Privacy Policy
Effective date: 26 August 2026
Legamap exists to hold some of the most sensitive information a person can write down: a structured map of what you own, and who should receive it when you are gone. That is why this policy is written in plain language, tells you honestly what we can and cannot see, and does not hide the uncomfortable parts.
Data controller: MB Kocius, a limited liability company registered in Lithuania, European Union (company code 307051502, VAT LT100018675617). Data protection requests: privacy@legamap.com · General contact: hello@legamap.com
You can verify the company in the Lithuanian Register of Legal Entities.
1. The short version
- Your data is stored in the European Union and processed under GDPR. We do not move it outside the EU.
- We collect the minimum the product needs, and the product actively refuses passwords, PINs, full account numbers, card numbers, and crypto recovery phrases.
- Sensitive fields are individually encrypted, but we are not a zero-knowledge service — our servers can decrypt your data. This is a deliberate, publicly stated design decision, because on the day it matters your recipients will not have your key.
- Nothing is ever delivered to anyone automatically without human confirmation — your trustee's, or a manual document review by us.
- We do not sell data, we do not run advertising, and we do not use third-party advertising trackers.
- You can export everything and delete everything, at any time, from your account.
The rest of this policy is the detail behind those sentences.
2. Before the service opens
The Legamap service is not open yet. Until it opens, this website collects only:
- Waitlist emails. If you join the waitlist, we store your email address — and your first name, if you give it, so we can greet you by it — to send you one launch email, and — only if you opt in — a monthly progress note. Legal basis: your consent, which you can withdraw with one click in any email. Unsubscribing removes you from the list.
- First-party analytics. Anonymous usage events (pages viewed, button clicks, approximate country derived from your connection). No advertising trackers, no cross-site tracking, no sale of data.
No accounts exist and no payments are taken before opening day. From the day the service opens, the rest of this policy applies in full.
3. What we collect
Account and security data. Email address, phone number, an optional secondary email, password (stored only as a hash), two-factor authentication secret, your name (we use it, together with your email address, when we write to the people you add), country, timezone, language. Session and device information needed to keep the account secure.
Your map. The asset entries you create — institution names, countries, last four digits of identifiers, approximate values, your access instructions and notes — and any documents you attach. Access instructions, notes, and document contents carry field-level encryption on top of standard encryption (Section 8).
People you add. Names and contact details of your recipients and your trustee, and your description of your relationship to them. This is data about other people — Section 6 explains how we treat it.
Check-in and protocol records. When check-ins were sent, delivered, opened, and answered; bounce reasons; pauses; trustee requests and responses; the full audit trail of any triggered case. If a death certificate is submitted, we store it for manual verification, treat it with particular care, and never make it available to recipients.
Payment records. Purchases are processed by Paddle, our merchant of record, which acts as an independent controller for checkout and payment data under its own privacy policy. We never see or store your card details; we receive transaction records (what was bought, when, for how much, and tax jurisdiction data).
Support correspondence. Emails you send us, kept with your account so we have context.
Audit logs. Every read of customer data — including by our own administrators — is logged.
What we refuse to collect. The product blocks input that looks like a full bank account number (IBAN), a payment card number, a PIN, a password, a BIP39 recovery phrase, or a national personal identification number. This is data minimization built into the fields themselves: a map of where things are, never the keys to them.
4. Why we process it, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the service: your account, your map, check-ins, exports, delivery | Contract (6(1)(b)) |
| Storing recipient and trustee contact details you provide | Legitimate interest (6(1)(f)), with the notice described in Section 6 |
| Security: 2FA, access logs, abuse and fraud prevention | Legitimate interest (6(1)(f)) and legal obligation (6(1)(c)) |
| Payment, invoicing, tax, accounting records | Legal obligation (6(1)(c)); checkout itself — Paddle as merchant of record |
| Waitlist and optional progress notes | Consent (6(1)(a)) |
| First-party product analytics and service improvement | Legitimate interest (6(1)(f)) |
| Verifying a submitted death certificate before any delivery | Contract (6(1)(b)) and legitimate interest (6(1)(f)) — preventing wrongful disclosure |
We do not use your data for advertising, do not sell it, and do not share it with anyone except the sub-processors in Section 7, the people you yourself designated (and only per protocol), and authorities where the law leaves us no choice.
5. The delivery protocol and your data
The entire point of Legamap is that, in one narrow circumstance, your map leaves your account and reaches the people you chose. Because that is also the most privacy-critical moment of the product, the protocol is deliberately conservative:
- Until delivery, your recipients can see only the fact that they have been named — never any content.
- Delivery happens only after the check-in protocol completes and a human confirms: your trustee, or our manual verification of a death certificate. There is no fully automated path from silence to delivery. In case of any doubt, the system waits.
- After a declaration there is a 72-hour undo window during which nothing is visible to anyone.
- At delivery, each recipient receives only the part of the map you assigned to them.
- Delivered data becomes the recipient's to use for settling your affairs; we tell them what it is and what it is for.
6. People you add: recipients and trustees
When you add a recipient or trustee, we start holding personal data of a person who did not give it to us. EU law (GDPR Article 14) normally requires that they be told. For each recipient, you choose when:
- Tell them now that they are listed (the default). Within 30 days of being added — in practice, about a day after — the person receives a neutral notification: that they have been named as a Legamap contact by you, that no content about your assets is disclosed to them, and that they can object. We name you in that notice, because GDPR Article 14(2)(f) requires us to tell people where their data came from — and because without knowing, they could not meaningfully exercise their rights.
- Tell them nothing until delivery. The person hears nothing from us about being listed. They are told when your map is delivered to them, at which point they also receive its content.
- You can change this choice for any recipient at any time. Either way, the delivery email itself goes to every recipient when your case is triggered.
- The notice deliberately reveals nothing about your map — not the number of entries, not their nature, not their value.
- Objecting takes one click, not an email. Every notice we send carries a link that removes them, and anyone who has opened an account can do the same from it. That link does not expire — the right does not either. Writing to privacy@legamap.com works too, and we do the same thing by hand.
- What objecting does. We delete their email address and phone number, we stop contacting them, nothing of yours is left to them any more, and we keep a one-way fingerprint of the address for 12 months so it cannot quietly be added to your list again. We tell you, we mark the record, and the decision about what they were left stays with you. If they demand erasure of everything we hold about them, we remove the record itself — name and relationship included — and ask you to name someone else. We keep the same one-way fingerprint for 12 months in that case too, so the erasure cannot be undone by re-adding the address; and we do not tell you who it was, because their name was part of what they asked us to delete.
- Once a year, only if you ask us to, we email your trustee and the recipients who have been told they are listed, asking them to confirm that the address still reaches them. Recipients you chose to tell nothing are never contacted this way. We record whether and when they confirmed.
- Recipients and trustees have the same GDPR rights as you (Section 10) over the data we hold about them — which, until delivery, is only their contact details, their role, the notification record, and whether they confirmed their address.
7. Where your data lives, and who touches it
- Everything is stored in the European Union. Our infrastructure — database, file storage, backups — runs in EU data centers.
- We use a small number of sub-processors for hosting, email delivery, SMS delivery, and file storage, each bound by a data processing agreement. We do not engage sub-processors outside the EU/EEA for stored customer data. The current list is published on the Security page and updated when it changes.
- Paddle, as merchant of record, is an independent controller for payments — its processing is governed by its own privacy policy, linked at checkout.
- We do not transfer your stored data outside the EU/EEA. If that ever had to change, we would rely on the safeguards GDPR requires and update this policy first.
8. Security
The Security page describes the full program; the commitments that belong in this policy:
- Two-factor authentication is mandatory for every account, including recipients at delivery.
- All data is encrypted in transit and at rest. Access instructions, notes, and documents carry an additional layer of per-user field-level encryption.
- Every read of customer data is written to an audit log — including reads by us. Ordinary administration cannot open your access instructions; emergency access requires a documented procedure that automatically notifies you by email.
- Independent security testing is commissioned before we accept a single payment.
- The honest limit: Legamap is not a zero-knowledge system. Our servers are technically able to decrypt your data, because automatic delivery after your death is impossible otherwise. We state this publicly instead of hiding it, and we design everything else — minimization, refusal of credentials, field-level encryption, logged access — around that fact.
If a personal data breach ever puts your rights at risk, we will notify the supervisory authority and, where GDPR requires it, you — without undue delay.
9. How long we keep data
| Data | Retention |
|---|---|
| Trial account never activated | Deleted 30 days after the trial ends (with warnings before) |
| Active and lapsed accounts | Kept while the account exists, including the delivery guarantee period after payments stop (see Terms, Section 10) |
| Closed accounts (guarantee ended) | Deleted after a 30-day grace period |
| Account you delete yourself | Removed immediately from the product; purged from backups within 30 days |
| Backups | Rolling window of up to 30 days |
| Audit logs | 3 years |
| Fingerprint of a contact who objected or asked to be erased | 12 months, then deleted. We keep a one-way fingerprint, not the address — the address itself is deleted at the moment of the objection or the erasure |
| Record of a data request you make to us | 3 years after we close it. It holds the address you wrote from, what you asked for, and the dates — never a copy of the answer we sent. We keep it to be able to show that we handled your request lawfully |
| Waitlist emails | Until the launch email is sent and the launch period ends, or until you unsubscribe — whichever comes first |
| Payment and tax records | As required by accounting and tax law |
| Submitted death certificates and case files under review | For as long as the case is open, and never beyond the end of the delivery guarantee period for that account (see Terms, Section 10). When the guarantee ends, the case is closed and the files are deleted after a 30-day grace period. Access is restricted and the files are encrypted. |
Before any deletion driven by expiry, we warn you repeatedly and send a final encrypted export, so that deletion by us never means loss to your family that you did not see coming.
10. Your rights
Under GDPR you can, at any time: access what we hold about you; rectify it; erase it; restrict or object to processing based on legitimate interest; take your data with you (portability — the encrypted export gives you everything in machine-readable form); and withdraw consent where processing rests on it, without affecting past processing.
Write to privacy@legamap.com. Every request is logged the day it arrives, and the one-month clock starts then — not when we work out who you are. We will verify it is really you: if you have an account, by asking you to sign in; if you do not, by answering to the address we already hold for you. We ask for a copy of an ID document only where we have a genuine doubt — for most requests it would mean collecting more about you than we hold. We answer within one month, extendable by two further months only where GDPR allows it for complex requests, and only if we tell you inside that first month.
You can also complain to a supervisory authority: in Lithuania, the State Data Protection Inspectorate (vdai.lrv.lt), or the authority of the EU country where you live.
These rights belong equally to recipients and trustees for the data we hold about them.
11. Cookies
The website uses cookies that are necessary for it to function (session, security, load balancing) and first-party analytics as described in Section 2. We do not use advertising cookies or third-party tracking cookies. Where consent is required for non-essential cookies, we ask for it and function fully without it.
Our analytics runs on our own servers and sets no cookies at all. It stores nothing in your browser: no cookie, no local storage entry, no identifier. Visits are counted by a salted, one-way hash of your connection details that we cannot reverse, and your IP address is used only in memory — to derive an approximate country and to compute that hash — and is never written down. Because nothing is stored on your device, this analytics needs no consent banner, and there is none.
Approximate country is derived locally from a database on our own server; your connection details are not sent anywhere for this. This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.
12. Children
Legamap is for adults. We do not knowingly process data of anyone under 18, and accounts require confirming you are of age. If you believe a minor's data has reached us, write to privacy@legamap.com and we will delete it.
13. Automated decisions
The check-in protocol runs automatically — reminders, escalations, and state changes are machine-driven. But no decision with legal or similarly significant effect is fully automated: delivery of your map always requires human confirmation (your trustee, or manual verification by us), and account-ending events are preceded by warnings and a human-reviewable trail. A data protection impact assessment for this processing is carried out before the service opens.
14. Changes to this policy
We may update this policy. For material changes we give at least 30 days' notice by email before they take effect, and the version and date at the top always tell you what you are reading.
15. Contact
MB Kocius · Company code 307051502 · VAT LT100018675617 · Lithuania, European Union Data protection: privacy@legamap.com · Support: hello@legamap.com