Legal
Privacy policy
This policy explains how personal data is processed when using DUOLEXX (duolexx.com) under the General Data Protection Regulation (GDPR).
1. Controller
The controller is: VIYBS LLC, 254 Chapman Rd, Ste 208 #18174, Newark, DE 19702, USA Contact: support@duolexx.com · https://duolexx.com/support
2. Principles
We process personal data only as far as necessary for a functional and legally sound service. We treat your document contents as confidential: they are stored encrypted (see section 11), and no admin function displays contract contents.
3. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). You can exercise access and portability directly in your profile via “Export data”, and delete your account and all related data via “Delete account”. You may withdraw consent (e.g. statistics) at any time with effect for the future (Art. 7(3)), e.g. via “Cookie settings” in the footer. You also have the right to lodge a complaint with a supervisory authority (Art. 77).
4. Account & sign-in
Purpose: providing a user account, authentication. Data: name, email, password (stored only as a hash); optional Google sign-in (OAuth). Legal basis: Art. 6(1)(b) GDPR (contract). Retention: until the account is deleted.
5. Document creation
Purpose: creating your bilingual documents via the guided assistant. Data: the information you enter and the resulting document content, which may contain personal data of the contracting parties (e.g. names, addresses, bank details). Legal basis: Art. 6(1)(b) GDPR. Storage: the frozen document snapshot is stored encrypted (section 11). Retention: until deleted by you or with your account.
6. Electronic signature
Purpose: simple electronic signature (SES) for two parties and its evidentiary record. Data: name and email of signatories, the signature image (for a drawn signature), a timestamp, the signature method and a hashed IP address (the IP itself is not stored). The counterparty signs without an account via a link and is informed beforehand (Art. 13). Legal basis: Art. 6(1)(b) and our legitimate interest in provable signatures (Art. 6(1)(f)). Retention: for the duration of the document's evidentiary function and within statutory retention obligations; the signature image is stored encrypted.
7. Payments
Purpose: processing paid purchases (pay-per-document) and subscriptions (Pro). Data: purchase reference (amount, currency, transaction ID); billing address if tax collection is enabled. Payment details (e.g. card data) are processed solely by the payment provider Stripe; we do not receive full payment credentials. Legal basis: Art. 6(1)(b); invoice data additionally Art. 6(1)(c) (statutory retention). Retention: payment and invoice data are subject to statutory retention periods and are not deleted early.
8. Email delivery
Purpose: sending confirmation, verification and signature codes (OTP) and support replies. Data: email address and message content. Sent via the provider Resend. Legal basis: Art. 6(1)(b) or (f) GDPR. One-time codes are deleted after expiry (10 minutes) or redemption.
9. Analytics (consent only)
Purpose: privacy-friendly, aggregate usage statistics to improve the service via the self-hosted software Umami. We use analytics only with your consent; without consent no statistics script is loaded and no event is recorded. Umami works without cookies and without ad trackers. Legal basis: Art. 6(1)(a) GDPR (consent), § 25(1) TDDDG. Withdraw anytime via “Cookie settings” in the footer.
10. Support & feedback
Purpose: handling requests and feedback. Data: email address, subject and content, any account reference. Legal basis: Art. 6(1)(b) or (f) GDPR.
11. Recipients & processors
We use carefully selected providers as processors (Art. 28 GDPR): • Stripe — payment processing (based in the USA). • Resend — email delivery (based in the USA). • Umami — analytics, self-hosted in the EU. • Appwrite — database/storage, self-hosted in the EU. • Hosting/server — operated in the EU. We conclude data processing agreements under Art. 28 GDPR with our processors.
12. International transfers
The controller is based in the USA; some providers (Stripe, Resend) also process data in the USA. Where data is transferred to the USA or other third countries, we rely on appropriate safeguards, in particular the EU Standard Contractual Clauses or a certification under the EU-US Data Privacy Framework.
13. Cookies & local storage
Details on cookies and browser local storage are in our Cookie Policy: https://duolexx.com/legal/cookies.
14. Security of processing
We implement technical and organisational measures (Art. 32 GDPR): encryption of sensitive content (document snapshot, signature image) at rest, storage of IP addresses and one-time codes only as hashes, cryptographic sealing of signed documents (Ed25519, publicly verifiable at /api/verify), password hashing, and TLS transport encryption.
15. No automated decision-making
There is no solely automated decision-making or profiling producing legal effects within the meaning of Art. 22 GDPR.
16. Source of data (signing counterparty)
When a second party signs a document via a shared link, we obtain their data partly from the inviting person and partly from the counterparty's own input. The counterparty is informed before signing pursuant to Art. 13 GDPR.
17. Changes to this policy
We update this privacy policy where changes in processing require it. The version published on this page applies.