Data Processing Agreement
Processor terms for customer personal data.
This Data Processing Agreement applies when Esheria processes personal data on behalf of a customer through LexChat, LegalOS, Esheria API, developer tools, or related services.
Roles
For Customer Personal Data processed through the service, the customer is the controller or processor, as applicable, and Esheria is the processor or sub-processor, as applicable.
Esheria processes Customer Personal Data only on documented customer instructions. For website, marketing, sales, billing, account administration, and business relationship data, Esheria acts as a controller as described in the Privacy Policy.
Customer instructions
The customer instructs Esheria to process Customer Personal Data as necessary to provide, secure, support, maintain, and improve the service in accordance with the customer agreement, order form, product settings, user actions, and this DPA.
Esheria will notify the customer if it believes an instruction violates applicable data protection law, unless legally prohibited from doing so.
Processing details
The subject matter, duration, nature, purpose, categories of personal data, and categories of data subjects are set out in Annex 1.
Confidentiality
Esheria will ensure that personnel authorised to process Customer Personal Data are subject to confidentiality obligations and process Customer Personal Data only as needed to provide or support the service.
Security measures
Esheria will maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
Current measures are described in Annex 2 and may be updated from time to time, provided the overall level of protection is not materially reduced.
Sub-processors
The customer authorises Esheria to use sub-processors to provide the service.
Esheria will maintain a current sub-processor list through the trust pack or on request; enter into written agreements with sub-processors imposing data protection obligations materially equivalent to this DPA; remain responsible for sub-processor performance; and provide notice of new sub-processors where required by the customer agreement or applicable law.
Customers may object to a new sub-processor on reasonable data protection grounds by contacting privacy@esheria.ai within the notice period stated in the customer agreement or sub-processor notice.
International transfers
Where Customer Personal Data is transferred internationally, Esheria will use appropriate safeguards such as standard contractual clauses, equivalent contractual protections, transfer assessments, and technical controls where required.
Data residency options may be available for LegalOS and enterprise customers under a signed agreement.
Data-subject requests
Esheria will reasonably assist the customer in responding to data-subject requests, including requests to access, correct, delete, restrict, object, or export Customer Personal Data.
Where a data subject contacts Esheria directly about Customer Personal Data controlled by a customer, Esheria may refer the request to the customer unless legally required to respond directly.
Personal data breach
Esheria will notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
The notice will include available information about the nature of the breach, affected data, likely consequences, measures taken or proposed, and contact point for follow-up. Esheria may provide information in phases as it becomes available.
DPIAs, audits, and regulatory assistance
Taking into account the nature of processing and information available to Esheria, Esheria will reasonably assist customers with data protection impact assessments, regulator inquiries, and prior consultations where required by applicable law and related to Esheria's processing.
Esheria will make available information reasonably necessary to demonstrate compliance with this DPA. Audit rights may be satisfied through security documentation, third-party reports, trust documentation, questionnaires, or other reasonable assurance methods, unless a signed agreement provides otherwise.
Return and deletion
On termination or expiry of the service, Esheria will return or delete Customer Personal Data according to the customer agreement, product functionality, and documented customer instructions.
Backups and logs may be retained for limited periods for security, continuity, legal, or audit purposes and then deleted according to standard retention processes.
Customer responsibilities
The customer is responsible for having a lawful basis for processing Customer Personal Data; giving required notices and obtaining required consents; ensuring users are authorised to submit Customer Personal Data; configuring roles, permissions, retention, exports, and integrations appropriately; and reviewing AI outputs before legal, regulatory, client-facing, or high-impact use.
Annex 1: processing details
Subject matter: provision of Esheria legal AI, legal operations, legal research, regulatory data, API, CLI, MCP, support, security, and related services.
Duration: for the term of the customer agreement and any post-termination retention period required for deletion, return, legal, audit, security, or backup purposes.
Nature and purpose: hosting, storage, retrieval, analysis, search, summarisation, classification, extraction, workflow support, source retrieval, legal data processing, AI-assisted processing, audit logging, support, security, and service improvement.
Categories of data subjects may include customer employees, users, administrators, lawyers, counsel, clients, counterparties, vendors, directors, officers, beneficial owners, employees, data subjects mentioned in legal documents, matter participants, and other individuals included in Customer Personal Data.
Categories of personal data may include identifiers, contact details, professional details, account data, authentication data, legal matter information, document content, correspondence, employment or corporate information, compliance records, transaction-related information, API inputs, prompts, outputs, logs, and metadata.
Customer Personal Data may include sensitive or special category data where customers choose to upload or process such data through the service. Customers are responsible for ensuring they have a lawful basis and appropriate safeguards for such processing.
Annex 2: technical and organisational measures
Esheria maintains a security programme that includes encryption in transit; encryption at rest; role-based access controls; workspace and matter-level permissions where available; audit logging and traceability; production access controls and access reviews; SSO and MFA options for qualifying plans; secret management and API token controls; vulnerability management and patching; vendor and sub-processor review; backup and recovery processes; incident response procedures; security monitoring and logging; personnel confidentiality and security awareness; and controls ensuring customer data is not used to train foundation models.
Annex 3: sub-processors
The current sub-processor list is maintained through the trust pack or made available on request.
The list should include provider name, service category, processing purpose, processing location or region, data categories processed, and transfer mechanism where relevant.