Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the Outlex Terms of Service or any other written agreement governing the Customer's use of the Services ("Agreement").
This DPA applies where Outlex processes Customer Personal Data as processor on behalf of the Customer.
This DPA is maintained as a living document. Outlex may update the subprocessor list and technical details from time to time to reflect changes in the Services, provider configuration or applicable provider terms.
Parties
Processor
Outlex AI, Lda.
Portuguese limited liability company
VAT no. 518861660
Registered address: Rua Gomes Freire 11, 1150-176 Lisbon, Portugal
Controller
The customer entity identified in the applicable account, order form, subscription, invoice or written agreement ("Customer", "you" or "Controller").
1. Purpose and scope
1.1 This DPA governs Outlex's processing of Customer Personal Data as processor on behalf of Customer in connection with the Services.
1.2 The Services include the Outlex platform, website, software, AI-enabled features, Lexi, document analysis, legal Q&A, drafting, review, workflow automation, lawyer handoff, subscriptions, credits, integrations, support and related services.
1.3 This DPA does not apply where Outlex acts as an independent controller, including for account administration, billing administration, sales, marketing, website analytics, security monitoring, abuse prevention, legal compliance, service improvement not carried out on behalf of Customer, or other controller activities described in the Privacy Policy.
1.4 The details of the processing are set out in Annex A.
2. Roles and instructions
2.1 Customer acts as controller of Customer Personal Data. Outlex acts as processor when processing Customer Personal Data on behalf of Customer.
2.2 Outlex will process Customer Personal Data only on documented instructions from Customer, including as set out in the Agreement, this DPA, product settings, enabled integrations, support requests, user actions and other written instructions accepted by Outlex.
2.3 Customer instructs Outlex to process Customer Personal Data as necessary to provide, secure, maintain, support and improve the Services, perform the Agreement, prevent abuse, troubleshoot issues, comply with law and exercise legal rights.
2.4 Customer is responsible for ensuring that it has a lawful basis to submit Customer Personal Data to Outlex, that it provides any required notices to data subjects, and that its instructions comply with applicable data protection law.
2.5 Outlex will promptly inform Customer if, in Outlex's opinion, an instruction infringes GDPR or other applicable EU or Member State data protection law, unless prohibited by law from doing so.
3. Confidentiality and personnel
3.1 Outlex will ensure that persons authorised to process Customer Personal Data are bound by appropriate confidentiality obligations or are subject to an appropriate statutory obligation of confidentiality.
3.2 Outlex will limit access to Customer Personal Data to personnel, contractors, subprocessors and authorised Professionals who need access to perform the Services, support Customer, secure the platform or comply with the Agreement.
3.3 Outlex will maintain internal access controls designed to ensure that Customer Personal Data is accessed only on a need-to-know and least-privilege basis.
4. Security
4.1 Outlex will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against unauthorised or unlawful processing, accidental or unlawful destruction, loss, alteration, disclosure or access.
4.2 These measures are described in Annex B and may include encryption, access controls, authentication, logging, network security, vulnerability management, backup and recovery, incident response, personnel confidentiality and vendor review.
4.3 Customer is responsible for configuring its users, permissions, devices, integrations, exports and internal access policies appropriately.
4.4 Customer acknowledges that no online service can be guaranteed to be completely secure.
5. Subprocessors
5.1 Customer gives Outlex general written authorisation to engage subprocessors to process Customer Personal Data for the purpose of providing the Services.
5.2 Outlex will impose data protection obligations on subprocessors that are no less protective in substance than those set out in this DPA, to the extent applicable to the subprocessing services.
5.3 Outlex remains responsible to Customer for the performance of its subprocessors' data protection obligations.
5.4 The current list of subprocessors is set out in Annex C.
5.5 Outlex may add or replace subprocessors from time to time. Where required, Outlex will provide prior notice of material subprocessor changes by updating Annex C, providing in-product notice, email notice or another reasonable method.
5.6 Customer may object to a new subprocessor on reasonable data protection grounds by notifying Outlex within 15 days after notice. The parties will work in good faith to resolve the objection. If the objection cannot reasonably be resolved, Customer may stop using the affected feature or terminate the affected Services where legally required.
6. International transfers
6.1 Outlex is designed with EU data protection requirements in mind. Hosting and primary processing are intended to take place in the EEA where reasonably available.
6.2 Some subprocessors or service providers may process Customer Personal Data outside the EEA, United Kingdom or Switzerland.
6.3 Where Customer Personal Data is transferred internationally, Outlex will rely on appropriate transfer mechanisms, such as adequacy decisions, the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, the EU-US Data Privacy Framework for certified providers, and supplementary technical, contractual or organisational measures where appropriate.
6.4 Customer authorises Outlex and its subprocessors to make such transfers where necessary to provide the Services and subject to the safeguards described in this DPA.
7. Assistance to Customer
7.1 Taking into account the nature of the processing and the information available to Outlex, Outlex will reasonably assist Customer in complying with its obligations under GDPR Articles 32 to 36, including security, breach notification, data protection impact assessments and prior consultation with supervisory authorities.
7.2 Outlex will reasonably assist Customer in responding to data subject requests relating to Customer Personal Data, to the extent possible and taking into account the nature of the Services.
7.3 If Outlex receives a request from a data subject relating to Customer Personal Data, Outlex may refer the request to Customer unless legally required to respond directly.
7.4 Outlex may charge reasonable fees for assistance that is outside the standard functionality of the Services, unless the assistance is required due to Outlex's breach of this DPA.
8. Personal data breaches
8.1 Outlex will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
8.2 The notification will include information reasonably available to Outlex, such as the nature of the breach, affected data categories, likely consequences and measures taken or proposed to address the breach.
8.3 Outlex may provide information in phases as it becomes available.
8.4 Customer is responsible for determining whether it must notify supervisory authorities or affected data subjects.
9. Audits and information rights
9.1 Outlex will make available to Customer information reasonably necessary to demonstrate compliance with this DPA.
9.2 Where available, Outlex may satisfy audit requests by providing security documentation, policies, summaries, certifications, audit reports or responses to reasonable security questionnaires.
9.3 Customer may request an audit where required under Article 28 GDPR, provided that the audit is reasonable, proportionate, limited to Customer Personal Data, subject to confidentiality, does not compromise the security or confidentiality of other customers, and is conducted during normal business hours with reasonable prior notice.
9.4 Audits may not unreasonably disrupt Outlex's business operations or compromise platform security.
9.5 Customer will bear its own audit costs and reimburse Outlex for reasonable costs where the audit is extensive, repetitive or outside standard compliance support, unless the audit identifies a material breach by Outlex.
10. Return and deletion
10.1 Upon termination or expiry of the Services, Outlex will delete or return Customer Personal Data in accordance with the Agreement, product functionality, retention settings and this DPA.
10.2 Where technically available, Customer may export Customer Data during the subscription term and for a limited post-termination period.
10.3 Unless otherwise agreed, Customer Data will generally be available for export for 30 days after termination, after which it may be deleted or made inaccessible.
10.4 Outlex may retain copies of Customer Personal Data where required by law, necessary for legal claims, security, fraud prevention, audit, backup integrity or legitimate business records, provided such data remains protected and is not processed for other purposes.
10.5 Backups may persist for a limited period before being overwritten according to Outlex's backup cycles.
11. Government and third-party requests
11.1 If Outlex receives a legally binding request from a public authority, court, regulator, law enforcement body or third party seeking access to Customer Personal Data, Outlex will, where legally permitted, notify Customer.
11.2 Outlex will review such requests and disclose only the Customer Personal Data it is legally required to disclose.
11.3 Outlex will not voluntarily provide government or third-party access to Customer Personal Data except where legally required or authorised by Customer.
12. Records and cooperation
12.1 Outlex will maintain records of processing activities where required by applicable data protection law.
12.2 Outlex will cooperate with Customer and competent supervisory authorities as required by GDPR and applicable data protection law.
13. AI and human-in-the-loop specifics
13.1 Some Services rely on AI model providers, infrastructure providers and other subprocessors to generate, process, analyse or support AI Outputs.
13.2 Unless expressly agreed otherwise, Customer Personal Data is not used to train third-party foundation models. This applies to Outlex's current AI model providers, including OpenAI, Anthropic / Claude models and Google Gemini, subject to Outlex's applicable provider configuration and contractual terms.
13.3 Any optional training, fine-tuning, benchmarking or product improvement use involving Customer Personal Data will require a separate written agreement, product setting or other lawful mechanism where required.
13.4 AI Outputs may be generated from Customer Personal Data, user prompts, documents, workspace context, legal sources, templates, playbooks and other context made available through the Services.
13.5 Human Legal Support may involve access to Customer Personal Data by Professionals where Customer requests lawyer handoff or human review.
13.6 Depending on the matter, jurisdiction, engagement structure and applicable professional rules, Professionals may act as independent controllers, separate professional service providers, subprocessors or persons authorised to process data under Outlex's responsibility.
13.7 Where a Professional acts as a subprocessor or authorised person for Outlex, Outlex will ensure appropriate confidentiality and data protection obligations apply. Where a Professional acts as an independent controller or separate legal service provider, their own professional duties, privacy obligations and engagement terms may apply.
13.8 Customer is responsible for deciding whether to submit special category data, criminal offence data, highly confidential information or regulated information to the Services. Customer should submit such data only where necessary, lawful and appropriate for the relevant use case.
14. Liability and order of precedence
14.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, unless prohibited by applicable law.
14.2 If there is a conflict between this DPA and the Agreement regarding the processing of Customer Personal Data, this DPA prevails.
14.3 If there is a conflict between this DPA and the Standard Contractual Clauses, where applicable, the Standard Contractual Clauses prevail for the relevant international transfer.
15. Definitions
Agreement: means the Outlex Terms of Service or other written agreement governing Customer's use of the Services.
Customer Data: has the meaning given in the Agreement.
Customer Personal Data: means personal data contained in Customer Data that Outlex processes as processor on behalf of Customer.
Data protection law: means GDPR and any applicable EU, EEA, UK, Swiss, Portuguese or other data protection and privacy laws that apply to the relevant processing.
GDPR: means Regulation (EU) 2016/679.
Personal data, controller, processor, processing, subprocessor, personal data breach and data subject: have the meanings given in GDPR.
Professional: has the meaning given in the Agreement.
Services: has the meaning given in the Agreement.
Annex A — Description of Processing
Subject matter
Outlex processes Customer Personal Data to provide, secure, maintain, support and improve the Services, including the AI legal workspace, Lexi, document analysis, legal Q&A, drafting, review, workflow automation, lawyer handoff, integrations, account administration and support.
Duration
For the duration of the Agreement and for any additional period required for deletion, return, backup retention, legal compliance, security, audit, dispute resolution or legitimate business records.
Nature and purpose of processing
Processing may include collection, receipt, hosting, storage, organisation, structuring, retrieval, consultation, analysis, generation, summarisation, redlining, drafting, review, transmission, disclosure to authorised users or subprocessors, deletion and return.
The purposes include providing the Services, generating AI Outputs, supporting legal workflows, enabling collaboration, maintaining workspace history, securing the platform, preventing abuse, troubleshooting issues, providing support, enabling integrations and complying with Customer instructions.
Categories of data subjects
Customer users, employees, contractors, founders, officers, directors, shareholders, investors, counterparties, suppliers, customers, prospects, applicants, advisors, representatives, signatories, contacts and other individuals whose personal data is included in Customer Data.
Categories of personal data
Customer Personal Data may include names, email addresses, phone numbers, job titles, company details, account information, document contents, contracts, correspondence, prompts, chats, comments, matter information, counterparties, commercial information, employment-related information, billing-related business information, signatures, identifiers, metadata, user activity, workspace history and integration content selected by Customer.
Special category or sensitive data
Customer may choose to submit special category data, criminal offence data, confidential legal information, employment information, financial information or other sensitive information. Customer is responsible for ensuring such submission is lawful, necessary and appropriate.
Processing operations
Hosting, storing, retrieving, analysing, structuring, indexing, summarising, drafting, reviewing, redlining, generating outputs, routing tasks, enabling lawyer handoff, providing support, maintaining logs, securing the service, backing up data, deleting data and enabling integrations.
Customer instructions
The Agreement, this DPA, product settings, enabled integrations, user actions, support requests, written communications and any other documented instructions accepted by Outlex.
Annex B — Technical and Organisational Measures
Outlex maintains technical and organisational measures designed to protect Customer Personal Data. These may include:
Access control
- Role-based access controls.
- Least-privilege access.
- User authentication.
- Workspace permissions.
- Internal access limited to authorised personnel and service providers.
- Access review and revocation processes.
Encryption and transmission security
- Encryption in transit where supported.
- Encryption at rest where supported.
- Secure communication protocols.
- Protection of credentials and secrets.
Logging and monitoring
- System logs and security records.
- Access logs and audit trails where available.
- Monitoring for suspicious activity, abuse and unauthorised access.
- Incident detection and escalation processes.
Infrastructure and network security
- Secure hosting and infrastructure providers.
- Network security controls.
- Environment segregation where appropriate.
- Vulnerability management and patching processes.
- Secure configuration practices.
Data integrity, availability and resilience
- Backup and recovery procedures.
- Business continuity and disaster recovery measures proportionate to the Services.
- Measures designed to restore availability and access in a timely manner after incidents.
Personnel and confidentiality
- Confidentiality obligations for personnel, contractors and relevant Professionals.
- Internal policies and training appropriate to roles.
- Access limited based on business need.
Vendor and subprocessor management
- Vendor due diligence appropriate to risk.
- Written agreements with subprocessors.
- Flow-down data protection obligations.
- Subprocessor review and monitoring.
Data minimisation and retention
- Processing limited to the purposes of the Services.
- Retention controls and deletion processes.
- Customer export or deletion functionality where available.
- Backup deletion according to backup cycles.
Incident response
- Incident response procedures.
- Assessment and escalation of suspected personal data breaches.
- Notification to Customer without undue delay where Customer Personal Data is affected.
Annex C — Subprocessor List
Outlex uses the subprocessors listed below to provide, secure, support and improve the Services. Customer gives Outlex general written authorisation to use these subprocessors in accordance with this DPA.
Outlex may update this list from time to time. Where required, Outlex will provide prior notice of material additions or replacements of subprocessors and give Customer an opportunity to object on reasonable data protection grounds in accordance with this DPA.
Some technical details, including processing region, exact transfer safeguard and DPA/SCC status, may depend on Outlex's configuration and the provider's applicable terms. Outlex will update this Annex as those details are confirmed.
| Subprocessor | Service / purpose | Location of processing | Transfer safeguard, if outside EEA | Customer Personal Data processed |
|---|---|---|---|---|
| Vercel | Hosting, deployment, frontend/application hosting, serverless/application infrastructure, analytics and performance monitoring for the Outlex application and website | To be confirmed according to Outlex configuration and Vercel terms | EU Standard Contractual Clauses, EU-US Data Privacy Framework or other applicable safeguards, as applicable | Customer Data, workspace data, technical metadata, logs, usage data, device/browser data and performance data as applicable |
| Supabase | Backend infrastructure, database, storage, authentication infrastructure and related platform services | To be confirmed according to Outlex configuration and Supabase terms | EU Standard Contractual Clauses, EU-US Data Privacy Framework or other applicable safeguards, as applicable | Customer Data, documents, contracts, uploaded files, prompts, outputs, workspace data, account data, authentication data, metadata and technical logs as applicable |
| Authentication and access management, including Google sign-in where enabled | To be confirmed according to Outlex configuration and Google terms | Adequacy decision, EU Standard Contractual Clauses, EU-US Data Privacy Framework or other applicable safeguards, as applicable | User account data, name, email address, user ID, login metadata and authentication data | |
| Stripe | Payments, subscription billing, invoicing and payment processing | To be confirmed according to Outlex configuration and Stripe terms | Adequacy decision, EU Standard Contractual Clauses, EU-US Data Privacy Framework or other applicable safeguards, as applicable | Billing contact details, company information, invoice data, subscription data, payment metadata and limited payment-related information |
| Resend | Transactional and operational email delivery, including account, login, notification, invitation and system emails | To be confirmed according to Outlex configuration and Resend terms | EU Standard Contractual Clauses, EU-US Data Privacy Framework or other applicable safeguards, as applicable | Name, email address, account information, transactional email content, message metadata and delivery metadata as applicable |
| OpenAI | AI model provider for Lexi and AI-enabled features | To be confirmed according to Outlex configuration and OpenAI terms | Adequacy decision, EU Standard Contractual Clauses, EU-US Data Privacy Framework or other applicable safeguards, as applicable | Prompts, documents, contract text, user instructions, workspace context, generated outputs and related metadata required to provide AI features |
| Anthropic / Claude models | AI model provider for Lexi and AI-enabled features | To be confirmed according to Outlex configuration and Anthropic terms | Adequacy decision, EU Standard Contractual Clauses, EU-US Data Privacy Framework or other applicable safeguards, as applicable | Prompts, documents, contract text, user instructions, workspace context, generated outputs and related metadata required to provide AI features |
| Google Gemini | AI model provider for Lexi and AI-enabled features | To be confirmed according to Outlex configuration and Google terms | Adequacy decision, EU Standard Contractual Clauses, EU-US Data Privacy Framework or other applicable safeguards, as applicable | Prompts, documents, contract text, user instructions, workspace context, generated outputs and related metadata required to provide AI features |
| Google Analytics | Website and/or product analytics, usage measurement and performance analysis | To be confirmed according to Outlex configuration and Google terms | Adequacy decision, EU Standard Contractual Clauses, EU-US Data Privacy Framework or other applicable safeguards, as applicable | Usage data, device/browser data, pages viewed, events, identifiers, approximate location and technical metadata as applicable |
| PostHog | Product analytics, user behaviour analytics, feature usage measurement and product improvement | To be confirmed according to Outlex configuration and PostHog terms | EU Standard Contractual Clauses or other applicable safeguards, as applicable | Usage events, product telemetry, user/account identifiers, device/browser data, technical metadata and interaction data as applicable |
| Sentry | Error tracking, debugging, monitoring, reliability and security diagnostics | To be confirmed according to Outlex configuration and Sentry terms | EU Standard Contractual Clauses or other applicable safeguards, as applicable | Error logs, stack traces, user/account identifiers, device/browser data, IP address, technical metadata and limited contextual data as applicable |
| Google Drive / Google Workspace | Customer-enabled integration for importing, accessing or exporting files where enabled by Customer | Depends on Customer configuration and Google terms | Depends on Customer configuration and Google terms | Files, folders, documents, metadata and related content selected, connected or imported by Customer |
| Microsoft / Microsoft 365 | Customer-enabled integration for importing, accessing or exporting files or workspace content where enabled by Customer | Depends on Customer configuration and Microsoft terms | Depends on Customer configuration and Microsoft terms | Files, folders, documents, metadata, workspace content and related content selected, connected or imported by Customer |
| Slack | Customer-enabled integration for workspace communications or related workflows where enabled by Customer | Depends on Customer configuration and Slack terms | Depends on Customer configuration and Slack terms | Workspace messages, channel content, user identifiers, metadata and related content selected, connected or imported by Customer |
| DocSend.js | Signature, document signing, document sharing or document workflow functionality where enabled by Customer | To be confirmed according to Outlex configuration and DocSend.js terms | Adequacy decision, EU Standard Contractual Clauses, EU-US Data Privacy Framework or other applicable safeguards, as applicable | Documents, signature-related data, recipient details, sender details, access metadata and related document workflow information as applicable |
| Composio / Sampark Inc. | Customer-enabled integration infrastructure for connecting third-party applications, including Google Calendar, Gmail, Slack and other supported tools; OAuth/token management, API connectivity, data sync and integration workflow execution where enabled by Customer | To be confirmed according to Outlex configuration and Composio terms / DPA | To be confirmed under Composio DPA, including EU Standard Contractual Clauses, EU-US Data Privacy Framework or other applicable safeguards, as applicable | OAuth tokens, connected account identifiers, integration metadata, synced calendar/email/workspace content, messages, files, events, contact/account data, logs and technical metadata selected, connected or processed through Customer-enabled integrations |
Outlex does not use Customer Personal Data to train third-party foundation models by default, unless expressly agreed otherwise with Customer.