Privacy Policy
Last updated 8 September 2026
1. About this policy
Letzscale S.à r.l. - S. ("Letzscale", "we", "us") operates the website at letzscale.com and provides a service that reads supplier contracts and maps their content to the fields of a DORA information register. This policy explains what personal data we handle, why we handle it, and the rights you have.
It applies to visitors to letzscale.com, to people who request a Gap Audit, and to the administrators and users of a Letzscale account. It does not replace any separate agreement you have signed with us. Where a data processing agreement is in place, that agreement governs how we handle the data you submit into the service and prevails over this policy if the two conflict.
Letzscale is registered with the Luxembourg Trade and Companies Register under number B309937. Our registered office is 19, Um Kalleksuewen, L-7480 Tuntange, Helperknapp, Grand Duchy of Luxembourg.
2. When we are a controller and when we are a processor
We are the controller for personal data about visitors to letzscale.com, people who submit the Gap Audit form or otherwise contact us, and the individuals who administer, are billed for, or use a Letzscale account.
We are a processor acting on your instructions for the content that you or your organisation uploads into the service, including supplier contracts and the register entries derived from them. That material can contain personal data, for example the names and contact details of signatories and account managers. For that processing your organisation is the controller, its own privacy information applies to the people concerned, and our data processing agreement sets out our obligations.
When we act as a processor, our data processing agreement sets out our obligations under Article 28 of the GDPR. Read the Data Processing Agreement
3. Personal data we collect as controller
Data you give us
- Gap Audit form: your name, work email address, and company name.
- Account setup and administration: name, work email, job title, and the organisation you act for.
- Billing: the name and email of your billing contact and your organisation's invoicing details. Card details are handled by our payment processor and are not stored by us.
- Correspondence: the content of messages you send us and our replies.
Data we collect automatically
- Usage analytics: aggregate statistics about pages viewed and actions taken, collected through a privacy-focused analytics tool. [PLACEHOLDER: name the analytics provider, state whether it sets cookies, and link its privacy policy.]
- Essential cookies and similar technologies needed to keep you signed in and to keep the service secure. See section 6.
- Server logs, which record the IP address, browser type, and time of each request and are used to operate and protect the service. The Letzscale application and the documents you upload are hosted in the European Union, in the Frankfurt, Germany region (eu-central-1). [PLACEHOLDER: name the provider and country for the marketing website host, which is separate infrastructure from the application.]
Data from other sources
We do not buy personal data and we do not enrich your record from data brokers. [PLACEHOLDER: if single sign-on, meeting scheduling, or CRM tools are added, describe what personal data they provide.]
4. Content you upload into the service
When you use the service you upload supplier contracts and related documents, and the service produces a gap analysis and an export file. We process that content only to run the analysis you asked for and return the result, to operate, secure, support, and maintain the service, and to meet a legal obligation.
The service is deterministic. It matches the text of a document against the fields the regulation defines, and every field it fills is traceable to a quote in your document. We do not sell your content, and neither we nor any provider we use trains machine-learning models on it.
Part of the analysis uses a third-party AI model service to read your documents. It runs inside our European Union processing region, it receives your content only to return the analysis you asked for, and it is contractually prohibited from using that content to train or improve any model. It is named on our subprocessor page. [PLACEHOLDER: once the zero-data-retention addendum is in force, state here that the provider retains no copy of the content it processes.]
Access inside Letzscale is limited to staff who need it to run or support the service, under confidentiality obligations.
5. Why we use personal data, and our legal basis
We rely on the following legal bases under Article 6(1) of the GDPR.
- Responding to a Gap Audit request or other enquiry
- Steps taken at your request before entering into a contract, and our legitimate interest in responding to prospective customers.
- Providing the service and administering the account
- Performance of our contract with your organisation.
- Billing and keeping accounting records
- Performance of a contract, and compliance with a legal obligation.
- Securing the service and preventing abuse
- Our legitimate interest in keeping the service safe and available.
- Measuring website usage
- Your consent where it is required, and otherwise our legitimate interest in a working website. [PLACEHOLDER: align with the analytics decision in section 6.]
- Sending service messages about your account
- Performance of our contract with your organisation.
- Meeting legal, regulatory, or court requirements
- Compliance with a legal obligation.
We do not carry out automated decision-making that produces legal or similarly significant effects about you.
6. Cookies and analytics
We use cookies and similar technologies that are strictly necessary to run the site and the signed-in service. They keep your session active, remember your cookie choices, and help protect against fraudulent activity. Strictly necessary technologies do not require consent.
For usage measurement we use [PLACEHOLDER: analytics tool]. [PLACEHOLDER: state whether it sets cookies or is cookieless, whether the data is aggregated, and, if consent is required, describe the consent banner and how to withdraw consent.]
You can block or delete cookies in your browser settings. The signed-in service may not work correctly without the strictly necessary ones.
7. Who we share personal data with
- Service providers that process personal data on our behalf under written contracts that limit them to our instructions: hosting and infrastructure, analytics, email delivery, customer support tools, and payment processing.
- Professional advisers such as lawyers, auditors, and accountants, where needed and under a duty of confidence.
- Authorities and other parties where we are required to disclose by law, regulation, or a valid order, or where disclosure is necessary to establish, exercise, or defend legal claims.
- A buyer or successor if Letzscale is involved in a merger, acquisition, or sale of assets. We will tell affected customers if this happens.
We keep a current list of the service providers that process personal data on our behalf. See our subprocessors
We do not sell personal data and we do not share it for cross-context behavioural advertising.
8. International transfers
Customer content, including the documents you upload, is stored and processed in the European Union, in the Frankfurt, Germany region (eu-central-1). Our infrastructure and AI model provider is contracted to keep that content in that region, both at rest and during processing. Some of our providers belong to groups with entities outside the European Economic Area, and limited access from outside the EEA can occur for support, security, or abuse-prevention purposes. Where a service provider processes personal data outside the European Economic Area, we rely on an adequacy decision or on the European Commission's standard contractual clauses together with any further safeguards that are required. You can ask us for a copy of the relevant transfer mechanism using the contact details below.
9. How long we keep personal data
- Gap Audit submissions and any documents provided for the audit: deleted within [PLACEHOLDER: 90] days of us delivering the analysis, unless your organisation becomes a customer, in which case they move under the customer relationship.
- Customer content in the service: kept for the term of the subscription. After termination it can be exported for [PLACEHOLDER: 30] days and is then deleted within [PLACEHOLDER: 90] days, unless the data processing agreement provides otherwise.
- Account records: kept for the life of the account and then for the period needed to handle any dispute.
- Invoices and accounting records: kept for the retention period required by Luxembourg law. [PLACEHOLDER: confirm the period, commonly ten years for accounting records.]
- Correspondence: kept for as long as needed to handle the matter and a reasonable period afterwards.
10. How we protect personal data
We use encryption in transit and at rest, access controls, logging, and least-privilege access for staff. Customer content is isolated per tenant and is stored and processed in the European Union, in the Frankfurt, Germany region (eu-central-1). [PLACEHOLDER: add backup and restoration practice, and the infrastructure certifications you rely on, for example the provider's ISO 27001 certification and SOC 2 report.] No system is completely secure. If a personal data breach occurs we will notify the regulator and affected people where the law requires.
11. Your rights
If you are in the European Union or the United Kingdom you have the right to ask for a copy of the personal data we hold about you, to have inaccurate data corrected, to have data erased in certain circumstances, to restrict or object to certain processing including processing based on legitimate interests, to receive certain data in a portable format, and to withdraw consent where we rely on it without affecting processing already carried out.
To exercise a right, email us using the details in section 13. We will respond within one month and may ask you to confirm your identity. If your request concerns content held in the service on behalf of a customer, we will direct you to that customer, who is the controller for that data.
You can also lodge a complaint with the Commission nationale pour la protection des données (CNPD), 15, Boulevard du Jazz, L-4370 Belvaux, Grand Duchy of Luxembourg, www.cnpd.lu, or with the supervisory authority where you live or work.
12. Children
Letzscale and letzscale.com are business tools intended for people acting for an organisation. They are not directed at children and we do not knowingly collect personal data from anyone under 18.
13. How to contact us
[PLACEHOLDER: confirm the privacy contact address, either jonas.sampaio@letzscale.com or a dedicated alias such as privacy@letzscale.com.]
Letzscale S.à r.l. - S., 19, Um Kalleksuewen, L-7480 Tuntange, Helperknapp, Grand Duchy of Luxembourg.
14. Changes to this policy
We update this policy when our practices change. If a change is material we will give notice through the service or by email before it takes effect. The date at the top of this page shows when the current version was published.