Data Processing Agreement (DPA)
Between: Navarro Hernandez, P.L. ("Processor") and the law firm customer ("Controller") Effective: On acceptance of Terms of Service
⚠ LEGAL REVIEW REQUIRED — DPA template. Counsel review essential before publication. Particularly: confirm sub-processor flow-through clauses match current vendor contracts.
1. Definitions
"Customer Data" means data the Controller uploads or enters into Trial Commander, including client information, matter details, time entries, trust records, and documents.
"Data Protection Laws" means applicable laws governing privacy and data protection, including Florida Statutes § 501.171, Florida Bar Rule 4-1.6(e), HIPAA (where applicable), GDPR, CCPA, and their successors.
"Security Incident" means unauthorized access, use, disclosure, alteration, or destruction of Customer Data.
"Sub-processor" means any third party that processes Customer Data on behalf of the Processor.
2. Roles
The Controller determines the purposes and means of processing Customer Data. The Processor processes Customer Data only on the Controller's documented instructions to provide the Service.
3. Processor Obligations
The Processor:
3.1 Processes only on instruction. We process Customer Data only to provide the Service as described in our Terms and Privacy Policy, or as otherwise instructed in writing. We do not use Customer Data for our own purposes, training AI models, advertising, or resale.
3.2 Personnel confidentiality. All employees and contractors with access to Customer Data are bound by confidentiality obligations that survive termination of their engagement.
3.3 Security. We maintain appropriate technical and organizational measures:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Field-level encryption for privileged data
- Access controls with MFA for privileged access
- Tamper-evident audit logs
- Regular security testing and dependency scanning
- Incident response procedures with documented recovery time objectives
- Background checks and security training for personnel
3.4 Sub-processors. We engage sub-processors (listed in § 7) subject to data protection obligations equivalent to those in this DPA. We are liable for sub-processor compliance.
3.5 Data subject requests. If a data subject contacts us directly, we will forward the request to the Controller and not respond ourselves (except to acknowledge receipt and direct them to the Controller).
3.6 Assistance. We assist the Controller in complying with data protection law, including by:
- Providing audit logs and access records
- Responding to security questionnaires (annually, or on reasonable request)
- Notifying of breach within 72 hours
- Cooperating with regulator inquiries
3.7 Audits. Upon 30 days' written notice and subject to confidentiality, the Controller may audit our compliance with this DPA no more than once per year, during business hours, at Controller's expense. We may satisfy this by providing current SOC 2 Type II or ISO 27001 reports where available.
3.8 Deletion on termination. On termination of the Service, we delete Customer Data per the schedule in the Privacy Policy (30 days after cancellation, with up to 90-day backup retention).
4. Controller Obligations
The Controller:
4.1 Lawful basis. Has a lawful basis for processing Customer Data and has obtained necessary consents or authorizations from data subjects (clients, third parties mentioned in matters).
4.2 Accuracy. Is responsible for the accuracy, legality, and content of Customer Data.
4.3 Client notification. Is responsible for notifying clients about the use of cloud software, including AI features, as required by Florida Bar Rule 4-1.6(e) and ABA Formal Opinion 512.
4.4 Instructions. Issues instructions to the Processor that comply with data protection law. If Processor believes an instruction violates law, it will inform Controller and not act on the instruction.
4.5 Appropriate use. Uses the Service consistent with Florida Bar rules and does not use it to circumvent trust account, confidentiality, or other regulatory requirements.
5. Security Incidents
5.1 We will notify the Controller within 72 hours of confirming a Security Incident affecting their data, via:
- Email to the firm admin contact on file
- Detailed incident report within 7 days
5.2 The notification will include (to extent known):
- Nature and scope of the incident
- Categories and approximate volume of data affected
- Likely consequences
- Measures taken or proposed to address it
- Contact for more information
5.3 We will provide reasonable cooperation in the Controller's own breach-notification obligations.
6. International Transfers
If Customer Data is transferred out of EEA/UK:
- We rely on the European Commission's Standard Contractual Clauses (2021 Module 2, Controller-to-Processor)
- Or UK ICO International Data Transfer Addendum where applicable
7. Sub-processors
Current authorized sub-processors:
| Sub-processor | Purpose | Data Category | Location | Certifications |
|---|---|---|---|---|
| Clerk Inc. | Authentication | User identity, session | USA | SOC 2 Type II |
| Stripe Inc. | Payment processing | Billing info | USA | PCI-DSS Level 1, SOC 2 |
| Anthropic PBC | AI processing (no model training on customer data; limited or zero retention per the AI Disclosure) | Matter content for AI features | USA | SOC 2 Type II |
| Postmark (AC PM LLC) | Transactional email | Recipient info | USA | SOC 2 Type II |
| Sentry (Functional Software, Inc.) | Error monitoring | Stack traces (PII scrubbed) | USA | SOC 2 Type II |
| Cloudflare, Inc. (R2) | File storage | Uploaded documents | USA | SOC 2 Type II |
| Upstash Inc. | Rate limiting / Redis | IP, hashed user IDs | USA | — |
| Microsoft Corporation (Azure) | Application hosting and database | All Customer Data | USA (East US 2 — Virginia) | SOC 2 Type II, ISO 27001, HITRUST |
Notice of Changes. We maintain this list at https://www.trialcommander.com/sub-processors. Material changes require 30 days' notice. Controllers may object within 14 days; we will work to address concerns or offer cancellation with pro-rated refund.
8. HIPAA Considerations
For Controllers representing clients in medical malpractice or other matters involving Protected Health Information (PHI):
- A separate Business Associate Agreement (BAA) must be executed
- Additional safeguards apply (see HIPAA Addendum)
- Not available on the TRIAL tier; requires Complete or Enterprise subscription
9. Term and Survival
This DPA takes effect on acceptance of Terms and remains in force as long as Processor holds Customer Data. Obligations regarding deletion, audit log retention, and breach notification survive termination.
10. Liability
Liability under this DPA is subject to the limitations in the Terms of Service, except where data protection law prohibits such limitation.
11. Contact
- Data Protection Officer: dpo@trialcommander.com
- Privacy: privacy@trialcommander.com
- Security Incidents: security@trialcommander.com (monitored 24/7 for urgent reports)
Template version 1.0 — requires counsel review before publication.