Data Processing Agreement

Version 1.0 — Effective:

About the provisions marked in red

This Agreement is in force and binds Legaltra as written. The provisions shown in bold red were drafted on our own research into the GDPR, UK GDPR and the CCPA/CPRA and on prevailing market practice, and have not yet been reviewed by external counsel. They are operative; the marking records that they are the first items our reviewing attorney will examine.

Where obligations or time windows differ between regimes, this Agreement adopts the most constraining of them, so that one set of commitments satisfies all of them at once. The single exception is identified expressly in clause 6.3.

Summary of Key Points

This Agreement forms part of, and is incorporated by reference into, the Legaltra Legal Terms. It governs our processing of personal data in your Case Materials. It applies automatically to every customer; no signature is required and none is offered.

  • What does it cover? Your Case Materials — clients, cases, claim charts, claims, blocks, comments, media, exports and collaboration documents. For that content you are the controller and Legaltra is the processor.

  • What does it not cover? Account, billing and contact-form data. Legaltra is the controller for that, and our Privacy Policy governs it.

  • How quickly do we tell you about a breach? Within 24 hours of becoming aware.

  • How are international transfers handled? For customers in the EEA, Switzerland or the UK, by the European Commission's 2021 Standard Contractual Clauses, Module Two, with the UK Addendum where the UK is engaged.

  • What happens to your data when you leave? We delete or return all of it at your choice, including generated exports and the snapshots behind them, and we certify the deletion in writing on request.

Table of Contents

1. Parties2. Definitions3. Roles of the Parties4. Scope, Term and Instructions5. Description of the Processing6. Subprocessors7. Confidentiality and Personnel8. Deletion and Return at End of Service9. Assistance with Data-Subject Rights10. Personal Data Breach11. CCPA/CPRA Service-Provider Terms12. Audit and Information13. International Transfers14. Security15. GeneralAnnex I — Parties and Transfer DescriptionAnnex II — Technical and Organisational MeasuresAnnex III — Subprocessors

1. Parties

Legaltra LLC ("Legaltra", "we", "us"), a limited liability company registered in the State of Wyoming, United States, with its principal address at 1501 S Greeley Hwy, Ste C, Cheyenne, WY 82007, United States. Registered Agent: Registered Agents Inc., 30 N Gould St, Ste R, Sheridan, WY 82801, United States.

The Customer ("Customer", "you") — the law firm, company or other organisation that holds a Legaltra account and uploads or creates Case Materials. Each is a "Party" and together the "Parties".

2. Definitions

Terms defined in the GDPR — including personal data, processing, controller, processor, data subject, personal data breach and supervisory authority — carry those meanings. Terms defined in the CCPA/CPRA — including business, service provider, sell, share and business purpose — carry those meanings where the CCPA/CPRA applies.

  • Case Materials means the clients, cases, claim charts, claims, blocks, comments, media, exports and collaboration documents that you or your authorised users upload to or create within the Legaltra platform, together with any personal data contained in them.

  • Data Protection Law means, as applicable, Regulation (EU) 2016/679 (GDPR); the UK GDPR and the Data Protection Act 2018; the California Consumer Privacy Act as amended by the CPRA and its implementing regulations; and any other privacy or data protection law applicable to a Party's processing under this Agreement.

  • Standard Contractual Clauses means the clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (controller to processor).

  • UK Addendum means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, issued by the Information Commissioner under section 119A of the Data Protection Act 2018.

3. Roles of the Parties

  • Case Materials: Legaltra is the processor; the Customer is the controller.

  • Account, billing and contact-form data: user records, organization and case memberships, invitations, invoices, payment-provider identifiers and contact submissions. Legaltra is the controller.

This Agreement governs the first category only. Legaltra's processing of account, billing and contact data is its own controller-side processing and is governed by the Privacy Policy. The distinction is operative: it determines who must notify a supervisory authority of a breach, and who answers a data subject's request. Clauses 9 and 10 apply it.

Where the CCPA/CPRA applies, the Customer is the business and Legaltra is a service provider in respect of Case Materials.

4. Scope, Term and Instructions

4.1 Term

This Agreement takes effect when the Customer first accepts the Legal Terms and continues for as long as Legaltra processes Case Materials, and thereafter for so long as any clause expressed to survive remains in effect. Clauses 8, 11, 14 and 15 survive termination.

4.2 Documented instructions

Legaltra processes Case Materials only on the Customer's documented instructions, including as to transfers to a third country, unless required to process by Union or Member State law — in which case Legaltra informs the Customer of that requirement before processing, unless that law prohibits such information on important grounds of public interest.

The Customer's use of the platform through its ordinary interfaces, together with this Agreement and the Legal Terms, constitutes the Customer's complete documented instructions. Any other instruction must be agreed in writing.

4.3 Infringing instructions

Legaltra immediately informs the Customer if, in its opinion, an instruction infringes Data Protection Law, and may suspend performance of that instruction until it is confirmed, withdrawn or amended.

4.4 Customer warranties

The Customer warrants that it has a lawful basis for the processing it instructs; that it has given all notices and obtained all consents required; and that its instructions comply with Data Protection Law. The Customer is responsible for the lawfulness of the Case Materials it uploads.

5. Description of the Processing

Provided under Article 28(3) GDPR.

  • Subject-matter: provision of the Legaltra claim-charting platform — hosting, collaborative editing, storage and export of patent-litigation work product.

  • Duration: the term of the Customer's subscription, plus the post-termination period in clause 8.

  • Nature and purpose: storage, structuring, organisation, retrieval, collaborative editing, generation of exports, and transmission to the Customer's authorised users, solely to provide the platform.

  • Types of personal data: names, email addresses and account identifiers of the Customer's authorised users; and any personal data the Customer places within Case Materials, which may include names and identifying details of parties, inventors, witnesses, experts and other third parties appearing in litigation documents.

  • Categories of data subjects: the Customer's personnel and authorised users; the Customer's own clients; and any individual named in material the Customer uploads.

5.1 Special-category and criminal-offence data

Legaltra does not solicit special-category data (Article 9 GDPR) or criminal-offence data (Article 10 GDPR), and the platform has no feature requiring it. Legaltra does not prohibit its presence, because litigation exhibits can contain such data incidentally and a prohibition Legaltra could not enforce would be a worse protection than none.

Where Case Materials contain such data, the Customer remains responsible for identifying the Article 9(2) or Article 10 condition relied upon, and Legaltra applies the security measures in Annex II to all Case Materials uniformly, without distinction, so that the presence of such data requires no additional configuration by the Customer.

6. Subprocessors

6.1 General authorisation

The Customer grants Legaltra general written authorisation to engage subprocessors, under Article 28(2) GDPR. The current subprocessors are listed in Annex III.

6.2 Notice and objection

Legaltra gives the Customer at least 30 days' prior written notice of the intended addition or replacement of a subprocessor. The Customer may object on reasonable grounds relating to data protection within 30 days of that notice.

If the Customer objects, the Parties will work in good faith to agree an alternative. If none can be agreed within 30 days of the objection, the Customer may terminate the affected part of the service without penalty and receive a pro-rata refund of prepaid fees for the unused remainder of the term. Silence after the objection window closes constitutes acceptance.

6.3 The one case where 30 days is not available

Legaltra's own upstream providers do not all give Legaltra 30 days' notice of their subprocessor changes; one gives 14 days. Where an upstream change is imposed on Legaltra with less than 30 days' notice, Legaltra will notify the Customer within 5 business days of becoming aware, give the Customer the longest objection window the upstream notice permits, and state in the notice why the full period was unavailable. Legaltra does not promise a period it cannot deliver.

6.4 Flow-down and liability

Legaltra imposes on each subprocessor, by written contract, data protection obligations no less protective than those in this Agreement, and remains fully liable to the Customer for the performance of each subprocessor's obligations.

7. Confidentiality and Personnel

Legaltra ensures that persons authorised to process Case Materials are bound by an obligation of confidentiality — contractual or statutory — that survives the end of their engagement, and that access is limited to those personnel who require it to deliver or support the platform.

8. Deletion and Return at End of Service

8.1 The obligation

At the Customer's choice, notified within 30 days of termination, Legaltra deletes or returns all Case Materials and deletes existing copies, unless Union or Member State law requires storage.

8.2 What deletion covers

Deletion under clause 8.1 covers all Case Materials in every form in which Legaltra holds them, including clients, cases, claim charts, claims, blocks, comments and uploaded media; generated export archives; the chart and claims snapshots retained behind each export; and real-time collaboration documents. Legaltra does not rely on a generic "retention required by law" exception to keep any category of Case Materials outside this clause.

8.3 Timing

Absent a Customer election, Legaltra retains Case Materials for 30 days from the date it receives the deletion request, to allow retrieval, then deletes them. Deletion is completed within 90 days of the deletion request, including from routine backups by expiry of the backup cycle.

8.4 Certification

Legaltra certifies deletion in writing on the Customer's request.

9. Assistance with Data-Subject Rights

Legaltra assists the Customer, by appropriate technical and organisational measures and insofar as possible, in fulfilling the Customer's obligation to respond to data-subject requests, and provides that assistance within 10 business days of the Customer's request — a period set so the Customer can meet a one-month statutory deadline with margin.

Requests received directly. Where a data subject contacts Legaltra directly about Case Materials, Legaltra does not respond substantively. It directs the data subject to the Customer as controller and notifies the Customer without undue delay. This is the correct position for a processor and Legaltra will not depart from it.

Where the Customer is a business under the CCPA/CPRA, Legaltra enables the Customer to comply with consumer requests to know, delete, correct, opt out and limit, to the extent the relevant personal information is within Case Materials.

10. Personal Data Breach

10.1 Notification to the Customer

On becoming aware of a personal data breach affecting Case Materials, Legaltra notifies the Customer without undue delay and in any event within 24 hours. Legaltra adopts 24 hours — the shorter end of the prevailing 24-to-48-hour contractual range — under the drafting rule stated at the top of this Agreement.

10.2 Who notifies the supervisory authority

Legaltra does not notify the supervisory authority for Case Materials. For that data the Customer is the controller and Article 33(1) is the Customer's obligation. Legaltra's duty runs to the Customer under Article 33(2).

10.3 Content of the notice

The notice describes the nature of the breach; the categories and approximate number of data subjects and records concerned; a contact point; the likely consequences; and the measures taken or proposed. Approximate figures are given rather than withheld pending precision, and are supplemented as more is established.

10.4 Assistance

Legaltra assists the Customer with Articles 32 to 36, including any notification the Customer must make to a supervisory authority or to data subjects, and including data protection impact assessments and prior consultations.

10.5 US state breach laws

Where a breach engages a US state notification statute and Legaltra holds the affected data as service provider, Legaltra provides the Customer with the information the Customer needs to meet the shortest applicable deadline. Legaltra's internal readiness targets are the most constraining then in force, currently California's 30-day resident-notification and 15-day Attorney-General deadlines under Civil Code sections 1798.29 and 1798.82 as amended by SB 446.

11. CCPA/CPRA Service-Provider Terms

Given under 11 CCR section 7051. Legaltra:

  1. will not sell or share personal information collected under this Agreement;

  2. processes it only for the business purpose of providing, securing and supporting the Legaltra platform as described in clause 5 — and for no other purpose;

  3. will not retain, use or disclose it for any purpose other than that business purpose, or for any commercial purpose, except as the CCPA permits;

  4. will not retain, use or disclose it outside the direct business relationship with the Customer;

  5. will not combine it with personal information received from, or on behalf of, any other person, or collected from Legaltra's own interactions, except as the CCPA permits;

  6. complies with the CCPA, including by providing the same level of privacy protection the CCPA requires of a business, and maintains reasonable security procedures appropriate to the nature of the information;

  7. grants the Customer the right to take reasonable and appropriate steps — including the monitoring, review and audit rights in clause 12 — to ensure Legaltra's use is consistent with the Customer's CCPA obligations;

  8. notifies the Customer promptly after determining that it can no longer meet its CCPA obligations;

  9. grants the Customer the right, on notice, to stop and remediate unauthorised use; and

  10. enables the Customer to comply with consumer requests under the CCPA.

Legaltra imposes materially the same terms on each subcontractor that processes personal information under this Agreement, as section 7051(b) requires.

12. Audit and Information

Legaltra makes available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR and section 7051.

The Customer may audit Legaltra's processing, itself or through an independent auditor it mandates: once in any 12-month period, on 30 days' prior written notice, during normal business hours, and without unreasonable disruption. Additionally and without those limits, the Customer may audit following a personal data breach affecting its Case Materials, or where a supervisory authority requires it.

The auditor must be bound by confidentiality obligations no less protective than those in the Legal Terms, and must not be a competitor of Legaltra. The Customer bears its own and the auditor's costs. Audit findings are Legaltra's confidential information.

No certification is substituted. Legaltra is not SOC 2 certified, and this Agreement does not offer a third-party attestation in place of the audit right above. Legaltra models its internal controls on the SOC 2 security principles; that is a design posture and is not represented as a certification.

13. International Transfers

13.1 When this clause applies

Only where the Customer is established in, or the processing is subject to GDPR or UK GDPR in respect of, the EEA, Switzerland or the United Kingdom. A Customer with no such connection does not engage this clause.

13.2 A narrowing under EDPB Guidelines 05/2021

A Chapter V transfer requires that an exporter subject to GDPR makes the data available to an importer in a third country. Personal data a data subject provides directly to Legaltra is therefore not a restricted transfer. This clause governs the case where the Customer, as exporter, makes Case Materials available to Legaltra.

13.3 European Union

The Standard Contractual Clauses, Module Two, are incorporated into this Agreement by reference and form an integral part of it, with the Customer as data exporter and Legaltra as data importer. Annexes I, II and III to this Agreement serve as Annexes I, II and III to the Clauses. Where the Clauses conflict with any other term, the Clauses prevail.

The optional docking clause (Clause 7) does not apply. In Clause 9, Option 2 (general written authorisation) applies with the notice period in clause 6.2. In Clause 11, the optional independent-dispute-resolution paragraph does not apply. In Clause 17, the governing law is the law of Ireland. In Clause 18(b), the forum is the courts of Ireland.

The Clause text is not reproduced here and must not be modified — modification invalidates them. Module Two also satisfies Article 28(3).

13.4 United Kingdom

The UK Addendum applies to any UK restricted transfer, appended to the Clauses. Table 1 is completed with the Parties' details in clause 1 and the Customer's own details; Table 2 selects the Clauses as incorporated by clause 13.3; Table 3 is completed with Annexes I to III of this Agreement; and in Table 4, the Party that may end the Addendum when the Approved Addendum changes is the Importer (Legaltra). The EU Clauses alone are not valid for a UK restricted transfer, which is why this clause exists.

13.5 Switzerland

The Clauses apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, and the competent authority read as the Swiss Federal Data Protection and Information Commissioner.

13.6 Transfer impact assessment (Clause 14)

Legaltra has no reason to believe that the laws of the United States prevent it from fulfilling its obligations under the Clauses in respect of the Case Materials it holds. Legaltra maintains a record of that assessment for each subprocessor that is not certified under the EU-US Data Privacy Framework, and makes it available under clause 12. Where a subprocessor is certified, transfers to it proceed under the adequacy decision and no assessment is required.

13.7 Government access

Legaltra has received no order requiring disclosure of Case Materials to a public authority. If Legaltra receives one it will, to the extent legally permitted: notify the Customer without undue delay; challenge the order where there is a reasonable basis; disclose only the minimum required; and keep a record. Where notice is prohibited, Legaltra will use reasonable efforts to obtain a waiver.

13.8 The Article 3(2) position

The Clauses are recognised as an imperfect fit where the importer is itself directly subject to GDPR under Article 3(2), and the European Commission's intended additional clause set for that scenario has not been adopted. Pending its adoption, Legaltra uses the Clauses as the available approved mechanism, in line with prevailing practice, and complies with GDPR in its own right to the extent Article 3(2) reaches it. Legaltra will adopt the additional clause set within a reasonable period of its becoming available.

13.9 Data Privacy Framework

Legaltra is not currently self-certified under the EU-US Data Privacy Framework. This clause does not rely on it.

14. Security

Legaltra implements the technical and organisational measures in Annex II, appropriate to the risk, under Article 32 GDPR. Legaltra may update them provided the level of protection is not reduced.

15. General

Order of precedence. In respect of the processing of Case Materials, this Agreement prevails over the Legal Terms; the Standard Contractual Clauses prevail over this Agreement.

Liability. Each Party's liability under this Agreement is subject to the limitations and exclusions in the Legal Terms, except where Data Protection Law does not permit them to apply.

Governing law. This Agreement is governed by the law of the State of Wyoming, United States, except that clause 13.3 is governed by the law of Ireland as the Clauses require, and except where Data Protection Law mandates otherwise.

Changes. Legaltra may update this Agreement where required by law or to reflect a change in the platform, on 30 days' notice, provided the change does not reduce the level of protection. Material changes reducing protection require the Customer's agreement.

Severability. If a provision is held invalid, the remainder continues in effect.

Annex I — Parties and Transfer Description

A. List of parties. Data exporter: the Customer, as identified in its Legaltra account. Activities: instructing the processing of Case Materials for patent-litigation work. Role: controller. Contact: the account owner's registered address and email. Signature and date: by acceptance of the Legal Terms.

Data importer: Legaltra LLC, 1501 S Greeley Hwy, Ste C, Cheyenne, WY 82007, United States. Contact: privacy@legaltra.com. Activities: provision of the claim-charting platform. Role: processor. Signature and date: by making this Agreement available and performing it.

B. Description of transfer. Categories of data subjects, categories of personal data, special categories, and the nature, purpose and duration of the processing are as set out in clause 5. Frequency: continuous, for the term. Retention: as set out in clause 8. Subprocessors: Annex III, for the duration and purposes stated there.

C. Competent supervisory authority. Determined under Clause 13 by reference to the Customer as data exporter: where the Customer is established in an EEA Member State, the supervisory authority of that Member State; where the Customer is not established in the EEA but is subject to GDPR under Article 3(2) and has appointed an Article 27 representative, the supervisory authority of the Member State in which that representative is established; where the Customer is not established in the EEA and has appointed no representative, the supervisory authority of a Member State in which the data subjects are located; for UK restricted transfers, the Information Commissioner's Office; and for Swiss transfers, the Federal Data Protection and Information Commissioner.

Annex II — Technical and Organisational Measures

These are Legaltra's contractual commitments under clause 14, given under Article 32 GDPR.

  • Encryption. Case Materials are encrypted in transit using TLS. The database cluster is configured with storage encryption enabled. Object storage holding uploaded evidence and export archives is encrypted at rest.

  • Access control. Access to Case Materials is governed by organization-level and case-level role matrices enforced server-side on every request. Access is limited to the Customer's own authorised users and to Legaltra personnel who require it to deliver or support the platform.

  • Authentication. Authentication is delegated to a specialist identity provider. Multi-factor authentication is required on every account without exception, including accounts held by Legaltra personnel.

  • Logging and monitoring. Application requests emit structured events carrying actor identifiers, retained for approximately 3 days, enabling reconstruction of who accessed what.

  • Segregation. Each Customer's Case Materials are logically segregated and access-scoped to its organization. The real-time collaboration service is self-hosted on Legaltra's own infrastructure and persists to the same database; collaboration content does not pass to a third party.

  • Resilience and recovery. The database is operated as a managed cluster with automated backups and point-in-time recovery.

  • Incident management. Legaltra maintains a documented breach-response procedure covering detection, assessment, notification and record-keeping, including the role split in clause 3.

  • Governance. Legaltra is not SOC 2 certified. Controls are modelled on the SOC 2 security principles as a design posture only. Legaltra does not currently operate a scheduled penetration-testing or formal vulnerability-management programme, and does not represent otherwise.

Annex III — Subprocessors

  • Amazon Web Services — cloud infrastructure (managed database, object storage, email delivery, compute and logs), United States. Hosts all Case Materials.

  • Clerk — authentication and identity, United States. Names, email addresses, credentials and session data of authorised users.

  • Stripe — payments and tax, United States. Billing identity; does not receive Case Materials.

  • PostHog — product analytics, United States. Usage telemetry and account identifiers; does not receive Case Materials.

Legaltra maintains a fuller internal register of the governing terms, acceptance mechanism and certification status of each subprocessor, available to the Customer under clause 12.

Questions, requests and notices under this Agreement: privacy@legaltra.com, or by post to the address in clause 1.

1501 South Greeley Hwy, Ste C #1495, Cheyenne, WY 82007

info@legaltra.com

Terms of Service

Privacy Policy

Refund Policy