Data Processing Agreement
Centralize Legal — processor terms for law firm customers. Effective July 4, 2026.
This Data Processing Agreement ("DPA") forms part of the agreement between the law firm or organization subscribing to Centralize Legal ("Customer", "Controller") and Centralize Legal ("Processor", "we", "us") for the processing of Personal Data in connection with the Centralize Legal service at https://centralizelegal.com.
By using the service, Customer agrees to this DPA. For a countersigned copy, use the signable DPA (print to PDF) or contact support@centralizelegal.com.
1. Definitions
- Personal Data means information relating to an identified or identifiable natural person that Customer submits to or that flows through the service, including account data and metadata derived from connected practice systems.
- Customer Data means all data Customer or its users submit, connect, or generate through the service, including Personal Data.
- Subprocessor means a third party engaged by Processor to process Customer Data. Current list: Subprocessor List.
2. Roles & scope
Customer is the Controller of Customer Data. Processor processes Customer Data only to provide the Centralize Legal integration service: OAuth connection management, federated search and retrieval, non-privileged metadata indexing, optional notifications, billing, and support.
Processor does not determine the purposes of processing Client Confidential Information beyond providing the service as configured by Customer's users.
3. Processor obligations
Processor shall:
- Process Customer Data only on documented instructions from Customer (use of the service constitutes such instructions).
- Ensure personnel authorized to process Customer Data are bound by confidentiality obligations.
- Implement appropriate technical and organizational measures as described in the Security Overview.
- Not sell Customer Data or use it for advertising.
- Not use Customer Data to train machine learning models — Processor does not operate an LLM on Customer Data.
- Assist Customer with reasonable requests regarding data subject rights, to the extent Processor holds relevant data and applicable law requires assistance.
- Notify Customer without undue delay, and no later than 72 hours after confirmation of a breach affecting Customer Data, to the extent permitted by law.
3a. BYO-AI boundary
Content retrieved via the service is transmitted to the AI environment the Customer connects. That AI provider is a Customer-connected system under the Customer's own agreement, not a Subprocessor of Centralize Legal.
4. Subprocessors
Customer authorizes Processor to engage Subprocessors listed at https://centralizelegal.com/subprocessors. Processor will impose data protection obligations on Subprocessors substantially similar to this DPA. Processor will update the Subprocessor list and provide notice of material additions (continued use after notice constitutes acceptance, or Customer may terminate per the Terms).
5. Security measures
Processor maintains measures including: TLS encryption in transit; envelope encryption for OAuth tokens at rest; tenant-scoped database access; metadata-only audit logging; and pass-through handling of privileged content without persistent storage in the index. See Security Overview.
6. Data retention & deletion
- Disconnecting a source removes that OAuth connection and associated index data for that connection.
- Upon firm account closure (following any applicable grace period described in the Terms), Processor purges operational Customer Data including connections, index rows, and checklist data. Audit metadata may be retained where required for legal or compliance purposes.
- Customer may request information about deletion by contacting support@centralizelegal.com.
7. International transfers
Customer Data is processed in United States — Google Cloud and Railway region us-west1 (Oregon / US West). See Data Residency Statement. Customer Data may be accessed by Customer's users and connected third-party systems (Clio, Microsoft, Dropbox) under Customer's existing agreements with those providers.
8. Customer responsibilities
- Customer is responsible for having a lawful basis to connect practice systems and to process data through the service.
- Customer is responsible for the security and appropriateness of the AI environment it connects (business/enterprise tier recommended for client-confidential workflows). Processor provides retrieval plumbing only; Customer's AI provider relationship is separate.
- Customer shall ensure users connect only accounts they are authorized to use and comply with applicable law, including attorney-client privilege and TCPA consent for SMS.
9. Audits
Upon reasonable written request, Processor will provide information necessary to demonstrate compliance with this DPA, and allow for audits no more than once per year with 30 days' notice, subject to confidentiality and security constraints. Processor may satisfy audit requests through its Security Overview, this DPA, and SOC reports from Subprocessors where available.
10. Liability & order of precedence
Liability limits in the Terms of Service apply to this DPA. If this DPA conflicts with the Terms on data protection matters, this DPA controls.
11. Term
This DPA remains in effect for the duration of Customer's use of the service and until Customer Data is deleted per Section 6.
Contact
Related: Privacy Policy · Terms of Service · Security Overview · Data Processing Agreement · Subprocessors · Data Residency