Legal Documentv1.1

Data Processing Agreement

How we process customer data on your instructions, and every sub-processor involved. Takes effect with your acceptance of the Terms; no signature required.

Effective: August 14, 2026

1. DEFINITIONS

1.1 Definitions

In this DPA, the following terms shall have the meanings set forth below:

"Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a Party.

"Authorized Sub-processor" means a third-party processor engaged by the Company as set forth in Annex II.

"Controller" means the entity that determines the purposes and means of processing Personal Data.

"Customer Data" means any Personal Data that the Company processes on behalf of the Customer in the course of providing the Service.

"Data Protection Laws" means all laws and regulations applicable to the processing of Personal Data under this DPA, including:

  • The General Data Protection Regulation (EU) 2016/679 ("GDPR")
  • The UK General Data Protection Regulation
  • The California Consumer Privacy Act ("CCPA")
  • Any other applicable data protection or privacy laws

"Data Subject" means the identified or identifiable natural person to whom Personal Data relates.

"EEA" means the European Economic Area.

"Personal Data" means any information relating to a Data Subject.

"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data.

"Processing" means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.

"Processor" means an entity that processes Personal Data on behalf of a Controller.

"Security Incident" means any unauthorized or unlawful breach of security leading to the destruction, loss, alteration, or disclosure of Customer Data.

"Service" means the Prosei AI legal case management platform and related services as described in the Principal Agreement.

"Standard Contractual Clauses" means the standard contractual clauses for the transfer of personal data to processors established in third countries approved by the European Commission.

"Sub-processor" means any Processor engaged by the Company to process Customer Data.


2. PROCESSING OF CUSTOMER DATA

2.1 Roles of the Parties

The Parties acknowledge and agree that:

  • The Customer is the Controller of Customer Data
  • The Company is the Processor of Customer Data
  • The Company will process Customer Data only on behalf of and in accordance with the Customer's documented instructions

2.2 Customer Instructions

The Customer instructs the Company to process Customer Data:

  • To provide the Service in accordance with the Principal Agreement
  • As initiated by Users through their use of the Service
  • To comply with other documented reasonable instructions provided by the Customer that are consistent with the Principal Agreement
  • As required by applicable law

2.3 Compliance with Laws

Each Party shall comply with its respective obligations under Data Protection Laws. The Customer shall ensure that:

  • Its instructions comply with Data Protection Laws
  • It has all necessary rights to provide Customer Data to the Company
  • The processing of Customer Data is lawful

2.4 Details of Processing

The details of processing are described in Annex I, including:

  • Subject matter and duration of processing
  • Nature and purpose of processing
  • Types of Personal Data
  • Categories of Data Subjects

3. COMPANY OBLIGATIONS

3.1 Confidentiality

The Company shall:

  • Process Customer Data only in accordance with Customer's documented instructions
  • Ensure that persons authorized to process Customer Data are subject to confidentiality obligations
  • Not disclose Customer Data to third parties except as permitted under this DPA

3.2 Security

The Company shall implement and maintain appropriate technical and organizational measures to protect Customer Data against Personal Data Breach, including the measures described in Annex III.

3.3 Sub-processors

3.3.1 Authorization

The Customer provides general authorization for the Company to engage Sub-processors to process Customer Data, subject to the requirements set forth in this Section.

3.3.2 Current Sub-processors

The Customer acknowledges and agrees to the engagement of the Sub-processors listed in Annex II.

3.3.3 New Sub-processors

The Company shall:

  • Notify the Customer of any intended addition or replacement of Sub-processors
  • Provide the Customer opportunity to object to such changes
  • Ensure Sub-processors are bound by data protection obligations no less protective than this DPA

3.3.4 Objection Right

The Customer may object to a new Sub-processor by notifying the Company within ten (10) business days of notice. If the Customer objects, the Company will use reasonable efforts to provide an alternative.

3.4 Data Subject Rights

The Company shall:

  • Provide reasonable assistance to enable the Customer to respond to Data Subject requests
  • Forward any Data Subject requests received directly to the Customer without undue delay
  • Not respond to Data Subject requests except on documented instructions from the Customer

3.5 Personal Data Breach

3.5.1 Notification

The Company shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data.

3.5.2 Information Provided

Such notification shall include:

  • Nature of the Personal Data Breach
  • Categories and approximate number of Data Subjects affected
  • Categories and approximate number of Personal Data records affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

3.5.3 Assistance

The Company shall provide reasonable assistance to the Customer in investigating and mitigating the effects of a Personal Data Breach.

3.6 Data Protection Impact Assessment

The Company shall provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities, considering the nature of processing and information available to the Company.

3.7 Deletion and Return

Upon termination of the Principal Agreement, the Company shall, at the Customer's option:

  • Delete all Customer Data
  • Return all Customer Data to the Customer
  • Provide certification of deletion

This requirement shall not apply to the extent the Company is required by applicable law to retain Customer Data.

3.8 Audit Rights

3.8.1 Information

The Company shall make available to the Customer all information necessary to demonstrate compliance with this DPA.

3.8.2 Audits

The Customer may conduct audits, including inspections, of the Company's compliance with this DPA:

  • Upon reasonable notice
  • No more than once per year (unless required by Data Protection Laws)
  • Subject to execution of appropriate confidentiality agreements
  • At the Customer's expense

3.8.3 Third-Party Audits

The Customer may use a third-party auditor, subject to the Company's approval (not to be unreasonably withheld).


4. CUSTOMER OBLIGATIONS

4.1 Lawfulness

The Customer represents and warrants that:

  • It has complied with all applicable Data Protection Laws
  • It has all necessary rights and consents to provide Customer Data to the Company
  • Its instructions to the Company comply with applicable laws

4.2 Instructions

The Customer shall:

  • Provide clear and lawful instructions for processing
  • Ensure instructions are consistent with the Principal Agreement
  • Not instruct the Company to process Customer Data in violation of Data Protection Laws

4.3 Necessary Disclosures

The Customer is responsible for:

  • Providing any required notices to Data Subjects
  • Obtaining any required consents from Data Subjects
  • Ensuring the lawfulness of transferring Customer Data to the Company

5. INTERNATIONAL DATA TRANSFERS

5.1 Transfer Mechanisms

Where the Company processes Customer Data originating from the EEA, UK, or Switzerland in a country that does not provide adequate protection:

5.1.1 Standard Contractual Clauses

The Parties agree to be bound by the Standard Contractual Clauses, which are incorporated by reference.

5.1.2 Alternative Mechanisms

The Parties may agree to alternative transfer mechanisms as recognized under Data Protection Laws.

5.2 Customer Authorization

The Customer authorizes the Company to make international transfers of Customer Data in accordance with this DPA.

5.3 Supplementary Measures

The Company implements supplementary measures to ensure adequate protection of Customer Data, including:

  • Encryption in transit and at rest
  • Access controls and authentication
  • Regular security assessments

6. LIABILITY AND INDEMNIFICATION

6.1 Liability Cap

Each Party's liability under this DPA shall be subject to the exclusions and limitations of liability set forth in the Principal Agreement.

6.2 Indemnification

Each Party shall indemnify the other against losses resulting from the indemnifying Party's violation of this DPA or Data Protection Laws.

6.3 Allocation of Liability

The Parties agree that:

  • The Customer shall be liable for its compliance with its obligations under Data Protection Laws
  • The Company shall be liable for its compliance with its obligations under this DPA

7. GENERAL PROVISIONS

7.1 Term

This DPA shall commence on the effective date of the Principal Agreement and continue for the duration of the Principal Agreement.

7.2 Termination

This DPA shall automatically terminate upon termination of the Principal Agreement.

7.3 Governing Law

This DPA shall be governed by the laws specified in the Principal Agreement, except where Data Protection Laws require otherwise.

7.4 Amendment

This DPA may only be amended by written agreement of both Parties, except that the Company may update the Sub-processor list in accordance with Section 3.3.

7.5 Severability

If any provision of this DPA is held invalid, the remaining provisions shall continue in full force and effect.

7.6 Entire Agreement

This DPA, including its Annexes, constitutes the entire agreement between the Parties regarding the processing of Customer Data.

7.7 Hierarchy

In case of conflict:

  • Data Protection Laws prevail over this DPA
  • This DPA prevails over the Principal Agreement with respect to processing of Customer Data

ANNEX I: DETAILS OF PROCESSING

A.1 Subject Matter

The processing of Personal Data as necessary to provide the Prosei AI legal case management platform and related services.

A.2 Duration

The duration of the Principal Agreement plus the period until deletion of all Customer Data in accordance with this DPA.

A.3 Nature and Purpose of Processing

  • Nature: Collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, and destruction.

  • Purpose: Provision of legal case management services including:

    • Case and document management
    • Deadline tracking
    • Party management
    • AI-powered document analysis (if enabled)
    • Motion drafting assistance
    • Legal research assistance

A.4 Types of Personal Data

  • Identity data (names, usernames)
  • Contact data (email addresses, phone numbers)
  • Case information (case titles, numbers, descriptions)
  • Document content (legal documents, pleadings, correspondence)
  • Party information (names, roles, contact details)
  • Usage data (access logs, feature usage)
  • Technical data (IP addresses, browser information)

A.5 Categories of Data Subjects

  • Customers (users of the Service)
  • Customer's clients (if applicable)
  • Parties to legal proceedings
  • Attorneys and legal representatives
  • Witnesses and other case participants
  • Customer's employees or agents

A.6 Sensitive Data

Customer Data may include:

  • Legal case information
  • Court documents
  • Information about legal disputes
  • Potentially privileged communications

ANNEX II: AUTHORIZED SUB-PROCESSORS

Current Sub-processors

Sub-processorPurposeLocationWebsite
Google LLC (Firebase, Cloud Storage, Cloud Run)Infrastructure, authentication, database, file storage, and document format conversionUnited Statescloud.google.com
Vercel Inc.Application hosting and deliveryUnited Statesvercel.com
Anthropic, PBCAI processing of document text to produce summaries, answers, and draftsUnited Statesanthropic.com
Voyage AIConverts document text into numeric embeddings for semantic searchUnited Statesvoyageai.com
Supabase, Inc.Stores those embeddingsUnited Statessupabase.com
Stripe, Inc.Payment processingUnited Statesstripe.com
ResendTransactional email deliveryUnited Statesresend.com
PostHog, Inc.Product analyticsUnited Statesposthog.com
Functional Software, Inc. (Sentry)Application error monitoringUnited Statessentry.io
InfoTrack US, Inc.Court e-filing transmission, engaged only when the Customer files a documentUnited Statesinfotrack.com

Of these, Google, Vercel, Anthropic, Voyage AI, Supabase, and InfoTrack may process Customer Data content. Stripe, Resend, PostHog, and Sentry receive account and diagnostic data only.

Sub-processor Updates

For the current list of Sub-processors, visit: https://www.prosei.ai/security

Notification of changes will be provided via:

  • Email to Customer's registered address
  • In-application notification
  • Update to the above URL

ANNEX III: TECHNICAL AND ORGANIZATIONAL MEASURES

A. Technical Measures

A.1 Encryption

  • Encryption in transit: TLS 1.2 or higher
  • Encryption at rest: AES-256
  • Key management: Industry-standard key management practices

A.2 Access Control

  • Multi-factor authentication available
  • Role-based access control (RBAC)
  • Principle of least privilege
  • Regular access reviews

A.3 System Security

  • Firewalls and network segmentation
  • Intrusion detection and prevention systems
  • Regular security updates and patches
  • Vulnerability scanning and penetration testing

A.4 Data Security

  • Data minimization practices
  • Pseudonymization where appropriate
  • Secure deletion procedures
  • Backup and recovery procedures

B. Organizational Measures

B.1 Personnel

  • Background checks for employees with data access
  • Confidentiality agreements
  • Regular privacy and security training
  • Clear data handling procedures

B.2 Incident Management

  • Incident response plan
  • Breach notification procedures
  • Regular incident response testing
  • Post-incident reviews

B.3 Vendor Management

  • Security assessment of Sub-processors
  • Contractual security requirements
  • Regular vendor reviews
  • Data processing agreements

B.4 Physical Security

  • Secure data center facilities
  • Access controls and monitoring
  • Environmental controls
  • Secure disposal of media

C. Compliance Measures

C.1 Policies and Procedures

  • Information security policy
  • Privacy policy
  • Data retention policy
  • Acceptable use policy

C.2 Monitoring and Audit

  • Security monitoring and logging
  • Regular internal audits
  • Third-party security assessments
  • Compliance reviews

C.3 Business Continuity

  • Business continuity plan
  • Disaster recovery procedures
  • Regular backup testing
  • Redundancy and failover capabilities

ANNEX IV: STANDARD CONTRACTUAL CLAUSES

[If applicable, attach or incorporate by reference the appropriate Standard Contractual Clauses for international data transfers]


EXECUTION

This Data Processing Agreement is incorporated into, and forms part of, the Principal Agreement. By accepting the Principal Agreement, the Customer agrees to be bound by it. No signature is required for it to take effect.

If your organisation requires a countersigned copy for its own records, email legal@prosei.ai and we will provide one.


Copyright © 2026 Prosei AI LLC. All rights reserved.