Legal
Data Processing Addendum
Last updated: 10 July 2026
1. Overview
This Data Processing Addendum ("DPA") forms part of the agreement between LawDep ("Processor") and the subscribing organization ("Controller") for the processing of personal data in connection with the Service. This DPA reflects the requirements of the EU General Data Protection Regulation (GDPR) and India’s Digital Personal Data Protection Act 2023 (DPDP Act).
2. Roles and scope
The Controller determines the purposes and means of processing. The Processor processes personal data only on documented instructions from the Controller, and only for the purposes of providing the Service.
3. Details of processing
Categories of data subjects: the Controller’s employees, contractors, counterparties, and other individuals whose personal data appears in documents stored in the Service.
Categories of personal data: names, email addresses, signatures, and any personal data contained within uploaded documents, contracts, and records.
Processing operations: storage, retrieval, organization, structuring, and transmission to LLM providers for the generation of AI output on the Controller’s instruction.
4. Processor obligations
The Processor shall: (a) process personal data only on documented instructions; (b) ensure persons authorized to process the data have committed to confidentiality; (c) implement appropriate technical and organizational measures; (d) assist the Controller in meeting its obligations regarding data subject rights; and (e) notify the Controller of personal data breaches without undue delay.
5. Sub-processors
The Processor may engage sub-processors (including hosting and LLM providers). The current list of sub-processors is available on request. The Controller may object to changes on reasonable grounds.
6. International transfers
Personal data is hosted in the region selected during onboarding (US, EU, or India). Where transfers outside the EEA occur, the Processor relies on appropriate safeguards including standard contractual clauses.
7. Data subject rights
The Processor shall provide reasonable assistance to the Controller in responding to requests from data subjects to exercise their rights under applicable law.
8. Security measures
The Processor maintains technical and organizational measures including encryption in transit and at rest, access controls, authentication with lockout, and organization-level data isolation. These measures are described in more detail in the Security section of the Service’s architecture documentation.
9. Deletion and return
Upon termination of the Service, the Processor shall, at the Controller’s election, delete or return all personal data, unless retention is required by law. Standard deletion timelines apply as set out in the Terms of Service.
10. Contact
DPA inquiries: privacy@lawdep.com