Version: 21 August 2026
1. Who we are / Controller
The controller is:
Digilaw SRL, the company that owns the “Lawgitech” trademark and operates the Lawgitech Academy platform,
Rue du Congrès 35, 1000 Brussels, Belgium.
CBE / RLE Brussels: 0675.487.115 – VAT: BE 0675.487.115.
In this policy, any reference to “Lawgitech” or “Lawgitech Academy” refers to the company Digilaw SRL.
Privacy contact / Data Protection Officer (where applicable):
info@lawgitech.eu.
For any question concerning this policy or to exercise your rights, you can contact us at this address.
2. Legal bases and purposes of processing
- Performance of the contract: managing your registration, access to courses, issuing certifications, invoicing, support and educational follow-up.
- Legal compliance: retaining and verifying data as part of tax obligations, in particular verifying the VAT status of professional customers.
- Security and prevention of abuse: logging, anomaly detection, fraud prevention and safeguarding the integrity of the platform (legitimate interest, balanced against your rights).
- Communications to members: informing registered members about courses, webinars and other similar services of the platform (basis: legitimate interest — Article 6(1)(f) GDPR). You can object to these communications at any time, without giving reasons and free of charge, via the unsubscribe link included in each message or by writing to academy@lawgitech.eu; such requests are acted upon immediately.
- Processing based on consent: for other non-essential purposes, such as marketing newsletters sent to non-registered individuals or non-essential cookies. Consent can be withdrawn at any time.
3. Data we collect
a. Comments and public contributions
When you leave a comment on the website, we collect the data provided in the form (name, email, content), your IP address and the browser user-agent string for spam detection. An anonymised hash of your email may be sent to the Gravatar service to display your avatar.
b. User accounts and learning activity
If you register, we retain the information you provide (name, email, username, preferences), your progress, quiz results, certificates obtained, questions submitted and your interactions in order to perform the contract and personalise the service.
c. Gamification
Lawgitech Academy uses gamification mechanisms (points, badges, levels, leaderboards, rewards). The following are collected in particular:
- the internal user identifier;
- triggering events (module completion, quiz success, interactions);
- points awarded or deducted, badges unlocked, levels reached;
- the timestamps of events and progression;
- the data visible in leaderboards;
- additional data linked to enabled extensions (e.g. referral tracking, export via xAPI).
d. Cookies and tracking data
We use cookies and similar technologies to:
- manage sessions and authentication;
- remember display preferences;
- carry out statistical analysis if you consent to it;
- enable marketing purposes with your agreement;
- determine location for the application of VAT (e.g. a combination of billing address and IP).
Cookies that are not strictly necessary are placed only after your explicit consent.
e. Embedded content
Some pages may contain embedded content (e.g. videos, widgets). This external content behaves as if you were visiting the third-party website directly: it may collect data, place cookies and track your interactions.
f. Password reset and security
When you request a password reset, your IP address is included in the reset email for security reasons.
4. Who we share your data with
We may share or disclose your personal data with the following categories:
- Service providers: hosting, payment methods, email sending, spam detection, consent manager, educational integrations, analytics tools.
- Competent authorities: where required by law or to comply with regulatory obligations (e.g. a tax audit).
- Restructuring operations: in the event of a merger, acquisition or restructuring, with safeguards for maintaining compliance.
International transfers:
If we transfer data outside the EU/EEA, this is done only under appropriate safeguards (adequacy decisions, standard contractual clauses, supplementary measures) to ensure an equivalent level of protection.
5. Retention period
- Comments and associated metadata: retained indefinitely to facilitate follow-up and moderation.
- User accounts and contractual data: retained for the duration of performance of the contract and thereafter in accordance with legal obligations (e.g. 7 years for tax supporting documents).
- Consent records: retained for as long as the processing is based on consent and in order to demonstrate compliance.
- Gamification data: retained for the duration of the account’s activity, then in accordance with the same rules as user/contractual data.
6. Your rights
In accordance with the GDPR and Belgian law, you have the following rights:
- right of access;
- right to rectification;
- right to erasure (subject to legal obligations);
- right to restriction of processing;
- right to object to processing based on a legitimate interest, including the right to object at any time and without giving reasons to the communications referred to in section 2, point 4;
- right to data portability;
- right to withdraw your consent without affecting the lawfulness of prior processing;
- right to lodge a complaint with the Belgian Data Protection Authority (DPA / GBA).
Requests are handled within one month, which may be extended by two months in the event of complexity, with prior notice.
7. Security
We implement appropriate technical and organisational measures (encryption, access controls, logging, system updates) to protect data against unauthorised access, disclosure, loss or alteration. Processing activities are documented to ensure accountability.
8. Cookies and consent management
A banner or management module makes it possible to obtain and record consent for non-essential cookies. Strictly necessary cookies may be placed without prior consent; the other categories (analytics, marketing, referral) require explicit opt-in. You can withdraw or change your choices at any time via the management panel.
9. Changes to the policy
We may update this policy from time to time. The most recent version is published on the website with the update date. In the event of substantial changes, we will inform you by appropriate means (a notice on the dashboard or an email if you are registered).
10. Contact / compliance officer
To exercise your rights, ask a question or lodge a complaint, write to:
info@lawgitech.eu.
11. Specific cases / specific recipients
- VAT verification: intra-Community VAT numbers are verified via the VIES system and proof of verification is retained with a timestamp for compliance.
- Questions / answers: exchanges are used solely for educational purposes; any request going beyond the scope of general clarification (personalised legal advice) is the subject of a separate proposal.
11bis. Gamification
Lawgitech Academy may use gamification mechanisms. The data collected includes: user identifiers, triggering events, rewards (points, badges, levels), timestamps, visibility in leaderboards, and any additional data from integrations (xAPI export, referral tracking).
- Purposes: performance of the contract (follow-up, certificates); improving the experience (legitimate interest); internal reporting and conditional logic.
- Legal bases: performance of the contract for essential follow-up; legitimate interest for optimising the experience, with the possibility of opting out.
- Consent: cookies linked to certain extensions (e.g. referral) are placed only after explicit consent.
Users may request to be excluded from leaderboards or from certain analytics by contacting
info@lawgitech.eu. This deactivation may affect the visibility of rewards or educational logic. - Integrations: gamification data is stored locally by default. If external integrations are enabled (xAPI export, synchronisation), these third parties are treated as processors and subject to a contract.
- Retention: like other user data, it is retained while the account is active and thereafter in accordance with standard retention rules.
12. Intended audience
The platform is intended for professionals. We do not knowingly target minors. If we learn that a minor has provided data without appropriate consent, we will delete it.
