Processor: Dogetlawyer AI Ltd, registered in England and Wales (company number 16719329) · 124–128 City Road, London EC1V 2NX, United Kingdom · support@dogetlawyer.com
1. Parties, roles and precedence
- "Customer", "you": the business or professional account holder. You are the controller of personal data contained in Customer Content (or a processor for your own client, in which case we are your subprocessor and you warrant your instructions are authorised).
- "Dogetlawyer", "we": Dogetlawyer AI Ltd (company number 16719329), acting as your processor.
- "Customer Content": documents, files, chat inputs, contract-register entries and other material you or your team submit to the Service, including any personal data in them.
- "Data Protection Laws": the UK GDPR and Data Protection Act 2018 (as amended, including by the Data (Use and Access) Act 2025), and — where it applies to you — the EU GDPR.
- If this DPA conflicts with the Terms on a data-processing matter, this DPA prevails.
2. Details of the processing
| Subject matter | Hosting and processing of Customer Content to provide the Service (document drafting, contract review, contract lifecycle management, AI chat, storage, related features) |
|---|---|
| Duration | The life of your account, plus the export and deletion periods in section 8 |
| Nature and purpose | Storage, retrieval, display, transmission to the AI subprocessors listed in the Privacy Policy (section 7) to generate features you request, backup, and deletion — solely to provide the Service |
| Categories of data subjects | Your clients, employees, contractors, counterparties and other individuals appearing in Customer Content |
| Categories of personal data | Names, contact details, employment and contractual details, financial figures, and any other personal data you choose to include in Customer Content |
| Special category / criminal-offence data | Only if and to the extent you choose to include it. You are responsible for ensuring you have an appropriate condition under Articles 9–10 UK GDPR (or EU GDPR) before uploading it; we apply the same technical protections to it as to all Customer Content |
3. Our obligations as processor
Dogetlawyer will:
- Documented instructions — process Customer Content only on your documented instructions (the Terms, this DPA, and your use of the Service's controls are those instructions), including as regards international transfers, unless UK or (where applicable) EU law requires otherwise — in which case we will tell you before processing, unless that law prevents it. We will inform you if, in our opinion, an instruction infringes Data Protection Laws.
- Confidentiality — ensure that every person we authorise to process Customer Content is bound by a contractual or statutory duty of confidentiality.
- Security (Article 32) — implement and maintain appropriate technical and organisational measures, including: encryption in transit (TLS); passwords stored only as salted secure hashes; role-based, least-privilege access to production systems; and encrypted backups with automatic expiry (within 90 days after live-system deletion). We describe only measures in place, and will notify business customers as additional controls come online.
- Subprocessors — you give general written authorisation for the subprocessors listed in the Privacy Policy, section 7. We will update that list and notify business customers by email at least 14 days before adding or replacing a subprocessor that processes Customer Content. If you reasonably object on data-protection grounds and we cannot offer an alternative, you may terminate the affected part of the Service with a proportionate refund of pre-paid, unused fees. Every subprocessor is bound by a contract imposing data-protection obligations equivalent to this DPA, and we remain fully liable to you for their performance.
- Data-subject rights — taking into account the nature of the processing, assist you with appropriate technical and organisational measures (export tools, deletion controls, and direct assistance on request) in fulfilling your obligation to respond to data-subject requests under Articles 12–23. If a data subject contacts us directly about Customer Content, we will pass the request to you promptly and not respond over your head (see Your Data Rights, section 8).
- Breach notification and assistance — notify you without undue delay after becoming aware of a personal-data breach affecting Customer Content, with the information Article 33(3) requires (as available, supplemented as we learn more), and assist you with your obligations under Articles 32–36 (security, breach notification, data-protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to us.
- Deletion and return — at the end of the services, delete or return (at your choice) all Customer Content: you have a 30-day export window after account closure, after which content is deleted from live systems within 30 days (normally no later than 60 days after closure) and residual copies in encrypted backups expire automatically within 90 days after that deletion, except where UK or EU law requires continued storage.
- Audits and information — make available to you the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits: first through written responses and documentation (which resolves most requests), and — where Data Protection Laws give you a right to more — an audit conducted on reasonable notice, no more than once in any 12-month period, during business hours, under confidentiality, at your cost, and without access to other customers' data.
4. International transfers
Customer Content is processed in the UK and, via the subprocessors in the Privacy Policy, in the EEA and the United States. Every transfer out of the UK (or, for EU customers, out of the EEA) is protected by adequacy regulations/decisions (including the UK Extension to the EU–US Data Privacy Framework where the recipient is certified), or by the UK International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses, with supplementary measures where needed. Details: Privacy Policy, section 8.
5. Our AI-specific commitments for Customer Content
- Customer Content is sent to AI subprocessors only to generate the feature you requested, via business APIs whose terms state the content is not used to train the provider's foundation models.
- We do not use Customer Content to train AI models and we do not sell it.
- No solely automated decision producing legal or similarly significant effects is made about any data subject by the Service.
6. Your obligations as controller
- You warrant that you have a lawful basis (and, for special category or criminal-offence data, an appropriate condition) for the personal data you include in Customer Content, and that you have given any required transparency information to the individuals concerned.
- You are responsible for the accuracy and lawfulness of Customer Content and for configuring team access appropriately.
- You will not instruct us to process personal data in violation of Data Protection Laws.
7. Liability and claims
Each party's liability under this DPA is subject to the liability provisions of the Terms (section 16), except that nothing limits either party's liability to data subjects under Article 82 UK GDPR or a supervisory authority's powers.
8. Duration, governing law and changes
This DPA applies for as long as we process Customer Content on your behalf, plus the deletion periods in section 3(7). It is governed by the law of England and Wales, like the Terms. We may update this DPA to reflect changes in law or the Service; material changes are notified to business customers by email at least 14 days in advance, and the version at this page always applies.
Version 1.1 · Effective 24 July 2026 · Implements UK GDPR Article 28(2)–(4) and, for EU customers, EU GDPR Article 28 · Subprocessor list: Privacy Policy §7 · Transfers: Privacy Policy §8 · Incorporated automatically into the Terms & Conditions (§18).