GDPR Notice

Last updated: March 2026  ·  Scanlex  ·  contact@scanlex.eu

This notice fulfils Scanlex's transparency obligations under Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 (GDPR). It describes how we process personal data in connection with our website and compliance advisory services.

1. Data Controller

The data controller for personal data processed through this website and in connection with Scanlex advisory engagements is:

Scanlex Ltd
Registration number: 14232412
Registered address: Tornimäe tn 5, Kesklinna linnaosa, Tallinn, Harju maakond, 10145, Estonia, EU
Email: contact@scanlex.eu
Website: scanlex.eu

2. What Personal Data We Process

Data categoryExamplesSource
Contact and identification dataName, email, company, job titleProvided by you via contact forms
Professional context dataIndustry sector, service interest, compliance situationProvided by you via contact forms
Engagement dataCorrespondence, deliverables, meeting notesGenerated during service delivery
Technical dataIP address, browser type (server logs only)Automatically collected on site visit

3. Purposes and Legal Bases

PurposeLegal basis (GDPR Art. 6)
Responding to enquiries and arranging scoping callsArt. 6(1)(b) — pre-contractual steps
Delivering compliance advisory servicesArt. 6(1)(b) — performance of contract
Sending regulatory updates relevant to your stated interestsArt. 6(1)(f) — legitimate interests
Maintaining records for legal and professional obligationsArt. 6(1)(c) — legal obligation
Improving our services based on engagement experienceArt. 6(1)(f) — legitimate interests

4. Retention Periods

Data typeRetention period
Enquiry data where no engagement proceeds12 months from initial contact
Engagement data (correspondence, deliverables)Duration of engagement + 6 years
Financial records (invoices, payments)7 years (legal obligation)
Server log technical data30 days (automatic deletion)

5. Your Rights

Right of Access (Art. 15)

Request a copy of all personal data we hold about you, including the purposes and recipients.

Right to Rectification (Art. 16)

Request correction of inaccurate or incomplete personal data without undue delay.

Right to Erasure (Art. 17)

Request deletion of your data where it is no longer necessary or processing is unlawful.

Right to Restriction (Art. 18)

Request that we limit processing of your data in certain defined circumstances.

Right to Portability (Art. 20)

Receive your data in a structured, machine-readable format where technically feasible.

Right to Object (Art. 21)

Object to processing based on legitimate interests, including direct marketing.

To exercise any right, contact us at contact@scanlex.eu. We will respond within 30 days. We may ask you to verify your identity before processing your request. There is no fee for exercising your rights.

6. Automated Decision-Making

We do not subject any individual to automated decision-making or profiling as defined under GDPR Article 22. All decisions made in connection with our services involve human review.

7. International Transfers

We do not transfer personal data to countries outside the European Economic Area (EEA) except where adequate safeguards are in place (such as EU Standard Contractual Clauses) and we have assessed transfer impact appropriately. Where we use service providers based outside the EEA, we ensure GDPR-compliant data processing agreements are in place.

8. Data Security

We implement appropriate technical and organisational measures to protect personal data against accidental loss, destruction, alteration, unauthorised disclosure, or access. These include encrypted communication channels, access controls, and secure data storage. We review our security measures regularly.

9. Right to Lodge a Complaint

If you believe we have processed your personal data unlawfully or in breach of your rights, you have the right to lodge a complaint with your national data protection supervisory authority. A full list of EU supervisory authorities is available at edpb.europa.eu.

We encourage you to contact us first at contact@scanlex.eu so we can attempt to resolve any concern directly.

10. Updates to This Notice

We review and update this GDPR Notice regularly. The date of the most recent update is shown at the top of this page. Material changes will be communicated to existing clients by email where appropriate.