Privacy Policy
Privacy Policy
Lexgo GmbH — lexgo.vision
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and of other national data protection laws of the Member States as well as further data protection provisions is:
Lexgo GmbH
Zeil 109, 60313 Frankfurt am Main, Germany
Represented by the Managing Director Dr. Jochen Brandhoff
E-mail: Info@lexgo.vision
2. Data Protection Officer
A data protection officer has not been appointed.
3. Scope and categories of data processed
This privacy policy applies to the website lexgo.vision, including its German-, English- and Italian-language versions. Depending on your use, we process the following categories of personal data:
• Master and contact data (e.g. name, e-mail address, telephone number),
• Content data (e.g. your message sent via the contact form),
• Usage data as well as meta/communication data (e.g. IP address, time of access, pages accessed, device and browser information).
Data subjects are visitors and users of the website as well as interested parties who contact us.
4. Relevant legal bases
In accordance with the GDPR, we process personal data on the basis of the applicable legal basis in each case. Where we obtain consent, this is Art. 6(1)(a) GDPR; for the performance of a contract or for pre-contractual measures, Art. 6(1)(b) GDPR; for compliance with a legal obligation, Art. 6(1)(c) GDPR; for safeguarding legitimate interests, provided that your interests, fundamental rights and fundamental freedoms do not override them, Art. 6(1)(f) GDPR. The legitimate interest pursued in each case is stated in connection with the individual processing activities (sections 6 et seq.).
For the storage of information on your terminal device and access to information already stored (in particular cookies), Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG) additionally applies. In addition, national data protection provisions, in particular the Federal Data Protection Act (BDSG), may apply.
5. Security measures and encryption
In accordance with Art. 32 GDPR and taking into account the state of the art, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk. This website is accessed via transport encryption (SSL/TLS) in conjunction with the highest level of encryption supported by your browser. You can recognise an encrypted connection by the “https://” prefix and the padlock symbol in your browser bar.
6. Provision of the website and server log files
Each time our website is accessed, access data is automatically processed in server log files by the system of our hosting service provider. This may include:
• the IP address of the requesting terminal device,
• the date and time of access,
• the name and URL of the file accessed and the volume of data transferred,
• the browser and operating system used as well as the previously visited page (referrer).
The purpose of the processing is the delivery of the website, ensuring stability and security, and technical administration. The legal basis is our legitimate interest in a technically error-free and secure provision of our online offering pursuant to Art. 6(1)(f) GDPR.
7. Hosting and content delivery (Wix)
Our website is operated and hosted via the platform Wix. The provider is Wix.com Ltd., 5 Yunitsman St., Tel Aviv 6936025, Israel (hereinafter “Wix”). In this context, Wix processes, among other things, the access and log data referred to in section 6 as well as the content transmitted via the website, and makes the page content available via a worldwide content delivery network (including data centres in the USA and in Ireland).
Wix acts as a processor on our behalf. For this purpose, Wix provides a contract for processing on our behalf (Data Processing Addendum) pursuant to Art. 28 GDPR, which automatically forms part of the Wix Terms of Use. The legal basis for the use of Wix is our legitimate interest in a secure and efficient provision of our online offering pursuant to Art. 6(1)(f) GDPR. Further information can be found in Wix's privacy policy (wix.com/about/privacy).
8. Data transfer to third countries
When using Wix, processing of personal data outside the European Union / the EEA is possible, in particular by Wix.com Ltd. in Israel as well as by group companies and sub-processors (including Wix.com Inc., USA). The transfer is safeguarded by the following guarantees:
• Israel: European Commission adequacy decision 2011/61/EU of 31 January 2011 (Art. 45 GDPR);
• USA: adequacy decision on the EU-U.S. Data Privacy Framework (Implementing Decision (EU) 2023/1795 of 10 July 2023), insofar as the recipient (e.g. Wix.com Inc.) is DPF-certified (Art. 45 GDPR);
• supplementary/subsidiary: EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914) pursuant to Art. 46(2)(c) GDPR.
You can request a copy of the EU Standard Contractual Clauses used from us via the contact details specified in section 1; their wording is also publicly available at eur-lex.europa.eu (Implementing Decision (EU) 2021/914).
Wix.com, Inc. is certified under the EU-U.S. Data Privacy Framework. Insofar as other US services are also used (see section 11), they are safeguarded on the same bases (adequacy decision or Standard Contractual Clauses).
9. Cookies and similar technologies
Our website uses cookies. Cookies are small text files that are stored on your terminal device. In legal terms, a distinction must be drawn between the storage or reading of information on your terminal device (Section 25 TDDDG) and the subsequent processing of the data thus obtained (Art. 6 GDPR).
Technically necessary cookies do not require consent pursuant to Section 25(2) no. 2 TDDDG; the subsequent processing is based on Art. 6(1)(f) GDPR. During the technical review of the website, only cookies set by Wix and classified as technically necessary were identified, in particular:
• XSRF-TOKEN — security / protection against cross-site request forgery (session),
• bSession — measurement of system performance (approx. 1 day),
• svSession — recognition of unique visitors, security and core functions (approx. 12 months).
Further cookies classified by Wix as necessary (e.g. ssr-caching, TS*, fedops.logger.sessionId) may be added; Wix provides an up-to-date overview in each case (support.wix.com). Cookies that are not technically necessary (e.g. for reach measurement or marketing) are only set with your prior consent pursuant to Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR.
10. Reach measurement (Wix Analytics)
The Wix platform offers an integrated reach measurement (“Wix Analytics”) with which usage data (e.g. pages accessed, time spent, approximate origin, device/browser information) can be analysed. This analysis is carried out exclusively on the basis of your consent, which you give via our cookie banner. The legal basis is Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. You can withdraw your consent at any time with effect for the future (e.g. via the cookie settings).
11. Error and performance logging (Sentry)
To detect and remedy technical errors, the service Sentry (provider: Functional Software, Inc. d/b/a Sentry, San Francisco, USA; browser.sentry-cdn.com) is loaded. In this process, technical information such as browser type, operating system, time, error messages and the IP address may be processed. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a stable, secure and error-free operation). Any associated transfer to the USA is safeguarded by the guarantees referred to in section 8 (EU-U.S. Data Privacy Framework or Standard Contractual Clauses).
12. Contacting us via the contact form and by e-mail
You can contact us via our contact form. In doing so, we process:
• first name and surname,
• e-mail address,
• telephone number (optional),
• your message and the time of transmission.
We use this data exclusively to process your enquiry and for any follow-up questions. The legal basis is Art. 6(1)(b) GDPR, insofar as your enquiry is directed at the conclusion or performance of a contract, otherwise Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries). The same applies to contact by e-mail. The data transmitted via the form is stored as part of the processing on our behalf by Wix (Wix Contacts).
To protect against spam, a CAPTCHA check may be used for forms. During the technical review of the contact form, no Google reCAPTCHA was loaded; accordingly, no data is currently transmitted to Google in this respect.
13. Links to external networks (LinkedIn)
Our website contains a reference (link) to an external profile on LinkedIn. Data is only transmitted to LinkedIn once you actively click the link and access the LinkedIn pages. The respective provider (LinkedIn Ireland Unlimited Company) is responsible for the processing that takes place there; its data protection provisions apply.
14. Recipients of the data
The recipient is our hosting and platform service provider Wix as a processor (sections 7 and 8). Disclosure to further third parties only takes place insofar as this is legally permissible, you have consented, or it is necessary for the processing of the contract or the enquiry. Personal data is not sold.
Further recipients are the analytics service Wix Analytics (subject to your consent, section 10) and the error-monitoring service Sentry (section 11). If Google reCAPTCHA is activated in the future (section 12), Google is additionally to be classified as a recipient.
15. Storage period and erasure
We process and store personal data only for as long as is necessary to achieve the respective purpose or as provided for by statutory retention periods. Server log files are deleted or anonymised after a short time. We erase enquiries submitted via the contact form or by e-mail as soon as they have been conclusively dealt with and no statutory retention obligations (e.g. commercial or tax law periods) prevent this.
16. Rights of data subjects
As a data subject, you have the following rights:
• access to the data processed about you (Art. 15 GDPR),
• rectification of inaccurate data (Art. 16 GDPR),
• erasure (Art. 17 GDPR),
• restriction of processing (Art. 18 GDPR),
• data portability (Art. 20 GDPR),
• objection to certain processing activities (Art. 21 GDPR; on this, see separately and prominently section 17),
• withdrawal of a consent given, with effect for the future, without affecting the lawfulness of the processing carried out until the withdrawal (Art. 7(3) GDPR).
To exercise these rights, an informal notification to the contact details specified in section 1 is sufficient.
Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
Without prejudice to any other legal remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, place of work or the place of the alleged infringement. The authority regularly responsible for Lexgo GmbH is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (Hessian Commissioner for Data Protection and Freedom of Information)
Postfach 31 63, 65021 Wiesbaden (Hausanschrift: Wilhelmstraße 7, 65185 Wiesbaden)
poststelle@datenschutz.hessen.de · datenschutz.hessen.de
17. Right to object
Right to object pursuant to Art. 21 GDPR
You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(f) GDPR (legitimate interest). If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims. Where data is processed for the purposes of direct marketing, you have the right to object at any time without giving reasons.
18. Obligation to provide data; no automated decision-making
The provision of your personal data is neither legally nor contractually required. However, in order to use the contact form, the data marked as mandatory fields must be provided; without this data we cannot process your enquiry. A decision based solely on automated processing — including profiling — within the meaning of Art. 22 GDPR does not take place.
19. Currency and amendment of this privacy policy
This privacy policy is dated 15 July 2026. Due to the further development of the website or as a result of changed legal or regulatory requirements, it may become necessary to amend this privacy policy.
20. Definitions
The terms used in this policy (including “personal data”, “processing”, “controller”, “processor”, “consent”) are legally defined in Art. 4 GDPR. Accordingly, personal data means any information relating to an identified or identifiable natural person.
.png)