Parties
This Data Processing Agreement ("DPA") is entered into between:
- Data Controller: The entity or individual that executes an Order Form or accesses the LegisGate™ Service (referred to as "Customer" or "Controller"); and
- Data Processor: LegisGate™ Inc., a corporation organized under the laws of the State of Delaware, with its principal place of business in the United States ("LegisGate™" or "Processor").
This DPA forms part of and is incorporated into the LegisGate™ Terms of Service or other written agreement between the parties governing Customer's use of the LegisGate™ platform (the "Agreement"). In case of conflict between this DPA and the Agreement on data protection matters, this DPA controls.
1. Definitions
In this DPA, the following terms have the meanings set out below, and capitalized terms not defined herein have the meanings given to them in the Agreement:
- "Applicable Data Protection Law"
- means all applicable privacy and data protection laws and regulations, including (to the extent applicable): the EU General Data Protection Regulation 2016/679 (GDPR); the UK General Data Protection Regulation and UK Data Protection Act 2018 (UK GDPR); the Swiss Federal Act on Data Protection as revised (revFADP); and any other applicable national or regional data protection law.
- "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Supervisory Authority"
- have the meanings given in the GDPR.
- "Personal Data Breach"
- means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed by LegisGate™.
- "SCCs"
- means the Standard Contractual Clauses for the transfer of Personal Data to third countries pursuant to the GDPR, as approved by the European Commission (Decision 2021/914, June 4, 2021).
- "Sub-processor"
- means any third-party processor engaged by LegisGate™ to process Personal Data on behalf of Customer.
- "Services"
- means the LegisGate™ platform, APIs, and related services provided to Customer under the Agreement.
2. Scope and Roles
2.1 This DPA applies to the Processing of Personal Data by LegisGate™ on behalf of Customer in connection with the provision of the Services.
2.2 The parties acknowledge that, with regard to the Processing of Personal Data described in Annex I, Customer acts as the Controller and LegisGate™ acts as the Processor. LegisGate™ will process Personal Data only on documented instructions from Customer, including with regard to transfers of Personal Data to a third country, unless required to do so by applicable law.
2.3 If LegisGate™ is required by applicable law to process Personal Data for its own purposes, it shall separately inform Customer of that legal requirement before processing, to the extent that law does not prohibit such notification.
3. Processing Instructions
3.1 LegisGate™ shall process Personal Data only on Customer's documented instructions. Customer's instructions are: (a) as set out in this DPA; (b) as set out in the Agreement; and (c) as otherwise provided by Customer in writing from time to time, including through Customer's configuration of the Services.
3.2 LegisGate™ shall promptly inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. In such case, LegisGate™ is entitled to refrain from processing until Customer provides a lawful instruction.
3.3 LegisGate™ shall not process Personal Data for any purpose other than the provision of the Services, unless required to do so by applicable law, in which case LegisGate™ shall inform Customer before such processing unless legally prohibited from doing so.
4. Confidentiality
4.1 LegisGate™ shall ensure that persons authorized to process Personal Data are subject to a binding obligation of confidentiality, or are under an appropriate statutory obligation of confidentiality, with respect to Personal Data.
4.2 LegisGate™ shall ensure that access to Personal Data is limited to those personnel who require access for the purposes of providing the Services.
5. Security of Processing
5.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, LegisGate™ shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including at a minimum the measures set out in Annex II.
5.2 LegisGate™ shall assess the appropriate level of security taking into account, in particular, the risks that Processing presents, including in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
5.3 Customer is responsible for implementing appropriate technical and organizational measures on its own systems, and for using the Services in a secure manner consistent with Applicable Data Protection Law.
6. Sub-processors
6.1 General authorization. Customer provides a general authorization for LegisGate™ to engage Sub-processors, subject to the conditions in this Section 6.
6.2 Current Sub-processors. The Sub-processors currently engaged by LegisGate™ are listed in Annex III to this DPA. Customer acknowledges and approves the engagement of those Sub-processors as of the effective date of this DPA.
6.3 New Sub-processors. LegisGate™ shall give Customer at least 30 days' prior written notice of the appointment of any new Sub-processor, including details of the processing to be undertaken. Customer may object to the appointment of a new Sub-processor within 14 days of such notice on reasonable data protection grounds by notifying LegisGate™ in writing. LegisGate™ will work with Customer in good faith to resolve the objection. If the objection cannot be resolved, either party may terminate the relevant Services without penalty on 30 days' written notice.
6.4 Sub-processor obligations. LegisGate™ shall impose data protection obligations on each Sub-processor that are no less protective than those imposed on LegisGate™ under this DPA. LegisGate™ shall remain liable to Customer for the Sub-processor's failure to fulfill its data protection obligations.
6.5 Transfer mechanisms. Where a Sub-processor processes Personal Data outside the EEA, UK, or Switzerland, LegisGate™ shall ensure that appropriate transfer mechanisms are in place, including (as applicable) SCCs, the UK IDTA, or the Swiss FDPIC-approved transfer mechanism.
7. Data Subject Rights
7.1 LegisGate™ shall, taking into account the nature of the Processing, assist Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of Customer's obligation to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law (including rights of access, rectification, erasure, restriction, portability, and objection).
7.2 LegisGate™ shall promptly notify Customer (and in any event within 5 business days) if LegisGate™ receives a request from a Data Subject in relation to Customer's Personal Data. LegisGate™ shall not respond to any such request without Customer's prior written authorization, except to inform the Data Subject that their request has been passed to Customer.
7.3 LegisGate™ shall also assist Customer with fulfilling its obligations relating to Data Protection Impact Assessments (DPIAs) and prior consultation with Supervisory Authorities under Articles 35 and 36 of the GDPR, taking into account the nature of the Processing and information available to LegisGate™.
8. Personal Data Breach Notification
8.1 LegisGate™ shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer's Personal Data. LegisGate™ will endeavor to provide initial notification within 24 hours of confirmed awareness of a breach, to enable Customer to meet its 72-hour regulatory notification obligation under GDPR Article 33.
8.2 Notification shall include, to the extent available at the time: (a) a description of the nature of the Personal Data Breach including, where possible, the categories and approximate number of Data Subjects and Personal Data records concerned; (b) the name and contact details of the LegisGate™ data protection contact; (c) a description of likely consequences of the Personal Data Breach; and (d) a description of measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.
8.3 LegisGate™ shall maintain records of all Personal Data Breaches, including those not requiring notification to a Supervisory Authority or Data Subjects.
9. Audit Rights
9.1 LegisGate™ shall make available to Customer all information reasonably necessary to demonstrate compliance with its obligations under this DPA, and shall allow for and contribute to audits, including inspections, conducted by Customer or a mandated third-party auditor.
9.2 Customer shall provide LegisGate™ with reasonable prior written notice (at least 30 days) of any intended audit. Audits shall be conducted during normal business hours, shall not unreasonably interfere with LegisGate™'s business operations, and shall be subject to appropriate confidentiality obligations. Customer shall bear all costs of any audit.
9.3 LegisGate™ may satisfy its audit obligations by providing Customer with current third-party audit reports (such as SOC 2 Type II), certifications, or penetration test summaries. Customer agrees to use such documentation as a first resort before requesting a direct audit.
10. Return and Deletion of Personal Data
10.1 Upon termination or expiry of the Agreement, LegisGate™ shall, at Customer's written election: (a) return to Customer a complete copy of all Personal Data in a standard machine-readable format; or (b) delete all Personal Data and confirm deletion in writing. Customer must make this election within 30 days of termination or expiry.
10.2 If Customer does not make an election within 30 days, LegisGate™ shall delete all Personal Data within 60 days of termination or expiry, unless applicable law requires retention.
10.3 LegisGate™ shall ensure that its Sub-processors comply with equivalent data return and deletion obligations.
11. International Data Transfers
11.1 EU/EEA transfers. To the extent that LegisGate™ processes Personal Data subject to the GDPR that is transferred from the EEA to the United States, the parties agree that the EU Standard Contractual Clauses (Module 2: Controller to Processor), as set forth in European Commission Decision 2021/914 and amended from time to time, are incorporated into this DPA by reference and apply to such transfers. Customer (as data exporter) and LegisGate™ (as data importer) are deemed to have executed the SCCs as of the effective date of this DPA.
11.2 UK transfers. To the extent that LegisGate™ processes Personal Data subject to the UK GDPR that is transferred from the UK to the United States, the parties agree that the UK International Data Transfer Addendum to the EU SCCs (IDTA) issued by the UK Information Commissioner's Office under S.119A(1) of the UK Data Protection Act 2018 applies, and is incorporated into this DPA by reference.
11.3 Swiss transfers. To the extent that LegisGate™ processes Personal Data subject to the Swiss revFADP that is transferred from Switzerland, the parties agree that the applicable SCCs (as required by the Swiss FDPIC) apply, incorporated by reference, with Switzerland substituted for the EU/EEA where necessary.
12. Liability
12.1 Each party's liability arising out of or relating to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Agreement.
12.2 Notwithstanding Section 12.1, nothing in this DPA limits either party's liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; (c) any liability that cannot be excluded or limited under Applicable Data Protection Law or any other applicable mandatory law.
13. Duration and Termination
13.1 This DPA shall commence on the date Customer first accesses or uses the Services and shall remain in force until the termination or expiry of the Agreement, except that obligations relating to return and deletion of Personal Data (Section 10), confidentiality (Section 4), and audit rights (Section 9) shall survive termination.
13.2 LegisGate™ may update this DPA from time to time to reflect changes in Applicable Data Protection Law or the Services. LegisGate™ will provide at least 30 days' notice of any material changes. Customer's continued use of the Services after the effective date of such changes constitutes acceptance.
14. Governing Law and Jurisdiction
This DPA and any dispute arising out of or in connection with it shall be governed by and construed in accordance with the law specified in the Agreement. Notwithstanding the foregoing, where the parties have agreed to the SCCs, UK IDTA, or Swiss transfer mechanisms as required by Applicable Data Protection Law, those instruments shall be interpreted in accordance with their governing law provisions, which shall take precedence over the governing law of the Agreement with respect to those transfer mechanisms.
Annex I — Description of Processing
| Data exporter | Customer (as identified in the Agreement) |
| Data importer | LegisGate™ Inc., United States |
| Categories of data subjects | Customer's employees, contractors, and authorized platform users; individuals whose data appears in documents or assessments uploaded by Customer |
| Categories of personal data | Account and identity data (name, email, role); platform usage and audit data; content data within assessments, documents, and vendor profiles uploaded by Customer; any personal data within AI-analyzed documents submitted by Customer |
| Special categories of data | None by default. Customer may submit documents containing special category data; Customer is responsible for ensuring appropriate legal bases for such processing. |
| Purposes of processing | Provision of the LegisGate™ Compass Reports platform; authentication and access control; platform support; security monitoring; service improvement (aggregate/anonymized only) |
| Retention period | For the duration of the Agreement plus 60 days post-termination, subject to Customer's election under Section 10; longer if required by applicable law |
| Nature of processing | Collection, storage, analysis, retrieval, disclosure (to Customer only), deletion |
Annex II — Technical and Organizational Security Measures
LegisGate™ implements the following technical and organizational measures to ensure a level of security appropriate to the risk:
- Encryption in transit using TLS 1.2 minimum
- Encryption at rest using AES-256
- Role-based access controls limiting data access to authorized personnel
- Multi-factor authentication for platform and administrative access
- Comprehensive audit logging of all data access events
- Automated security monitoring and anomaly detection
- Regular security assessments and penetration testing
- Employee security awareness training and acceptable use policies
- Documented incident response and breach notification procedures
- Network segmentation and firewall controls
- Vulnerability management and patch management program
- Data minimization and purpose limitation controls
LegisGate™ reviews and updates these measures periodically in accordance with industry standards and the evolving threat landscape.
Annex III — Approved Sub-processors
The following sub-processors are approved as of the effective date of this DPA:
| Processor | Purpose | Location | Transfer Safeguard |
|---|---|---|---|
| Stripe, Inc. | Payment processing for orders and subscriptions — card and payment-method data are collected and stored by Stripe, not by LegisGate | United States (Stripe global infrastructure) | Stripe DPA / SCCs as published by Stripe |
| Anthropic, Inc. | Executive narrative, vendor documentation research summaries, and optional conversational features — not regulatory finding substance | United States | Standard Contractual Clauses |
| Supabase, Inc. | Database infrastructure and authentication | United States | Standard Contractual Clauses |
| Vercel, Inc. | Platform hosting and edge computing | United States | Standard Contractual Clauses |
| Resend, Inc. | Transactional email delivery | United States | Standard Contractual Clauses |
LegisGate™ will provide at least 30 days' notice before adding any new sub-processor. See Section 6.3 for the objection procedure.
Execution
This DPA is entered into by the parties as of the date Customer first accesses or uses the Services, or such earlier date as specified in the Agreement or Order Form. Where a physical signature is required, please contact legal@legisgate.com to request a countersigned copy.
Data Controller (Customer)
Authorized Signature
Name & Title
Date
LegisGate™ Inc. (Data Processor)
Authorized Representative
LegisGate™ Inc.
Effective: March 1, 2026