Data Processing Agreement
Last updated: March 15, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Legalithm ("Processor") and the customer ("Controller") for the processing of personal data in connection with the Legalithm platform and services.
This DPA is entered into pursuant to Article 28 of the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).
1. Scope of Processing
1.1 Subject Matter
The Processor processes personal data on behalf of the Controller to provide compliance scanning, AI-powered risk classification, consent management, cookie scanning, and related analytics services.
1.2 Duration
Processing shall continue for the duration of the service agreement and for any retention period required by law or as specified in our Privacy Policy.
1.3 Categories of Data Subjects
- Controller's employees and authorized users
- Controller's website visitors (consent data only)
- Data subjects whose personal data is included in scanned websites or documents
1.4 Types of Personal Data
- Account information (name, email, organization)
- Website URLs and scan results
- Cookie identifiers and consent preferences
- AI system descriptions and compliance assessments
- Usage logs and analytics data
2. Obligations of the Processor
- Process personal data only on documented instructions from the Controller, unless required by EU or Member State law.
- Ensure that persons authorized to process personal data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk (see Section 5).
- Assist the Controller in fulfilling its obligation to respond to data subject requests (see Section 4).
- Delete or return all personal data to the Controller after the end of the provision of services, at the Controller's choice, and delete existing copies unless EU or Member State law requires storage.
- Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR.
3. Sub-processors
The Processor engages the following sub-processors for the provision of the Service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase (EU) | Database, authentication, storage | Frankfurt, Germany (EU) |
| Vercel | Application hosting, CDN | EU region |
| PostHog (EU) | Product analytics | Frankfurt, Germany (EU) |
| Resend | Transactional email | US (SCCs in place) |
| OpenAI | AI risk classification (zero data retention) | US (SCCs + zero retention) |
| Sentry | Error monitoring | EU region |
The Processor shall inform the Controller of any intended changes to sub-processors, giving the Controller the opportunity to object within 14 days.
The operational list is maintained at /legal/subprocessors.
4. Data Subject Rights
The Processor shall assist the Controller in responding to requests from data subjects exercising their rights under GDPR, including:
- Right of access (Article 15)
- Right to rectification (Article 16)
- Right to erasure (Article 17)
- Right to restriction of processing (Article 18)
- Right to data portability (Article 20)
- Right to object (Article 21)
The Processor shall respond to data subject requests forwarded by the Controller within 72 hours.
5. Security Measures
The Processor implements the following technical and organizational measures:
Technical Measures
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest
- Row-level security (RLS) for multi-tenant data isolation
- Multi-factor authentication support
- Automated vulnerability scanning and dependency monitoring
- Regular security updates and patching
Organizational Measures
- Access control on a need-to-know basis
- Confidentiality obligations for all personnel
- Regular security reviews and code audits
- Incident response procedures
- Data protection impact assessments where required
6. Data Breach Notification
In the event of a personal data breach, the Processor shall notify the Controller without undue delay and no later than 48 hours after becoming aware of the breach. The notification shall include:
- Description of the nature of the breach
- Categories and approximate number of data subjects affected
- Likely consequences of the breach
- Measures taken or proposed to address the breach
7. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), the Processor ensures appropriate safeguards are in place, including:
- EU Standard Contractual Clauses (SCCs) with all non-EU sub-processors
- Transfer Impact Assessments (TIAs) for each non-EU sub-processor
- Preference for EU-hosted services wherever possible
8. Audit Rights
The Controller or a mandated third-party auditor may conduct audits to verify the Processor's compliance with this DPA. Audits shall be conducted with reasonable notice (minimum 30 days) and during normal business hours. The Processor shall cooperate fully and make relevant documentation available.
9. Governing Law
This DPA shall be governed by and construed in accordance with the laws of the European Union and the applicable national laws of the Netherlands.
10. Contact
For questions about this DPA or to exercise your rights, please contact:
Pedram MadaniData Protection Contact
Legalithm
Email: pedram@legalithm.com