Skip to content
Legiscope
Menu
Publisher and data protection information

Privacy notice

Legiscope builds GDPR compliance software and publishes practical data-protection guidance. This notice applies that same standard of clarity to our own website processing.

01

Controller and publisher

Legiscope UAB is the controller for the processing described here and the professional publisher of this website. The details below identify the responsible legal entity, publication director and website host.

This notice covers the public website, the contact form and correspondence, privacy-rights handling, and the public demonstration-booking flow. Legiscope is the controller for these website processing operations only.

The Legiscope application follows a different logic: for the personal data customers manage there, Legiscope acts as a processor, under the Terms of Service and the Data Processing Agreement.

Controller · website publisher · information-society service provider

Legiscope UAB

Lithuanian private limited company
Legal registration
Register of Legal Entities of the Republic of Lithuania · company code 304581221
Registered office
Laisvės pr. 60-1107, LT-05120 Vilnius, Lithuania
VAT identification
LT100011142510
Publication director
Thiébaut Devergranne
Website hosting
Amazon Web Services EMEA SARL · 38 Avenue John F. Kennedy, L-1855 Luxembourg · +352 2789 0057
Privacy contact
To reduce automated address harvesting and spam, contact us directly through the privacy form.
02

Processing activities

Each card describes one processing activity. The common request procedure is stated once in “How to exercise your rights”; the final row of each card identifies the rights and choices specific to that activity.

If a colleague gives us your details in an enquiry, or a person booking a demonstration identifies another attendee, we provide or link to this notice at our first communication with you unless you already have the information or an Article 14 GDPR exception applies.

No processing activity described here produces a decision with legal or similarly significant effects solely by automated means. The reCAPTCHA risk assessment used to protect public forms is explained in P-04.

Processing activityP-01
Public pages · network delivery · fault and abuse prevention

Website delivery and security

Legitimate interests
Why and who
Deliver requested pages, maintain availability, prevent abuse and diagnose faults. This concerns website visitors and the devices requesting public resources.
Data and source
Your device and network services supply the IP address, request time and address, referrer where present, browser, device and protocol details, and response, error or security-event data.
Basis and necessity
Article 6(1)(f) GDPR — legitimate interests in operating and securing a reliable website. Connection data is generated automatically and is necessary to return the requested content.
Recipients and transfers
Amazon Web Services provides delivery and infrastructure. Global edge delivery or support access is covered, where required, by the AWS DPA and 2021 EU Standard Contractual Clauses.
Retention
Request data is kept only through the configured operational period needed for delivery, security monitoring and fault investigation. A record attached to a documented incident or claim is separated from routine logs and deleted when that incident and any applicable claim period close.
Rights for this activity
Access, rectification, erasure, restriction and objection may apply. Portability does not apply because this processing is not based on consent or contract.
Processing activityP-02
Sales · procurement · security · other correspondence

Business and general enquiries

Legitimate interests
Why and who
Answer and follow up sales, procurement, security or general enquiries. This concerns the sender and any business contacts identified in the correspondence.
Data and source
You, a colleague or your organisation supplies names, professional contact and role details, the message, subject, attachments and ordinary correspondence metadata.
Basis and necessity
Article 6(1)(f) GDPR — legitimate interests in answering professional enquiries and managing prospective relationships. Article 6(1)(b) applies only where the individual is personally the prospective contracting party and requests pre-contract steps. A return contact and enough context are necessary; everything else is optional.
Recipients and transfers
Google Workspace provides correspondence services and may use global processing or support locations. Restricted transfers follow its data-processing terms and applicable EU Standard Contractual Clauses.
Retention
Prospective-business correspondence is kept for up to three years after the last meaningful contact. Contractual records or correspondence needed for a legal obligation or claim follow the applicable contract, accounting or limitation period.
Rights for this activity
Access, rectification, erasure, restriction and objection may apply. Portability applies only to data you provided that is processed automatically under Article 6(1)(b).
Processing activityP-03
Availability · calendar invitation · requested product meeting

Demonstration booking and follow-up

Legitimate interests
Why and who
Show live availability, then create, administer and follow up a requested product demonstration. This concerns visitors who open the booking page, people who book and any attendees they include.
Data and source
Loading availability sends the requested date window and ordinary connection metadata, including the IP address, to the booking endpoint. If you book, you provide the required name, work email and selected time, plus an optional organisation and note; calendar and meeting data are then created.
Basis and necessity
Article 6(1)(f) GDPR — legitimate interests in showing availability and administering a requested professional meeting. Connection data is necessary to return available times; name, work email and time are necessary to book. Organisation and message are optional, and booking creates no account, purchase or commitment.
Recipients and transfers
AWS handles availability and booking through an endpoint in us-east-1. Google Workspace and Calendar handle correspondence and meeting details. Restricted transfers use the applicable provider DPA and 2021 EU Standard Contractual Clauses; safeguard information may be requested through the privacy form.
Retention
Booking and prospect follow-up records are kept for up to three years after the meeting or last meaningful contact. A record needed for an established contract, legal obligation or claim follows the applicable contract, accounting or limitation period.
Rights for this activity
Access, rectification, erasure, restriction and objection may apply. Portability does not apply because this activity is based on legitimate interests.
Processing activityP-04
Contact form · booking form · bot and fraud risk analysis

reCAPTCHA protection for public forms

Necessary security
Why and who
Protect the contact and demonstration-booking forms from automated abuse. This concerns people and devices that proceed to either protected form.
Data and source
Your device, browser, network and interaction supply the IP address and risk signals. Google creates the reCAPTCHA token, assessment and _GRECAPTCHA cookie.
Basis and necessity
The GDPR basis is Article 6(1)(f): legitimate interests in protecting public forms and service availability. Separately, Legiscope relies on the strictly-necessary terminal-access exemption because reCAPTCHA is limited to securing a form the visitor has chosen to use. Any broader terminal use would require prior consent.
Recipients and transfers
Google acts as processor for reCAPTCHA Customer Data under the Google Cloud terms. Global processing and restricted transfers follow the Cloud DPA and applicable EU Standard Contractual Clauses.
Retention
The form uses the token for the protected submission and does not reuse it for marketing. Google deletes Customer Data under the reCAPTCHA service and Cloud DPA lifecycle; after a complete deletion instruction, the Cloud DPA allows up to 180 days for deletion. The _GRECAPTCHA cookie follows the service lifetime and may be cleared through browser controls.
Rights for this activity
Access, rectification, erasure, restriction and objection may apply; portability does not. The risk assessment may stop an abusive-looking submission, but it does not produce a legal or similarly significant decision about you.
Processing activityP-05
Request intake · identity assurance · response evidence

Privacy-rights requests and complaints

Legal obligation
Why and who
Authenticate where necessary, investigate and answer a privacy request or complaint, and retain proportionate handling evidence for the requester or authorised representative.
Data and source
You, your representative and relevant systems provide contact details, the request and correspondence, lookup information, proportionate verification or authority evidence, investigation notes and the response.
Basis and necessity
Article 6(1)(c) GDPR for rights and accountability obligations; Article 6(1)(f) for legal-claim evidence. Enough information to locate the data and authenticate the requester is necessary; less intrusive verification is preferred.
Recipients and transfers
Relevant providers, advisers and the competent authority or court may assist where necessary. Google Workspace correspondence uses its data-processing terms and applicable Standard Contractual Clauses; the underlying activity’s safeguards otherwise apply.
Retention
The request and response record is kept for five years after closure as accountability and legal-claim evidence. Additional identity evidence is deleted when verification is complete unless it remains necessary for a dispute or binding legal requirement.
Rights for this activity
Access, rectification and restriction may apply. Erasure and objection apply only to the legal-claim portion based on legitimate interests, not where retention is required to comply with a legal obligation. Portability does not apply.
03

Cookies and browser storage

The reviewed website does not load an advertising or audience-analytics runtime and does not use browser storage to build an advertising profile or follow visitors across websites. The security technology below is limited to the contact and demonstration-booking forms.

Google reCAPTCHA

_GRECAPTCHA

Technology
Cookie and associated device access
When used
When reCAPTCHA executes for a contact-form or demonstration-booking submission
Purpose
Security, fraud and automated-abuse prevention
Consent position
Strictly-necessary security exemption for the requested protected submission; consent would be required before any broader use
Lifetime
Google-controlled service lifetime; removable through browser controls
04

Recipients, transfers and safeguards

Access is limited by role and purpose. Legiscope uses Amazon Web Services for website and booking infrastructure, Google Workspace for professional correspondence and appointments, and Google reCAPTCHA to protect the contact and booking forms. Their operational boundaries are described in the public provider register.

Legiscope does not sell the personal data covered by this notice. A professional adviser or public authority receives information only where advice, a legal claim or a binding legal requirement makes the disclosure necessary.

For a restricted transfer under Chapter V GDPR, the provider terms identified for the applicable processing activity incorporate the relevant 2021 EU Standard Contractual Clauses. A person may use the contact page to ask for information about the safeguard and a copy of the applicable clauses, subject to protection of confidential information.

05

How to exercise your rights

The final row of each processing-activity card identifies the rights relevant to that activity. Where processing is based on legitimate interests, you may object on grounds relating to your particular situation; Legiscope will stop unless it demonstrates overriding compelling grounds or needs the data for a legal claim.

None of the activities described here relies on consent as its GDPR legal basis. If Legiscope later introduces an optional terminal technology requiring consent, it must remain disabled until a valid choice is made and withdrawing that choice must be as easy as giving it.

06

Legal framework and changes

This notice applies the transparency requirements of the GDPR and Lithuania’s supplementary data-protection rules. The controller and publisher section identifies the legal entity, registration, office, publication director and website host. Terminal access is assessed under the Lithuanian Electronic Communications Law and, for users in France, Article 82 of the French Data Protection Act.

If Legiscope intends to use personal data for a materially different purpose, it will provide the information required for that further processing before it begins. This notice will also be updated when a provider, purpose, data category, transfer or retention rule changes materially. The review date at the top identifies the current version.