Skip to content
LexHub

Data Processing Addendum

Last updated: 1 July 2025

This Data Processing Addendum ("DPA") is between LexHub B.V. ("LexHub") and the Customer, incorporated into the LexHub Terms and Conditions. The DPA takes precedence regarding personal data processing.

1. Subject Matter, Scope and Duration

1.1 Subject Matter

This DPA applies to all personal data processing LexHub performs on the Customer's behalf while providing Services.

1.2 Duration

This DPA remains effective throughout the Agreement and until all Customer Personal Data is deleted or returned.

1.3 Nature and Purpose of Processing

LexHub processes personal data for service provision and improvement, including: storage, retrieval, AI-assisted analysis, workflow automation, document review, monitoring, reporting, support, security monitoring, billing, backup, and disaster recovery.

1.4 Types of Processed Data

Includes documents, emails, contracts, user account information, logs, metadata, usage statistics, credit data, and AI-generated content.

1.5 Categories of Data Subjects

May include customer employees, customer clients, counterparties, and third parties mentioned in uploaded materials.

2. Roles and Responsibilities

2.1–2.2 Party Roles

Customer acts as Data Controller; LexHub acts as Data Processor.

2.3 Customer Responsibilities

Must ensure lawful basis for uploaded data, avoid unnecessary special category data, inform data subjects, ensure accuracy, and review AI-generated output.

2.4 Processor Instructions

LexHub processes data only on documented instructions from the Customer unless law requires otherwise. Unlawful instructions trigger notification.

3. LexHub Obligations

3.1 Confidentiality

All personnel with data access must maintain confidentiality obligations.

3.2 Security Measures

Implements ISO 27001-level practices including encryption, access controls, logging, vulnerability scanning, secure development, data segmentation, and regular security reviews.

3.3 Assistance to Controller

Supports data subject rights requests, DPIAs, authority consultations, and breach handling.

3.4 No Unauthorized Use

Prohibits data selling, advertising use, or model training without explicit separate written agreement.

4. AI Processing

4.1–4.2 AI Operations

Uses AI models for analysis, summaries, drafts, classifications, translations, and insights strictly for service provision per customer instructions.

4.3 AI-Generated Content

Output containing personal data is treated as Customer Personal Data under this DPA.

4.4 Model Training

LexHub does not train foundation models on Customer Personal Data unless the Customer explicitly opts in via a separate written agreement.

5. Sub-Processors

5.1–5.2 Engagement

LexHub may use sub-processors; the current list is available at lexhub.app/sub-processors.

5.3 Notice Requirements

LexHub provides at least ten (10) days notice before adding or replacing sub-processors.

5.4 Customer Rights

Customers may object on reasonable grounds; unresolved disputes allow terminating affected Services only.

5.5 Liability

LexHub remains fully liable for sub-processor performance.

6. International Transfers

6.1 Storage Location

Customer Personal Data is stored within the European Economic Area (EEA).

6.2 External Transfers

If necessary, LexHub implements GDPR Chapter V safeguards including Standard Contractual Clauses, adequacy decisions, and additional protective measures.

7. Data Subject Rights

7.1 Assistance

LexHub supports responses to access, rectification, erasure, portability, objection, restriction, and automated processing rights requests.

7.2 Direct Requests

LexHub forwards directly-submitted requests to the Customer without responding unless authorized.

8. Security Incidents

8.1 Notification Timing

LexHub notifies Customer without undue delay, and in any event within 72 hours of personal data breaches.

8.2 Notification Content

Includes breach nature, scope, affected data categories, likely consequences, proposed measures, and follow-up contact.

8.3 Support

LexHub assists with regulatory notifications and communications.

9. Audits and Compliance

9.1 Documentation

LexHub makes documentation available demonstrating DPA compliance.

9.2 Audit Rights

One annual audit is permitted with 30 days notice; satisfaction may be achieved through ISO 27001 certifications, SOC 2 reports, third-party audits, whitepapers, or policies.

9.3 Additional Audits

Permitted when legally or regulatory required.

10. Return or Deletion of Data

10.1 Export Window

Customers may export data within a 30-day window post-termination.

10.2 Deletion Timeline

LexHub deletes data after the export window unless legally required.

10.3 Retention Schedule

Backup and log deletion follow LexHub's standard secure retention schedule.

10.4 Confirmation

LexHub confirms deletion in writing upon request.

11. Processing of Usage Data

11.1 Purposes

LexHub processes usage data and metadata for billing, security, abuse detection, optimization, troubleshooting, analytics, and improvements.

11.2 Controller Status

Such data processing occurs as an independent controller and excludes document content.

12. Third-Party Integrations

12.1 Integration Processing

When customers enable integrations (Microsoft Word, Google Drive, OneDrive, iManage, external legal sources), LexHub processes only necessary data.

12.2 Third-Party Terms

Third-party systems operate under their own terms and privacy policies.

12.3 Customer Responsibility

Customers ensure compliance when enabling third-party integrations.

13. Liability

13.1 Limitations

Agreement liability limitations apply to this DPA.

13.2 No Liability

LexHub is not liable for customer failure to obtain lawful bases, unlawful special category data uploads, or customer misuse of AI-generated content.

14. Governing Law and Jurisdiction

This DPA follows Netherlands law; disputes are resolved exclusively by competent Midden-Nederland courts (Utrecht location).

15. Contact

LexHub B.V., Email: privacy@lexhub.app, Registered Office: Seizoentuinenlaan 8, 3452 RA Vleuten, The Netherlands, Registration number: 96561998

By using LexHub's services, the Customer agrees to be bound by the terms of this DPA.