Data Processing Agreement (DPA)
Last updated: 14 August 2026
This DPA forms part of the Terms of Service between Jadthena Limited, a company registered in England and Wales (company no. 16232930), registered office: 62 Border Brook Lane, Worsley, Manchester, England, M28 1XJ ("Processor", "we"), and the customer ("Controller", "you"), and applies where we process personal data on your behalf in providing "Counsel AI".
1. Definitions
"UK GDPR", "EU GDPR", "personal data", "processing", "data subject", "controller", "processor", and "supervisory authority" have the meanings given in applicable data-protection law. "Applicable Data Protection Law" means the UK GDPR and Data Protection Act 2018 and/or the EU GDPR, as applicable to the processing.
2. Roles and scope
You are the controller and we are the processor of the Customer Content you submit. We process personal data only to provide and support the Service and on your documented instructions (which include the Terms, this DPA, and your configuration of the Service). We will inform you if, in our opinion, an instruction infringes Applicable Data Protection Law.
3. Details of processing (Article 28(3))
- Subject matter: provision of the "Counsel AI" AI legal-workflow service.
- Duration: for the term of the Terms and until deletion under section 9.
- Nature and purpose: automated analysis/generation of legal work product from documents and prompts you submit, plus storage and retrieval.
- Types of personal data: any personal data contained in the documents and prompts you choose to submit, and the resulting outputs. You control what you upload.
- Categories of data subjects: as determined by your content (e.g. your personnel, counterparties, customers). You should avoid submitting special-category data unless necessary and lawful.
4. Processor obligations
We will: (a) process personal data only on your documented instructions; (b) ensure persons authorised to process are bound by confidentiality; (c) implement the technical and organisational measures in the Annex (Article 32); (d) assist you, taking into account the nature of processing, with data-subject requests (Article 12–23) and with your obligations under Articles 32–36 (security, breach notification, DPIAs, prior consultation); (e) make available information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, on reasonable notice and subject to confidentiality; and (f) delete or return personal data under section 9.
5. Sub-processors
5.1 You grant general authorisation for us to engage sub-processors to provide the Service. Current sub-processors:
| Sub-processor | Purpose | Location | Retention by that sub-processor |
|---|---|---|---|
| Anthropic, PBC | AI model (Claude API) used to generate outputs | USA | Up to 30 days for trust-and-safety, then deleted. Inputs and outputs are not used to train Anthropic's models. Zero-data-retention is not available for the Claude 5-series models the Service uses. |
| Hetzner Online GmbH | Hosting, database, object storage | EU (Hetzner Online GmbH, Germany) | For the life of the data in the Service (see section 9). |
| Stripe | Subscription billing / payments (limited personal data) | EU/US | Per Stripe's own terms; no Customer Content is sent to Stripe. |
| Local Ollama (our infrastructure) | Zero-cost local AI path when no external model key is configured | EU (Hetzner Online GmbH, Germany) | Nothing is retained outside our infrastructure on this path. |
5.2 We impose data-protection obligations on each sub-processor equivalent to those in this DPA. We will give you prior notice of any intended addition or replacement of a sub-processor and you may object on reasonable data-protection grounds.
6. International transfers
Where processing involves a transfer of personal data outside the UK/EEA, we will ensure an appropriate safeguard is in place — the UK IDTA/Addendum or, where EU GDPR applies, the EU Standard Contractual Clauses (with the relevant modules), together with any necessary supplementary measures.
7. Security (Article 32)
We implement appropriate technical and organisational measures appropriate to the risk, as set out in the Annex, including encryption in transit, access control, tenant isolation, and least-privilege administration.
8. Personal data breach
We will notify you without undue delay after becoming aware of a personal-data breach affecting your data, and provide information reasonably available to help you meet your own breach-notification obligations.
9. Return and deletion
On termination, or earlier on your request, we will delete or return your personal data and delete existing copies within a reasonable period, save to the extent we are required by law to retain it.
Independently of termination, uploaded documents are deleted automatically by a scheduled job once they are older than the configured retention period (90 days by default, configurable per organisation). Analysis outputs are retained for the life of the account as the controller's own work product, and are deleted on request. The audit log records metadata about actions taken in the Service — never document contents — and is retained beyond the document-retention period so that it remains a reliable record; it is exportable by organisation admins at any time.
10. Liability and governing law
Liability under this DPA is subject to the limitations in the Terms. This DPA is governed by the law of England and Wales. In the event of conflict between this DPA and the Terms on the subject of data protection, this DPA prevails.
Annex — Technical and organisational measures (summary)
- Encryption of data in transit (TLS); encryption at rest where supported by the hosting platform.
- Passwordless authentication (magic link); session expiry; bearer/cookie session controls.
- Logical tenant isolation between organisations at the application layer.
- Role-based, least-privilege administrative access; platform-admin access restricted to an allowlist.
- Sub-processor due diligence and contractual data-protection terms.
- Configurable data-retention with automatic deletion; deletion on request.
- Logging and monitoring for security and reliability.
*"Counsel AI" produces AI-generated drafts for review by a qualified legal professional. It does not provide legal advice.*
