Data Processing Addendum

  • Effective Date: January 01, 2026
  • Contracting Entity: Legal Husk, a United States business entity doing business as LegalHusk
  • Contact: [email protected]

Marketplace model. LegalHusk operates an online technology marketplace where Clients and independent Professionals meet, communicate, form direct engagements, and work toward the successful completion of Professional Services. LegalHusk facilitates marketplace access, administrative workflows, communications, records, support, and payment administration through third party providers. LegalHusk does not provide Professional Services, is not a law firm, does not employ or supervise Professionals, is not a party to Client and Professional engagements, and does not guarantee any legal, financial, commercial, or other result.

Limited application. This Data Processing Addendum applies only when LegalHusk processes Personal Data solely on a business customer's documented instructions as a processor or service provider. LegalHusk remains an independent controller or business for its own account, security, marketplace, verification, support, analytics, payment administration, legal compliance, and claims activities.

1. Parties and Effective Date

This Data Processing Addendum, referred to as the DPA, is between Legal Husk, a United States business entity doing business as LegalHusk, and the organization identified as the business Customer in the account and authenticated DPA acceptance record, referred to as Customer. It supplements the agreement under which LegalHusk provides Platform Services to Customer, referred to as the Main Agreement.

The DPA takes effect on the later of August 22, 2026 or the date Customer accepts it. If the signatory acts for Customer, the signatory represents that the signatory may bind Customer.

2. Definitions

Applicable Data Protection Law means a law applicable to the Processing addressed by this DPA, including the GDPR, UK GDPR, applicable United States state privacy laws, and implementing regulations.

Controller, Processor, Business, Service Provider, Contractor, Consumer, Data Subject, Personal Data, Personal Information, Process, Sale, Share, and Supervisory Authority have the meanings given by Applicable Data Protection Law. Personal Data includes Personal Information where relevant.

Customer Personal Data means Personal Data that LegalHusk Processes solely on Customer's documented instructions under the Main Agreement and the Processing Details in Annex 1.

LegalHusk Independent Data means Personal Data LegalHusk Processes for its own purposes as described in the Privacy Notice or Main Agreement, including account, identity, credential, marketplace, security, fraud, support, payment administration, analytics, legal compliance, and claims data.

Personal Data Breach means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, as defined by applicable law.

Subprocessor means a person engaged by LegalHusk to Process Customer Personal Data on Customer's behalf.

Restricted Transfer means a transfer of Personal Data that requires a transfer mechanism under Applicable Data Protection Law.

3. Scope and Data Roles

Customer is the Controller or Business and LegalHusk is the Processor, Service Provider, or Contractor only for Customer Personal Data identified in Annex 1. Customer determines the lawful purposes and essential means of that Processing.

LegalHusk is an independent Controller or Business for LegalHusk Independent Data. This DPA does not convert independent Processing into processor activity. A Professional generally acts as a separate Controller, professional custodian, or regulated service provider for matter information used to evaluate or perform Professional Services.

If the parties jointly determine purposes and means for a specific Processing activity, they will enter a separate joint controller arrangement before that activity begins where required.

4. Customer Instructions

LegalHusk will Process Customer Personal Data only on documented instructions from Customer, including the Main Agreement, this DPA, Annex 1, Customer's lawful configuration and use of Platform functions, and additional written instructions accepted by LegalHusk.

LegalHusk may Process Customer Personal Data where required by law. Unless prohibited, LegalHusk will inform Customer of the legal requirement before Processing.

If LegalHusk reasonably believes an instruction violates Applicable Data Protection Law, it will inform Customer and may pause the affected Processing until the parties resolve the concern. LegalHusk is not required to provide legal advice or follow an unlawful instruction.

Additional instructions that materially change scope, cost, security, or technical operation require written agreement and may be subject to reasonable fees.

5. Customer Obligations

Customer represents and warrants that:

  • it has authority and a valid legal basis for Customer Personal Data and instructions;
  • it has provided required privacy notices and obtained required consents;
  • its instructions are specific, lawful, and consistent with the rights of Data Subjects;
  • it will not submit Personal Data unnecessary for the stated purpose;
  • it will configure access, retention, sharing, and security settings appropriately;
  • it will not use the Platform to disclose privileged, confidential, regulated, or sensitive information unlawfully; and
  • it is responsible for responding to Data Subjects and Supervisory Authorities unless this DPA assigns assistance to LegalHusk.

Customer must identify any special legal or security requirement before Processing. LegalHusk does not warrant that a general Platform feature satisfies a sector specific rule that Customer has not disclosed and the parties have not accepted.

6. Processing Requirements

LegalHusk will:

  • Process Customer Personal Data only for the subject, duration, nature, and purpose stated in Annex 1;
  • ensure that authorized personnel are bound by confidentiality;
  • implement appropriate technical and organizational measures;
  • assist Customer with Data Subject requests, security, breach notification, assessments, and consultations as stated in this DPA;
  • maintain records required by Applicable Data Protection Law;
  • delete or return Customer Personal Data at the end of services as stated below; and
  • make information reasonably necessary to demonstrate compliance available to Customer.

LegalHusk will not sell Customer Personal Data, share it for cross context behavioral advertising, retain or use it outside the direct business relationship, or combine it with Personal Data from another source except as permitted by Applicable Data Protection Law and Customer's instructions.

7. Confidentiality

LegalHusk will authorize access only for personnel and Subprocessors who reasonably need Customer Personal Data for the instructed Processing. Authorized persons will be subject to contractual, professional, or statutory confidentiality obligations.

LegalHusk will provide appropriate privacy and security training and will apply access removal procedures when access is no longer required.

Customer must treat nonpublic security, audit, and Subprocessor information received from LegalHusk as confidential and use it only to assess the services and comply with law.

8. Security Measures

Taking account of technology, implementation cost, nature, scope, context, purposes, and risk, LegalHusk will maintain appropriate administrative, technical, and physical safeguards. The baseline measures are described in Annex 2.

LegalHusk may update safeguards to reflect technology and risk, provided the overall level of protection is not materially reduced during the Main Agreement.

Customer is responsible for account administration, authorized Users, role assignment, device security, secure authentication, lawful sharing, downloaded copies, and its own systems. Customer must notify LegalHusk promptly of suspected account compromise or vulnerability.

9. Personal Data Breach

LegalHusk will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. Where feasible, LegalHusk will provide initial notice within forty eight hours after confirmation, but this operational target does not change any shorter period required by law.

Notice will include available information concerning the nature of the breach, affected data and persons, likely consequences, containment and remediation, and a contact for follow up. LegalHusk may provide information in phases as the investigation continues.

LegalHusk will take reasonable steps to contain, investigate, mitigate, remediate, and prevent recurrence. Customer is responsible for deciding whether to notify Data Subjects or authorities, except where law directly requires LegalHusk to notify.

Notification is not an admission of fault or liability. Customer will coordinate public statements with LegalHusk where reasonably practicable and lawful.

10. Data Subject Requests

If LegalHusk receives a request concerning Customer Personal Data and can identify Customer, LegalHusk will direct the requester to Customer or notify Customer unless law prohibits it. LegalHusk will not independently respond except on Customer's documented instruction or as required by law.

Taking account of the nature of Processing, LegalHusk will provide reasonable technical and organizational assistance for access, correction, deletion, restriction, portability, objection, consent withdrawal, and automated decision rights. Customer is responsible for verifying identity, evaluating exceptions, and delivering the substantive response.

Assistance beyond standard Platform functions may be subject to reasonable fees when permitted and disclosed in advance.

11. Assessments, Consultations, and Regulatory Cooperation

LegalHusk will provide information reasonably available and necessary for Customer's data protection impact assessment, risk assessment, prior consultation, or similar duty relating to Customer's use of the services.

LegalHusk will cooperate with a competent Supervisory Authority as required by law. Customer will promptly notify LegalHusk of an inquiry concerning the Processing and will not make a statement on LegalHusk's behalf without authority.

Each party is responsible for its own regulatory obligations and costs, except to the extent the Main Agreement or law provides otherwise.

12. Subprocessors

Customer grants general authorization for LegalHusk to use Subprocessors that support hosting, storage, security, authentication, communications, support, analytics limited to instructed Processing, document transmission, and other functions stated in Annex 3.

LegalHusk will impose written data protection obligations that are no less protective in material respects than the obligations applicable to the relevant Subprocessor Processing. LegalHusk remains responsible for Subprocessor performance to the extent required by Applicable Data Protection Law.

LegalHusk will maintain a current Subprocessor list or provide it on request. Where required, LegalHusk will give reasonable advance notice of a new Subprocessor. Customer may object on reasonable data protection grounds within fifteen calendar days. The parties will attempt a practical resolution. If none is available, LegalHusk may suspend the affected feature or Customer may terminate the affected service without penalty for future unused service, subject to the Main Agreement and mandatory law.

An independent Payment Provider, Professional, regulator, or service chosen and directly instructed by Customer is not a LegalHusk Subprocessor merely because the Platform connects to it.

13. International Transfers

LegalHusk will not make a Restricted Transfer without a lawful mechanism. Depending on the transfer, the parties may rely on an adequacy decision, approved certification, binding corporate rules, Standard Contractual Clauses, the United Kingdom International Data Transfer Agreement or Addendum, or another valid safeguard.

For a transfer subject to the GDPR that is not covered by an adequacy decision, the European Commission Standard Contractual Clauses adopted by Implementing Decision 2021/914 are incorporated by reference. The appropriate module is determined by the parties' roles. Annexes 1, 2, and 3 provide the relevant description, security measures, and Subprocessor information. The clauses prevail over conflicting commercial terms.

For a transfer subject to the UK GDPR, the parties incorporate the current approved United Kingdom Addendum to the European Commission Standard Contractual Clauses or another lawful mechanism selected in Annex 4.

For Switzerland, references in the applicable clauses will be adapted as required by Swiss data protection law and the competent Swiss authority.

The parties will provide reasonable information for a transfer risk assessment and will implement supplementary safeguards where required. If a transfer mechanism becomes invalid, the parties will cooperate to adopt a replacement and may suspend the affected transfer until lawful.

14. Government Requests

LegalHusk will review a government request for Customer Personal Data, verify authority where reasonably practicable, and disclose only information legally required. Where lawful and practicable, LegalHusk will notify Customer before disclosure and will challenge an unlawful or disproportionate request where reasonable.

LegalHusk may publish aggregated transparency information where lawful. LegalHusk will not create a method of access for an authority that is not required by law.

15. Return, Deletion, and Retention

During the Main Agreement, Customer may use available Platform functions to access or export Customer Personal Data. Customer is responsible for maintaining records it must retain and must not use LegalHusk as its only record repository.

At termination or Customer's lawful instruction, LegalHusk will delete or return Customer Personal Data within a reasonable period, unless law requires retention. Backup copies may remain during controlled backup cycles and will remain protected and isolated from ordinary use.

LegalHusk may retain LegalHusk Independent Data and information required for security, fraud, taxes, payment disputes, legal holds, claims, or law as an independent Controller or Business. This DPA does not require deletion that would violate law or the rights of another person.

16. Audit and Demonstration of Compliance

LegalHusk will make available information reasonably necessary to demonstrate compliance, which may include current third party audit reports, certifications, security summaries, policies, or questionnaire responses, subject to confidentiality and security limits.

If that information is not reasonably sufficient, Customer may request one audit in a twelve month period by an independent qualified auditor, with reasonable advance notice, during normal business hours, and without disrupting operations. Additional audits may occur after a material Personal Data Breach or where a Supervisory Authority requires them.

The audit must avoid access to another customer's data, source code, vulnerability details that create unreasonable risk, and information prohibited by law. Customer bears reasonable audit costs unless the audit identifies a material breach by LegalHusk.

17. United States State Privacy Terms

To the extent LegalHusk is a Service Provider or Contractor under an applicable United States state privacy law, LegalHusk will Process Customer Personal Data only for the business purposes in the Main Agreement and this DPA; will not sell or share it; will not retain, use, or disclose it outside the direct business relationship except as permitted by law; and will provide the same level of privacy protection required by applicable law.

Customer may take reasonable and appropriate steps to help ensure consistent Processing. LegalHusk will notify Customer if it determines it can no longer meet an applicable obligation and will allow reasonable steps to stop and remediate unauthorized use.

The parties certify that they understand and will comply with these restrictions.

18. Liability and Order of Precedence

Liability arising under this DPA is subject to the limitations and exclusions in the Main Agreement to the extent permitted by Applicable Data Protection Law. Nothing limits Data Subject rights or regulatory powers that cannot lawfully be limited.

If documents conflict concerning Customer Personal Data, mandatory law applies first, followed by incorporated transfer clauses, this DPA, and then the Main Agreement. The Privacy Notice controls LegalHusk's disclosures to individuals and does not expand Customer's commercial rights.

19. Term and Changes

This DPA remains in effect while LegalHusk Processes Customer Personal Data. Provisions concerning confidentiality, security, deletion, audit, transfers, liability, and regulatory cooperation survive as necessary.

LegalHusk may update this DPA for legal or operational changes. A material reduction in Customer's protections will receive reasonable notice and will not apply retroactively where law prohibits it.

20. Notices

LegalHusk privacy and DPA notices may be sent to [email protected]. Customer notices will be sent to the privacy administrator designated in the Customer account, or, if none is designated, to the account email used for the authenticated DPA acceptance. Each party must keep contact information current.

21. Governing Law and Exclusive Delaware Forum

This DPA and any dispute, controversy, or difference arising out of, relating to, or in connection with the Platform, Platform Services, or this Agreement are governed by the laws of the State of Delaware, United States of America, without giving effect to its conflict of laws principles.

Subject only to mandatory law that cannot lawfully be waived, any dispute, controversy, or difference which may arise between the parties out of, in relation to, or in connection with this Agreement is hereby irrevocably submitted to the exclusive jurisdiction of the courts of Delaware, United States of America, to the exclusion of any other courts, without giving effect to its conflict of laws provisions or Customer's actual state or country of residence.

For this purpose, the courts of Delaware include the state courts of the State of Delaware and the United States District Court for the District of Delaware, as subject matter jurisdiction permits. Each party consents to personal jurisdiction and venue in those courts and waives any objection based on inconvenient forum, except to the extent applicable law makes that waiver unenforceable.

Incorporated transfer clauses and mandatory data protection law prevail over this Section to the extent of a direct conflict.

Annex 1. Processing Details

Customer. The organization, location, and contact identified in the Customer account and authenticated DPA acceptance record.

LegalHusk. Legal Husk, doing business as LegalHusk, United States, [email protected]

Subject matter. The processor feature or configured Platform workflow identified in the Main Agreement, Order, or Customer account configuration.

Duration. The term of the Main Agreement plus the deletion, backup, legal hold, and retention periods described in this DPA.

Nature and purpose. Hosting, storage, transmission, support, workflow administration, and other operations that Customer initiates through the configured processor feature, solely to provide that feature under the Main Agreement.

Data Subjects. Customer personnel, clients, representatives, authorized users, and other persons whose Personal Data Customer lawfully submits through the configured processor feature.

Personal Data categories. Identifiers, contact details, account data, communications, matter or workflow information, transaction records, and other Personal Data Customer lawfully submits through the configured processor feature.

Sensitive data. Only sensitive or special category data that Customer is legally authorized to submit and that is necessary for the configured processor feature. Customer must not submit sensitive data unless supported by a lawful basis and appropriate safeguards.

Processing frequency. As initiated by Customer and its authorized users during the term of the Main Agreement.

Retention. The Customer configuration and retention periods stated in the Main Agreement, Privacy Notice, or applicable feature notice, subject to backups, legal holds, and mandatory law.

Documented instructions. The Main Agreement, this DPA, Customer configuration, authenticated use of Platform functions, support instructions from authorized Customer contacts, and instructions required by applicable law.

Annex 2. Baseline Security Measures

LegalHusk will maintain measures appropriate to the risk, which may include:

  • documented security governance, risk assessment, assigned responsibility, and policy review;
  • logical access controls, role based permissions, least privilege, authentication safeguards, and periodic access review;
  • encryption in transit and encryption at rest where appropriate to the system and risk;
  • secure software development, change control, dependency review, testing, and vulnerability management;
  • malware protection, network controls, logging, monitoring, alerting, and incident response;
  • availability, backup, restoration, continuity, and recovery controls appropriate to Platform functions;
  • vendor due diligence, written data protection terms, and Subprocessor oversight;
  • personnel confidentiality, security training, and access removal;
  • data minimization, retention, secure deletion, and controlled media disposal;
  • periodic testing and evaluation of safeguard effectiveness; and
  • physical and environmental controls for facilities used to support Processing.

Specific security commitments approved for Customer are only those stated in a written enterprise order signed or electronically accepted by both parties; if no such order exists, no additional measures beyond this Annex are promised. Security measures do not guarantee that every incident can be prevented.

Annex 3. Approved Subprocessor Categories

LegalHusk may use providers for cloud hosting and storage; content delivery and network security; account authentication; communications; customer support; monitoring and incident response; document and file transmission; data deletion and backup; and other instructed Platform operations.

The current named Subprocessor list will be made available through the Platform privacy or trust page when published, or on request to [email protected]. The list will identify the provider, service, processing location where reasonably available, and purpose.

Annex 4. Transfer Choices

EEA transfer mechanism. An applicable adequacy decision where available; otherwise the European Commission Standard Contractual Clauses adopted by Implementing Decision 2021/914, using the module that corresponds to the parties' actual roles.

United Kingdom transfer mechanism. An applicable adequacy regulation where available; otherwise the current approved United Kingdom Addendum to the European Commission Standard Contractual Clauses, or the International Data Transfer Agreement where appropriate.

Swiss transfer mechanism. An applicable adequacy decision where available; otherwise the European Commission Standard Contractual Clauses with the adaptations required by Swiss data protection law and the competent Swiss authority.

Competent authority and governing choice for incorporated clauses. The authority and law determined by the incorporated transfer clauses based on the Data Exporter's establishment and applicable data protection law. Where the clauses permit a contractual selection and no mandatory selection applies, Ireland is selected for European Economic Area clauses and England and Wales is selected for the United Kingdom Addendum.

Supplementary measures. Encryption in transit, risk based encryption at rest, access controls, least privilege, confidentiality commitments, request review, data minimization, logging, incident response, and any additional measure identified by a documented transfer risk assessment.

Annex 5. Acceptance

Customer. The organization identified in the Customer account and authenticated DPA acceptance record.

Name and title. The authorized person and title recorded in the applicable authenticated acceptance event.

Signature or electronic acceptance. The authenticated acceptance event retained with the DPA record.

Date. The date and time recorded in the applicable authenticated acceptance event.

LegalHusk. Legal Husk, doing business as LegalHusk

Name and title. The authorized person and title recorded in the applicable authenticated acceptance event.

Signature or electronic acceptance. The authenticated acceptance event retained with the DPA record.

Date. The date and time recorded in the applicable authenticated acceptance event.