Privacy Policy

Updated: 2 July 2026. This version replaces the August 2020 policy. It adds the AI features, our current processors, international transfers, retention periods, cookies, and your rights.

Who we are

Legalcomplex is the trade name of the sole proprietorship (eenmanszaak) of R.M. Blijd, registered with the Trade Register of the Dutch Chamber of Commerce under number 71150072, VAT NL002364151B52, established at Jan de Louterstraat 113, 1063 KZ Amsterdam, Netherlands. R.M. Blijd is the data controller for the processing described in this policy. The Services are offered via legalcomplex.com, legalpioneer.org and sabaio.com. Contact: raymond@legalcomplex.com.

What personal data we collect

Account and usage data:

  • Your name and email address
  • Login credentials (your password is stored hashed, we cannot read it)
  • Subscription tier and payment status. Card and bank details are held by Mollie, our payment provider, not by us
  • Your research chat prompts, conversations, and saved findings
  • Documents you upload for analysis
  • Voice audio when you use voice input (transcribed, then discarded)
  • Google Drive files or Gmail drafts you explicitly select, only if you link your Google account
  • If you contact us via a form, your message and contact details

Website statistics: your IP address, browser, language, referring site, visit time, and what you clicked. We use only our own server logs for this. We do not run third-party analytics or advertising trackers.

Why we process your data and on what legal basis

  • Providing your account, subscriptions, and the research chat: performance of our contract with you (art. 6(1)(b) GDPR)
  • Payment processing via Mollie and invoicing: contract performance (art. 6(1)(b)) and legal obligation (art. 6(1)(c), Dutch tax rules)
  • Google Drive/Gmail linking: your consent (art. 6(1)(a)), revocable at any time in your profile or via your Google account settings
  • Voice input transcription: contract performance (art. 6(1)(b)). Audio is processed transiently and not stored by us
  • Security logging (IP addresses, access logs): our legitimate interest (art. 6(1)(f)) in protecting the service
  • Responding to enquiries and leads: our legitimate interest (art. 6(1)(f)) in following up when you contact us

AI features

Our research chat and document review features are powered by third-party large language model providers. When you submit a prompt, upload a document, or use voice input, that content is transmitted to our AI processors to generate a response: xAI Corp. (USA) for text generation and Groq, Inc. (USA) for voice transcription. Under their service terms, these providers do not use your content to train their models; xAI may hold API data up to 30 days for abuse monitoring, Groq does not retain it by default. Do not submit personal data of third parties or confidential information you are not authorised to share. Responses are generated by an AI system, not a human.

Who receives your data

We use these processors and service providers:

  • Mollie B.V. (Netherlands): payments
  • Our hosting provider (Netherlands): the server this site runs on, under a data processing agreement
  • Google Cloud EMEA: data infrastructure
  • Google LLC (USA): optional Drive/Gmail linking, only with your consent
  • xAI Corp. (USA): AI chat responses
  • Groq, Inc. (USA): voice transcription
  • Cal.com, Inc. (USA): meeting booking, if you book a call
  • GitHub, Inc. (USA, Microsoft): deployment infrastructure

Pages may embed content from YouTube and LinkedIn; those load from their servers and are covered under Cookies below. We do not sell or rent your data. We do not use third-party advertising or analytics trackers.

International transfers

Your data is primarily stored in the Netherlands (our own server) and the EU. Some of our providers are located in the United States: xAI Corp., Groq Inc., Google LLC, GitHub Inc., and Cal.com Inc. Where a provider is certified under the EU-US Data Privacy Framework, we rely on the European Commission's adequacy decision of 10 July 2023; otherwise we rely on the European Commission's Standard Contractual Clauses (art. 46(2)(c) GDPR) concluded in the provider's data processing agreement. You can request a copy of the applicable safeguards via raymond@legalcomplex.com.

Google user data

If you link your Google account, our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We access only the files and drafts needed for the feature you invoke, never use Google user data for advertising, and never transfer it to third parties except as needed to provide the feature you requested.

How long we keep your data

  • Account data: for the life of your account and 30 days after deletion
  • Chat history and research findings: until you delete them or your account is deleted
  • Invoices and payment records: 7 years (Dutch tax law, art. 52 AWR). This is why deleting your account does not delete invoices
  • Server access logs: 90 days
  • Voice audio: processed transiently for transcription, not retained
  • Google Drive/Gmail tokens: until you unlink or your account is deleted

Cookies

We use only functional cookies that are necessary to operate the site (login session and security cookies). We do not use advertising or analytics cookies. Some pages embed third-party content (YouTube videos, LinkedIn posts, Cal.com scheduling). These embeds may set their own cookies when loaded; we use privacy-enhanced modes where the provider offers them. See the providers' own cookie policies for details.

Automated decision-making

We do not use your personal data for automated decisions that have legal or similarly significant effects on you (art. 22 GDPR). AI features generate research content on your request; they do not evaluate or score you.

Your rights

You can ask us at any time to:

  • Access the personal data we hold about you (art. 15 GDPR)
  • Correct it (art. 16)
  • Delete it (art. 17)
  • Restrict processing (art. 18)
  • Receive it in a portable format (art. 20)
  • Object to processing based on legitimate interest (art. 21)

Where processing is based on consent (such as Google account linking), you can withdraw consent at any time without affecting prior processing. Email raymond@legalcomplex.com; we respond within one month. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.

How we protect your privacy

  • Legalcomplex.com is hosted in the Netherlands and has a data processing agreement with our hosting provider
  • We will not rent or sell your information
  • If somebody buys Legalcomplex, we will tell you via the website and channels that your information will be transferred to them
  • If we stop Legalcomplex, we will delete our accounts with our hosting provider and third-party services
  • If authorities like the police want your data, we require a valid warrant from the Dutch authorities and will notify you of the request unless we are legally prohibited from doing so
  • We may occasionally publish aggregate numbers about how our products are used; you cannot be identified as an individual in these publications. We will never publish your email

Changes to our Privacy Policy

Legalcomplex may update this Privacy Policy, so we encourage you to check this page for changes. The policy and its revision history are on GitHub where you can review changes over time. If you have subscribed by email, you might also receive an alert about material changes.

Questions

Contact raymond@legalcomplex.com, your privacy contact at Legalcomplex. If you have any complaints about this policy or the way Legalcomplex processes your personal data, you can submit a complaint to the Dutch Data Protection Authority at autoriteitpersoonsgegevens.nl.