Data Processing Agreement

Last updated: March 15, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Legalithm ("Processor") and the customer ("Controller") for the processing of personal data in connection with the Legalithm platform and services.

This DPA is entered into pursuant to Article 28 of the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).

1. Scope of Processing

1.1 Subject Matter

The Processor processes personal data on behalf of the Controller to provide compliance scanning, AI-powered risk classification, consent management, cookie scanning, and related analytics services.

1.2 Duration

Processing shall continue for the duration of the service agreement and for any retention period required by law or as specified in our Privacy Policy.

1.3 Categories of Data Subjects

  • Controller's employees and authorized users
  • Controller's website visitors (consent data only)
  • Data subjects whose personal data is included in scanned websites or documents

1.4 Types of Personal Data

  • Account information (name, email, organization)
  • Website URLs and scan results
  • Cookie identifiers and consent preferences
  • AI system descriptions and compliance assessments
  • Usage logs and analytics data

2. Obligations of the Processor

  • Process personal data only on documented instructions from the Controller, unless required by EU or Member State law.
  • Ensure that persons authorized to process personal data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk (see Section 5).
  • Assist the Controller in fulfilling its obligation to respond to data subject requests (see Section 4).
  • Delete or return all personal data to the Controller after the end of the provision of services, at the Controller's choice, and delete existing copies unless EU or Member State law requires storage.
  • Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR.

3. Sub-processors

The Processor engages the following sub-processors for the provision of the Service:

Sub-processorPurposeLocation
Supabase (EU)Database, authentication, storageFrankfurt, Germany (EU)
VercelApplication hosting, CDNEU region
PostHog (EU)Product analyticsFrankfurt, Germany (EU)
ResendTransactional emailUS (SCCs in place)
OpenAIAI risk classification (zero data retention)US (SCCs + zero retention)
SentryError monitoringEU region

The Processor shall inform the Controller of any intended changes to sub-processors, giving the Controller the opportunity to object within 14 days.

The operational list is maintained at /legal/subprocessors.

4. Data Subject Rights

The Processor shall assist the Controller in responding to requests from data subjects exercising their rights under GDPR, including:

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object (Article 21)

The Processor shall respond to data subject requests forwarded by the Controller within 72 hours.

5. Security Measures

The Processor implements the following technical and organizational measures:

Technical Measures

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for data at rest
  • Row-level security (RLS) for multi-tenant data isolation
  • Multi-factor authentication support
  • Automated vulnerability scanning and dependency monitoring
  • Regular security updates and patching

Organizational Measures

  • Access control on a need-to-know basis
  • Confidentiality obligations for all personnel
  • Regular security reviews and code audits
  • Incident response procedures
  • Data protection impact assessments where required

6. Data Breach Notification

In the event of a personal data breach, the Processor shall notify the Controller without undue delay and no later than 48 hours after becoming aware of the breach. The notification shall include:

  • Description of the nature of the breach
  • Categories and approximate number of data subjects affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

7. International Data Transfers

Where personal data is transferred outside the European Economic Area (EEA), the Processor ensures appropriate safeguards are in place, including:

  • EU Standard Contractual Clauses (SCCs) with all non-EU sub-processors
  • Transfer Impact Assessments (TIAs) for each non-EU sub-processor
  • Preference for EU-hosted services wherever possible

8. Audit Rights

The Controller or a mandated third-party auditor may conduct audits to verify the Processor's compliance with this DPA. Audits shall be conducted with reasonable notice (minimum 30 days) and during normal business hours. The Processor shall cooperate fully and make relevant documentation available.

9. Governing Law

This DPA shall be governed by and construed in accordance with the laws of the European Union and the applicable national laws of the Netherlands.

10. Contact

For questions about this DPA or to exercise your rights, please contact:

Pedram Madani
Data Protection Contact
Legalithm
Email: pedram@legalithm.com