Data Processing Agreement

LegalFormsOS — Data Processing Agreement (DPA)

Last updated: 2026-07-14. Version: 2026-07-14. This DPA forms part of the Terms of Service between LegalFormsOS ("Processor") and the customer ("Controller") and governs LegalFormsOS's processing of personal data on the Controller's behalf. Where the GDPR/UK GDPR or a U.S. state privacy law applies, this DPA controls over any conflicting term.

1. ROLES. For the personal data a Controller enters about its own clients and matters ("Customer Personal Data"), the Controller is the controller and LegalFormsOS is the processor. LegalFormsOS processes Customer Personal Data only on the Controller's documented instructions (which include using the Service as intended), except where law requires otherwise.

2. SUBJECT-MATTER, NATURE & PURPOSE. Processing consists of hosting, storing, generating documents from, and securing the data the Controller submits, for the purpose of providing the Service. Duration: for the term of the account plus the retention periods in the Privacy Policy.

3. CATEGORIES OF DATA & DATA SUBJECTS. Data subjects: the Controller's clients and their household/parties (e.g., spouses, children referenced in family-law forms). Data: identity, contact, financial, and family-law matter data, which may include special-category data and sensitive identifiers (e.g., Social Security numbers). Sensitive identifiers are encrypted at rest and are render-only (never logged, indexed, exported to analytics, or exposed in search).

4. LegalFormsOS'S OBLIGATIONS. LegalFormsOS will: (a) process Customer Personal Data only on documented instructions; (b) ensure personnel are bound by confidentiality; (c) implement the technical and organizational security measures in Annex A; (d) respect the sub-processor terms in Section 5; (e) assist the Controller, taking into account the nature of processing, with data-subject requests and with the Controller's obligations under Articles 32–36 GDPR; (f) at the Controller's choice, delete or return Customer Personal Data at the end of the relationship, subject to legal retention; and (g) make available information reasonably necessary to demonstrate compliance and allow for audits (Section 7).

5. SUB-PROCESSORS. The Controller authorizes LegalFormsOS to engage sub-processors listed at /p/subprocessors (e.g., hosting, email delivery, payment processing). LegalFormsOS imposes data-protection obligations on each sub-processor no less protective than this DPA and remains liable for their performance. LegalFormsOS will give notice of intended changes and the Controller may object on reasonable data-protection grounds.

6. INTERNATIONAL TRANSFERS. Customer Personal Data is stored in the United States. Where a transfer is subject to the GDPR/UK GDPR, the parties rely on the applicable Standard Contractual Clauses (or a valid successor mechanism), which are incorporated by reference.

7. AUDITS & EVIDENCE. On reasonable prior request and no more than once per year (or after a material incident), LegalFormsOS will provide its current security self-assessment (the 13-layer audit report), its deletion/data-cascade map, its incident-response summary, and answers to a reasonable security questionnaire. On-site audits, where required by law, are by prior appointment, during business hours, under confidentiality, and without compromising other customers' data.

8. PERSONAL-DATA BREACH. LegalFormsOS will notify the Controller without undue delay (and, where feasible, within 72 hours) after becoming aware of a personal-data breach affecting Customer Personal Data, with the information the Controller reasonably needs to meet its own notification duties. LegalFormsOS's incident-response plan governs internally.

9. DELETION & RETURN. On termination or on the Controller's instruction, LegalFormsOS deletes Customer Personal Data per the Privacy Policy and the deletion map: immediate soft-delete, 30-day recovery window, then permanent, irreversible purge (files securely erased; principals anonymized), retaining only records the law requires.

10. LIABILITY. Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service.

ANNEX A — TECHNICAL & ORGANIZATIONAL MEASURES. Encryption in transit (TLS 1.2+, HSTS) and at rest (field-level AES-256-GCM for sensitive data; strong password hashing via scrypt). Strict tenant isolation (every query scoped by organization). Role-based access control and least privilege. Two-factor authentication. CSRF, strict Content-Security-Policy, and other security headers. Per-IP and per-account rate limiting. Single-use, short-lived download links. Audit logging with PII redaction. Non-root, loopback-bound application behind a hardened reverse proxy (firewall, fail2ban, automatic security updates). Continuous 13-layer security self-assessment; dependency scanning; documented incident-response and data-deletion procedures. A full, re-runnable evidence report is available to the Controller.

Contact: support@legalformsos.com.

Disclaimer

LegalFormsOS is document automation software only — not legal advice, not a law firm, not affiliated with any court or government agency.