Accordo di trattamento dati (DPA)

Ultimo aggiornamento: 11 August 2026

Bozza — revisione richiesta prima del lancio pubblico. Questo documento è mantenuto da Digital Ways LLC e contiene ancora segnaposto tra parentesi quadre che devono essere convalidati da un avvocato qualificato della giurisdizione operativa prima dell'uso in produzione.

This page summarises the Data Processing Agreement ("DPA") that Digital Ways LLC signs with customers who use the LexAI Service to process personal data of their own clients or third parties. A signed copy is available on request at privacy@lexai.enterprises.

1. Roles

The Customer acts as Data Controller. Digital Ways LLC acts as Data Processor for content uploaded by the Customer into the platform.

2. Subject and duration

Processing lasts for the duration of the subscription and any post-termination retention described in the Privacy Policy.

3. Nature and purpose of processing

Storage, indexing, retrieval, AI-assisted analysis, drafting and export of legal content uploaded by the Customer.

4. Categories of data subjects and data

  • Clients and counterparties of the Customer's law firm.
  • Identification data, contact data, matter facts and documents.
  • Potentially special categories of data (Art. 9 GDPR) if included in matter files.

5. Instructions

Digital Ways LLC processes personal data only on documented instructions from the Customer, which are primarily given through the configuration and use of the Service.

6. Confidentiality

Personnel authorized to process the data are bound by confidentiality obligations.

7. Security measures

Digital Ways LLC implements the technical and organizational measures described in the Security page, including encryption in transit and at rest, row-level security, role-based access, activity logging and least-privilege backend access.

8. Sub-processors

The Customer authorizes Digital Ways LLC to engage the sub-processors listed at /subprocessors. Digital Ways LLC will give reasonable prior notice of additions or changes.

9. International transfers

Any transfer outside the EEA is covered by Standard Contractual Clauses or equivalent safeguards. Hosting and storage regions: United States and European Union.

10. Data-subject rights

Digital Ways LLC assists the Customer, taking into account the nature of the processing, in responding to data-subject requests through appropriate technical and organizational measures.

11. Breach notification

Digital Ways LLC notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, and provides the information reasonably needed for the Customer to comply with Art. 33 GDPR.

12. Return or deletion

Upon termination, at the Customer's choice, data is deleted or returned in a commonly used format, subject to legal retention obligations and backup rotation.

13. Audits

Digital Ways LLC makes available all information reasonably necessary to demonstrate compliance and allows audits, including on-site inspections, conducted by the Customer or a qualified auditor mandated by the Customer, subject to reasonable notice and confidentiality.