Skip to content
Legiscope
Menu
Publisher and data protection information

Privacy notice

Legiscope builds GDPR compliance software and publishes practical data-protection guidance. This notice applies that same standard of clarity to our own website processing.

01

Controller and publisher

Legiscope UAB is the controller for the processing described here and the professional publisher of this website. The details below identify the responsible legal entity, publication director and website host.

This notice covers the public website, the contact form and correspondence, privacy-rights handling, and the public demonstration-booking flow. Legiscope is the controller for these website processing operations only.

The Legiscope application follows a different logic: for the personal data customers manage there, Legiscope acts as a processor, under the Terms of Service and the Data Processing Agreement.

Controller · website publisher · information-society service provider

Legiscope UAB

Lithuanian private limited company
Legal registration
Register of Legal Entities of the Republic of Lithuania · company code 304581221
Registered office
Laisvės pr. 60-1107, LT-05120 Vilnius, Lithuania
VAT identification
LT100011142510
Publication director
Thiébaut Devergranne
Website hosting
Amazon Web Services EMEA SARL · 38 Avenue John F. Kennedy, L-1855 Luxembourg · +352 2789 0057
Privacy contact
To reduce automated address harvesting and spam, contact us directly through the privacy form.
02

Processing activities

Each card describes one processing activity. The common request procedure is stated once in “How to exercise your rights”; the final row of each card identifies the rights and choices specific to that activity.

If a colleague gives us your details in an enquiry, or a person booking a demonstration identifies another attendee, we provide or link to this notice at our first communication with you unless you already have the information or an Article 14 GDPR exception applies.

No processing activity described here produces a decision with legal or similarly significant effects solely by automated means. The reCAPTCHA risk assessment used to protect public forms is explained in P-04.

Sub-processing activities

Activity 1 of 5Website delivery and security

ActivityP-01
Public pages · network delivery · fault and abuse prevention

Website delivery and security

Controller activity
Purpose
Deliver requested pages, maintain availability, prevent abuse and diagnose faults.
Data subjects
Website visitors and the people using devices that request public resources.
Personal data and source
The device and network services automatically supply the IP address, request time and address, referrer where present, browser, device and protocol details, and response, error or security-event data.
Legal basis
Article 6(1)(f) GDPR — legitimate interests in operating and securing a reliable website.
Recipients and transfers
Amazon Web Services provides delivery and infrastructure. Global edge delivery or support access is covered, where required, by the AWS DPA and 2021 EU Standard Contractual Clauses.
Retention
Request data is kept only through the configured operational period needed for delivery, security monitoring and fault investigation. A record attached to a documented incident or claim is separated from routine logs and deleted when that incident and any applicable claim period close.
Requirement and consequences
Connection data is generated automatically and is necessary to return the requested public content. Without it, the website cannot respond to the device.
Individual rights
Access, rectification, erasure, restriction and objection may apply. Portability does not apply because this processing is not based on consent or contract.
Automated decisions
No solely automated decision produces legal or similarly significant effects for an individual.
03

Cookies and browser storage

The reviewed website does not load an advertising or audience-analytics runtime and does not use browser storage to build an advertising profile or follow visitors across websites. The security technology below is limited to the contact and demonstration-booking forms.

Google reCAPTCHA

_GRECAPTCHA

Technology
Cookie and associated device access
When used
When reCAPTCHA executes for a contact-form or demonstration-booking submission
Purpose
Security, fraud and automated-abuse prevention
Consent position
Strictly-necessary security exemption for the requested protected submission; consent would be required before any broader use
Lifetime
Google-controlled service lifetime; removable through browser controls
04

Recipients, transfers and safeguards

Access is limited by role and purpose. Legiscope uses Amazon Web Services for website and booking infrastructure, Google Workspace for professional correspondence and appointments, and Google reCAPTCHA to protect the contact and booking forms. Their operational boundaries are described in the public provider register.

Legiscope does not sell the personal data covered by this notice. A professional adviser or public authority receives information only where advice, a legal claim or a binding legal requirement makes the disclosure necessary.

For a restricted transfer under Chapter V GDPR, the provider terms identified for the applicable processing activity incorporate the relevant 2021 EU Standard Contractual Clauses. A person may use the contact page to ask for information about the safeguard and a copy of the applicable clauses, subject to protection of confidential information.

05

How to exercise your rights

The final row of each processing-activity card identifies the rights relevant to that activity. Where processing is based on legitimate interests, you may object on grounds relating to your particular situation; Legiscope will stop unless it demonstrates overriding compelling grounds or needs the data for a legal claim.

None of the activities described here relies on consent as its GDPR legal basis. If Legiscope later introduces an optional terminal technology requiring consent, it must remain disabled until a valid choice is made and withdrawing that choice must be as easy as giving it.

06

Legal framework and changes

This notice applies the transparency requirements of the GDPR and Lithuania’s supplementary data-protection rules. The controller and publisher section identifies the legal entity, registration, office, publication director and website host. Terminal access is assessed under the Lithuanian Electronic Communications Law and, for users in France, Article 82 of the French Data Protection Act.

If Legiscope intends to use personal data for a materially different purpose, it will provide the information required for that further processing before it begins. This notice will also be updated when a provider, purpose, data category, transfer or retention rule changes materially. The review date at the top identifies the current version.