Data Processing Addendum
Last updated: 1 July 2025
This Data Processing Addendum ("DPA") is between LexHub B.V. ("LexHub") and the Customer, incorporated into the LexHub Terms and Conditions. The DPA takes precedence regarding personal data processing.
1. Subject Matter, Scope and Duration
1.1 Subject Matter
This DPA applies to all personal data processing LexHub performs on the Customer's behalf while providing Services.
1.2 Duration
This DPA remains effective throughout the Agreement and until all Customer Personal Data is deleted or returned.
1.3 Nature and Purpose of Processing
LexHub processes personal data for service provision and improvement, including: storage, retrieval, AI-assisted analysis, workflow automation, document review, monitoring, reporting, support, security monitoring, billing, backup, and disaster recovery.
1.4 Types of Processed Data
Includes documents, emails, contracts, user account information, logs, metadata, usage statistics, credit data, and AI-generated content.
1.5 Categories of Data Subjects
May include customer employees, customer clients, counterparties, and third parties mentioned in uploaded materials.
2. Roles and Responsibilities
2.1–2.2 Party Roles
Customer acts as Data Controller; LexHub acts as Data Processor.
2.3 Customer Responsibilities
Must ensure lawful basis for uploaded data, avoid unnecessary special category data, inform data subjects, ensure accuracy, and review AI-generated output.
2.4 Processor Instructions
LexHub processes data only on documented instructions from the Customer unless law requires otherwise. Unlawful instructions trigger notification.
3. LexHub Obligations
3.1 Confidentiality
All personnel with data access must maintain confidentiality obligations.
3.2 Security Measures
Implements ISO 27001-level practices including encryption, access controls, logging, vulnerability scanning, secure development, data segmentation, and regular security reviews.
3.3 Assistance to Controller
Supports data subject rights requests, DPIAs, authority consultations, and breach handling.
3.4 No Unauthorized Use
Prohibits data selling, advertising use, or model training without explicit separate written agreement.
4. AI Processing
4.1–4.2 AI Operations
Uses AI models for analysis, summaries, drafts, classifications, translations, and insights strictly for service provision per customer instructions.
4.3 AI-Generated Content
Output containing personal data is treated as Customer Personal Data under this DPA.
4.4 Model Training
LexHub does not train foundation models on Customer Personal Data unless the Customer explicitly opts in via a separate written agreement.
5. Sub-Processors
5.1–5.2 Engagement
LexHub may use sub-processors; the current list is available at lexhub.app/sub-processors.
5.3 Notice Requirements
LexHub provides at least ten (10) days notice before adding or replacing sub-processors.
5.4 Customer Rights
Customers may object on reasonable grounds; unresolved disputes allow terminating affected Services only.
5.5 Liability
LexHub remains fully liable for sub-processor performance.
6. International Transfers
6.1 Storage Location
Customer Personal Data is stored within the European Economic Area (EEA).
6.2 External Transfers
If necessary, LexHub implements GDPR Chapter V safeguards including Standard Contractual Clauses, adequacy decisions, and additional protective measures.
7. Data Subject Rights
7.1 Assistance
LexHub supports responses to access, rectification, erasure, portability, objection, restriction, and automated processing rights requests.
7.2 Direct Requests
LexHub forwards directly-submitted requests to the Customer without responding unless authorized.
8. Security Incidents
8.1 Notification Timing
LexHub notifies Customer without undue delay, and in any event within 72 hours of personal data breaches.
8.2 Notification Content
Includes breach nature, scope, affected data categories, likely consequences, proposed measures, and follow-up contact.
8.3 Support
LexHub assists with regulatory notifications and communications.
9. Audits and Compliance
9.1 Documentation
LexHub makes documentation available demonstrating DPA compliance.
9.2 Audit Rights
One annual audit is permitted with 30 days notice; satisfaction may be achieved through ISO 27001 certifications, SOC 2 reports, third-party audits, whitepapers, or policies.
9.3 Additional Audits
Permitted when legally or regulatory required.
10. Return or Deletion of Data
10.1 Export Window
Customers may export data within a 30-day window post-termination.
10.2 Deletion Timeline
LexHub deletes data after the export window unless legally required.
10.3 Retention Schedule
Backup and log deletion follow LexHub's standard secure retention schedule.
10.4 Confirmation
LexHub confirms deletion in writing upon request.
11. Processing of Usage Data
11.1 Purposes
LexHub processes usage data and metadata for billing, security, abuse detection, optimization, troubleshooting, analytics, and improvements.
11.2 Controller Status
Such data processing occurs as an independent controller and excludes document content.
12. Third-Party Integrations
12.1 Integration Processing
When customers enable integrations (Microsoft Word, Google Drive, OneDrive, iManage, external legal sources), LexHub processes only necessary data.
12.2 Third-Party Terms
Third-party systems operate under their own terms and privacy policies.
12.3 Customer Responsibility
Customers ensure compliance when enabling third-party integrations.
13. Liability
13.1 Limitations
Agreement liability limitations apply to this DPA.
13.2 No Liability
LexHub is not liable for customer failure to obtain lawful bases, unlawful special category data uploads, or customer misuse of AI-generated content.
14. Governing Law and Jurisdiction
This DPA follows Netherlands law; disputes are resolved exclusively by competent Midden-Nederland courts (Utrecht location).
15. Contact
LexHub B.V., Email: privacy@lexhub.app, Registered Office: Seizoentuinenlaan 8, 3452 RA Vleuten, The Netherlands, Registration number: 96561998
By using LexHub's services, the Customer agrees to be bound by the terms of this DPA.