Data processing addendum
Data processing addendum
This addendum forms part of the terms of service and applies whenever we process personal data on your behalf. You are the controller; [legal entity name] is the processor.
1. Subject matter and duration
We analyse the signals your deployment of the Lawpatch SDK sends us and store the resulting report, for as long as your workspace exists and for 30 days after you delete it.
2. Nature and purpose
Scanning, analysis against a precedent corpus, report generation, and the notifications you configure.
3. Categories of data subject and data
- Your personnel: the people who sign into your workspace (e-mail, display name, account identifier).
- Derived signals: rule identifiers, repository-relative file paths, line numbers, route and entity names, dependency names and versions, and — only if you switch on snippet sharing — one masked line of code per signal. These are normally about software, not people; a path or a variable name can nonetheless incidentally contain a person’s name, which is why they are treated as personal data here.
4. Your instructions
We process only on your documented instructions, which are these terms plus the settings in your workspace. If we think an instruction breaches data protection law we will tell you before acting on it.
5. Confidentiality and security
Everyone with access is bound by confidentiality. Our technical measures are described in the security model: data in transit is encrypted, API keys are stored only as SHA-256 hashes and are scoped to one project, workspace isolation is enforced by database rules rather than only by application code, raw scan signals are held in memory for the duration of the analysis and never written to disk, and requests to model providers are sent with retention disabled where the provider supports it.
6. Sub-processors
You give general authorisation for the sub-processors listed here. We will announce a new one on that page at least 30 days before it starts processing, and you may object on reasonable data protection grounds — if we cannot resolve it, you may terminate the affected service.
7. Assistance
We help you respond to data subject requests, and with data protection impact assessments and prior consultations, taking into account the nature of the processing and the information available to us. Most requests you can satisfy yourself from the dashboard.
8. Breach notification
We notify you without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting your data, with the information you need for your own 72-hour notification.
9. Deletion and return
Delete a project or a workspace and the associated scans and findings are removed within 30 days, including from backups on their normal rotation. On request we export your findings as JSON before deletion.
10. Audit
We make available the information needed to demonstrate compliance and will answer a reasonable security questionnaire once a year. On-site audits are available to customers with a negotiated agreement.
11. International transfers
Where a sub-processor is outside the EEA, the UK or Türkiye, transfers are made under the EU Standard Controller-to-Processor Clauses (Module Two or Three as applicable) with the UK International Data Transfer Addendum, and under KVKK Art. 9 for Turkish data. Those clauses are incorporated into this addendum by reference.
Need this signed on your paper, or with a named contact and jurisdiction filled in? Write to legal@lawpatch.studio.