Privacy policy
This Privacy Policy describes how MXLEX, a Mangold Systems product, processes personal data, in compliance with the LFPDPPP (Mexico), Ley 1581 de 2012 (Colombia), Ley 81 de 2019 (Panama), and the GDPR (European Union). We distinguish account data (where we act as controller) from the matter content a firm uploads (where we act as processor on the firm's behalf; the firm is the controller toward its clients).
1. Controller and identity
Controller of account data: Mangold Systems (MXLEX). Privacy contact: privacy@mxlex.app.
In Mexico, this document serves as the privacy notice (aviso de privacidad) required by the LFPDPPP. In Colombia, it forms the data-processing policy required by Decreto 1377 de 2013. In Panama, it meets the duty to inform under Ley 81 de 2019.
2. Roles: controller and processor
Account data (name, email, billing, usage): MXLEX is the controller.
Matter content (documents, the firm's client data): the firm is the controller and MXLEX is the processor, handling that data only under the firm's instructions and the Data Processing Agreement.
3. Personal data we process
Identification and contact data: name, email, firm, role, and credentials.
Usage data: technical logs, product-usage metrics, and diagnostics.
Matter content: documents, facts, and instructions a firm uploads, which may contain third parties' personal data and even sensitive data. In Mexico, sensitive data requires express consent under the LFPDPPP; such processing always occurs on the firm's instructions.
4. Purposes and legal basis
Primary purposes: providing and operating the service, authenticating users, support, and billing.
Secondary purposes: security, fraud prevention, legal compliance, and product improvement using aggregated, anonymized data. We do not use your matter content to train AI models.
Legal bases: performance of the contract and consent under the LFPDPPP; the data subject's prior, express, and informed authorization under art. 9 of Ley 1581 de 2012 (Colombia); consent under Ley 81 de 2019 (Panama); and art. 6 of the GDPR (contract, legitimate interest, and consent) for EU clients.
5. Sub-processors and international transfers
Sub-processors: Anthropic (AI generation, no training), AWS (infrastructure), and Supabase (database, authentication, and storage).
Our infrastructure is hosted in the United States, so international transfers may occur. These rely on: the transfer provisions of the LFPDPPP (Mexico); the transfer and accountability regime of Decreto 1377 de 2013 and SIC guidance (Colombia); the transfer chapter of Ley 81 de 2019 (Panama); and the standard contractual clauses (SCCs) under art. 46 of the GDPR for EU data.
6. Retention
Account data: while the account is active and as needed to meet legal, accounting, and legal-defense obligations.
Matter content: under the firm's instructions; on termination it is returned or deleted under the Data Processing Agreement.
7. Security
We apply the technical and organizational measures on our Security page (encryption in transit and at rest, firm-level isolation via RLS, role-based access), meeting the security principle of the LFPDPPP, Ley 1581 de 2012, Ley 81 de 2019, and art. 32 of the GDPR.
8. Your rights, by country
Mexico (LFPDPPP, DOF March 20, 2025): ARCO rights (access, rectification, cancellation, and opposition), withdrawal of consent, and, under the reform, the right to object to automated decisions that significantly affect you. Requests to privacy@mxlex.app. Authority: Transparencia para el Pueblo, under the Secretaría Anticorrupción y Buen Gobierno.
Colombia (Ley 1581 de 2012, Decreto 1377 de 2013; constitutional art. 15, Habeas Data): to know, update, rectify, and delete your data, and to revoke authorization. Complaints to the controller and, where applicable, to the Superintendencia de Industria y Comercio (SIC).
Panama (Ley 81 de 2019, Decreto Ejecutivo 285 de 2021): access, rectification, cancellation, opposition, and portability. Authority: Autoridad Nacional de Transparencia y Acceso a la Información (ANTAI).
European Union (GDPR, arts. 15 to 22): access, rectification, erasure, restriction, portability, and objection, including as to automated decisions.
If you are a firm's client, contact your firm as the controller of your data; MXLEX, as processor, will assist it.
9. Changes and contact
We will post any material change to this Policy on this page. Controller: Mangold Systems / MXLEX. Privacy: privacy@mxlex.app. We will handle requests within the timeframes set by the applicable law of your country.