1. Summary
Lexradar is a regulatory intelligence platform. We collect the minimum data needed to run the service — primarily your account, billing, and the regulatory changes you choose to track. We do not sell personal data, and we do not use your content to train third-party AI models. Where we use sub-processors that transfer data outside the UK, those transfers are protected by UK adequacy regulations or the relevant Standard Contractual Clauses.
The full text below is the operative document.
2. Definitions
- Lexradar / we / us — the service operated by TITADE Ltd.
- Customer / you — the individual or legal entity that has registered for a Lexradar account.
- End user — any individual authorised by a Customer to use a workspace (e.g. a compliance officer added to a Team plan).
- Personal data — has the meaning given in Article 4(1) UK GDPR.
- Processing — any operation performed on Personal Data (collection, storage, analysis, transmission, deletion, etc.).
- Service Data — Personal Data we process to provide Lexradar (account, billing, audit logs, etc.). Service Data is distinct from Customer Content, which is the regulatory information you load into the platform.
3. Data controller and contact
The data controller is TITADE Ltd, a private limited company registered in England and Wales (Companies House no. 17106008), with ICO data controller registration ZC109721.
For any question, request, or complaint relating to this policy, contact our Data Protection Lead at Admin@lexradar.co or by post at the registered office address listed on Companies House. We aim to respond to all written enquiries within 30 calendar days.
4. Scope of this policy
This policy applies to Lexradar (the web application at app.lexradar.co, the marketing site at www.lexradar.co, and any subdomains) and to all processing carried out by us as controller. It does not apply to third-party sites we link to; those sites have their own policies.
5. Personal data we collect
We process the following categories of Personal Data:
- Account data. Email address, name, password hash (handled by our authentication provider, never stored in plain text by us), and OAuth profile data where you sign in via Google.
- Billing data. Plan tier, subscription status, billing email, and the last four digits of your payment card. Full card numbers are stored exclusively by our payment processor and never touch our systems.
- Workspace content. Regulatory changes you have saved, checklist items, evidence files you upload, and notes you write. Evidence files are stored in a private object store and are never shared with other customers.
- Usage data. Timestamps of logins, page views, API calls, AI assistant messages, and storage consumption. We use this to enforce plan limits, prevent abuse, and improve the product.
- Support correspondence. Anything you send us when you emailAdmin@lexradar.co or open a support ticket.
- Technical data. IP address, user agent, and referer, captured in application logs and our error monitoring service. We retain raw logs for 30 days and aggregate analytics for longer.
We do not collect special-category data (race, religion, health, sexual orientation, etc.). If you choose to enter such data into a free-text field (for example, a checklist note), you do so at your own risk and we will treat it as Customer Content under section 9.
6. Lawful basis for processing
Under UK GDPR Article 6, we rely on the following bases:
- Contract (Art. 6(1)(b)) — to provide the service you signed up for and bill you for it.
- Legitimate interests (Art. 6(1)(f)) — for product analytics, abuse prevention, security monitoring, and improving the service. We balance these interests against your rights and freedoms.
- Legal obligation (Art. 6(1)(c)) — to keep tax and accounting records (HMRC requires 6 years) and respond to lawful requests.
- Consent (Art. 6(1)(a)) — for non-essential cookies and any marketing communications. You can withdraw consent at any time without affecting the lawfulness of prior processing.
7. How we use personal data
- To create and authenticate your account.
- To deliver the regulatory feed, AI assistant, and document storage.
- To process subscription payments and send billing receipts.
- To send service notifications (security alerts, plan changes, planned maintenance). These are not marketing and are not opt-outable while you hold an account.
- To respond to support requests.
- To detect and prevent fraud, abuse, and security incidents. We may suspend an account without notice if we have reasonable grounds to believe it is being used for unlawful activity.
- To comply with applicable law.
8. AI-assisted processing
Our AI assistant and document classification pipelines are powered by Anthropic (provider of the Claude family of large language models). When you ask the assistant a question or upload a document for classification, the relevant excerpt of Customer Content is sent to Anthropic's API for inference.
- We do not use your Customer Content to train any model. Our configuration of the Anthropic API is set to zero-retention and zero-training; prompts and responses are discarded by Anthropic after the inference call completes. This is governed by our Data Processing Agreement with Anthropic.
- Data location. Anthropic processes inference requests in the United States. The transfer is protected by the UK–US Data Bridge and the EU–US Data Privacy Framework, both of which the UK government has recognised as providing adequate protection for personal data.
- Human review. Lexradar staff do not routinely read Customer Content. We will only access your content (a) at your written request to support you, (b) to investigate an abuse report, or (c) to comply with a legal obligation.
- Output accuracy. AI outputs can be wrong. See the AI & Regulatory Disclaimer for the limits of our AI-assisted content.
9. Third-party processors
We use the following categories of sub-processors. A current list with the legal basis for each transfer is maintained in our DPA, available on request.
| Processor | Purpose | Location |
|---|---|---|
| Supabase (database, auth, storage) | Hosting, authentication, evidence file storage | EU / US (with EU region pinning on request) |
| Anthropic (Claude API) | AI assistant, classification, briefings | United States |
| Stripe | Payment processing and subscription management | United States / Ireland |
| Sentry | Error monitoring (PII-redacted at the client) | United States |
| Resend (transactional email) | Receipts, security notifications, password resets | United States / EU |
We will give you at least 30 days' notice by email before adding a new sub-processor that handles Personal Data. You may object to a new sub-processor; if we cannot agree on a workable alternative, you may terminate the affected service for a pro-rated refund.
10. International transfers
Some of our sub-processors (notably Anthropic, Stripe, and Sentry) are based in the United States. We protect those transfers by:
- relying on the UK–US Data Bridge where the recipient is certified;
- executing the UK International Data Transfer Addendum (IDTA) with the recipient otherwise;
- running a Transfer Risk Assessment for each recipient and refreshing it annually.
You can request a copy of any active transfer mechanism by emailing Admin@lexradar.co.
11. Retention periods
We retain Personal Data only for as long as needed for the purpose it was collected. Specific periods:
- Account data: the lifetime of the account, plus 30 days after deletion (for restore windows), after which it is permanently deleted from primary storage and within a further 30 days from backups.
- Billing records: 6 years from the date of the transaction, in line with HMRC requirements.
- Audit logs (login, export, billing change): 12 months by default; up to 36 months on the Team plan if you opt in.
- Application logs: 30 days at full granularity, then aggregated (counts and trends) for up to 24 months.
- AI assistant transcripts: 30 days, then deleted unless you have explicitly saved them as a note.
- Support correspondence: 24 months from the last contact.
12. Security measures
We treat Personal Data as a confidential asset and apply industry-standard controls. These include: TLS 1.3 in transit, AES-256 at rest, row-level security on the application database, single-tenant encryption of evidence files, principle-of-least privilege on staff access, mandatory MFA on all production systems, and a documented incident response procedure.
Where we use Sentry, the client wrapper redacts obvious PII fields (cookies, authorisation headers, email-like fields in event extras) before the error payload leaves your browser. See the Cookie Policy for the full list of PII fields scrubbed.
We will notify affected customers and the ICO of any personal data breach within 72 hours of becoming aware of it, in line with our regulatory obligations.
13. Your rights as a data subject
Subject to the conditions in the UK GDPR, you have the right to:
- access the Personal Data we hold about you (Art. 15);
- rectify inaccurate or incomplete data (Art. 16);
- request erasure, where the data is no longer needed (Art. 17);
- restrict or object to processing (Arts. 18 and 21);
- port your data to another service in a machine-readable format (Art. 20);
- withdraw consent at any time, where consent is the lawful basis.
To exercise any of these rights, email Admin@lexradar.co. We will respond within 30 calendar days. You can also download your data at any time from the in-product Account → Data export screen, and you can delete your account and all associated data from Account → Delete account.
14. Complaints to the ICO
If you believe we have not handled your Personal Data properly, we would prefer you to give us the chance to put it right — email Admin@lexradar.co. You are also entitled to lodge a complaint with the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
Website: ico.org.uk/make-a-complaint
15. Children
Lexradar is a B2B service intended for use by compliance professionals. We do not knowingly collect Personal Data from anyone under 18. If you believe a minor has created an account, email Admin@lexradar.co and we will close it.
16. Changes to this policy
We may update this policy from time to time. When we do, we will revise the Last updated date at the top and, for material changes, email registered users at least 14 days before the new version takes effect. The previous versions are kept in our public archive (link on request).