Data Processing Addendum
Effective date: September 7, 2026
This Addendum forms part of the Terms & Conditions between IDT Solutions LLC (“Processor”) and the firm or individual using the Service (“Controller”), and applies whenever Customer Data includes personal data. It takes effect automatically on acceptance of the Terms; no signature is required, though we will sign a copy on request.
Who is who
You are the controller. You decide what to upload, whose data it concerns, and why. We are the processor. We act only on your instructions, and using the Service is the instruction. We never determine the purpose of processing your matter data.1. Subject matter and duration
We process personal data for as long as you keep it in the Service. Evidence-extraction uploads and reports are deleted automatically 24 hours after creation. Matter documents and analyses are retained for the life of the matter and deleted when you delete them, or within 30 days of account termination.
On deletion, content is removed from the Service immediately — including the passages indexed from a document, so it can no longer be retrieved or cited — and purged from storage within 24 hours. Encrypted database backups may retain document metadata and generated analysis for up to 35 days before rolling off; they exist only to recover from a failure and are not used for any other purpose.
We retain the BILLING RECORD of deleted work: what was charged, the rate applied, and the matter name and dates it related to, marked as deleted by you. This is a financial record we are required to keep and which allows any charge to be explained. It contains no document text and no analysis.
2. Nature and purpose of processing
- storing and retrieving files you upload;
- extracting text, including optical character recognition of scanned documents;
- generating numeric representations of text for search within a single matter;
- sending retrieved passages to AI models to produce draft analysis;
- generating reports, and recording who approved them;
- maintaining an audit trail of actions taken in your account.
3. Categories of data subject and personal data
Determined entirely by you. In practice this typically includes your firm’s personnel, your clients, opposing parties, witnesses, deponents and third parties whose communications appear in evidence. Data may include names, contact details, message content, financial information, and — depending on the matter — special categories such as health information. We do not require, request, or separately process special-category data; it is simply whatever your documents contain.
4. Our obligations
- Process only on documented instructions. We will not process Customer Data for our own purposes, and specifically will not use it to train or improve any model.
- Confidentiality. Personnel with access are bound by confidentiality obligations, and access to production data is limited to what operating the Service needs.
- Security. Encryption in transit and at rest, per-firm and per-matter isolation, least-privilege access, short-lived download links, and an append-only audit trail. Each matter’s search index is physically separate.
- Sub-processors. Listed at /subprocessors, with at least 30 days’ notice before any addition and a right to object.
- Assistance. We will help you respond to data-subject requests, and with data-protection impact assessments and regulator enquiries, so far as the Service allows.
- Deletion. On termination, and on request, we delete Customer Data. Audit and payment records are retained where law requires.
- Audit. We will answer reasonable security questionnaires and provide available documentation. Physical audits of AWS facilities are not within our gift.
5. Personal data breach
We will notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting your Customer Data, with the information available at the time, and will update you as the picture becomes clearer. Notice goes to the firm owner’s email address, so keep it current.
6. International transfers
The Service operates in the United States (AWS us-east-1). Customer Data is not transferred outside the United States in the ordinary course. If you are subject to UK or EU data protection law, you are responsible for establishing a lawful transfer mechanism for sending data to us; we will enter into Standard Contractual Clauses on request.
7. Your obligations
You warrant that you have a lawful basis and all necessary authority, rights, consents or legal process to upload and process the personal data you provide — including third-party communications contained in a phone backup, which frequently include people who are not your client and have not consented. You are responsible for providing any notices data subjects are owed, and for not uploading data you have no right to hold.
8. Liability
Each party’s liability under this Addendum is subject to the limitations and exclusions in the Terms & Conditions.
9. Conflict
Where this Addendum conflicts with the Terms & Conditions in relation to the processing of personal data, this Addendum prevails.
10. Contact
Data protection enquiries, signed copies, and Standard Contractual Clauses: ap@idtsol.com or +1 954-604-4098.