
Data handling
What we process and where
Categories of data
- Contact and demo-request data (name, company, email, phone)
- Account data (login identity, roles, settings)
- Invoice and receipt documents and the financial data extracted from them
- Usage and audit data (actions, timestamps, approvals)
Where processing happens
- EU-hosted infrastructure for application and document storage
- Encryption in transit (TLS) and at rest
- Role-based access controls; access on a least-privilege basis
- Timestamped audit log of every document, suggestion and approval
Retention and deletion
- Documents are retained for as long as your contract runs, so the learning history stays intact.
- On termination you can request export and deletion of your documents and extracted data.
- Records already written to your Lexware Office account remain in your account under your own retention obligations.
Subprocessors
We use a small number of processors for hosting, AI-assisted document extraction and transactional email. The current, specifically named list is provided as an annex to the Data Processing Agreement and on request before you sign — we do not want a website page and a contract annex drifting apart.
Position
What we claim, and what we don't
We say
- Our infrastructure is designed for GDPR compliance.
- A DPA under Art. 28 GDPR is available for every client.
- Processing takes place on EU-hosted infrastructure.
- Designed to support GoBD-relevant workflows: original documents are retained and every change is logged.
We do not say
- "Certified GDPR compliant" — we hold no such certification.
- "GoBD-certified" — no such certificate exists for our software.
- "Tax-compliant guaranteed" — correctness of your accounting remains with you and your Steuerberater.
Lexware Office remains the authoritative accounting record for your business. Our copies exist to run the automation and to give you an audit trail.