Data Processing Agreement (DPA)

Between: iHOST LABS, LLC ("Processor") and the law firm customer ("Controller") Effective: On acceptance of Terms of Service Last updated: 2026-10-09

Changes taking effect on 30 October 2026. On 30 October 2026, the wording quoted below replaces the text of this agreement that it names. Until then, the current text below stays in force. Notice of these changes was emailed to the administrators of every customer firm; to object to any of them, or to ask about them, write to privacy@trialcommander.com before 30 October 2026.

§ 3.8 becomes: “3.8 Deletion on termination. On termination of the Service, we delete Customer Data per the schedule in the Privacy Policy (no sooner than 30 days after cancellation, with backups retained as described in Terms of Service § 8.3).”

1. Definitions

"Customer Data" means data the Controller uploads or enters into Trial Commander, including client information, matter details, time entries, trust records, and documents.

"Data Protection Laws" means applicable laws governing privacy and data protection, including Florida Statutes § 501.171, Florida Bar Rule 4-1.6(e), HIPAA (where applicable), GDPR, CCPA, and their successors.

"Security Incident" means unauthorized access, use, disclosure, alteration, or destruction of Customer Data.

"Sub-processor" means any third party that processes Customer Data on behalf of the Processor.

2. Roles

The Controller determines the purposes and means of processing Customer Data. The Processor processes Customer Data only on the Controller's documented instructions to provide the Service.

3. Processor Obligations

The Processor:

3.1 Processes only on instruction. We process Customer Data only to provide the Service as described in our Terms and Privacy Policy, or as otherwise instructed in writing. We do not use Customer Data for our own purposes, training AI models, advertising, or resale.

3.2 Personnel confidentiality. All employees and contractors with access to Customer Data are bound by confidentiality obligations that survive termination of their engagement.

3.3 Security. We maintain appropriate technical and organizational measures:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Field-level encryption for privileged data
  • Access controls with MFA for privileged access
  • Tamper-evident audit logs
  • Regular security testing and dependency scanning
  • Incident response procedures with documented recovery time objectives
  • Background checks and security training for personnel

3.4 Sub-processors. We engage sub-processors (listed in § 7) subject to data protection obligations equivalent to those in this DPA, except as stated in § 7 for Free Law Project (engaged only under its public API terms), Google Calendar (events held under the connecting user's own agreement with Google; Google acts as an independent controller) and Intuit (QuickBooks Online data held under the Controller's own agreement with Intuit; Intuit acts as an independent controller). We are liable for sub-processor compliance.

3.5 Data subject requests. If a data subject contacts us directly, we will forward the request to the Controller and not respond ourselves (except to acknowledge receipt and direct them to the Controller).

3.6 Assistance. We assist the Controller in complying with data protection law, including by:

  • Providing audit logs and access records
  • Responding to security questionnaires (annually, or on reasonable request)
  • Notifying of breach within 72 hours
  • Cooperating with regulator inquiries

3.7 Audits. Upon 30 days' written notice and subject to confidentiality, the Controller may audit our compliance with this DPA no more than once per year, during business hours, at Controller's expense. We may satisfy this by providing current SOC 2 Type II or ISO 27001 reports where available.

3.8 Deletion on termination. On termination of the Service, we delete Customer Data per the schedule in the Privacy Policy (30 days after cancellation, with backups retained as described in Terms of Service § 8.3).

4. Controller Obligations

The Controller:

4.1 Lawful basis. Has a lawful basis for processing Customer Data and has obtained necessary consents or authorizations from data subjects (clients, third parties mentioned in matters).

4.2 Accuracy. Is responsible for the accuracy, legality, and content of Customer Data.

4.3 Client notification. Is responsible for notifying clients about the use of cloud software, including AI features, as required by Florida Bar Rule 4-1.6(e) and ABA Formal Opinion 512.

4.4 Instructions. Issues instructions to the Processor that comply with data protection law. If Processor believes an instruction violates law, it will inform Controller and not act on the instruction.

4.5 Appropriate use. Uses the Service consistent with Florida Bar rules and does not use it to circumvent trust account, confidentiality, or other regulatory requirements.

5. Security Incidents

5.1 We will notify the Controller within 72 hours of confirming a Security Incident affecting their data, via:

  • Email to the firm admin contact on file
  • Detailed incident report within 7 days

5.2 The notification will include (to extent known):

  • Nature and scope of the incident
  • Categories and approximate volume of data affected
  • Likely consequences
  • Measures taken or proposed to address it
  • Contact for more information

5.3 We will provide reasonable cooperation in the Controller's own breach-notification obligations.

6. International Transfers

If Customer Data is transferred out of EEA/UK:

  • We rely on the European Commission's Standard Contractual Clauses (2021 Module 2, Controller-to-Processor)
  • Or UK ICO International Data Transfer Addendum where applicable

7. Sub-processors

Current authorized sub-processors:

Sub-processorPurposeData CategoryLocationCertifications
Clerk Inc.AuthenticationUser identity, sessionUSASOC 2 Type II
Stripe Inc.Payment processingBilling infoUSAPCI-DSS Level 1, SOC 2
Anthropic PBCAI processing (no model training on customer data; retention per the AI Disclosure)Matter content for AI featuresUSASOC 2 Type II
Postmark (AC PM LLC)Transactional emailRecipient infoUSASOC 2 Type II
Sentry (Functional Software, Inc.)Error monitoringStack traces (PII scrubbed)USASOC 2 Type II
Cloudflare, Inc. (R2)File storage and backup storageUploaded documents; and the Service's daily per-firm database backups, which contain all Customer DataUSASOC 2 Type II
Upstash Inc.Rate limiting / RedisIP, hashed user IDsUSA—
Intuit Inc. (QuickBooks Online)Accounting sync — only for Controllers that connect QuickBooksClient name, client billing email, invoice and payment amounts and dates, matter referenceUSA—
Microsoft Corporation (Azure, Microsoft Graph)Application hosting and database; document sync and email filing (OneDrive/SharePoint, Outlook) for Controllers that connect them; calendar sync for users who connect their own Microsoft 365 / Outlook calendar (push, and reading that user's own events back to show them in the Service); speech-to-text transcription of deposition audio (Azure AI Speech) for Controllers that use transcription on our servers, from the effective date of the notice of this changeAll Customer Data; where connected, also matter documents and filed client email bodies and attachments; where a user connects their Outlook calendar, the deadlines and consultations pushed to it (the same fields as the Google Calendar row); for deposition transcription, the recorded audio and, as recognition hints, the deponent's and matter's names (audio not stored by the Processor)USA (East US 2 — Virginia)SOC 2 Type II, ISO 27001, HITRUST
OpenAI, L.L.C.Voice-memo transcription — only once it is set up on the ServiceWhen set up: audio of voice memos users recordUSA—
Free Law Project (CourtListener)Case-law research search, citation check and federal docket tracking (docket tracking not yet available)Case citation strings extracted from a draft (never the draft text); research search terms users type; once docket tracking is available, case numbers and courts a Controller tracksUSA—
Google LLC (Google Calendar)Calendar sync — only for users who connect their own Google Calendar, and only once connecting is set up on the Service: push, and reading that user's own events back to show them in the ServicePushed deadlines (title, date, priority, rule, matter number and name, client name) and consultations (time, location, prospective client's name, email, phone and stated reason)USA—

Notice of Changes. We maintain this list at https://www.trialcommander.com/sub-processors. Material changes require 30 days' notice. Controllers may object within 14 days; we will work to address concerns or offer cancellation with pro-rated refund.

Terms of the 2026-09-27 additions. The list above was updated on 2026-09-27. OpenAI and Google are new sub-processors. Notice of the change was sent to customer Controllers on 2026-09-29, and on that date the Processor decided not to wait the 30 days provided under Notice of Changes: both may be used from 2026-09-29. Each is used only once its feature is set up on the Service, and only when a user records a voice memo or connects their own Google Calendar. Free Law Project was added, and the Microsoft row corrected to include calendar push, to disclose processing that was already happening before it was listed; that processing should have been listed, with 30 days' notice, before it began, and was not. The obligations each is engaged under, and where those differ from this Agreement (Free Law Project is engaged only under its public API terms; Google Calendar events are held under the connecting user's own agreement with Google), are stated in the notes on the Sub-processors page. Notice of these changes is given to customer Controllers by email, and a Controller may object to any of them within 14 days of that notice, as provided under Notice of Changes above.

Change of 2026-10-09. Section 3.4 now states that Google (Google Calendar) and Intuit (QuickBooks Online) act as independent controllers, under their own terms and the Controller's or user's own agreement with them, rather than as processors engaged under terms equivalent to this Agreement; no sub-processor was added or removed. The Microsoft row in this § 7 now also lists speech-to-text transcription of deposition audio (Azure AI Speech), a new purpose for an existing sub-processor, which the Processor does not use before the effective date of the notice of this change. Separately, § 11 now lists privacy@trialcommander.com as our privacy contact, in place of the contact it listed before. Notice of these changes is given to customer Controllers by email, and they take effect for each Controller on the date that notice states.

8. HIPAA Considerations

For Controllers representing clients in medical malpractice or other matters involving Protected Health Information (PHI):

  • A separate Business Associate Agreement (BAA) would have to be executed, and none is currently available on any plan
  • A BAA cannot be offered until a BAA is in place with every sub-processor that would handle PHI; the status of each is stated on the Sub-processors page
  • The HIPAA Addendum was withdrawn on 2026-09-16 and will be republished only when a BAA can be executed. Until then this Agreement does not create a business-associate relationship, and PHI should not be processed through the Service under one

9. Term and Survival

This DPA takes effect on acceptance of Terms and remains in force as long as Processor holds Customer Data. Obligations regarding deletion, audit log retention, and breach notification survive termination.

10. Liability

Liability under this DPA is subject to the limitations in the Terms of Service, except where data protection law prohibits such limitation.

11. Contact