Legal

Data Processing Addendum

Last updated: July 6, 2026

This Data Processing Addendum (“DPA”) supplements the Terms of Service between you (“Controller” or “Business”) and Dispute Gene AI (“Processor” or “Service Provider”) and governs the processing of personal data by us on your behalf. Where personal data is subject to the EU GDPR or the UK GDPR, the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Modules Two and Three) and the UK IDTA/Addendum are incorporated by reference. Where personal information is subject to U.S. state privacy laws (CCPA/CPRA, CPA, CTDPA, VCDPA, UCPA, TDPSA), the service-provider and processor terms below apply.

1. Definitions

Capitalized terms not defined here have the meanings given in the Terms, GDPR, or applicable law. “Personal Data” means any information relating to an identified or identifiable natural person processed by us on Controller's behalf under the Terms. “Subprocessor” means a third party engaged by us to process Personal Data.

2. Roles & Scope

Controller determines the purposes and means of processing. Processor processes Personal Data only on Controller's documented instructions, including as reflected in the Terms and Controller's configuration of the Services. Processing is limited to the duration of the Services, the categories of data submitted by Controller, and the following purposes: providing, securing, monitoring, supporting, and improving the Services.

3. Confidentiality

Processor ensures that personnel authorized to process Personal Data are bound by written confidentiality obligations and have received appropriate privacy and security training.

4. Security Measures

Processor implements and maintains appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, including: encryption in transit (TLS 1.2+); encryption at rest; role-based access control and least privilege; per-tenant row-level security in the database; centralized secret management; production access logging and monitoring; vulnerability scanning; secure software development lifecycle; hardened cloud infrastructure with reputable providers; documented incident-response procedures; and mandatory security training for personnel.

5. Subprocessors

Controller authorizes Processor to engage Subprocessors to perform specific processing activities, provided that Processor: (a) enters into a written contract imposing data-protection obligations no less protective than this DPA; (b) remains responsible for Subprocessor performance; and (c) maintains a current list of Subprocessors available on request. Processor will provide advance notice of new Subprocessors and, where reasonably objected to on legitimate data-protection grounds, work in good faith to resolve the objection or permit Controller to terminate the affected portion of the Services.

6. Data Subject Rights

Taking into account the nature of the processing, Processor will provide reasonable assistance to Controller to enable Controller to respond to requests from data subjects seeking to exercise their rights (access, rectification, deletion, restriction, portability, objection). Where Processor receives a request directly from a data subject, Processor will promptly forward it to Controller and will not respond substantively without Controller's instruction.

7. Security Incidents

Processor will notify Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Controller's Personal Data, and will provide information reasonably necessary for Controller to comply with its own notification obligations. Notification is not an acknowledgment of fault or liability.

8. Data Protection Impact Assessments

Processor will provide reasonable assistance to Controller with data protection impact assessments and prior consultations with supervisory authorities to the extent required by law.

9. Return and Deletion

Upon termination or expiration of the Services, Processor will, at Controller's choice, delete or return all Personal Data, unless applicable law requires continued storage. Backup copies will be purged in accordance with Processor's documented retention schedule.

10. Audits

Processor will make available information necessary to demonstrate compliance with this DPA, including summaries of independent third-party audits and security certifications, where obtained. On-site audits by Controller are permitted no more than once every twelve (12) months, with at least thirty (30) days' prior written notice, during business hours, subject to reasonable confidentiality and safety controls, and at Controller's expense, unless a Personal Data Breach or material non-compliance is identified.

11. International Transfers

Where Processor transfers Personal Data outside the EEA, UK, or Switzerland, the parties agree that the Standard Contractual Clauses (Modules Two and Three) and, where applicable, the UK IDTA/Addendum, apply and are incorporated herein by reference. Docking clauses, governing law, and forum selections default to those of the Controller's establishing member state unless the parties agree otherwise in writing.

12. U.S. State Privacy Laws

Where Processor acts as a “Service Provider,” “Processor,” or “Contractor” under CCPA/CPRA, CPA, CTDPA, VCDPA, UCPA, TDPSA, or similar laws, Processor certifies that it: (a) will not sell or share Personal Data; (b) will not retain, use, or disclose Personal Data outside the direct business relationship or for any purpose other than the specific purpose of performing the Services; (c) will not combine Personal Data with information received from other sources except as permitted by law; and (d) will notify Controller if it can no longer meet these obligations.

13. Liability

Liability under this DPA is subject to the limitations of liability in the Terms.

14. Order of Precedence

In case of conflict, the SCCs prevail over this DPA on matters they cover, this DPA prevails over the Terms on data-protection matters, and the Terms prevail otherwise.

15. Execution

By accepting the Terms and enabling the Services on personal data subject to the laws above, Controller and Processor are deemed to have entered into this DPA. A counter-signed copy is available on written request via our contact page.

This page is maintained by Dispute Gene AI and describes the platform's practices as an infrastructure provider. Tenants (workspace owners) that resell services to their own customers are independent businesses and must publish their own policies for the offerings they sell. Nothing on this page is legal advice.