Legal

Data Processing Addendum

Last updated: 10 July 2026

1. Overview

This Data Processing Addendum ("DPA") forms part of the agreement between LawDep ("Processor") and the subscribing organization ("Controller") for the processing of personal data in connection with the Service. This DPA reflects the requirements of the EU General Data Protection Regulation (GDPR) and India’s Digital Personal Data Protection Act 2023 (DPDP Act).

2. Roles and scope

The Controller determines the purposes and means of processing. The Processor processes personal data only on documented instructions from the Controller, and only for the purposes of providing the Service.

3. Details of processing

Categories of data subjects: the Controller’s employees, contractors, counterparties, and other individuals whose personal data appears in documents stored in the Service.

Categories of personal data: names, email addresses, signatures, and any personal data contained within uploaded documents, contracts, and records.

Processing operations: storage, retrieval, organization, structuring, and transmission to LLM providers for the generation of AI output on the Controller’s instruction.

4. Processor obligations

The Processor shall: (a) process personal data only on documented instructions; (b) ensure persons authorized to process the data have committed to confidentiality; (c) implement appropriate technical and organizational measures; (d) assist the Controller in meeting its obligations regarding data subject rights; and (e) notify the Controller of personal data breaches without undue delay.

5. Sub-processors

The Processor may engage sub-processors (including hosting and LLM providers). The current list of sub-processors is available on request. The Controller may object to changes on reasonable grounds.

6. International transfers

Personal data is hosted in the region selected during onboarding (US, EU, or India). Where transfers outside the EEA occur, the Processor relies on appropriate safeguards including standard contractual clauses.

7. Data subject rights

The Processor shall provide reasonable assistance to the Controller in responding to requests from data subjects to exercise their rights under applicable law.

8. Security measures

The Processor maintains technical and organizational measures including encryption in transit and at rest, access controls, authentication with lockout, and organization-level data isolation. These measures are described in more detail in the Security section of the Service’s architecture documentation.

9. Deletion and return

Upon termination of the Service, the Processor shall, at the Controller’s election, delete or return all personal data, unless retention is required by law. Standard deletion timelines apply as set out in the Terms of Service.

10. Contact

DPA inquiries: privacy@lawdep.com