your cookie choice) and, only with consent, analytics cookies. The app does not use cookies. Details: Cookie Policy.

6. Data recipients (processors)

ProviderPurposeLocation
Supabase, Inc.hosting and databaseAWS eu-central-1 (Germany)
Cloudflare, Inc.hosting of the website and the app; forwarding of emails to contact@ and privacy@global network (EU/USA)
Stripe Payments Europe, Ltd. / Stripe, Inc.paymentsEU/USA
Resend (Plus Five Five, Inc.)transactional emails and the newsletter listUSA
Google LLCGoogle sign-in, analytics, the mailbox for emails to contact@ and privacy@, calendar and Google Meet for the calls in section 3.9EU/USA
Cal.com, Inc.booking page for calls (section 3.9)USA
Fathom Video, Inc.recording, transcribing and summarising calls, only with consent (section 3.9)USA
Microsoft CorporationClarity (analytics)EU/USA
Telegramnotification delivery, only if the user has set up a Telegram channeloutside the EU
Anthropic, PBCAI processing of State Gazette publicationsUSA
INSAIT, Sofia University “St. Kliment Ohridski” (BgGPT)backup provider for AI processing of publicationsEU (Netherlands)

Anthropic and INSAIT receive only the texts of State Gazette publications, not user data. Publications may contain the data of persons described in section 3.7.

The Platform:

  • does not sell personal data
  • does not share data with advertising networks
  • does not use data brokers

7. International transfers

For transfers outside the EEA we rely on:

  • the EU–US Data Privacy Framework (for certified providers)
  • Standard Contractual Clauses (SCCs)
  • additional technical measures, including encryption in transit and at rest

8. Retention periods

DataRetention
Account data, rules and settingsuntil the account is deleted
Notification historywhile the account exists; visibility depends on the plan; deleted with the account
Accepted terms (version and time)until the account is deleted
Notification delivery logs and webhook responses90 days
Security logs14 days
Operational copies for alerts and failed processing90 days
Data export fileuntil the download link expires (24 hours)
Customer and invoices in Stripe10 years (Bulgarian Accountancy Act); kept after the account is deleted
Newsletteruntil you unsubscribe; the address then stays marked as unsubscribed
Emails to contact@ and privacy@as long as needed to reply and to protect our rights
Analytics dataas set by Google LLC / Microsoft Corporation
Call bookings12 months
Call recordings, transcripts and summaries6 months
Source of sign-up and subscriptionuntil the account is deleted
State Gazette publicationsas an archive of the public record

9. Security

We apply technical and organisational measures, including:

  • HTTPS/TLS encryption
  • encryption at rest
  • Row Level Security (RLS)
  • bcrypt password hashing
  • HMAC-SHA256 webhook signing
  • CORS protection
  • Content Security Policy
  • session management and token rotation
  • masking of sensitive data in logs

10. Data subject rights

You have the right to:

  • access (Art. 15 GDPR)
  • rectification (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction (Art. 18 GDPR)
  • portability (Art. 20 GDPR)
  • object (Art. 21 GDPR)
  • withdraw consent (Art. 7 GDPR)

Data export and account deletion are available directly under Settings → Data & Privacy in the app.

Requests: [email protected]

11. Automated decision-making

The Platform does not carry out profiling or automated decision-making under Article 22 GDPR.

12. Children’s data

The service is a professional tool and is not intended for persons under 18.

13. Google OAuth compliance

The Platform complies with the Google API Services User Data Policy:

  • uses only the basic OAuth scopes
  • uses the data only for sign-in
  • does not use it for advertising
  • does not sell it
  • does not share it beyond what authentication requires

14. Complaints

You can lodge a complaint with:

Commission for Personal Data Protection (КЗЛД) https://www.cpdp.bg

15. Changes to this policy

This policy may be updated when the service or the law changes. New versions are published at lexalert.bg/en/privacy with a number and date; previous versions remain available (e.g. version 1).

16. Contact

  • [email protected]
  • [email protected]

Language

This is an English translation of the Bulgarian original. If the two differ, the Bulgarian version prevails.

Terms of service Privacy policy Cookies

© 2026 Lex Alert · [email protected] ·