Legal Center
Here you will find the terms and policies governing your relationship with Whisperly when you subscribe to any Whisperly plan or engage Whisperly for consulting services, in addition to any specific terms agreed upon in writing.
Privacy Notice
Last updated on 28th May 2026
For Whisperly Platform Users
This notice is issued by Lexelerate OÜ ("Lexelerate", "we", "us") and applies to individuals who access the Whisperly Platform on behalf of a subscribing organisation (the "Customer"). It explains how we process personal data both as a data processor acting on the Customer's instructions and as an independent data controller for certain limited purposes.
1Who We Are
Lexelerate OÜ, Sepapaja 6, Lasnamäe District, Tallinn, Harju County, 15551, Estonia, company number 17224471 (hereinafter: Lexelerate)
For any questions related to data protection, you can contact us at office@lexelerate.ai.
2Scope of This Notice
This notice covers two distinct ways in which Lexelerate processes personal data in connection with the Whisperly platform:
- As data processor (Section 4), processing personal data on the Customer's behalf and under its instructions, in accordance with the Data Processing Agreement (DPA) between Lexelerate and the Customer.
- As independent data controller (Section 5), processing certain personal data for Lexelerate's own limited purposes.
For processing under Section 4, the Customer is the data controller responsible for determining the purposes and means of processing. If you have questions about how your organisation processes your data through the platform, please contact your organisation's data protection contact.
3Key Definitions
| Term | Meaning |
|---|---|
| GDPR | General Data Protection Regulation (EU) 2016/679. |
| Personal data | Any information relating to an identified or identifiable natural person. |
| Processing | Any operation performed on personal data, whether by automated means or otherwise. |
| Data controller | The entity that determines the purposes and means of processing. |
| Data processor | An entity that processes personal data on behalf of a controller. |
| Customer | The organisation that has subscribed to Whisperly under an Order Form. |
| Platform / Service | The Whisperly web-based SaaS platform for data protection compliance, AI governance, and vendor assessment. |
4Processing as Data Processor (on the Customer's Instructions)
When you or your colleagues use the Whisperly platform, you may enter or upload personal data into the Service (for example, in the course of completing data protection impact assessments, vendor questionnaires, records of processing activities, or AI governance documentation). Lexelerate processes this data exclusively as a data processor acting on the Customer's documented instructions and in accordance with the DPA.
What data is involved
The categories and extent of personal data processed depend on the Customer's configuration and use of the Service. Such data may typically include:
- Authentication data, identification and contact details, professional data.
- Any personal data contained in Customer Content uploaded or created through the platform; the scope and categories are determined solely by the Customer.
Our obligations as processor
- We process this data only on the Customer's instructions and for the purposes of providing the Service.
- We implement appropriate technical and organisational security measures (detailed in Appendix 2 of the DPA).
- We do not use this data for our own purposes, share it with third parties except authorised subprocessors, or retain it beyond the end of the subscription unless required by law.
For data subject rights requests in relation to this processing (access, erasure, rectification, etc.), please contact your organisation as the Data controller.
5Processing as Independent Data Controller
In addition to our processor role, Lexelerate processes certain personal data as an independent Data controller for the following limited purposes. This processing is separate from and does not affect the Customer's processing under the DPA.
| Purpose | Data processed | Legal basis | Retention |
|---|---|---|---|
| Service improvement | De-identified and aggregated usage and technical data (e.g. feature usage statistics, performance metrics). | Legitimate interests (Art. 6(1)(f) GDPR), developing and improving the Service. | Duration of subscription + 6 months. |
| Security and fraud prevention | IP addresses, access logs, usage patterns, authentication events. | Legitimate interests (Art. 6(1)(f) GDPR), protecting the security and integrity of the Service. | Up to 2 months from collection, unless a longer period is required for an active security investigation. |
| Customer relationship management | Name, job title, business email address, and telephone number of designated contact persons. | Legitimate interests (Art. 6(1)(f) GDPR), managing the contractual relationship. | Duration of the contractual relationship + 3 years. |
| Legal claims and compliance with legal obligations | Any personal data contained in a legal claim, complaint, regulatory request, or enforcement proceeding. | Legal obligation (Art. 6(1)(c) GDPR) and/or legitimate interests (Art. 6(1)(f) GDPR), establishing, exercising, or defending legal claims. | As required by applicable law or for the duration of the relevant proceedings. |
| Cookies, for purposes see Section 6 | Session identifiers, IP address, browser technical data. See Section 6 for full details. | Legitimate interests (Art. 6(1)(f) GDPR), platform security, session management, and fraud prevention. | Session / up to 1 year; see Section 6. |
Automated decision-making and profiling
We do not engage in automated decision-making or profiling that produces legal or similarly significant effects within the meaning of Article 22 GDPR.
6Cookies and Similar Technologies
The Whisperly platform uses a limited number of cookies and similar technologies. All cookies listed below are strictly necessary for the operation of the Service and do not require your consent under Article 5(3) of the ePrivacy Directive. The legal basis for the processing of personal data through each cookie under the GDPR is indicated in the table below.
| Cookie / Technology | Provider | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Authentication & session cookies (__Host-GAPS, __Host-GAP) | Authenticate identity and maintain the logged-in session via Google OAuth single sign-on. | Art. 6(1)(f) GDPR, legitimate interests (secure session management and platform access control). | Session / short-term (renewed on login) | |
| Security verification cookie (cf_clearance) | Cloudflare | Records that the browser has passed Cloudflare's security check, preventing repeated verification challenges. | Art. 6(1)(f) GDPR, legitimate interests (protection of platform infrastructure against abuse and attacks). | Up to 1 year |
| Abuse and fraud prevention cookies (AEC, __Secure-*) | Google / Infrastructure providers | Protect the platform against automated abuse, fraudulent requests, and unauthorised access attempts. | Art. 6(1)(f) GDPR, legitimate interests (fraud prevention and platform security). | Session / short-term |
We do not use analytics, advertising, or tracking cookies on the platform. The platform does not serve third-party advertising.
If you access the Whisperly website (whisperly.ai), a separate Cookie Policy governs cookies used there, available at https://whisperly.ai/cookie-policy.
7Data Transfers
Personal data processed under this notice may be transferred to or accessed from countries outside the European Economic Area (EEA) where our subprocessors operate. All such transfers are carried out in compliance with Chapter V GDPR using one or more of the following safeguards:
- An adequacy decision by the European Commission (including the EU-U.S. Data Privacy Framework where applicable);
- The European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914);
- Supplementary technical and organisational measures applied where necessary to ensure an essentially equivalent level of protection.
Transfer documentation is available upon request at office@lexelerate.ai.
8Subprocessors and Third-Party Sharing
We share personal data only with authorised subprocessors required to deliver the Service. The current list of subprocessors, including their registered seats, purposes of processing, and transfer safeguards, is maintained at the Whisperly Trust Center: https://trust-center.whisperly.ai/. We do not sell personal data or share it with third parties for marketing purposes.
We may share personal data with competent authorities where required by applicable law or a lawful order.
9Your Rights
In relation to personal data for which Lexelerate is the data controller (Section 5), you have the following rights under the GDPR:
| Right | What it means |
|---|---|
| Access (Art. 15) | Request a copy of the personal data we hold about you. |
| Rectification (Art. 16) | Ask us to correct inaccurate or incomplete data. |
| Erasure (Art. 17) | Request deletion of your data where there is no longer a valid reason to process it. |
| Restriction (Art. 18) | Ask us to restrict processing in certain circumstances. |
| Portability (Art. 20) | Receive your data in a structured, machine-readable format where processing is based on consent or contract. |
| Object (Art. 21) | Object to processing based on legitimate interests. We will cease processing unless we have compelling legitimate grounds. |
| Withdraw consent (Art. 7(3)) | Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing. |
To exercise any of the above rights, contact us at office@lexelerate.ai. We will respond within 30 days. For data processed by Lexelerate as a data processor (Section 4), please contact your organisation directly.
10Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. A detailed description of our measures is set out in Appendix 2 of the DPA. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
11Right to Lodge a Complaint
If you have concerns about our processing of your personal data, you may lodge a complaint with the competent data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. List of Personal Data Protection Competent Authorities can be found here: https://digital-strategy.ec.europa.eu/en/library/list-personal-data-protection-competent-authorities
12Changes to This Notice
We may update this notice from time to time. The current version is always available at https://whisperly.ai/legal-center. Material changes will be communicated to Customers via email or through the platform before they take effect.
13Contact
For any questions about this notice or to exercise your rights, contact us at office@lexelerate.ai or by post: Lexelerate OÜ, Sepapaja 6, Lasnamäe District, Tallinn, Harju County, 15551, Estonia.