← Trust & Security

Data Processing Agreement

Last updated: November 1, 2025

1. Parties & Scope

This Data Processing Agreement ("DPA") is entered into between the subscribing law firm ("Controller") and neoLEGAL AI ("Processor"), and governs Processor's handling of Personal Data on behalf of Controller in connection with the neoLEGAL AI platform ("Services").

2. Roles

Controller is the data controller of Personal Data of its clients, prospective clients, employees, and website visitors. Processor acts solely as data processor and processes Personal Data only on Controller's documented instructions, including as set out in this DPA and Controller's use of the Services.

3. Categories of Data & Data Subjects

4. Subprocessors

Processor uses the following subprocessors:

Processor will provide 30 days' notice before adding or replacing a subprocessor. Controller may object in writing; if the parties cannot agree on a resolution, Controller may terminate the Services with a prorated refund of prepaid fees for unused periods.

5. Security Measures

6. Confidentiality

Processor personnel with access to Personal Data are bound by written confidentiality obligations. Access is limited to what is necessary to operate and support the Services.

7. Data Subject Requests

Processor will, taking into account the nature of the processing, assist Controller in responding to data-subject requests (access, rectification, erasure, portability) within 10 business days of Controller's written request.

8. Security Incident Notification

Processor will notify Controller without undue delay, and no later than 72 hours after becoming aware, of any confirmed security incident involving Controller's Personal Data, along with known facts and mitigation steps.

9. Data Retention & Deletion

On subscription cancellation, Controller's data remains available in read/export mode for 40 days. After 40 days, all Personal Data (leads, intakes, documents, calendar, KB, usage logs) is permanently deleted by an automated purge job. Prospective-client PII on rejected/conflicted leads older than 90 days is redacted automatically to comply with Florida Bar Rule 4-1.18 prospective-client retention.

10. International Transfers

Personal Data is stored in the United States. Controllers whose data subjects are located outside the US should evaluate this posture and rely on Standard Contractual Clauses (SCCs) where required. Processor will execute SCCs on request at no additional cost.

11. Audit

Controller may request, no more than once per calendar year, a written summary of Processor's security posture, incident history, and subprocessor list. Physical audits are available on 60 days' notice at Controller's expense.

12. Term & Termination

This DPA takes effect on the date Controller accepts these terms (by subscribing) and remains in force for the duration of the Services. Deletion obligations survive termination.

13. Contact

For DPA-related requests, security incidents, or subprocessor objections, contact legal@neolegalai.com.

This DPA is provided as a good-faith template and does not constitute legal advice. Controllers should have counsel review this document against their own compliance obligations.