This Data Processing Agreement (“DPA”) forms part of the DecoverAI Terms of Service or other written or electronic agreement between the parties governing Customer’s access to and use of the Services, together with any applicable Order Form (collectively, the “Agreement”), and is entered into between DecoverHQ, Inc. (“DecoverAI,” “we,” “our,” or “us”) and the customer identified in the Agreement (“Customer” or “you”). It describes the obligations of each party with respect to the Processing of Personal Data in connection with the Services Customer has purchased. Capitalized terms used but not defined in this DPA have the meanings given to them in the Agreement.
Need a countersigned copy, our Standard Contractual Clauses, or a HIPAA business associate agreement? Email support@decover.ai. Where Customer and DecoverAI have executed a separately negotiated data processing agreement, that agreement controls over this DPA.
1. Definitions
1.1 “Applicable Data Protection Law” means each privacy, data protection, and data security law that applies to a party’s Processing of Customer Personal Data under the Agreement, including (i) European Data Protection Laws, (ii) Canadian Privacy Laws, and (iii) US Privacy Laws, in each case as amended, superseded, or replaced from time to time.
1.2 “Canadian Privacy Laws” means, as applicable, (i) the federal Personal Information Protection and Electronic Documents Act (PIPEDA); (ii) the Personal Information Protection Acts in force in Alberta and British Columbia; (iii) the Act respecting the protection of personal information in the private sector (Québec), as amended by Law 25; and (iv) Canada’s Anti-Spam Legislation (CASL), together with their implementing regulations.
1.3 “Controller” means the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the context concerns US Privacy Laws, references to a Controller include a “business” or “controller” as those terms are defined in the applicable law.
1.4 “Customer Personal Data” means Personal Data contained in Customer Data that DecoverAI Processes under the Agreement solely on Customer’s behalf. For clarity, Customer Personal Data includes Personal Data contained in documents, communications, and other materials that Customer or its authorized users upload to or generate within the Services, and any Personal Data contained in support requests Customer submits to DecoverAI.
1.5 “Data Privacy Framework” or “DPF” means, as applicable, the EU–U.S. Data Privacy Framework, the UK Extension to the EU–U.S. Data Privacy Framework, and the Swiss–U.S. Data Privacy Framework, each as administered by the U.S. Department of Commerce and as may be amended, superseded, or replaced.
1.6 “European Data Protection Laws” means, as applicable, (i) Regulation (EU) 2016/679 (the General Data Protection Regulation, or “GDPR”); (ii) Directive 2002/58/EC as amended by Directive 2009/136/EC (the e-Privacy Directive); (iii) any national implementations of (i) and (ii); (iv) the Swiss Federal Act on Data Protection as revised effective September 1, 2023, and its ordinances (the “Swiss FADP”); and (v) the United Kingdom Data Protection Act 2018 and the GDPR as retained in UK law (the “UK GDPR”), together with the Privacy and Electronic Communications (EC Directive) Regulations 2003; in each case as may be amended, superseded, or replaced.
1.7 “Personal Data” means any information relating to an identified or identifiable natural person, or that otherwise constitutes “personal data,” “personal information,” “personally identifiable information,” or an equivalent term as defined under Applicable Data Protection Law.
1.8 “Process,” “Processes,” “Processed,” and “Processing” have the meanings given under the relevant Applicable Data Protection Law or, where not defined, mean any operation or set of operations performed on Personal Data, including collection, access, storage, use, disclosure, and deletion.
1.9 “Processor” means the entity that Processes Personal Data on behalf of a Controller. Where the context concerns the California Consumer Privacy Act, a reference to DecoverAI as Processor means a “service provider” as defined in that statute.
1.10 “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Customer Data Processed by DecoverAI or its Sub-processors, or any event that DecoverAI reasonably suspects may constitute such an occurrence. Unsuccessful attempts and routine events that do not compromise the security of Customer Data — such as blocked login attempts, port scans, or denied firewall traffic — are not Security Incidents.
1.11 “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914 of June 4, 2021, available at commission.europa.eu.
1.12 “Sub-processor” means any Processor engaged by DecoverAI to Process Customer Personal Data in order to fulfill DecoverAI’s obligations under the Agreement.
1.13 “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, for transfers of Personal Data from the United Kingdom to a country not covered by UK adequacy regulations.
1.14 “US Privacy Laws” means all United States federal and state data privacy, information security, and data breach notification laws and their implementing regulations to the extent applicable to DecoverAI’s Processing of Customer Personal Data in performing the Services, excluding the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), which, where applicable, is addressed under a separate business associate agreement between the parties.
1.15 The terms “data subject,” “supervisory authority,” “consumer,” and “sensitive personal information” have the meanings given to them under the applicable Data Protection Law in which they appear.
2. Roles of the Parties
2.1 DecoverAI as Processor and Service Provider. As a Processor — and, to the extent applicable under US Privacy Laws, as a “service provider” or equivalent — DecoverAI will Process Customer Personal Data only on Customer’s behalf and in accordance with Customer’s lawful documented instructions as set out in this DPA and the Agreement. Customer discloses Customer Personal Data to DecoverAI only for the limited and specified purposes described in Schedule 1 and as otherwise permitted by Applicable Data Protection Law. DecoverAI will not: (a) sell or share Customer Personal Data; (b) retain, use, disclose, or otherwise Process Customer Personal Data for any purpose other than the limited and specified purposes described in Schedule 1 or as otherwise permitted by Applicable Data Protection Law; (c) Process Customer Personal Data outside the direct business relationship between Customer and DecoverAI; or (d) combine Customer Personal Data with Personal Data received from or on behalf of any other person, or collected through DecoverAI’s own interactions with data subjects, except as permitted by Applicable Data Protection Law. DecoverAI will comply with the obligations applicable to its role under Applicable Data Protection Law and will provide the level of privacy protection that law requires. DecoverAI will notify Customer if it determines it can no longer meet those obligations, in which case Customer may take reasonable and appropriate steps to stop and remediate any unauthorized Processing. DecoverAI will also notify Customer if it becomes aware, or reasonably believes, that an instruction from Customer infringes Applicable Data Protection Law, and may suspend that instruction until Customer modifies it, confirms its lawfulness, or withdraws it.
2.2 DecoverAI as Controller. With respect to Personal Data relating to user accounts, billing and contact records, and usage and telemetry data generated through operation of the Services, DecoverAI acts as a Controller and Processes such data to manage its relationship with Customer, to provide, secure, support, and improve the Services, and for other legitimate business purposes described in our Privacy Policy. DecoverAI does not act as a Controller with respect to the contents of Customer Data.
2.3 Customer. As between the parties, Customer is solely responsible for the accuracy, content, legality, and quality of Customer Personal Data and for the lawfulness of the instructions it gives DecoverAI. Customer represents and warrants that it has provided all notices and obtained all consents, permissions, and rights required under Applicable Data Protection Law for DecoverAI to Process Customer Personal Data for the purposes contemplated by the Agreement and this DPA. DecoverAI is not responsible for assessing the legality or accuracy of Customer Personal Data.
2.4 Model Training and AI Processing. DecoverAI does not use Customer Personal Data to train, fine-tune, or otherwise improve any foundation model or machine learning model, whether operated by DecoverAI or by a third party. Where the Services route Customer Personal Data to a model provider engaged as a Sub-processor, that provider is engaged under contractual terms that prohibit training on Customer Personal Data and that apply zero or minimal data retention where the provider makes such terms available. Outputs generated from Customer Personal Data are returned to Customer and treated as Customer Data under the Agreement. DecoverAI may use aggregated or de-identified data that does not identify Customer, any data subject, or any matter to operate and improve the Services, provided it does not attempt to re-identify that data.
3. Security
3.1 Security Measures. DecoverAI has implemented and will maintain appropriate technical and organizational measures designed to protect the confidentiality, integrity, and availability of Customer Data and to protect against Security Incidents. Those measures include, at a minimum, AES-256 encryption of Customer Data at rest, TLS 1.2 or higher in transit, role-based access controls with least-privilege provisioning, logical tenant isolation, logging and monitoring, and an annually assessed SOC 2 Type II control environment. A fuller description is available on our Security page and in the reports available through our Trust Center. Customer acknowledges that these measures are subject to technical progress and that DecoverAI may update them from time to time, provided no update materially reduces the overall level of security.
3.2 Customer Security Responsibilities. Customer is responsible for implementing and maintaining reasonable and appropriate technical and organizational measures to protect Customer Data and its accounts, including the security controls that Customer can select or configure within the Services — such as single sign-on, multi-factor authentication, session policies, user provisioning and de-provisioning, matter-level access restrictions, and retention settings.
3.3 Security Incidents. On becoming aware of a reasonably suspected Security Incident, DecoverAI will promptly investigate to determine whether a Security Incident has occurred. DecoverAI will notify Customer without undue delay and, in any event, within seventy-two (72) hours of confirming a Security Incident affecting Customer Data. DecoverAI will make reasonable efforts to identify the cause, mitigate the effects, and remediate the cause to the extent within its reasonable control, and will provide information relating to the Security Incident as it becomes available or on Customer’s reasonable request, so that Customer can meet its own notification obligations. DecoverAI’s notification of, or response to, a Security Incident is not an acknowledgment of fault or liability.
4. Sub-processing
4.1 General Authorization. Customer provides a general authorization for DecoverAI to engage Sub-processors to Process Customer Personal Data on DecoverAI’s behalf. The current list of Sub-processors is published at decover.ai/legal/subprocessors. DecoverAI will (i) enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than those set out in this DPA, and (ii) remain responsible for its own compliance with this DPA and for any act or omission of a Sub-processor that causes DecoverAI to breach its data protection obligations under this DPA.
4.2 Changes to Sub-processors. DecoverAI will give Customer at least thirty (30) days’ prior written notice by email before adding or replacing a Sub-processor that will Process Customer Personal Data. Customer may object on reasonable data protection grounds by notifying DecoverAI in writing within thirty (30) days of that notice, stating the grounds for the objection. The parties will work in good faith to resolve the objection; if they cannot agree on a resolution within ninety (90) days of DecoverAI receiving the objection, Customer may terminate the affected Services on written notice, without liability to either party and without prejudice to fees already incurred. To subscribe to Sub-processor change notifications, email support@decover.ai.
5. Requests
5.1 Data Subject Rights. Taking into account the nature of the Processing, DecoverAI will provide reasonable assistance to Customer in responding to requests from data subjects and from supervisory or regulatory authorities relating to the Processing of Customer Personal Data, to the extent Customer cannot independently address the request through the functionality of the Services and to the extent the relevant information is known to DecoverAI. If DecoverAI receives such a request directly, it will not respond to the substance of the request without Customer’s prior authorization, other than to acknowledge receipt and direct the requester to Customer. Where DecoverAI is legally required to respond, or Customer does not respond within the timeframe the law requires, DecoverAI may respond using the information known to it.
5.2 Third-Party Requests. Unless prohibited by law, DecoverAI will promptly notify Customer of any valid and enforceable subpoena, warrant, or court order from law enforcement or a supervisory, regulatory, or public authority compelling disclosure of Customer Personal Data, so that Customer may seek a protective order or other appropriate remedy. Given the privileged and confidential nature of much of the material processed through the Services, DecoverAI will, where legally permitted, redirect such requests to Customer and will not produce Customer Personal Data before Customer has had a reasonable opportunity to respond. Where DecoverAI is legally prohibited from notifying Customer and, after careful assessment, concludes there are reasonable grounds to consider the demand or the prohibition unlawful, DecoverAI will take commercially reasonable steps to challenge it. Nothing in this DPA requires DecoverAI to take or refrain from any action that would expose it to civil or criminal penalty, including contempt of court.
6. Deletion and Return of Customer Personal Data
Customer may access, export, or delete Customer Data at any time during the Subscription Term through the functionality of the Services. Following expiration or termination of the Subscription Term, Customer has thirty (30) days to export its Customer Data, and may request return or deletion of all Customer Data (including Customer Personal Data) by written request to support@decover.ai. DecoverAI will delete Customer Data from production systems, and instruct its Sub-processors to do the same, within thirty (30) days of the request or the end of the export window, whichever is earlier; deletion from encrypted backup and archival systems may take up to a further ninety (90) days. Deletion is performed using secure erasure methods consistent with NIST SP 800-88. On request, DecoverAI will provide written certification of deletion. DecoverAI may retain Customer Personal Data where required by Applicable Data Protection Law or other legal obligation, provided that it continues to maintain the confidentiality of the retained data, applies the protections of this DPA to it, and does not Process it further except as that law requires.
7. Audit
7.1 Audit Reports. The DecoverAI platform is audited on a recurring basis by independent third-party auditors. On request, and subject to Customer being bound by a non-disclosure agreement with DecoverAI, DecoverAI will make available a copy of its current SOC 2 Type II report, penetration test summary, and other relevant audit reports (each, a “Report”) through our Trust Center, so that Customer can verify DecoverAI’s compliance with the standards against which it has been assessed and with this DPA. Reports are DecoverAI’s Confidential Information. Where a Report does not allow Customer reasonably to verify compliance with this DPA, DecoverAI will, no more than once every twelve (12) months, provide written responses on a confidential basis to reasonable requests for information from Customer or Customer’s supervisory or regulatory authority relating to DecoverAI’s Processing of Customer Personal Data.
7.2 On-Site Audits. Only where Customer cannot reasonably verify DecoverAI’s compliance with this DPA through the rights in Section 7.1, or where Applicable Data Protection Law requires it, Customer may request to audit DecoverAI’s controls relating to the Processing of Customer Personal Data. To the extent permitted by law, any such audit must (i) take place during DecoverAI’s regular business hours; (ii) be preceded by at least thirty (30) days’ written notice, unless Applicable Data Protection Law or a supervisory authority requires otherwise; (iii) be conducted so as to minimize disruption to DecoverAI’s business, employees, and other customers; (iv) be conducted on a confidential basis and not extend to the data or systems of other customers; (v) occur no more than once every twelve (12) months; and (vi) be limited to information relevant to the Processing of Customer Personal Data. Except where the audit reveals that DecoverAI is in breach of this DPA or Applicable Data Protection Law, Customer will reimburse DecoverAI’s reasonable out-of-pocket expenses in supporting the audit.
7.3 Data Protection Impact Assessments. On Customer’s written request, DecoverAI will provide reasonable cooperation and assistance needed for Customer to carry out data protection impact assessments and related prior consultations with supervisory authorities in respect of Customer’s use of the Services, to the extent Customer does not otherwise have access to the relevant information and to the extent that information is available to DecoverAI.
8. Regional Specific Provisions
Customer Personal Data is hosted in the United States at all times. Customer acknowledges and agrees that DecoverAI and its Sub-processors may otherwise Process Customer Personal Data in any location where they maintain data processing operations, to the extent reasonably necessary to provide and support the Services, subject to the transfer safeguards set out in Schedule 2. Where DecoverAI Processes Customer Personal Data protected by Applicable Data Protection Law in one of the regions listed in Schedule 2 (Region-Specific Terms), the terms specified for that region also apply.
9. General
9.1 Applicability of the Agreement. This DPA is governed by, and construed in accordance with, the governing law and jurisdiction provisions of the Agreement, unless Applicable Data Protection Law requires otherwise, and in that event only for the purposes of this DPA and only in respect of that jurisdiction. Any ambiguity in this DPA will be resolved so as to permit the parties to comply with Applicable Data Protection Law. Where an express term of this DPA conflicts with the Agreement, this DPA controls as to that term; the Agreement controls in all other respects, including as to notice, assignment, severability, and the relationship of the parties.
9.2 Liability Caps and Damages Waiver. To the maximum extent permitted by Applicable Data Protection Law, each party’s total cumulative liability arising out of or relating to this DPA is subject to the exclusions, waivers, and limitations of liability set out in the Agreement.
9.3 Related-Party Claims. Any claim against DecoverAI arising out of or relating to this DPA may be brought only by the entity that is a party to the Agreement or applicable Order Form.
9.4 Changes to this DPA. DecoverAI may update this DPA from time to time to reflect changes in law, the Services, or its Sub-processors. Where a change materially reduces Customer’s rights or DecoverAI’s obligations, DecoverAI will provide at least thirty (30) days’ prior notice by email or in-product notification. The version in force is the one published at decover.ai/legal/dpa as of the effective date shown above.
Description of Processing
| Element | Description |
|---|---|
| Categories of data subjects | Customer determines and controls the categories of data subjects whose Personal Data is transmitted to the Services. These typically include Customer’s employees and contractors, its clients and their personnel, custodians, opposing parties and their representatives, witnesses, and other individuals whose communications or documents appear in a matter. Customer will not make available any category of data subject for which it does not have the rights required by Applicable Data Protection Law, unless the data is anonymized in accordance with that law. |
| Subject matter | Personal Data that Customer elects to transfer to DecoverAI in connection with DecoverAI’s performance of the Services under the Agreement. |
| Types of Personal Data | Limited to the types of Personal Data necessary for the Services, which may include names, job titles, business and personal contact details, email and chat message content, document contents and metadata, and other identifying information contained in collected material. Customer has sole discretion over the types of Personal Data it transmits, including any sensitive or special-category data. |
| Nature of the Processing | Ingestion, hosting, indexing, search, AI-assisted classification and review, privilege and confidentiality analysis, redaction, production, export, and deletion, together with related support, security, and backup operations. |
| Purpose of the Processing | To provide, maintain, secure, and support the Services in accordance with the Agreement and Customer’s documented instructions. Customer Personal Data is not used to train, fine-tune, or improve any AI model. |
| Duration and frequency | Continuous for the duration of the Subscription Term, and thereafter only as set out in Section 6 of this DPA. |
| Sub-processors | As listed at decover.ai/legal/subprocessors, for the durations and purposes described there. |
Region-Specific Terms
1. Data Privacy Framework
To the extent DecoverAI has self-certified to, and remains an active participant in, the applicable part of the Data Privacy Framework, DecoverAI may receive and Process Customer Personal Data transferred from the European Economic Area, the United Kingdom, Gibraltar, or Switzerland to the United States in reliance on that framework, and will comply with the applicable Data Privacy Framework Principles for Customer Personal Data received under it. If DecoverAI is no longer able to rely on the Data Privacy Framework for a transfer, it will notify Customer and the parties will rely on another valid transfer mechanism under Applicable Data Protection Law, including the SCCs and, where applicable, the UK Addendum.
2. Transfers outside the European Economic Area
In connection with any transfer of Customer Personal Data from the EEA or Switzerland to a country that is not the subject of an adequacy decision of the European Commission or the Swiss Federal Data Protection and Information Commissioner, DecoverAI agrees to abide by the SCCs, which are incorporated into this DPA by reference and completed as follows:
2.1 Module Two (Controller to Processor) applies where Customer is the Controller of Customer Personal Data, and Module Three (Processor to Processor) applies where Customer is a Processor of Customer Personal Data.
2.2 For Clause 7, the optional docking clause does not apply.
2.3 For Clause 9(a), Option 2 (general written authorization) applies, and the period for prior notice of Sub-processor changes is as set out in Section 4.2 of this DPA.
2.4 For Clause 9(c), where confidentiality restrictions prevent DecoverAI from providing a copy of a Sub-processor agreement, DecoverAI will provide, on a confidential basis, all information about that agreement that it reasonably can.
2.5 For Clause 11(a), the optional independent dispute resolution language does not apply.
2.6 For Clause 13 and Annex I.C, Customer will maintain accurate records of the applicable Member State(s) and competent supervisory authority, and will make those records available to DecoverAI on request.
2.7 For Clause 17, Option 1 applies and the SCCs are governed by the law of Ireland.
2.8 For Clause 18(b), disputes are to be resolved before the courts of Ireland.
2.9 For Annex I.A, the “data importer” is DecoverAI and the “data exporter” is Customer.
2.10 For Annex I.B, the description of the transfer is as set out in Schedule 1 of this DPA.
2.11 For Annex II, the technical and organizational measures are those described in Section 3.1 of this DPA and on the DecoverAI Security page.
2.12 For Annex III, the Sub-processors are those identified in accordance with Section 4.1 of this DPA.
For transfers subject to the Swiss FADP, references to the GDPR are to be understood as references to the Swiss FADP, the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner, and the term “Member State” does not prevent data subjects in Switzerland from bringing proceedings in their place of habitual residence.
3. United Kingdom
For transfers of Customer Personal Data from the United Kingdom or Gibraltar to the United States that are not covered by the UK Extension to the EU–U.S. Data Privacy Framework or another valid adequacy mechanism, DecoverAI agrees to abide by the SCCs as set out in Section 2 of this Schedule 2, as modified and interpreted by Part 2 (Mandatory Clauses) of the UK Addendum, which is incorporated into and forms an integral part of this DPA for the purposes of those UK transfers. Any conflict between the SCCs and the UK Addendum is resolved in accordance with Sections 10 and 11 of the UK Addendum. Tables 1 to 3 in Part 1 of the UK Addendum are completed with the information set out in Schedule 1 of this DPA, and Table 4 is deemed completed by selecting “neither party.”
4. Precedence of the Standard Contractual Clauses
Neither party intends this DPA to contradict or restrict the SCCs, and it does not have that effect. If an express term of this DPA conflicts with the SCCs, the SCCs control as to that term, but only to the extent of the conflict.
5. Alternative Transfer Mechanisms
If DecoverAI adopts, maintains, or becomes eligible to rely on another valid transfer mechanism for the transfers described in this Schedule 2 — including the Data Privacy Framework, an adequacy decision, an updated version of the SCCs, binding corporate rules, or another mechanism recognized under Applicable Data Protection Law — that mechanism will apply to the relevant transfer to the extent it provides a lawful basis for it. If the mechanism relied upon is invalidated or is otherwise no longer available, the parties will work in good faith to put an alternative lawful mechanism in place without undue delay.
6. United States
Where DecoverAI Processes Customer Personal Data subject to US Privacy Laws, DecoverAI acts as a “service provider,” “processor,” or equivalent, and the restrictions in Section 2.1 of this DPA apply. DecoverAI does not sell or share Customer Personal Data, does not use it for cross-context behavioral advertising, and does not retain, use, or disclose it except as necessary to perform the Services or as otherwise permitted by US Privacy Laws. DecoverAI will grant Customer the rights it needs to take reasonable and appropriate steps to help ensure that DecoverAI uses Customer Personal Data in a manner consistent with Customer’s obligations under US Privacy Laws, and to stop and remediate any unauthorized use. Where Applicable Data Protection Law imposes obligations on DecoverAI in respect of sensitive personal information, DecoverAI will Process such data only for the purposes permitted by that law.
7. Canada
Where DecoverAI Processes Customer Personal Data subject to Canadian Privacy Laws, DecoverAI Processes it only for the purposes described in Schedule 1, maintains safeguards appropriate to the sensitivity of the information, and acknowledges that Customer Personal Data will be stored and Processed in the United States and may therefore be accessible to U.S. authorities under lawful process, as described in Section 5.2 of this DPA. DecoverAI will assist Customer in responding to access and correction requests and in meeting any breach reporting or record-keeping obligations Customer owes under Canadian Privacy Laws.
Contact
Questions about this DPA, requests for a countersigned copy or executed Standard Contractual Clauses, and subprocessor change-notification requests should be sent to support@decover.ai. Legal notices may be sent to legal@decover.ai or to DecoverHQ, Inc., 400 Concar Dr, San Mateo, CA 94402.
Related pages: Privacy Policy · Terms of Service · Subprocessors · Security · Trust Center