Data Processing Agreement
Last updated 1 September 2026 — draft, pending solicitor review
This Data Processing Agreement ("DPA") is entered into between the law firm or organisation using Copacetic under a subscription agreement ("Controller", "you") and Copacetic Legal Technologies Ltd, a company registered in England and Wales (No. 14820019), registered office in Sunderland, Tyne and Wear ("Processor", "we"), and forms part of the Terms of Service between the parties.
1. Subject matter and scope
This DPA governs our processing of personal data on your behalf in the course of providing Copacetic, as described in our Privacy Policy. We process personal data only to provide, maintain and support the Service, on your documented instructions, or as required by applicable law.
2. Nature and purpose of processing
Data subjects: your staff, clients, and other individuals whose personal data appears in matters, documents, time entries, calendar entries, or messages within your workspace.
Categories of personal data: names, contact details, matter and case information, documents, time records, and communications — potentially including special category data where included within matter content by you.
Purpose: to provide the practice-management, collaboration and Lutey AI features of the Service.
3. Sub-processors
We engage the sub-processors listed in our published sub-processor list (as updated from time to time). We maintain an up-to-date list, give you at least 14 days' prior notice of any new or replacement sub-processor, impose data protection terms no less protective than this DPA on each one, and remain liable for their acts and omissions as if performed by us directly.
4. Security measures
We implement encryption of data in transit (TLS 1.2+) and at rest (AES-256), Row Level Security (RLS) enforcing workspace-level data isolation, API rate limiting and abuse protection, comprehensive audit logging of workspace and Lutey AI actions, least-privilege internal access controls, and a documented incident response process.
5. Personal data breach notification
We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting your data, providing the information reasonably necessary for you to meet your own notification obligations to the ICO and affected data subjects. You are responsible for assessing whether the breach must be reported.
6. Data subject requests
Where we receive a request from a data subject relating to your Customer Data, we will promptly forward it to you and will not respond directly (save to acknowledge receipt and redirect them), unless you instruct otherwise. We provide reasonable assistance with responding to access, rectification, erasure, portability and objection requests.
7. Data return and deletion on termination
On termination of your subscription, you may export your data for 30 days. After 30 days, we permanently delete all Customer Data, including vault documents, unless retention is required by law. If you request earlier deletion, we will complete it within 72 hours of that request.
8. Audit rights
On reasonable written notice (at least 30 days, save in the case of a suspected breach), and no more than once per 12-month period absent cause, you or your appointed auditor may request evidence of our compliance with this DPA. We may satisfy this by providing existing audit reports, security documentation, or a written questionnaire response.
9. International transfers
Personal data is stored in the UK/EU (Supabase eu-west-2 London; Cloudflare R2 EU). Where a sub-processor's processing involves a transfer outside the UK or EEA, we ensure it is subject to appropriate safeguards, including the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (or successor mechanism).
10. Liability, term and governing law
This DPA takes effect when your subscription commences and continues for as long as we process personal data on your behalf under the Terms of Service. Liability under this DPA is subject to the limitation of liability clause in the Terms of Service. This DPA is governed by the laws of England and Wales.
Questions about this DPA? Contact our Data Protection Officer at privacy@copacetic.legal.
