Skip to content
Legasus
ADDENDUM

Data Processing Addendum

How Legasus processes Customer Personal Data on your firm's behalf: instructions, security, subprocessors, incidents, audits, and deletion.

Effective: Effective April 1, 2026Version: Version 4Jurisdiction: Illinois, USAContact: privacy@legasus.ai

This Data Processing Addendum (“DPA”) forms part of the Legasus Master Subscription Agreement or other written agreement (the “Agreement”) between AIDAN LLC d/b/a Legasus (“Legasus”) and the Customer identified in the Agreement (“Customer”). It governs Legasus's Processing of Customer Personal Data on Customer's behalf in connection with the Services.

Capitalized terms not defined in this DPA have the meanings given in the Agreement.

1. Definitions

1.1 “Applicable Data Protection Law”

means privacy, data protection, and data-security laws applicable to a party's Processing under the Agreement, which may include, as applicable, the GDPR, UK GDPR, U.S. state comprehensive privacy laws, and laws using concepts such as controller/processor, business/service provider, or similar roles.

1.2 “Customer Personal Data”

means Personal Data contained in Customer Data that Legasus Processes on Customer's behalf under the Agreement.

1.3 “Data Subject”

means an identified or identifiable person to whom Personal Data relates and includes equivalent terms such as “consumer” where applicable.

1.4 “GDPR”

means Regulation (EU) 2016/679.

1.5 “Personal Data”

means information relating to an identified or identifiable natural person or information otherwise protected as “personal data,” “personal information,” or an equivalent concept under Applicable Data Protection Law.

1.6 “Process,” “Processing,” and “Processed”

have the meanings given under Applicable Data Protection Law and include operations such as collection, recording, organization, storage, adaptation, retrieval, consultation, use, analysis, disclosure, transmission, restriction, deletion, or destruction.

1.7 “Restricted Transfer”

means a transfer of Personal Data that requires an approved transfer mechanism under Applicable Data Protection Law.

1.8 “Security Incident”

means unauthorized access to, acquisition of, disclosure of, alteration of, loss of, or destruction of Customer Personal Data in Legasus's possession or control that compromises the security, confidentiality, or integrity of such data. Security Incident does not include unsuccessful attempts or activities that do not compromise Customer Personal Data, such as pings, port scans, unsuccessful login attempts, blocked attacks, or similar events.

1.9 “Subprocessor”

means a third party engaged by Legasus to Process Customer Personal Data on behalf of Customer in providing the Services.

1.10 “UK GDPR”

means the UK version of the GDPR as incorporated into United Kingdom law and amended from time to time.

2. Scope and Roles

2.1 Customer as Controller / Business

As between the parties, Customer is the controller, business, or equivalent entity responsible for determining the purposes and means of Processing Customer Personal Data, except where Customer itself acts as a processor for another entity.

2.2 Legasus as Processor / Service Provider

Legasus acts as Customer's processor, service provider, contractor, or equivalent role when Processing Customer Personal Data on Customer's behalf to provide the Services.

If Customer is a processor for another controller, Legasus acts as Customer's subprocessor to the extent applicable.

2.3 Each Party's Compliance

Each party will comply with Applicable Data Protection Law applicable to its own Processing and obligations. Customer is responsible for ensuring that its instructions to Legasus comply with Applicable Data Protection Law and for having an appropriate legal basis, notices, consents, authorizations, and rights for Customer Personal Data.

3. Processing Instructions

3.1 Documented Instructions

Legasus will Process Customer Personal Data only:

  1. to provide, operate, secure, maintain, and support the Services;
  2. according to Customer's documented instructions, including actions and configurations initiated through the Services;
  3. as described in the Agreement, this DPA, applicable Order Forms, Documentation, and Product-Specific Terms; or
  4. as required by applicable law.

The Agreement, Customer's use/configuration of the Services, and Customer's written instructions constitute documented instructions.

3.2 Unlawful Instructions

If Legasus reasonably believes a Customer instruction violates Applicable Data Protection Law, Legasus may notify Customer and suspend the affected Processing until the parties resolve the issue, unless law prohibits notice.

3.3 Required Processing

If law requires Legasus to Process Customer Personal Data outside Customer's instructions, Legasus will notify Customer before such Processing where legally permitted.

4. Confidentiality and Personnel

Legasus will ensure that personnel authorized to Process Customer Personal Data are subject to confidentiality obligations and receive access only as reasonably necessary for their roles.

Legasus will apply least-privilege principles and appropriate access controls as described in the Security Addendum.

5. Security

5.1 Security Measures

Legasus will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

The current contractual security baseline is described in the Legasus Security Addendum, which is incorporated into this DPA.

5.2 Customer Security Responsibilities

Customer remains responsible for security within its control, including user management, permissions, device security, integrations, authentication settings, Customer-provided credentials, exported data, and lawful configuration of the Services.

6. Subprocessors

6.1 General Authorization

Customer provides general written authorization for Legasus to engage Subprocessors as necessary to provide the Services, subject to this Section.

6.2 Subprocessor List

Legasus will maintain a current public or otherwise readily available list of Subprocessors that Process Customer Personal Data on behalf of Customer, including a description of their processing purpose and, where reasonably available, processing location.

6.3 Subprocessor Obligations

Legasus will enter into written agreements with Subprocessors that impose data-protection obligations appropriate to the services they perform and no less protective in material respects than Legasus's applicable obligations under this DPA, to the extent required by Applicable Data Protection Law.

Legasus remains responsible for its Subprocessors' performance of their data-protection obligations to the extent required by Applicable Data Protection Law and the Agreement.

6.4 Changes to Subprocessors

Legasus may add or replace Subprocessors. Where Applicable Data Protection Law requires notice of an intended new Subprocessor, Legasus will provide notice through the Subprocessor List, account notice, email, or another reasonable electronic mechanism before the new Subprocessor begins the legally relevant Processing, and Customer may object within the legally required or otherwise reasonable period on documented data-protection grounds.

If the parties cannot reasonably resolve a valid objection, Legasus may, in its discretion: (a) avoid use of the Subprocessor for Customer where commercially feasible; (b) offer a reasonable alternative; or (c) permit Customer to terminate the affected Service without penalty for the unused prepaid portion attributable solely to the affected Service, if required by Applicable Data Protection Law. This limited termination right does not apply to objections based solely on commercial preference.

7. Assistance With Data Subject Rights

Taking into account the nature of Processing, Legasus will provide reasonable assistance to Customer through available Service functionality or other reasonable measures to enable Customer to respond to legally valid Data Subject requests for access, correction, deletion, restriction, portability, objection, or similar rights.

If Legasus receives a request directly concerning Customer Personal Data, Legasus may direct the requester to Customer and will not independently respond regarding substantive Customer Personal Data except as authorized by Customer or required by law.

Customer is responsible for determining whether and how to fulfill a request.

8. Data Protection Impact Assessments and Regulatory Assistance

Taking into account the nature of Processing and information available to Legasus, Legasus will provide reasonable assistance to Customer with data-protection impact assessments, prior consultations, and regulator inquiries relating specifically to Legasus's Processing of Customer Personal Data, to the extent required by Applicable Data Protection Law.

If assistance requires material custom work beyond standard documentation or support, the parties may agree on reasonable fees unless law prohibits charging for the required assistance.

9. Security Incidents

9.1 Notification

Legasus will notify Customer without undue delay and, where reasonably practicable, within seventy-two (72) hours after Legasus confirms a Security Incident affecting Customer Personal Data, unless law prohibits or restricts notification.

Notification of a Security Incident does not constitute an admission of fault or liability.

9.2 Information

To the extent known and reasonably available, Legasus will provide information reasonably necessary for Customer to understand the nature of the Security Incident, categories of affected data, likely consequences, mitigation, and contact information for follow-up. Legasus may provide information in phases as the investigation progresses.

9.3 Mitigation and Cooperation

Legasus will take commercially reasonable steps to contain, investigate, mitigate, and remediate a Security Incident within its responsibility and will reasonably cooperate with Customer's legally required response.

9.4 Customer Notifications

Except where Legasus is independently required by law or the parties agree otherwise, Customer is responsible for determining whether notification to individuals, regulators, courts, clients, insurers, or other parties is required and for making such notifications.

10. Government Requests

If Legasus receives a legally binding request from a governmental authority for Customer Personal Data, Legasus will, where legally permitted and reasonably practicable:

  • notify Customer;
  • direct the authority to seek data from Customer where appropriate;
  • review the demand for facial validity and scope;
  • challenge or seek modification of requests Legasus reasonably believes are unlawful or overbroad where commercially and legally appropriate; and
  • disclose only data Legasus reasonably determines is legally required.

11. Return and Deletion

11.1 During the Term

Customer may use available Service functionality to access, export, correct, or delete Customer Personal Data, subject to product limitations and applicable law.

11.2 After Termination

Unless an Order Form, BAA, or law requires otherwise, Customer Personal Data will generally remain available for retrieval for up to sixty (60) days after termination or expiration, after which Legasus may begin deleting it from active systems.

Customer Personal Data may remain in backups, security logs, disaster-recovery systems, or archives until ordinary rotation/retention cycles expire. Legasus may retain data where required by law, legal process, security obligations, disputes, legal holds, or audit requirements. Retained data remains protected under applicable confidentiality and security obligations and will not be actively used for unrelated purposes.

11.4 Certification

Where required by Applicable Data Protection Law or a mutually executed enterprise agreement, Legasus will provide reasonable confirmation of deletion after applicable deletion processes are complete.

12. Audits and Compliance Information

12.1 Standard Documentation

Legasus will make available information reasonably necessary to demonstrate compliance with this DPA, which may include:

  • the Security Addendum;
  • security questionnaires;
  • relevant trust-center materials;
  • independent audit reports once available;
  • penetration-test summaries where appropriate;
  • subprocessor information; and
  • other reasonable documentation.

Sensitive security materials may require confidentiality protections and may be provided only to qualified Customers or auditors.

12.2 Customer Audits

If standard documentation is not reasonably sufficient to satisfy a legally required audit right, Customer may request an audit no more than once in a twelve-month period, unless a Security Incident or regulator requirement reasonably requires more frequent review.

Any audit must:

  • be limited to Legasus's compliance with this DPA;
  • occur during normal business hours;
  • avoid unreasonable disruption;
  • protect other customers and Legasus Confidential Information;
  • comply with Legasus security requirements; and
  • be conducted by an independent auditor that is not a competitor of Legasus and is bound by confidentiality obligations.

The parties will agree on reasonable scope, timing, and method. Customer bears its audit costs and, if an audit requires material resources beyond standard compliance support, reasonable Legasus costs unless Applicable Data Protection Law requires otherwise.

No audit right permits access to source code, data belonging to another customer, vulnerability details that would create security risk, or information Legasus is legally prohibited from disclosing.

13. U.S. State Privacy Requirements

To the extent Legasus Processes Customer Personal Data subject to a U.S. state privacy law in the role of a service provider, processor, contractor, or equivalent, Legasus will:

  1. Process Customer Personal Data only for the business purposes and services described in the Agreement or Customer's documented instructions;
  2. not sell Customer Personal Data;
  3. not share Customer Personal Data for cross-context behavioral advertising or targeted advertising unrelated to providing the Services;
  4. not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except as permitted by applicable law;
  5. not combine Customer Personal Data with personal information received from another person or collected from Legasus's own interaction with an individual except as permitted by applicable law;
  6. provide the same level of privacy protection required of service providers/processors under applicable law;
  7. notify Customer if Legasus determines it can no longer meet a legally applicable obligation;
  8. allow Customer to take reasonable and appropriate steps required by applicable law to help ensure compliant use; and
  9. provide reasonable assistance for applicable consumer-right requests.

Legasus certifies that it understands and will comply with applicable restrictions to the extent they legally apply to Legasus in its role for Customer.

14. International Data Transfers

Restricted Transfers are governed by the Legasus Data Transfer Addendum, incorporated into this DPA.

Where the parties need to execute additional transfer documentation required by Applicable Data Protection Law, they will cooperate in good faith to implement the required lawful mechanism.

15. AI Processing

15.1 No Generalized Training

Legasus will not use Customer Personal Data to train generalized/shared Legasus AI models for unrelated customers unless Customer separately and expressly authorizes such use in writing.

15.2 AI Subprocessors

Where an approved AI Subprocessor Processes Customer Personal Data to provide an enabled AI-Enabled Feature, Legasus will use business/API arrangements intended to prohibit or prevent the Subprocessor from using Customer Personal Data to train its generalized models, subject to applicable provider terms and any separately disclosed optional feature conditions.

15.3 Customer-Specific AI Configuration

Where Customer enables Customer-Specific AI Configuration, Customer instructs Legasus to Process applicable Customer Personal Data for that isolated Customer-specific purpose. Such configuration will not be used to improve another customer's private agents or a generalized/shared Legasus model.

16. Protected Health Information

If Customer Personal Data includes Protected Health Information subject to HIPAA, the BAA controls with respect to PHI. Customer will not submit PHI to Services not designated as HIPAA-eligible where a BAA is required.

17. Liability

Liability arising under this DPA is subject to the exclusions and limitations of liability in the Agreement unless Applicable Data Protection Law prohibits such limitation or an executed Order Form expressly provides otherwise.

18. Term

This DPA begins when Legasus first Processes Customer Personal Data on Customer's behalf and continues for as long as Legasus Processes such data, including any legally permitted post-termination retention.

19. Processing Details — Annex I

A. Subject Matter

Provision of Legasus legal-technology, case-management, CRM, document, communication, AI, research, intake, automation, portal, integration, and related Services selected by Customer.

B. Duration

For the term of the Agreement and any post-termination period during which Legasus lawfully retains Customer Personal Data.

C. Nature and Purpose of Processing

Depending on Customer's use, Processing may include collection, receipt, organization, hosting, storage, indexing, retrieval, search, analysis, AI inference, Customer-Specific AI Configuration, transcription, communication, document generation, workflow automation, legal research support, intake classification/scoring, integration, backup, security monitoring, troubleshooting, export, deletion, and other Processing necessary to provide Customer's configured Services.

D. Categories of Data Subjects

May include:

  • Customer personnel and Authorized Users;
  • Customer clients and former clients;
  • prospective clients and leads;
  • Client Users;
  • opposing parties and counsel;
  • witnesses;
  • experts;
  • healthcare providers;
  • insurers and adjusters;
  • vendors;
  • court personnel;
  • government contacts;
  • family members and representatives;
  • employees or applicants involved in a matter;
  • contacts contained in connected accounts; and
  • other individuals whose information Customer lawfully Processes through the Services.

E. Categories of Personal Data

May include:

  • identity and contact information;
  • account and authentication information;
  • professional information;
  • legal matter/case information;
  • communications;
  • documents and evidence;
  • financial and transaction information;
  • insurance information;
  • medical and health information;
  • government identifiers where included by Customer;
  • litigation, discovery, settlement, and claim information;
  • calendar and email content;
  • recordings and transcripts;
  • electronic signature data;
  • usage and technical data associated with Customer's use;
  • AI Inputs and Outputs; and
  • other Customer-directed data.

F. Sensitive / Special Categories

Depending on Customer's matters, Customer Personal Data may include sensitive data, special-category data, criminal-offense information, health information, biometric or voice information where applicable, financial information, government identifiers, privileged information, or other regulated data. Customer is responsible for ensuring it has authority and a lawful basis to Process such data.

G. Frequency

Continuous or as initiated by Customer and its users during use of the Services.

H. Deletion

As described in Section 11 and the Agreement, generally including a 60-day post-termination retrieval period followed by deletion from active systems, subject to backup cycles, legal requirements, and other permitted retention.

20. Security Measures — Annex II

The technical and organizational measures applicable to Customer Personal Data are described in the Legasus Security Addendum, including measures relating to:

  • encryption at rest and in transit;
  • authentication and MFA;
  • role-based access control;
  • least privilege;
  • tenant isolation;
  • audit logging;
  • secure development/code review;
  • vulnerability scanning;
  • penetration testing;
  • incident response;
  • backup and recovery;
  • business continuity/disaster recovery;
  • vendor risk management;
  • access review; and
  • security monitoring.

21. Subprocessors — Annex III

Customer generally authorizes the Subprocessors listed in the current Legasus Subprocessor List, as updated in accordance with this DPA.

22. Contact

Privacy and DPA inquiries: privacy@legasus.ai
Legal notices: legal@legasus.ai