Data Processing Agreement
The Article 28 terms governing JuriPro’s processing of personal data on behalf of its customers, including sub-processors, transfers, audit rights and breach notification.
Last updated: 1 September 2026 · Effective: 1 September 2026
1. Scope and roles
This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Controller”) and JuriPro (“Processor”) for the provision of the Services, and applies to the extent that JuriPro processes personal data on the Controller’s behalf.
The parties acknowledge that the Controller determines the purposes and means of processing and that JuriPro acts only on the Controller’s documented instructions. Where the Controller is itself a processor for its own client, JuriPro acts as a sub-processor and the obligations in this DPA apply accordingly.
An executable copy of this DPA is available on request from [email protected]. Enterprise customers may execute it as a standalone document with signature.
2. Details of processing
Subject matter: provision of AI-assisted document analysis, legal research, compliance scanning, due diligence and document generation services.
Duration: the term of the agreement, plus the retention period configured by the Controller.
Nature and purpose: storage, text extraction, indexing, classification, analysis, retrieval and generation, in each case to provide the Services.
Categories of data subject: as determined by the Controller. Typically: the Controller’s personnel; the Controller’s clients and their personnel; counterparties to documents uploaded; and individuals named in those documents.
Categories of personal data: as determined by the Controller. Typically: identification and contact details, employment details, commercial information, and any other personal data contained in uploaded documents.
Special category data: the Services are not designed for special category data. Where a document contains it incidentally, JuriPro applies the same technical and organisational measures; the Controller remains responsible for establishing an Article 9 condition.
3. Processor obligations
JuriPro will:
- process personal data only on the Controller’s documented instructions, including as to international transfers, unless required otherwise by law (in which case it will inform the Controller unless the law prohibits this on important grounds of public interest);
- ensure that persons authorised to process personal data are subject to binding confidentiality obligations and receive data protection training;
- implement the technical and organisational measures described in section 6 and in the Security Overview;
- respect the conditions in section 4 for engaging sub-processors;
- assist the Controller, by appropriate technical and organisational measures and insofar as possible, in responding to data subject rights requests;
- assist the Controller with data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to it;
- at the Controller’s election, delete or return all personal data at the end of the provision of the Services, and delete existing copies unless retention is required by law; and
- make available all information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits as set out in section 7.
No training on Controller data. JuriPro will not use personal data processed under this DPA to train, fine-tune or evaluate any model made available to any other customer.
4. Sub-processors
The Controller grants general authorisation for the engagement of sub-processors, subject to the conditions in this section. JuriPro maintains a current list of sub-processors, available at [email protected] and in the platform’s trust centre. The list identifies each sub-processor, the processing carried out and its location.
JuriPro will give at least 30 days’ notice before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Controller may terminate the affected Services without penalty and with a pro-rata refund of prepaid fees.
JuriPro imposes on each sub-processor obligations no less protective than those in this DPA and remains fully liable to the Controller for the performance of each sub-processor’s obligations.
| Sub-processor | Purpose | Location |
|---|---|---|
| Primary cloud infrastructure provider | Hosting, storage, compute | EU (Frankfurt, Paris) or US (N. Virginia, Oregon) per Controller election |
| Managed model inference provider | Model execution within the elected region | Same region as hosting |
| Error monitoring provider | Application diagnostics (identifiers only, no document content) | Same region as hosting |
| Support ticketing provider | Customer support correspondence | EU |
5. International transfers
Personal data is processed in the region elected by the Controller. Where a transfer outside the EEA or the UK is necessary, it takes place on the basis of an adequacy decision or, failing that, the European Commission’s Standard Contractual Clauses (Modules Two and Three as applicable), together with the UK International Data Transfer Addendum for UK transfers, which are incorporated into this DPA by reference and completed as follows: the Controller is the data exporter, JuriPro the data importer; the optional docking clause applies; Clause 17 selects the law of France; Clause 18 selects the courts of Paris. Annexes I, II and III are populated by sections 2, 6 and 4 of this DPA respectively.
6. Technical and organisational measures
JuriPro maintains at minimum: encryption of personal data in transit (TLS 1.3) and at rest (AES-256); logical tenant isolation; role-based access control with least privilege; mandatory multi-factor authentication for all personnel; a formal joiners, movers and leavers process; centralised audit logging with tamper-evident storage; vulnerability management with defined remediation windows; annual independent penetration testing; documented business continuity and disaster recovery with tested restore procedures; secure development practices including code review and dependency scanning; and an information security management system certified to ISO/IEC 27001.
Full detail is set out in the Security Overview, which JuriPro may update from time to time provided the level of protection is not reduced.
7. Audit
JuriPro will make available its most recent ISO/IEC 27001 certificate, SOC 2 Type II report and penetration test summary, and will respond to reasonable written security questionnaires, in each case no more than once in any twelve-month period unless required by a supervisory authority or following a personal data breach.
Where these are not sufficient to demonstrate compliance, the Controller may conduct or mandate an audit on 30 days’ written notice, during business hours, no more than once a year, subject to confidentiality undertakings and conducted so as not to disrupt JuriPro’s operations or compromise other customers’ data. The Controller bears the cost unless the audit reveals material non-compliance.
8. Personal data breach
JuriPro will notify the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Controller’s personal data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact. Where information is not available at the time, it will be provided in phases without undue further delay.
JuriPro will not notify a supervisory authority or data subjects on the Controller’s behalf unless instructed to do so in writing.
9. Return and deletion
On termination or expiry, the Controller may export its data through the platform for 30 days. Thereafter, or earlier on written instruction, JuriPro will delete all personal data from live systems within 7 days and from backups within 35 days, and will provide written confirmation of deletion on request. Deletion cascades to derived artefacts including extracted text, search indices, vector representations and cached renderings.
10. Liability and precedence
Each party’s liability under this DPA is subject to the limitations and exclusions in the agreement, save to the extent that such limitation is prohibited by applicable data protection law. In the event of conflict, this DPA prevails over the agreement in respect of the processing of personal data, and the Standard Contractual Clauses prevail over this DPA.
Questions about this document? Write to [email protected], or to JuriPro SARL, 18 Rue de la Paix, 75002 Paris, France.