Data Processing Agreement (DPA)
Last updated: 8 August 2026
This template governs the entrustment of personal data processing by the firm (controller) to the operator of the legisto.pl platform (processor), in accordance with Art. 28 GDPR. Entrustment takes place solely for the purpose and to the extent necessary to provide the service.
1. Subject matter and duration
The subject is the processing of data entered into the platform in connection with using the service (including cases, clients, documents, deadlines, billing).
The entrustment lasts for the term of the main agreement. After it ends, data is returned or deleted in accordance with section 8.
2. Nature and purpose of processing
Processing includes storing, organizing, making available to authorized firm users, and operations necessary for the platform's features to work.
The processor acts solely on documented instructions from the controller, which also includes using the platform's features for their intended purpose.
3. Type of data and categories of persons
Data of the firm's employees and collaborators, and data of clients and persons appearing in cases (to the extent entered by the controller).
The controller is responsible for the lawfulness of the scope of data entered into the platform and for the legal basis of its processing.
4. Obligations of the processor
Processing solely on the controller's instructions; ensuring confidentiality of authorized persons; implementing security measures in accordance with Art. 32 GDPR.
Supporting the controller in fulfilling data-subject rights and obligations under Art. 32 to 36 GDPR, taking into account the nature of processing and available information.
5. Sub-processing (subprocessors)
The processor uses trusted providers under agreements ensuring a level of protection no lower than in this template. Current list:
Vercel (hosting, EU region), Supabase (database and authentication, EU region), Anthropic (AI features), Resend (e-mail), Stripe (payments, where applicable).
The controller is informed of changes to the subprocessor list, with the right to raise a justified objection.
6. Security measures
Encryption in transit and at rest, isolation of each firm's data at the database level (RLS), role-based access control, two-factor authentication, and an audit log.
Integration secrets stored in an encrypted vault. AI models are not trained on firm data. For the most sensitive data, a firm-controlled key option is available.
7. Breach notification
The processor notifies the controller of a personal data breach without undue delay after becoming aware of it, providing the information necessary for the controller to fulfil its obligation to notify the supervisory authority within 72 hours (Art. 33 GDPR).
8. Deletion or return of data
After the service ends, data is, at the controller's choice, returned or deleted together with copies, unless the law requires further storage.
The controller may export its data at any time during the agreement (portability, no vendor lock-in).
9. Audit and data location
The controller has the right to information necessary to demonstrate compliance and to audit on terms agreed between the parties.
Data is hosted in the European Union. Any transfer outside the EEA takes place solely under the mechanisms of Chapter V GDPR.