Data Processing Agreement
Effective: April 21, 2026 · Last updated: April 21, 2026
This Data Processing Agreement reflects Lagelia’s good-faith commitments during our pre-launch phase. It is under continuous review and will be finalized by licensed counsel prior to paid customer onboarding at our October 1, 2026 general availability launch. Firm customers requiring a countersigned DPA for procurement purposes may email legal@lagelia.ai.
1. Parties & Scope
This Data Processing Agreement (“DPA”) forms part of the agreement between Lagelia (“Processor”) and the law firm customer (“Controller”) regarding processing of personal data in connection with the Service. This DPA governs all processing of Customer Personal Data by Lagelia on behalf of the Controller.
2. Definitions
Customer Personal Data.Any personal data uploaded, processed, or generated through the Service by or on behalf of Controller, including matter content relating to the Controller’s clients, opposing parties, witnesses, or other individuals.
Processing. Any operation performed on personal data, including collection, storage, analysis, generation of AI outputs, transmission, and deletion.
Sub-processor. Any third party engaged by Lagelia to process Customer Personal Data on its behalf.
3. Processing Details
| Subject matter | Provision of the Lagelia Legal Operating System. |
|---|---|
| Duration | For the term of the Controller’s subscription, plus up to 30 days for deletion. |
| Nature & purpose | Document ingestion, embedding generation, AI-assisted research and drafting, matter organization, user collaboration, analytics. |
| Data categories | Identification data, contact details, employment data (legal professionals), matter content (which may include sensitive personal data about clients, witnesses, opposing parties). |
| Data subjects | Controller personnel, Controller’s clients, third parties referenced in matters. |
4. Lagelia Obligations
- Process Customer Personal Data only on documented instructions from the Controller, including as set out in the Terms of Service.
- Ensure personnel authorized to process Customer Personal Data are bound by confidentiality obligations.
- Implement and maintain the technical and organizational security measures described in Section 5.
- Assist Controller in responding to data subject rights requests and regulatory inquiries.
- Not use Customer Personal Data for any purpose other than providing the Service. In particular, Lagelia will not disclose Customer Personal Data to any third-party model provider and will not use it to train any model, its own or anyone else’s.
5. Security Measures
5.1 Measures in place today
Lagelia represents that the following measures are implemented in the Service as of the effective date of this DPA. We list only what is built. Controls we have not yet built are stated separately in Section 5.2 and are not represented as current measures.
- All AI processing runs on models Lagelia operates. Language model inference and embedding generation execute on infrastructure we run directly. Customer Personal Data is never transmitted to OpenAI, Anthropic, Google, or any other third-party model provider. No outside provider receives Customer Personal Data, and therefore none can retain or train on it.
- Matter and document records carry the owning firm’s identifier, and data access is scoped to that firm.
- Role-based access control on administrative functions, with owner, admin, and member roles.
- Parameterized database queries for all user-supplied values, so user input is never interpolated into SQL.
- Path containment checks on every endpoint that serves a stored file, and directory components stripped from uploaded filenames on write.
- Share links and client-portal tokens generated from a cryptographically secure random source, with expiry and revocation checks on each use.
- Uploads restricted to an allowlist of document file types, with request rate limiting on the API.
- Application logs exclude document text and client identifiers. Error monitoring, where enabled, is configured not to transmit personal data.
- Product analytics are computed locally from your own data and are not transmitted to any external analytics service.
5.2 Measures on our roadmap, not yet in place
Lagelia states the following as commitments, not as facts, and makes no representation that any of them is implemented today. Each is scheduled ahead of paid customer onboarding at our October 1, 2026 general availability launch, and we will update this DPA as each is delivered.
- Encryption of traffic in transit at the hosted service boundary.
- Encryption of stored data at rest.
- Multi-factor authentication.
- Audit logging of access to Customer Personal Data.
- Recurring vulnerability scanning and independent penetration testing.
- A documented least-privilege access policy and incident response runbooks.
- SOC 2 Type II certification. No audit has commenced. We will not claim the certification until it is issued.
6. Sub-processors
Controller authorizes Lagelia to engage sub-processors to process Customer Personal Data. A current list of sub-processors (including cloud hosting, authentication, and payment processing) is maintained and made available upon request to legal@lagelia.ai.
No AI model provider is a sub-processor. Because all model inference runs on infrastructure Lagelia operates, no third-party model provider receives, stores, or processes Customer Personal Data at any point.
Lagelia will impose, on each sub-processor, data protection obligations no less protective than those in this DPA. Lagelia will provide notice of new sub-processors at least 30 days in advance, allowing Controller to object on reasonable grounds.
7. Data Subject Rights
Lagelia will, taking into account the nature of the processing, assist Controller in fulfilling its obligations to respond to requests from data subjects for access, correction, deletion, portability, or objection, through the tools exposed in the Service.
8. Personal Data Breach Notification
Lagelia will notify Controller without undue delay (and in any event within 72 hours) upon becoming aware of a personal data breach affecting Customer Personal Data, including information reasonably necessary for Controller to meet its own notification obligations.
9. Audit Rights
Lagelia will make available to Controller, upon reasonable request, information necessary to demonstrate compliance with this DPA, including summaries of any security audits and certifications then in effect. As of the effective date, no third-party security audit has been performed and no certification has been issued. For on-site audits, the parties will agree in good faith on scope, frequency (no more than annually absent a material incident), and cost-sharing.
10. Return or Deletion of Data
Upon termination, and at the Controller’s choice, Lagelia will return or delete all Customer Personal Data within 30 days, except where retention is required by law. Controller may export data through the Service at any time during the subscription term.
11. International Transfers
Lagelia will store and process Customer Personal Data in the United States, and will not transfer Customer Personal Data outside the United States without Controller’s written consent and appropriate safeguards. Controller may request written confirmation of the hosting regions in use at any time.
12. Term & Precedence
This DPA is effective from the effective date of the Controller’s subscription and continues for so long as Lagelia processes Customer Personal Data on Controller’s behalf. In the event of any conflict between this DPA and the Terms of Service, this DPA controls with respect to processing of Customer Personal Data.
13. Governing Law
This DPA is governed by the laws of the State of Delaware, consistent with the Terms of Service.
14. Contact
DPA requests, sub-processor list, or security questionnaires: legal@lagelia.ai