1. Parties & Scope
This Data Processing Agreement ("DPA") is entered into between the subscribing law firm ("Controller") and neoLEGAL AI ("Processor"), and governs Processor's handling of Personal Data on behalf of Controller in connection with the neoLEGAL AI platform ("Services").
2. Roles
Controller is the data controller of Personal Data of its clients, prospective clients, employees, and website visitors. Processor acts solely as data processor and processes Personal Data only on Controller's documented instructions, including as set out in this DPA and Controller's use of the Services.
3. Categories of Data & Data Subjects
- Prospective clients: name, phone, email, county, matter description, intake transcript.
- Firm users: name, email, role, authentication metadata.
- Uploaded documents: any file Controller uploads to the Documents module.
4. Subprocessors
Processor uses the following subprocessors:
- Supabase, Inc. — managed Postgres, authentication, object storage. US region.
- Cloudflare, Inc. — edge compute, CDN, DDoS mitigation.
- Google Cloud (Gemini) — LLM inference for intake conversations. No training on Controller data.
- Stripe, Inc. — payment processing. Processor does not store card numbers.
- Resend — transactional email delivery.
- Twilio (optional add-on) — SMS delivery.
Processor will provide 30 days' notice before adding or replacing a subprocessor. Controller may object in writing; if the parties cannot agree on a resolution, Controller may terminate the Services with a prorated refund of prepaid fees for unused periods.
5. Security Measures
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Row-Level Security isolating every firm's data by
firm_id. - Least-privilege service accounts; secrets stored in an isolated key store.
- Rate limiting on public intake endpoints.
- Automated database backups retained by the managed Postgres provider.
- Optional MFA for firm owner accounts.
6. Confidentiality
Processor personnel with access to Personal Data are bound by written confidentiality obligations. Access is limited to what is necessary to operate and support the Services.
7. Data Subject Requests
Processor will, taking into account the nature of the processing, assist Controller in responding to data-subject requests (access, rectification, erasure, portability) within 10 business days of Controller's written request.
8. Security Incident Notification
Processor will notify Controller without undue delay, and no later than 72 hours after becoming aware, of any confirmed security incident involving Controller's Personal Data, along with known facts and mitigation steps.
9. Data Retention & Deletion
On subscription cancellation, Controller's data remains available in read/export mode for 40 days. After 40 days, all Personal Data (leads, intakes, documents, calendar, KB, usage logs) is permanently deleted by an automated purge job. Prospective-client PII on rejected/conflicted leads older than 90 days is redacted automatically to comply with Florida Bar Rule 4-1.18 prospective-client retention.
10. International Transfers
Personal Data is stored in the United States. Controllers whose data subjects are located outside the US should evaluate this posture and rely on Standard Contractual Clauses (SCCs) where required. Processor will execute SCCs on request at no additional cost.
11. Audit
Controller may request, no more than once per calendar year, a written summary of Processor's security posture, incident history, and subprocessor list. Physical audits are available on 60 days' notice at Controller's expense.
12. Term & Termination
This DPA takes effect on the date Controller accepts these terms (by subscribing) and remains in force for the duration of the Services. Deletion obligations survive termination.
13. Contact
For DPA-related requests, security incidents, or subprocessor objections, contact legal@neolegalai.com.