Data Processing Agreement
Last updated:
This agreement forms part of the Terms of Service and is accepted together with them at signup. It governs how we process the client data your firm uploads to the product. If we have also signed a negotiated agreement, that one prevails in a conflict.
1. Parties and roles
In this agreement “the firm” means the organisation using the service, and “we” means the business identified at the foot of this page.
For the files, filings, client information and assistant prompts your firm uploads, the firm is the controller and we are the processor. For account signup, billing, support, security logs and product usage measurement we are the controller, and that processing is governed by the Privacy Policy.
This agreement covers only the first group: customer content.
2. Subject matter and duration
The subject matter is the provision of the service: search, the legal research assistant, drafting, matter management, and the storage, text extraction, indexing and model inference those require.
The categories of personal data are determined by what your firm chooses to upload. Typically these are the identity and contact details of clients and opposing parties, matter and case information, and the contents of uploaded documents. The categories of data subject are your firm’s clients, opposing parties and third parties named in a matter.
Processing continues while your account is open and ends as described in clause 8.
3. Instructions
We process customer content only on the firm’s documented instructions. The Terms of Service, this agreement and the firm’s use of the product together constitute those instructions.
If we consider an instruction to infringe data protection law, we tell you without undue delay.
We do not use customer content for our own purposes. We do not use it to train, fine-tune or evaluate any AI model. We do not use it to serve any other customer, and we do not sell it.
If law compels us to process, we notify you first unless that notice is itself prohibited.
4. Confidentiality
Access to customer content is limited to people who need it to do their work, and every one of them is under a written confidentiality obligation.
That obligation survives the end of their engagement.
5. Security measures
We implement and maintain technical and organisational measures appropriate to the risk. The measures in place are set out on the Security page, which forms part of this agreement.
In summary: TLS in transit; encryption at rest applied by the storage provider in the object storage holding uploaded files; database backups encrypted before they leave the server; role-based access; and a tenant and matter boundary enforced server side that no client-supplied parameter can widen.
The server running the application has no disk-level encryption, and we hold no security certification. We state both here as well as on the Security page.
6. Subprocessors
The firm gives general authorisation for the subprocessors listed in the Privacy Policy, each with its function and the country it operates in.
We enter a written data protection agreement with every subprocessor on terms no less protective than this one, and we remain liable to the firm for their compliance.
Before we add or replace a subprocessor we give at least thirty days’ notice to your account email address. To object, write to us within ten days of that notice. If we cannot reach a reasonable resolution, you may stop using the affected service and terminate that part of the agreement.
7. Data subject requests and breach notification
If a data subject contacts us directly, we do not answer them; we pass the request to the firm without undue delay. Answering it is the firm’s decision as controller.
We support you in meeting requests for access, correction, erasure, restriction, objection and portability through the product’s own functions and, where needed, reasonable technical assistance.
If we become aware of a security breach affecting customer content, we notify the firm without undue delay and in any event within seventy-two hours. The notice covers what is known at the time: the nature of the breach, the categories of data affected, the likely consequences and the measures taken. We update it as the investigation proceeds.
We give the firm reasonable assistance with notifications to a supervisory authority and to data subjects, with data protection impact assessments, and with any prior consultation.
8. Audit, return and deletion
We make available on request the information needed to demonstrate compliance with this agreement. The firm may commission an independent audit at its own expense, no more than once a year and on reasonable notice; that limit does not apply following a security breach.
You may close your account at any time, and you can export your data before closing.
On closure, your uploaded originals are deleted from object storage at once and irreversibly; because those files are never backed up, no other copy remains. Your database records leave the encrypted backups within thirty days. If the deletion chain cannot complete, it stops rather than leaving a half-deleted state.
9. International transfers
The application, its database and your uploaded files are held in the European Union. The AI features are the exception: text sent to them goes to our subprocessor in the United States for model inference. Clause 11 of the Terms has the detail.
That transfer rests on the data processing agreement between us and the subprocessor, and on the European Commission standard contractual clauses incorporated into it.
For transfers from Türkiye, we sign the controller-to-processor standard contract with the firm under Article 9 of Law No. 6698. The Board publishes that text and neither party may vary it; it is obtained from standartsozlesme.kvkk.gov.tr. We return a signed copy on request. Notifying the Authority within five business days of signature is the firm’s obligation as the transferring party unless the contract assigns it otherwise, and we supply the information you need to make that filing.
10. Special category data
Before sending files containing health, criminal conviction, biometric or comparable special category data to the AI features, you need our written agreement. Our subprocessor’s terms do not cover those categories by default.
This restriction concerns the AI features. It places no separate limit on uploading and storing documents in the product.
11. Term and conflict
This agreement remains in force while you use the service and ends when customer content has been deleted.
Where this agreement and the Terms of Service conflict on the processing of customer content, this agreement governs. A negotiated agreement signed between the parties takes precedence over both.