Legal Data Hunter, Inc. Data Processing Addendum
Effective date: August 23, 2026. This document applies prospectively and does not alter pre-publication records or obligations.
This Data Processing Addendum, the DPA, forms part of the agreement governing the services, the Agreement, between Legal Data Hunter, Inc., LDH, and the customer identified in the Agreement, Customer.
This DPA applies whenever LDH Processes Customer Personal Data on Customer's behalf as a Processor or Subprocessor. It does not apply to Processing for which LDH determines the purposes and means as an independent Controller. Capitalized privacy terms not defined here have the meanings given by Applicable Data Protection Law.
Acceptance, parties, and effective date
The Customer is the person or legal entity identified as the paid subscriber in the applicable online checkout and account records, or the legal entity identified in an Order Form or other Agreement. A person accepting this DPA for an organization represents that they have authority to bind that organization.
This DPA becomes binding when the earliest of the following occurs:
- Customer completes a paid online checkout that identifies and links this DPA and records Customer's acceptance of its applicable version;
- Customer and LDH execute or otherwise validly accept an Order Form or Agreement that incorporates this DPA; or
- Customer and LDH separately execute this DPA.
A separate signature on this DPA is not required for online checkout or an incorporated Order Form. For a signed Order Form, the authorized Customer representative and an authorized representative of Legal Data Hunter, Inc. sign the Order Form. If procurement requires this DPA to be signed separately, the same authorized representatives sign it.
Creating a Free account does not, by itself, constitute acceptance of this DPA. Once accepted, this DPA applies automatically only to activities for which LDH Processes Customer Personal Data as a Processor or Subprocessor. Its substantive Processing obligations begin when that Processing begins and continue for the applicable Processing period.
1. Definitions
Applicable Data Protection Law means privacy and data-protection law applicable to the Processing of Customer Personal Data under the Agreement, including, where applicable, the EU GDPR, UK GDPR, UK Data Protection Act 2018, and applicable U.S. state privacy laws.
Customer Personal Data means Personal Data that LDH Processes on Customer's behalf under the Agreement.
Paid Search Content means: (a) free-text search text and search parameters submitted through a Paid Search request to the extent they reveal the substance of the search, including copies or representations from which that text can reasonably be reconstructed; and (b) the ranked result payload returned for that request. Paid Search Content excludes inputs submitted solely to Resolve Reference, normalized legal references and canonical identifiers maintained by Resolve Reference, public legal documents, ordinary document-retrieval responses, and necessary non-content records. An exclusion from this definition is not an exclusion from privacy, confidentiality, or security obligations.
Restricted Transfer means a transfer of Personal Data that requires an approved transfer mechanism under Applicable Data Protection Law.
SCCs means the standard contractual clauses adopted by European Commission Implementing Decision (EU) 2021/914, as amended or replaced.
Subprocessor means a third party engaged by LDH to Process Customer Personal Data on Customer's behalf.
2. Roles and processing details
2.1 Customer is a Controller and LDH is a Processor when Customer determines the purposes and means of Processing Customer Personal Data.
2.2 If Customer acts as a Processor for another Controller, Customer appoints LDH as its Subprocessor and confirms that it is authorized to give LDH instructions and make that appointment.
2.3 The subject matter, duration, nature, purposes, data categories, and Data Subject categories are described in Annex 1 and any applicable Order Form.
3. Instructions and permitted use
3.1 LDH will Process Customer Personal Data only on Customer's documented instructions, including the Agreement, this DPA, an Order Form, Customer's authorized use and configuration of the services, and authorized support requests.
3.2 LDH may Process Customer Personal Data as required by law. Unless prohibited by law, LDH will inform Customer before that Processing.
3.3 LDH will promptly inform Customer if LDH reasonably believes an instruction violates Applicable Data Protection Law. LDH may suspend the affected Processing while the parties address the issue.
3.4 LDH will not use Customer Personal Data for advertising, profiling, unrelated secondary purposes, or generalized model training, fine-tuning, evaluation, or improvement, except on Customer's express written instruction where lawful. A Subprocessor may Process Customer Personal Data only to provide its disclosed service to LDH under applicable contractual restrictions.
3.5 Paid Search commitment. LDH will not intentionally store Paid Search Content after providing the Paid Search response in its application databases, customer or administrative dashboards, query caches, or intentional content logs. This commitment applies only to Paid Search. Resolve Reference may cache normalized legal references and canonical identifiers. The Resolve Reference cache, limited non-content records, transient infrastructure processing, provider processing, provider exceptions, and retention periods remain subject to the Subprocessor List and applicable retention disclosures.
3.6 Customer is responsible for the lawfulness, accuracy, quality, and minimization of Customer Personal Data and its instructions, including required notices, legal bases, consents, and authorizations.
4. Confidentiality
LDH will ensure that people authorized to Process Customer Personal Data are subject to appropriate confidentiality obligations, receive access only as needed for their responsibilities, and receive appropriate privacy and security instructions. LDH remains responsible for their compliance with this DPA.
5. Security
5.1 LDH will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, implementation costs, nature, scope, context, purposes, and risks of Processing.
5.2 The Legal Data Hunter Technical and Organizational Measures schedule, document key LDH-TOMS, is incorporated as Annex 2. LDH may update the measures if the overall level of protection is not materially reduced.
5.3 Customer is responsible for securely configuring its accounts, credentials, API keys, clients, and integrations, limiting authorized access, revoking unnecessary access, and avoiding unapproved sensitive data.
6. Personal Data Breaches
6.1 LDH will notify Customer without undue delay and, in any event, within 48 hours after becoming aware of a Personal Data Breach affecting Customer Personal Data. LDH will not delay an initial notice solely because its investigation is incomplete.
6.2 Notice may be phased and will include, where known and applicable, the nature of the breach, affected data and Data Subjects, likely consequences, mitigation measures, and a contact for follow-up.
6.3 LDH will take reasonable steps to contain, investigate, remediate, and mitigate the breach and provide material updates as reasonably available.
6.4 Customer is responsible for notices to Supervisory Authorities, Data Subjects, and third parties unless law assigns that duty directly to LDH. LDH will provide reasonable assistance, taking into account the nature of Processing and information available to LDH.
7. Subprocessors
7.1 Customer gives LDH general written authorization to engage the Subprocessors identified in the then-applicable Subprocessor List and new Subprocessors under this Section.
7.2 LDH will impose on each Subprocessor the same data-protection obligations stated in this DPA, to the extent applicable to the entrusted Processing. LDH remains responsible for a Subprocessor's performance as required by Applicable Data Protection Law.
7.3 LDH will provide at least 30 days' advance notice before authorizing an ordinary new or replacement Subprocessor to Process Customer Personal Data. LDH will post the change on a dated Subprocessor List and send notice by email to Customer's designated Privacy and DPA contact in the Order Form, online transaction record, or account record. If Customer has not designated that contact, LDH will use Customer's legal-notice email or, if none is available, the primary account-administrator email.
The 30-day period begins when the email is sent without an automated delivery-failure notice. If LDH receives a delivery-failure notice, LDH will make a reasonable attempt to resend the notice using another recorded Customer contact. LDH will retain the notice content, recipient address, sending timestamp, applicable Subprocessor List version, available provider message identifier, and delivery-failure status as notice evidence. Customer may object during the notice period on reasonable, documented data-protection grounds.
7.4 The parties will work in good faith to address a valid objection. If no commercially reasonable alternative is available, either party may terminate the affected services, and LDH will refund prepaid fees allocable to the terminated period.
7.5 For Processing not governed by the SCCs, LDH may use shorter notice when strictly necessary to address an immediate security, legal-compliance, or service-continuity emergency. LDH will give notice as soon as reasonably practicable. Where the SCCs apply, SCC Clause 9 controls.
8. Data Subject requests
Taking into account the nature of Processing, LDH will provide reasonable assistance through appropriate technical and organizational measures to help Customer respond to Data Subject requests. If LDH receives a request concerning Customer Personal Data, LDH will, where legally permitted, direct the requester to Customer, notify Customer, and respond substantively only on Customer's documented instructions or as required by law.
9. Compliance assistance
Taking into account the nature of Processing and information available, LDH will provide reasonable assistance with Customer's obligations concerning Processing security, breach assessment and notification, data-protection impact assessments, and prior consultation with a Supervisory Authority. LDH will make available information reasonably necessary to demonstrate compliance with applicable Processor obligations.
10. Audits
10.1 Customer may request one audit in any 12-month period and additional audits only following a material Personal Data Breach affecting Customer Personal Data, reasonable documented evidence of material non-compliance, or a binding regulator request or requirement.
10.2 Customer will first use current documentation, questionnaires, reports, and remote information reasonably made available by LDH. Further review is permitted where that material is reasonably insufficient.
10.3 Unless urgency is legally required, Customer will give at least 30 days' written notice. An audit must be proportionate, targeted to Customer Personal Data and the specific compliance issue, conducted during normal business hours, and designed to avoid disruption, security risk, and access to another customer's data, LDH source code, privileged material, or unrelated systems. No penetration test, vulnerability scan, production access, or on-site inspection is permitted without LDH's prior written approval. The auditor must be independent, qualified, bound by confidentiality, and not a competitor of LDH.
10.4 Customer bears all costs of an audit requested by or for Customer, including its auditor and advisers and LDH's reasonable internal time, professional fees, Subprocessor charges, travel, hosting, extraction, redaction, supervision, and other out-of-pocket costs. LDH may require advance payment or a reasonable deposit before assistance beyond standard documentation begins. This allocation applies regardless of the audit outcome, except to the minimum extent mandatory law or the SCCs expressly requires otherwise.
10.5 Customer must not use an audit to harass, burden, disrupt, benchmark, reverse engineer, obtain competitive information, access unrelated data or systems, or repeat a request already reasonably answered by current documentation. LDH may refuse, pause, or narrow an abusive, duplicative, disproportionate, unsafe, or legally impermissible audit request while providing the minimum access or information required by mandatory law or the SCCs.
11. Return and deletion
11.1 The End of Processing Services occurs when the applicable DPA-covered Paid Service or Order Form expires or terminates, Customer closes the applicable account or workspace, or Customer validly instructs LDH to stop the relevant Processing, whichever first ends LDH's role as Processor or Subprocessor for that Processing. On the End of Processing Services, LDH will, at Customer's choice and where return is reasonably available, return Customer Personal Data and delete remaining copies, or delete Customer Personal Data and all copies, unless law requires storage. If Customer makes no choice, LDH will delete the data subject to applicable law.
11.2 Subject to Sections 11.3 and 11.4, LDH will delete Customer Personal Data from active systems within 60 days after the End of Processing Services or, where Customer first requests return, within 60 days after completing the return. Customer Personal Data remaining solely in access-restricted backup copies will be put beyond ordinary use and deleted or overwritten no later than 90 days after the applicable deletion from active systems and, in any event, no later than 150 days after the End of Processing Services or, where Customer first requests return, no later than 150 days after completing the return. These requirements apply to LDH and its Subprocessors to the extent they Process Customer Personal Data on Customer's behalf.
11.3 Canceling a Paid subscription does not by itself close Customer's account. If the account remains available as a Free account, LDH may continue Processing ordinary account, authentication, security, and service-administration data as an independent Controller under the Privacy Notice. Customer must use a self-service account-closure function if one is available or otherwise send an authenticated closure request to end that continuing account relationship.
11.4 LDH may retain limited contract, billing, tax, fraud, security, acceptance, deletion-evidence, and legal-claim records as an independent Controller where required or reasonably necessary, subject to applicable law.
11.5 Customer Personal Data retained temporarily in backups will remain protected under this DPA, will not be restored or used for ordinary commercial Processing, and, if restored for disaster recovery or legal necessity, will have the applicable deletion instruction reapplied before ordinary Processing resumes where practicable.
12. U.S. state privacy laws
To the extent an applicable U.S. state privacy law treats LDH as a processor, service provider, or contractor for Customer Personal Data, LDH will:
- Process the data only for the limited and specified purposes stated in the Agreement and Customer's documented instructions;
- provide the same level of privacy protection required by the applicable law;
- not sell or share the data, use it for targeted or cross-context behavioral advertising, or retain, use, or disclose it outside the direct business relationship, except as permitted by law and the Agreement;
- not combine it with Personal Data received from another person or collected from LDH's own interaction with a consumer, except as permitted by law;
- notify Customer if LDH determines it can no longer meet an applicable obligation; and
- permit Customer to take reasonable and appropriate steps to verify, stop, and remediate unauthorized use as required by law.
This Section applies only to the extent the relevant state privacy law governs the Processing. If a mandatory state-law term is not already addressed by this DPA, the parties will apply it to the minimum extent required by that law.
13. Sensitive data
Customer may submit ordinary privileged or confidential legal-research inputs through Paid Services where authorized and reasonably necessary. LDH will treat those inputs as Customer Personal Data and Confidential Information where applicable and will not use them or authorize a Subprocessor to use them for generalized model training or unrelated purposes. Customer remains responsible for authority, minimization, privilege, work product, professional secrecy, and confidentiality. LDH does not guarantee that use of a third-party hosted service preserves privilege, work product, or professional secrecy in every jurisdiction.
Customer must not intentionally submit special-category data, criminal-offence data, health or biometric data, financial-account credentials, government identifiers, children's data, export-controlled data, or other highly sensitive regulated data unless an Order Form expressly authorizes the categories, Processing, and safeguards.
14. International transfers
Where an EU/EEA or UK business Customer makes Customer Personal Data available to LDH as Processor or Subprocessor, the parties will treat that disclosure as a Restricted Transfer unless an applicable adequacy decision or another lawful transfer mechanism applies. EEA processing locations and restricted non-EEA access are supplementary safeguards but do not, by themselves, determine whether a Restricted Transfer occurs. Where contractual safeguards are required, this DPA automatically incorporates the applicable SCC module and, for a UK Restricted Transfer, the UK Addendum through the International Data Transfer Completion Schedule.
14.1 The International Data Transfer Completion Schedule is incorporated automatically by the same paid online clickwrap or Order Form that incorporates this DPA. No separate signature, transfer questionnaire, role selection, or additional checkout assent is required. LDH records the existing acceptance timestamp, account identity, Order Form facts, document versions and hashes, and available account or billing information as internal execution evidence.
14.2 SCC Module 2 applies automatically to Processing for which Customer is a Controller and LDH is a Processor. SCC Module 3 applies automatically to Processing for which Customer is a Processor and LDH is a Subprocessor. If Customer acts in both roles for different Processing, each module applies to the Processing governed by that role. The parties' actual roles under Sections 2.1 and 2.2 control; a checkout classification does not.
14.3 For a UK Restricted Transfer relying on the EU SCCs, the then-current approved UK International Data Transfer Addendum is incorporated automatically. The Schedule completes its Part 1 Tables from the Agreement, DPA, account and Order Form records, and the fixed elections in that Schedule. Customer-specific information already held in account or billing records is used where available. A customer-specific enterprise variation belongs in the applicable Order Form or enterprise agreement and is not a condition of self-serve checkout.
14.4 The SCCs and UK Addendum are present fallback mechanisms and apply only when legally required. LDH does not rely on or represent participation in the EU-U.S. Data Privacy Framework, UK Extension, or Swiss-U.S. Data Privacy Framework unless LDH has separately completed and verified the applicable certification.
14.5 LDH will provide reasonable information for transfer assessments, notify Customer if it can no longer comply with an applicable transfer mechanism, review legally binding public-authority requests, challenge unlawful or disproportionate requests where reasonably available, disclose only legally required data, and notify Customer unless prohibited by law.
15. Liability, duration, and precedence
15.1 Liability under this DPA is subject to the exclusions and aggregate caps in the Agreement, except where Applicable Data Protection Law prohibits limitation.
15.2 This DPA continues while LDH Processes Customer Personal Data on Customer's behalf.
15.3 This DPA controls over the Agreement regarding Processing of Customer Personal Data. The SCCs control over both to the extent of conflict.
15.4 Except for the SCCs and mandatory Applicable Data Protection Law, this DPA follows the Agreement's governing-law and dispute provisions.
15.5 This DPA follows any assignment, transfer, or delegation of the applicable Agreement permitted under that Agreement, provided that the assignee assumes the applicable data-processing obligations in writing and implements any transfer mechanism required by Applicable Data Protection Law. No assignment, transfer, or delegation reduces Customer's rights under this DPA or displaces the SCCs or another mandatory transfer instrument.
Annex 1: Processing details
| Item | Description |
|---|---|
| Subject matter | Provision, authentication, security, support, administration, and termination of contracted LDH services |
| Duration | The Agreement term plus verified deletion, backup, legal, security, and recordkeeping periods |
| Nature and purpose | Receive authorized requests; authenticate and authorize users; provide selected search, retrieval, citation, reference-resolution, API, MCP, support, and security functions; transmit responses; administer usage; return or delete data |
| Data Subjects | Customer personnel, administrators, authorized users, clients, contacts, and other individuals whose Personal Data Customer lawfully submits |
| Customer Personal Data | Account and authentication identifiers; IP, device, session, security, API-key, connected-client, endpoint, timestamp, status, request ID, and usage metadata; support communications; query and result content where submitted; derived representations where generated |
| Sensitive data | Ordinary privileged or confidential legal-research inputs are permitted for Paid Services under Section 13; other highly sensitive regulated categories are not authorized unless an Order Form expressly states the categories, Processing, and safeguards |
| Frequency | Continuous or intermittent according to Customer's use |
| Retention | Paid Search Content as stated in Section 3.5; Resolve Reference may temporarily cache normalized legal references and parsed results; Customer Personal Data is deleted from active systems within 60 days after the applicable trigger, while access-restricted backup copies are deleted or overwritten no later than 90 days after the applicable deletion from active systems and, in any event, no later than 150 days after the End of Processing Services or, where Customer first requests return, no later than 150 days after completing the return; limited independent-Controller records follow the Privacy Notice and Section 11.4 |
Annex 2: Technical and organizational measures
The Legal Data Hunter Technical and Organizational Measures schedule, document key LDH-TOMS, is incorporated into this DPA.
Annex 3: Subprocessors and transfers
The dated Subprocessor List and International Data Transfer Completion Schedule are incorporated here when applicable.
Sources
- Regulation (EU) 2016/679, especially Articles 28, 32, 33, and 44 to 49: https://eur-lex.europa.eu/eli/reg/2016/679/oj
- European Commission Implementing Decision (EU) 2021/914: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj