Security is our priority

    Security and protection of your legal information are the foundation of our platform. We built Lexomat with emphasis on transparency, compliance, and maximum data protection.

    How do we protect your data?

    We implement the strictest security standards to protect your data

    Encryption at every level

    All data is encrypted in transit (TLS 1.3) and at rest (AES-256). This applies to your searches, documents, and chat history.

    Your content is confidential

    We access technical data such as settings and metadata only for system maintenance or security incidents. We access your chat and search queries only with your explicit consent.

    Data is not used for training

    Your data is not used for AI model training. We select providers and settings that exclude such use.

    All user and legal data stays in the EU*

    All user data is processed and stored on servers in the European Union. Payment processing by Stripe and authentication are secured via GDPR-compliant transfer mechanisms (SCCs, DPF).

    Limited data access

    Only authorized team members have access to the production database. Every access requires MFA.

    Certified infrastructure

    Our hosting infrastructure is certified to ISO/IEC 27001:2022, the international standard for information security management.

    Designed per SAK guidelines

    SAK Presidency Resolution No. 12/4/2025

    SAK Presidency Resolution No. 12/4/2025 sets conditions for AI use in legal practice. Lexomat meets regime (c) requirements – professional secrecy is protected both contractually and technically: encryption (TLS 1.3, AES-256), MFA sign-in, data stored in the EU*. User data is never used for AI model training – this is ensured both contractually and technically. DPAs are in place with all providers. Need a processing agreement? Get in touch.

    MFA support - multi-factor authentication option
    Encryption - TLS 1.3 in transit, AES-256 at rest
    All user data stored in the EU*
    GDPR providers - DPAs in place with all sub-processors

    Technical minimums

    We meet security requirements of Art. 6(3) of the methodology: encryption, MFA, EEA data location.

    No-training policy

    Your data is not used for AI model training. We select providers and settings that exclude such use.

    DPA on request

    For lawyers in processor regime (c) under Art. 28 GDPR, we have DPAs in place with all providers. Contact us for a processing agreement.

    Lexomat meets the technical requirements of SAK guidelines. User data is never used for AI model training. DPAs are in place with all providers. For regime (c) under Art. 28 GDPR, contact us.

    GDPR Compliant

    GDPR Compliance

    We only work with data you need for your task - nothing more. We comply with all GDPR obligations including personal data protection and transparency.

    Data processing in EU

    User data (chat history, search queries, document analysis, settings, uploaded files) is stored in the EU. Authentication and payment processing use GDPR-compliant providers with EU transfer safeguards (SCCs, DPF).

    Full control over data

    We provide users with full control over their data including export and portability options.

    Right to erasure

    You have full ability to delete your data at any time. We respect your right to be forgotten.

    No secondary purposes

    Your data is not used for model training. We select providers and settings that exclude secondary use of your data.

    Data minimization

    We only work with data that is strictly necessary to provide the service.

    GDPR-compliant providers

    All sub-processors have Data Processing Agreements in place and confirmed no-training policies. All data is processed exclusively in the EU, except payments (Stripe, US), whose transfers are protected by SCCs and DPF. Authentication is handled by Supabase Auth within the EU.

    EU AI Act Compliance

    EU AI Act

    Regulation (EU) 2024/1689, Article 50

    The EU AI Act sets transparency requirements for AI systems. Lexomat is designed to meet all applicable obligations under Article 50 — so you can use AI for legal research with confidence that the platform operates responsibly and transparently.

    AI interaction disclosure — you are always informed that responses are generated by AI
    Machine-readable marking — AI-generated content includes metadata identifying it as AI-produced
    Shared content labeled — exported and shared sessions clearly indicate AI-generated content
    No training on your data — your data is never used to train AI models
    Human oversight — AI assists your research, it does not replace professional legal judgment

    Transparency by design

    Every AI response is clearly identified. You always know when you are interacting with AI and can verify outputs against primary legal sources.

    Content provenance

    AI-generated text includes machine-readable metadata and attribution, ensuring content provenance and traceability.

    Responsible AI use

    Lexomat is an AI research tool, not a replacement for a lawyer. We design the system to support — not supplant — professional judgment.

    Frequently asked questions

    Answers to questions about security and protection of your data

    Sources & Reliability

    Database & Content

    Features & Teams

    Updates & Accuracy

    Security & Privacy

    Discover what Lexomat can do

    Learn how Lexomat can save you hours on legal research with AI-powered tools built specifically for Slovak legislation.

    Why Lexomat

    Leave sources to us. Your time belongs to strategy.

    Unlock professional AI for your office. Try Lexomat – a universal legal AI tool connected to a legal database that automatically recognizes your task and delivers results with references to original texts. The service is completely free within limited usage.