Legal
Data Processing Agreement
Last updated: June 15, 2026
1. Scope and Purpose
This Data Processing Agreement ("DPA") forms part of the Terms of Service (or separate agreement) between Lawden, Inc. ("Data Processor") and the customer ("Data Controller"). It governs the processing of personal data by Lawden on behalf of the customer in connection with the provision of the Services. This DPA reflects the requirements of applicable data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), as amended.
2. Data Processing Terms
The subject matter of the processing is the provision of the Lawden deal room and matter management platform. The processing is performed on behalf of the Data Controller for the purpose of enabling collaboration, document management, and communication related to legal matters. The categories of personal data processed may include names, email addresses, job titles, firm affiliations, and user activity data. Special categories of data (sensitive data) are processed only to the extent uploaded by the Controller in the course of using the Services. The duration of processing corresponds to the term of the agreement plus the 30-day post-termination retention period.
3. Processor Obligations
Lawden shall process personal data only on documented instructions from the Controller, unless required to do so by applicable law. Lawden shall ensure that persons authorized to process the data are subject to confidentiality obligations. Lawden shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. Lawden shall assist the Controller in fulfilling its obligations regarding data subject rights, data breach notification, and data protection impact assessments.
4. Security Measures
Lawden maintains a comprehensive security program that includes: encryption of data at rest using AES-256 and in transit using TLS 1.3;严格的 access controls based on least privilege principles; regular security testing and vulnerability assessments; 24/7 monitoring with automated threat detection; incident response procedures tested periodically; and personnel background checks where permitted by law. Lawden holds SOC-2 Type II certification and maintains ISO 27001-aligned controls.
5. Sub-processors
The Controller authorizes Lawden to engage the following sub-processors: Amazon Web Services (cloud infrastructure), Stripe, Inc. (payment processing), and Resend, Inc. (email delivery). Lawden will notify the Controller at least 30 days before engaging any new sub-processor. Lawden imposes data protection obligations on all sub-processors that are at least as protective as those in this DPA. Lawden remains fully liable for its sub-processors' compliance.
6. Data Subject Rights
Lawden shall promptly notify the Controller of any request from a data subject to exercise their rights (access, rectification, erasure, restriction, portability, or objection). Lawden shall provide reasonable assistance to the Controller in responding to such requests. Where a data subject makes a request directly to Lawden, Lawden shall direct the request to the Controller and not respond to the request without the Controller's authorization.
7. Data Breach Notification
Lawden shall notify the Controller without undue delay (and in any event within 48 hours) after becoming aware of a personal data breach affecting Controller data. The notification shall include: the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach. Lawden shall cooperate with the Controller in investigating and mitigating the breach.
8. Data Transfers
Personal data processed under this DPA is primarily processed in the United States. For data subjects in the European Economic Area, the United Kingdom, or Switzerland, Lawden relies on Standard Contractual Clauses (2021/914) as an adequate transfer mechanism. A copy of the SCCs is available upon request. Data may also be processed in the EU (Frankfurt region) if the Controller selects EU data residency during setup.
9. Deletion and Return of Data
Upon termination of the agreement, Lawden shall, at the Controller's option, return or delete all personal data within 30 days, unless continued retention is required by applicable law. Lawden may retain aggregated, anonymized data that no longer identifies data subjects. Following deletion, data is permanently removed from all systems, including backups, within 90 days.
10. Contact and Dispute Resolution
Questions or requests under this DPA should be directed to dpo@lawden.dev. Disputes arising under this DPA shall be resolved in accordance with the Governing Law section of the Terms of Service. The Controller may request an audit of Lawden's data processing activities, subject to reasonable notice and confidentiality obligations. Audits shall be conducted no more than once per calendar year.