Privacy policy

Last updated: August 2026

1. Controller

RPK Digital Solutions GbR
Ludwig-Quidde-Straße 5
13127 Berlin, Germany
Email: contact@agimetis.com

Represented by Ramin Khorsandi and Parisa Khayamdar. Lawendo is a product of the AGIMetis brand.

2. Data protection officer

No data protection officer has been appointed, as the statutory conditions requiring one are not currently met. For any privacy matter, please use the contact details above.

3. This website

When you open this website, our hosting provider processes technically necessary connection data — IP address, request time, requested resource, referrer and user agent — in order to deliver the page and keep it secure.

  • Purpose: delivery, stability and security
  • Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation)
  • Retention: only as long as needed to deliver and secure the website

This website uses no analytics, marketing or tracking cookies. Fonts, stylesheets, scripts and images are served exclusively from our own domain; no connections to third parties are made.

4. Hosting and transfer outside the EEA

The website is hosted by Netlify, Inc., 101 2nd Street, San Francisco, CA 94105, USA. Netlify processes the connection data described in section 3 on our behalf.

  • Legal basis for processing: Art. 6(1)(f) GDPR
  • Processing agreement: Art. 28 GDPR
  • Transfer to the USA: this constitutes a transfer to a third country. It is based on the European Commission's standard contractual clauses, or on the adequacy decision where the recipient is certified under the EU-US Data Privacy Framework.

Note: despite these safeguards, access by US authorities to transferred data cannot be entirely excluded.

5. Contacting us

If you email us — for example through one of the access or contact links on this website — we process your details to handle the enquiry.

  • Legal basis: Art. 6(1)(b) GDPR for pre-contractual enquiries, otherwise Art. 6(1)(f)
  • Retention: enquiries are deleted no later than 24 months after the final substantive communication, unless statutory retention obligations or the establishment of legal claims require otherwise.

6. Using the Lawendo platform

To operate the platform we process account and profile data, case data, uploaded documents, messages, appointments, deadlines and billing data.

  • Legal basis: Art. 6(1)(b) GDPR (performance of the usage contract)
  • Special categories: case data may contain sensitive information within the meaning of Art. 9 GDPR. We process it only where necessary to operate the platform and where an exception under Art. 9(2) GDPR applies.
To be completed before the platform launches. The split of roles between us and the law firms operating on Lawendo — where we act as controller and where as processor on the firm's behalf — must be determined, described here, and reflected in data processing agreements. Also outstanding: the platform's concrete processors and their locations, the record of processing activities under Art. 30 GDPR, and, where required, a data protection impact assessment. This policy currently covers the website in full.

7. Your rights

Under the GDPR you have the right to:

  • access to the data processed about you (Art. 15)
  • rectification of inaccurate data (Art. 16)
  • erasure (Art. 17)
  • restriction of processing (Art. 18)
  • data portability (Art. 20)
  • object to processing based on legitimate interests (Art. 21)
  • withdraw consent with future effect (Art. 7(3))

As a platform user you can additionally request access or deletion directly in your account under “Security & privacy”.

8. Right to complain to a supervisory authority

You may lodge a complaint with a supervisory authority, in particular in the member state of your residence or of the alleged infringement. The authority responsible for us is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin, Germany

9. Technical and organisational measures

Access rights are enforced at the database level (row level security), every relation is covered by a declared authorisation manifest with default-deny access, and log data is stripped of sensitive fields before it is stored. A full description of our Art. 32 GDPR measures is available on request. An overview is also on our security and data protection page.

10. Changes to this policy

We update this policy when the processing changes — for example when the platform becomes publicly available. The version published here applies.

← Back to home