Legal Data Hunter Technical and Organizational Measures
Effective date: August 11, 2026. This document applies prospectively and does not alter pre-publication records or obligations.
This Schedule applies only when LDH acts as a Processor or Subprocessor under the DPA. It describes measures used to protect Customer Personal Data in that role and serves as DPA Annex 2 and, where required, SCC Annex II. It does not apply to website visitors, Free users, LDH's independent-Controller processing, or public legal-data delivery merely because those activities use LDH services.
The measures apply according to the Service, Processing, and risks involved. They reduce risk but do not guarantee that every incident will be prevented.
1. Data minimization
- LDH limits stored operational data to information reasonably needed for accounts, authentication, authorization, usage limits, billing, security, support, reliability, legal compliance, and service administration.
- LDH's usage records contain operational metadata such as account identifier, network address, route, status, plan, and timestamp, rather than query bodies or result payloads. Identifiable usage rows are subject to an automated 90-day deletion routine.
- LDH configures its error-monitoring integration to remove request bodies and query strings; filter authorization, cookie, and API-key headers; disable default personal-data collection; and exclude local variables.
- The Paid Search non-storage commitment is governed by DPA Section 3.5.
2. Identity and access control
- Protected API and administrative functions require authentication and applicable authorization.
- Administrative account-deletion functions require administrator authentication.
- API keys are generated using a cryptographically secure random generator. LDH stores a one-way hash and short display prefix rather than the complete key. The complete key is returned only when it is created.
- API keys may be revoked. Account and plan permissions are checked when protected requests are made.
- OAuth state and login-continuation cookies are configured as Secure, HttpOnly, short-lived, and SameSite=Lax.
- Production access is limited to authorized personnel and service providers with a legitimate operational need.
3. Communications and credentials
- LDH's production hosting configuration redirects public application traffic to HTTPS.
- Credentials and provider secrets are supplied through protected deployment configuration rather than intentionally embedded in public application code.
- Customers are responsible for protecting their own accounts, API keys, clients, and integrations and for promptly revoking credentials that may be compromised.
4. Application protection and monitoring
- LDH applies account or user request limits to protected billable functions to reduce abuse and protect service availability.
- LDH uses error and performance monitoring to identify operational failures and investigate incidents while applying the data-minimization controls in Section 1.
- LDH uses source control, review, automated testing where available, and controlled deployment processes for material application changes.
- LDH reviews material vulnerabilities and security updates according to risk and available provider and dependency information.
5. Infrastructure and availability
- LDH uses managed infrastructure providers identified in the Subprocessor List.
- The production application configuration uses health checks and more than one application machine, subject to provider availability and maintenance.
- LDH relies on its infrastructure providers for physical data-center security, underlying network and hardware controls, and provider-managed storage protections. LDH does not represent that it operates those physical facilities.
6. Incident response
LDH will receive and assess security reports, take reasonable containment and remediation steps, preserve appropriate evidence, evaluate notification duties, and notify affected Customers of a Personal Data Breach as required by the DPA. Initial notice may precede completion of the investigation.
7. Retention and deletion
- LDH returns or deletes Customer Personal Data as required by DPA Section 11.
- Customer Personal Data retained temporarily in protected backups or by a Subprocessor remains protected until deletion or expiry under the DPA and applicable provider terms.
- Records LDH retains as an independent Controller are outside this Schedule and are governed by DPA Section 11.4 and the Privacy Notice.
8. Personnel and provider management
- Persons authorized to access Customer Personal Data are subject to appropriate confidentiality duties and receive access according to their role and operational need.
- LDH maintains a public Subprocessor List and requires applicable data-protection obligations from Subprocessors.
- LDH may update these measures under DPA Section 5.2 only if the overall level of protection is not materially reduced.