Draft for legal review. This text is a working template and is not yet the final agreement.
Data Processing Agreement
Legal CRM · version 2026-10
This agreement forms part of the Terms of Service between the Firm (the Data Fiduciary) and Legal CRM (the Data Processor) for personal data of the Firm’s clients, prospective clients, opposing parties and others that the Firm puts into the service (“Client Data”), under the Digital Personal Data Protection Act, 2023 and its rules.
1. Instructions
We process Client Data only to provide the service as the Firm configures and uses it, and on the Firm’s documented instructions. We do not use Client Data for our own purposes, sell it, or use it to train AI models.
2. Confidentiality and access
Our staff access Client Data only when needed to provide support the Firm asks for or to keep the service secure, under confidentiality obligations. Our operator tools show counts, not client content.
3. Security
- Each firm’s data is isolated at the database level; access within the Firm follows the roles the Firm assigns.
- Encryption in transit and at rest; documents scanned for malware; two-step verification required for administrators.
- An audit log of actions that cannot be edited; daily encrypted backups; tested restore.
4. Sub-processors
The Firm authorises the sub-processors listed on the sub-processors page. We give 30 days’ notice of a new one; the Firm may object and terminate if we cannot accommodate the objection.
5. Location
Client Data is stored in India. Message delivery passes through Meta’s WhatsApp infrastructure, and AI features (when the Firm turns them on) send redacted text to the AI provider listed, as described on the sub-processors page.
6. Personal data breaches
We notify the Firm without undue delay, and in any case within 24 hours of becoming aware of a breach affecting Client Data, with the information the Firm needs to meet its own notification duties to the Data Protection Board and affected persons.
7. Rights requests
The service provides tools to export, correct and delete Client Data and to record and withdraw consent. We help the Firm respond to requests it cannot handle with those tools.
8. Deletion
When the Firm closes its workspace, Client Data is permanently deleted after 30 days, including backups within their rotation period (14 days).
9. Audit
On reasonable notice, once a year, we provide information needed to demonstrate compliance with this agreement.