Privacy policy
Last updated: 27 August 2026
Lexoperia is operated by Shopery S.A.C. (RUC 20610085297), Lima, Peru.
1. Information we collect
We collect information you provide directly: name, email, law firm information and billing details. If you connect State portals, we also collect your firm's access credentials for those portals and, where the Judiciary requires it, the identity-document data of the person making the query: document type and number, verification code, issue date and date of birth. Both categories are described in detail in sections 8 and 9. We also automatically collect service usage information, IP address and device data.
2. How we use your information
We use your information to provide and improve the service, process payments, send service communications and comply with legal obligations. We do not sell your personal information to third parties.
3. Your clients' data
Your clients' data entered into Lexoperia belongs to you. Your firm is the owner (titular) of its clients' personal data bank and we act as processor (encargado de tratamiento) on your behalf, under Law No. 29733 and its Regulation. We do not access that data except to provide the service or when required by law.
4. Processors (service providers)
To operate the service we share data, to the minimum extent necessary, with providers acting as processors under confidentiality agreements: application hosting (Vercel), database (Neon), judicial sync-service infrastructure (Hetzner), email delivery, and payment processing. For automated CEJ lookups we use third-party technical services (an outbound proxy in Peru and a captcha-solving service) that sit in the connection to the portal: the case number and party you enter travel over that connection and, when CEJ requires identity validation, so does the data described in section 9. We do not share data with third parties for marketing or advertising.
5. International data transfer
Some of our processors (for example, Vercel, Neon, Hetzner, our email and payment-processing providers, and the technical services described in section 4) may store or process information on servers located outside Peru. These international transfers are carried out under adequate safeguards and confidentiality and data-processing agreements that require a level of protection consistent with Law No. 29733 and its Regulation. By using the service, you are informed of this cross-border data flow.
6. Third-party integrations (Google and Microsoft)
If you connect your Google or Microsoft calendar, Lexoperia requests only the permission needed to manage calendar events (Google: the «calendar.events» scope) in order to create and sync your cases' hearings, deadlines and reminders to your calendar. We access and store only the data strictly necessary for this feature, keep it encrypted, and never sell it, share it with third parties, or use it for advertising or to train artificial-intelligence models. You can revoke access at any time from Settings → Integrations or from your Google/Microsoft account. Lexoperia's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Judicial sync (CEJ / Judiciary)
For case synchronization we query public information from Peru's Judiciary case-lookup portal (Consulta de Expedientes Judiciales, CEJ) using the case number and party you provide; that information is public and is added to your account solely for your management. CEJ uses no username or password, but since 2026 it requires validating the identity of the person querying before it will run the search (section 9). For the other State portals you connect — the Judiciary's SINOE mailbox, INDECOPI, SUNARP and SUNAT — the service does sign in on your firm's behalf with the credentials you register, and retrieves the notifications and filings addressed to it (section 8).
8. State portal credentials
If you connect a State portal — the Judiciary's SINOE mailbox, INDECOPI's Casilla Virtual, SUNARP's Casilla Electrónica and Publicidad Registral en Línea (SPRL), or SUNAT's Clave SOL — we store the username and password your firm registers for a single purpose: signing in on your behalf to retrieve your notifications, filings and documents from that portal. Passwords are encrypted at rest with AES-256-GCM and are never shown back in the interface: the screen only indicates whether a password is stored. They are decrypted only inside our sync service, at the moment of accessing the portal, and are not recorded in the audit log, which registers only which connectors are configured. Within your organization, only its administrators can register or modify them. You can update them, remove the connection or turn off automatic sync at any time from Settings → Integrations; if you also want us to delete a stored credential, write to privacidad@lexoperia.com.
9. Identity validation before the Judiciary
Since 2026 CEJ interposes an identity validation before running a query: without it, the cases the portal blocks return no acts at all. If your firm chooses to complete it, we store the document type and number of the person querying, its verification code, its issue date and their date of birth, for the sole purpose of proving to the Judiciary who is making the query, exactly as that portal now requires; we do not use them for any other purpose and do not transfer them to third parties. The number, the verification code and both dates are individually encrypted at rest, are never shown again in the interface — only whether they are configured — are not written to the service's logs or to the audit log, and are transmitted only to the Judiciary's own validation form, over the connection described in section 4. Where that data does not belong to the person entering it, your firm is responsible for holding its owner's authorization. You can delete it from the system at any time from Settings → Integrations, using the «Delete the stored data» checkbox.
10. Opportunity radar (SEACE)
If your plan includes the radar and you activate a search, we query the public portal of Peru's State procurement system (Sistema Electrónico de Contrataciones del Estado, SEACE) with the keywords and filters your firm saves, and we store the results to show them to you and alert you when a tender advances. What is stored are public tenders — reference, contracting entity, object, reference value, dates and stage: public information about State entities, not personal data about your clients. The tender catalog is therefore common to the platform; what belongs to your organization are your saved searches and your decisions on each opportunity, and those are not shared with other firms. This query is run by our own sync service, without the third-party technical intermediaries in section 4.
11. Security
We implement technical and organizational security measures to protect your information. We use AES-256 encryption at rest and TLS in transit. We conduct periodic security reviews.
12. Security incident notification
If we detect a security breach affecting your personal data or that of your clients, we will take measures to contain it and, where required under Law No. 29733 and its Regulation, we will notify affected users and the National Authority for the Protection of Personal Data without undue delay, describing the nature of the incident and the measures taken.
13. Data retention
We retain your information while your account is active and for as long as necessary to provide the service. State portal credentials are kept until you replace them or ask us to delete them; CEJ identity-validation data, until you delete it yourself (sections 8 and 9). After an account is closed, we keep data only for the periods required by applicable legal, accounting and tax obligations, or to handle claims; once those periods lapse, we securely delete or anonymize it. You can request deletion of your account and data at any time, except for what the law requires us to retain.
14. Your rights and how to exercise them (ARCO)
Under Law No. 29733 and its Regulation, you have the right to access your personal data, rectify it, delete (cancel) it and object to its processing (ARCO rights), as well as data portability. To exercise them, email privacidad@lexoperia.com stating the right you wish to exercise, your full name and identifying details, and the specifics of your request; we may ask you to verify your identity. We will respond within the timeframes set by the applicable rules (currently up to twenty business days for access and up to ten business days for rectification, cancellation or objection, counted from receipt of a complete request). If you are not satisfied with our response, you may contact the National Authority for the Protection of Personal Data.
15. Personal data bank registration
The personal data we process is organized into personal data banks. Shopery S.A.C. will register those data banks with the National Authority for the Protection of Personal Data of the Ministry of Justice and Human Rights (MINJUSDH), in accordance with Law No. 29733 and its Regulation.
16. Minors
The service is aimed at law firms, lawyers and professionals, not at minors. We do not knowingly collect personal data from children or adolescents. If we become aware that we have collected a minor's data without the appropriate authorization, we will delete it.
17. Cookies
We use essential cookies for service operation (authentication, preferences). We do not use third-party tracking cookies for advertising. See our Cookie Policy for details.
18. Changes to this policy
We may update this policy periodically. We will notify you by email about significant changes. Continued use of the service after changes constitutes acceptance of the new policy.
19. Contact
For privacy questions, contact us at: privacidad@lexoperia.com. Data controller: Shopery S.A.C. (RUC 20610085297), Lima, Peru.