Legal
Last updated June 2026
This Data Processing Addendum ("DPA") forms part of the Attorney Armor Terms of Service between Attorney Armor ("Processor") and the customer ("Controller") and governs the processing of personal data on the Controller's behalf.
Controller determines the purposes and means of processing; Processor processes personal data only on documented instructions from Controller and as necessary to provide the platform.
Processing consists of hosting, securing, analyzing, and reporting on assessment data and account information submitted by Controller, for the duration of the subscription.
Controller authorizes Processor to engage the subprocessors listed below. Processor will give 30 days' prior notice (via email to account administrators) of any new or replacement subprocessor; Controller may object on reasonable data-protection grounds.
| Subprocessor | Purpose | Region |
|---|---|---|
| Supabase (via Lovable Cloud) | Managed Postgres, authentication, file storage | United States / EU |
| Cloudflare Workers | Application hosting, edge runtime, CDN | Global edge |
| Stripe, Inc. | Payment processing and subscription billing | United States |
| Google (OAuth) | Optional single sign-on for end users | United States |
| Resend / transactional email | Account, security, and billing notifications | United States |
Processor maintains the technical and organizational measures described on the Security page, including encryption in transit (TLS 1.2+) and at rest, least-privilege access controls, MFA for administrators, audit logging, and continuous monitoring.
Where personal data is transferred outside the EEA, UK, or Switzerland, Processor relies on the European Commission's Standard Contractual Clauses (Module 2: controller-to-processor) and the UK International Data Transfer Addendum, incorporated by reference.
Processor will provide reasonable assistance to Controller in responding to data subject requests received through the platform within statutory deadlines.
Processor will notify Controller without undue delay, and in any event within 72 hours after becoming aware of a personal data breach affecting Controller data, and will provide information reasonably necessary for Controller's own notification obligations.
Upon termination, Processor will, at Controller's election, return or delete personal data within 90 days, subject to legal retention obligations.
Processor will make available information reasonably necessary to demonstrate compliance, including third-party audit summaries where available, no more than once per 12-month period absent a security incident.
To the extent the CCPA applies, Processor acts as a "service provider" and will not (a) sell or share personal information, (b) retain, use, or disclose it outside the direct business relationship, or (c) combine it with personal information received from other sources, except as permitted by law.
To countersign this DPA, contact our legal team with your firm name and billing contact.