Privacy Policy
Date of publication and entry into force:
July 29, 2026
1. Introduction
“TESLA QUANTUM CORE” limited liability company, with its registered seat in Banja Luka, adress Jovana Dučića no. 14, 78000 Banja Luka, Bosnia and Herzegovina, registration number (MB): 11261094, tax identification number (PIB): 440528300000 (hereinafter: the “Company”, “we” or the “Controller”), as the provider of Lexra — an application for legal practice and law firm management available at lexra.io (hereinafter: the “Application” or the “Service”) — treats the protection of personal data as a priority and processes personal data in accordance with this Policy.
This Policy has been drawn up in accordance with Regulation (EU) 2016/679 — the General Data Protection Regulation (hereinafter: the “GDPR”) — as the baseline standard of protection, as well as with other data protection laws applicable in the jurisdictions in which we offer the Service. If the laws of the jurisdiction in which you are located provide for additional or broader rights than those described here, those rights belong to you in full and you may exercise them in the same manner — by contacting us using the contact details set out in this Policy.
The terms used in this Privacy Policy (hereinafter: the “Policy”), such as “personal data”, “processing”, “controller”, “processor” and “personal data breach”, have the meaning given to them in Article 4 of the GDPR.
This Policy contains the information we are required to provide to the individuals whose personal data we process: what data we collect, for what purposes, on what legal basis, to whom we disclose it, how long we keep it, and what rights you have in relation to the processing.
2. Roles: Controller and Processor
Depending on the specific processing activity, the Company acts in two distinct roles:
The Company as Controller. This Policy applies to the processing of personal data that the Company carries out on its own behalf, determining the purposes and means of the processing. This covers: data of individuals who register a user account and use the Application (account data, billing data), data of visitors to the lexra.io website, data of individuals who communicate with us, and data of individuals subscribed to the newsletter.
The Company as Processor. The content that customers enter into the Application in the course of their work — matters, documents, data about clients and other individuals appearing in the customer’s records — is processed by the Company solely on behalf of and under the documented instructions of the customer, who acts as the controller of that data. That processing is not governed by this Policy but by the Data Processing Agreement (DPA). The customer of the Application is solely responsible for the lawfulness of the collection and processing of the personal data it enters into the Application, including the obligation to inform the data subjects and to ensure an appropriate legal basis for the processing.
3. Processing principles
The Company processes personal data in accordance with the principles of: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.
In particular, this means that:
- we base every processing operation on an appropriate legal basis;
- we collect data for specified, explicit and legitimate purposes;
- we process only the data necessary to achieve the purpose;
- we keep data only for as long as is necessary for the purpose; and
- we apply appropriate technical and organisational protection measures.
4. What data we process, for what purposes and on what basis
4.1 Registration and management of the user account
To create an account we mandatorily collect: first and last name and e-mail address. Optionally, you may provide a username and a contact telephone number. If you register as a business entity, we also process: the registration number of the registered natural person, the tax number of the natural or legal person, and the address of the registered seat. Your password is stored exclusively in cryptographically protected (hashed) form and is never available to us in readable form.
We process this data because it is necessary for the conclusion and performance of the contract with the customers of the Application, and we retain certain data in order to comply with our legal obligations.
4.2 Billing and financial operations
Payments for the Service are processed through the PayPal service, provided by the companies of the PayPal group — for customers from the European Union and the EEA, as a rule, PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg, and for other customers the PayPal entity determined by PayPal’s legal agreements for the relevant country — and its affiliates (hereinafter: “PayPal”). You can pay using your PayPal account or with a payment card through PayPal’s payment page, without being required to open a PayPal account. With respect to the data it processes in order to provide payment services, PayPal acts as an independent controller: the data you enter when making a payment — including payment card or PayPal account details — is collected and processed exclusively by PayPal, in accordance with its terms of use and its privacy statement, available on PayPal’s website. PayPal processes payment data primarily in the European Union (Luxembourg) and the United States of America, with possible processing in other countries in which PayPal and its service providers operate, applying appropriate safeguards for data transfers (standard contractual clauses and intra-group agreements).
We do not receive or store your full payment card details. Within the Application we retain only technical and business payment metadata: transaction identifier, payment status, amount and time of the transaction, as well as the data necessary for issuing invoices.
We process this data because it is necessary for the performance of our contract with you (charging the subscription and managing the subscription relationship), and we retain records of completed payments in order to comply with our tax and accounting obligations, within the periods prescribed by applicable law.
4.3 Communication and technical support
When you contact us (by e-mail, telephone or otherwise), we process your first and last name, e-mail address and any other data you choose to share with us, to the extent necessary to respond to your enquiry.
We process this data because it is necessary in connection with the conclusion or performance of the contract with the customers of the Application, and, where your enquiry does not relate to the contract, on the basis of our legitimate interest in responding to enquiries and providing support.
4.4 Newsletter and marketing communications
If you subscribe to the newsletter, we process your first and last name and e-mail address for the purpose of sending information about the Company’s news, benefits and activities. Subscribing to the newsletter is not a condition for using the Application.
We process this data on the basis of your informed consent, which you may withdraw at any time (via the unsubscribe link in every message or by contacting the Company), without affecting the lawfulness of processing carried out before the withdrawal. In certain cases the Company may use profiling for marketing and service-improvement purposes, but such processing does not involve automated decision-making.
4.5 Website and analytics
When you visit lexra.io, data may be processed — subject to your consent — through analytics cookies (e.g. anonymised IP address, browser and device type, navigation behaviour). The details are set out in the Cookie Policy. The Application itself does not use cookies or similar tracking technologies.
We process this data on the basis of your informed consent (for analytics cookies), or on the basis of the Company’s legitimate interest in providing the strictly necessary technical functions of the website.
4.6 System security
In order to protect the Application and our infrastructure from abuse and attacks, we process technical data such as IP address, device and browser information, access patterns and login attempts, as well as security and audit logs of actions performed in the system.
We process this data in pursuit of the Company’s legitimate interest in ensuring the security, integrity and availability of the Service, and in order to comply with our legal obligations to the extent that keeping such records is required by law.
5. Special categories of data
The Company, as Controller, does not collect or process special categories of personal data (such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic and biometric data, or data concerning health, sex life or sexual orientation). If the records that customers enter into the Application contain such data, that data is processed exclusively on behalf of the customer as controller, under the terms of the Data Processing Agreement (DPA) and with enhanced protection measures applied (including encryption using Always Encrypted with secure enclaves).
6. How we collect data
We collect personal data primarily directly from the data subjects (upon registration, communication or newsletter sign-up). Where we do not obtain the data directly — e.g. where an account administrator adds authorized users — we require that the person providing the data is authorised to disclose it and that they inform the data subjects about the processing, or refer them to this Policy.
7. Recipients of data
Personal data may be disclosed to the following categories of recipients, solely to the extent necessary to achieve the purpose of the processing:
- Cloud infrastructure providers (processors): Microsoft Azure and Amazon Web Services (AWS), on whose infrastructure the Application, the database, the built-in document storage, backups and cryptographic key management are hosted, in regions that geographically correspond to the customer’s location or that the customer selects (for customers from the EU/EEA, primarily within the EU/EEA);
- Payment service provider: PayPal (an independent controller with respect to the data it processes in order to provide payment services);
- External document storage services (Google Drive, Microsoft OneDrive) — only if the customer connects them itself; the selection, configuration and terms of use of those services are the customer’s responsibility;
- The accounting agency and providers of professional services (legal, audit), bound by confidentiality obligations;
- Companies maintaining our IT systems and other sub-contractors providing services on our behalf, authorised to use the data only to the extent necessary to provide those services;
- Competent public authorities, where necessary for the Company to comply with its legal obligations, with access limited to the minimum required to satisfy the specific legal request.
The Company has data processing agreements in place with all of its processors and remains responsible for the processing operations it has entrusted to them. An up-to-date list of sub-processors is available in Annex 1.3 of the Data Processing Agreement (DPA).
8. Transfers of data to third countries
Data is stored and processed in the data centres of our cloud infrastructure providers, in the region that geographically corresponds to the customer’s location or that the customer selects, and for customers from the EU/EEA primarily within the EU/EEA. If individual processing operations take place in third countries (e.g. the USA or other countries outside the EU/EEA), the transfer is carried out exclusively:
- to countries covered by a European Commission adequacy decision, or
- subject to appropriate safeguards, primarily the standard contractual clauses adopted by the European Commission, with supplementary measures where necessary.
9. Data retention periods
We keep data only for as long as is necessary to achieve the purpose for which it was collected, taking into account our legal obligations:
- User account data and account content: for the duration of the subscription and for a further 90 days after the subscription ends, during which the customer may reactivate the account, request an export of the data or raise claims relating to rights and obligations arising from the period of use. After the 90 days expire, the data is permanently deleted from active systems. Residual copies may temporarily persist in encrypted backups until they expire in the regular backup cycle;
- Data collected on the basis of consent (including the newsletter): until consent is withdrawn. After withdrawal, the data is deleted or anonymised without undue delay, and at the latest within 10 days;
- Financial and accounting records (including records of completed payments): for the periods prescribed by applicable tax and accounting regulations;
- Security and audit logs: for a period limited to what is necessary to ensure system security, demonstrate the integrity of processing and comply with legal obligations, after which they are deleted or archived.
The customer may delete its user account within the Application, which initiates the removal of the personal data associated with the account that is no longer necessary for the purposes of the processing, in accordance with the Terms of Service.
10. Rights of data subjects
Under the GDPR, you have the following rights:
- Right of access — to obtain confirmation as to whether we process your data, information about the processing and a free copy of the data;
- Right to rectification — to have inaccurate data corrected and incomplete data completed without undue delay; you can update most of your account data yourself in the account settings;
- Right to erasure (“right to be forgotten”) — to request the deletion of your data where the conditions under the GDPR are met; please note that we must retain certain data in order to comply with legal obligations or to establish, exercise or defend legal claims;
- Right to restriction of processing — the right to require that we temporarily only store your data, without further use — for example while the accuracy of data you have contested is being verified, or while your objection to processing is being assessed; during the restriction we process the data only with your consent or for the establishment, exercise or defence of legal claims;
- Right to data portability — to receive the data you have provided to us in a structured, commonly used and machine-readable format and to transmit it to another controller;
- Right to object — to processing based on legitimate interest, and, at any time and without giving reasons, to processing for direct marketing purposes;
- Rights relating to automated decision-making — the Company does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect individuals;
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal;
- Right to be notified of a data breach — where a breach is likely to result in a high risk to your rights and freedoms;
- Right to lodge a complaint with a supervisory authority — the authority competent for personal data protection, without prejudice to any other legal remedy.
To exercise your rights, contact the Company using the contact details in Section 14. We will respond to your request without undue delay and at the latest within 30 days of receipt; this period may be extended by a further two months where necessary due to the complexity or number of requests, in which case we will inform you.
11. Data protection measures
The Company applies appropriate technical and organisational data protection measures, including in particular:
- encryption of data at rest (AES-256) and in transit (TLS);
- for particularly sensitive data, the Always Encrypted mechanism with secure enclaves, whereby the cryptographic keys are not available to the database management systems or to the cloud provider’s personnel, and key management is performed through the Azure Key Vault service;
- strict role-based access control (RBAC) and the principle of least privilege;
- authentication through unique accounts, hashed passwords and short-lived, regularly refreshed security tokens (JWT);
- logical isolation of the data of different customer offices in a multi-tenant system;
- encrypted, access-restricted audit logs of security- and business-relevant events;
- regular backups and tested data recovery procedures;
- physical protection of data centres provided by the cloud providers in accordance with industry standards and certifications.
A detailed description of the measures is available in Annex 1.2 of the Data Processing Agreement (DPA).
12. Handling personal data breaches
In the event of a personal data breach, the Company will, without undue delay: assess the nature and risk of the breach; where applicable, notify the competent supervisory authority within 72 hours of becoming aware of it; notify the data subjects where the breach is likely to result in a high risk to their rights and freedoms; and take all necessary measures to contain and mitigate the consequences of the breach. Where we act as a processor, we notify the affected customers, as controllers, of the breach without undue delay and at the latest within 72 hours, in accordance with the Data Processing Agreement (DPA).
13. Minors
The Service is intended for legal professionals and persons over 18 years of age. The Company does not knowingly collect personal data of minors. If we learn that we have collected a minor’s personal data without an appropriate basis, we will delete that data without delay.
14. Contact and the person responsible for data protection
The Company has designated a person responsible for personal data protection (Privacy Officer), whom you can contact with any questions regarding the processing of personal data and in order to exercise your rights, at the e-mail address: support@lexra.com. We respond to requests without undue delay and at the latest within 30 days, with the possibility of an extension in complex cases in accordance with Section 10 of this Policy.
You can also contact the Company:
- by telephone: +387 51 498 410
- by post: Jovana Dučića 14, 78000 Banja Luka, Bosnia and Herzegovina
15. Changes to this Policy
This Policy enters into force on the day of its publication on the lexra.io website and is available on that website and at the Company’s business premises. The Policy may be updated from time to time. Data subjects will be notified of all material changes via the website, or by e-mail where appropriate, and changes enter into force on the day of publication. We recommend that you review the Policy regularly.
