Data Processing Agreement
Effective date: 13 August 2026
This Data Processing Agreement ("DPA") applies where Naman Kedia ("Processor", "we") processes personal data on behalf of a customer ("Controller", "you") in the course of providing the Services. It forms part of and is governed by our Terms of Service.
It is written to meet Article 28(3) of the General Data Protection Regulation (EU) 2016/679 ("GDPR"), and applies equally to the UK GDPR where relevant.
If you are a law firm or business customer and require a signed copy, contact namankedia@geppetto.work.
Note on roles. We act as Processor for personal data you instruct us to process in providing the Services. We act as an independent Controller for our own limited purposes — operating and securing the Services, billing, and complying with law — and our Privacy Policy governs that. Where we store an uploaded document for our own record of what we checked, we do so as Controller for that purpose; that is described in the Privacy Policy and you should ensure your own notices cover it.
1. Definitions
Terms defined in the GDPR — including "personal data", "processing", "data subject", "controller", "processor", "sub-processor", "personal data breach" and "supervisory authority" — have the same meaning here.
"Data Protection Law" means the GDPR, the UK GDPR, and any other data protection law applicable to the processing.
2. Subject matter and details of processing
2.1 Subject matter: our provision of the Services to you.
2.2 Duration: for as long as we provide the Services to you, plus any retention period stated in the Privacy Policy.
2.3 Nature and purpose: hosting, storage, transmission, text extraction, citation extraction, citation lookup against public case-law sources, website monitoring (where purchased), and related support and security operations, in each case to provide the Services.
2.4 Types of personal data:
- Personal data contained within documents you upload — which, for legal documents, may include names of parties, witnesses and third parties, contact details, and special categories of personal data (Article 9) and data relating to criminal convictions and offences (Article 10)
- Account data: name, email address, authentication data
- Usage and technical data: IP address, request logs
2.5 Categories of data subjects: your personnel and authorised users; your clients; and any other individual whose personal data appears in material you submit.
2.6 You determine the types of personal data and categories of data subjects by choosing what to submit.
3. Processing on documented instructions (Article 28(3)(a))
3.1 We will process personal data only on your documented instructions, including as to international transfers, unless required to do otherwise by law to which we are subject. Where law requires it, we will inform you before processing unless that law prohibits it on important grounds of public interest.
3.2 The Terms of Service, this DPA, and your use of the Services are your complete documented instructions. Additional instructions require our written agreement and may attract a fee.
3.3 We will inform you if, in our opinion, an instruction infringes Data Protection Law (Article 28(3), final paragraph). We may suspend the affected processing until the instruction is withdrawn or amended.
4. Confidentiality (Article 28(3)(b))
4.1 We will ensure that every person authorised to process personal data under this DPA is bound by an appropriate obligation of confidentiality, whether contractual or statutory.
4.2 We limit access to personal data to those who need it to provide the Services, to fix a fault, or to comply with law.
4.3 We do not read the contents of documents you upload for product development, feature testing, analytics or marketing (Terms of Service, section 7.4). We do not use them to train machine-learning or artificial-intelligence models (section 7.5).
5. Security (Article 28(3)(c) and Article 32)
5.1 We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, costs, and the nature, scope, context and purposes of processing.
5.2 The measures in place are described in our Security document, which is incorporated by reference and includes encryption of uploaded documents at rest, exclusion of document contents from logs, restricted production access, and enforced deletion.
5.3 You acknowledge that our measures are described factually and are not warranted to prevent every incident. You are responsible for satisfying yourself that they are appropriate for the personal data you choose to submit — including deciding whether to submit special-category or criminal-offence data at all.
5.4 We will not materially reduce the overall level of security during the term.
6. Sub-processors (Article 28(3)(d) and Article 28(2))
6.1 You give general written authorisation for us to engage sub-processors.
6.2 Our current sub-processors are listed at Sub-processors.
6.3 We will give you at least thirty (30) days' notice of any intended addition or replacement of a sub-processor, by updating that page and, where you have asked to be notified, by email.
6.4 You may object on reasonable data-protection grounds within that period. We will work with you in good faith to address the objection. If we cannot, you may terminate the affected Service and receive a refund of any prepaid, unused fees, which is your sole remedy.
6.5 We will impose on each sub-processor data protection obligations no less protective than those in this DPA, and we remain fully liable to you for their performance.
7. Assistance with data subject rights (Article 28(3)(e))
7.1 Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to data subject requests under Chapter III of the GDPR.
7.2 If we receive a request directly from a data subject relating to your personal data, we will not respond to it substantively, and will refer the data subject to you and inform you promptly, unless legally required to respond.
7.3 The Services provide self-service functions for deletion and, where accounts exist, access. Where those functions meet your need, they constitute our assistance.
7.4 A practical limitation you must be aware of: the Citation Verifier can be used anonymously. Where a document has been uploaded without an account, we hold no information linking it to any individual and cannot identify whose document it is. We can act on the document identifier issued at upload. Where we cannot identify a data subject from the data we hold, Article 11 applies.
8. Assistance with breaches, impact assessments and consultations (Article 28(3)(f))
8.1 We will notify you without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a personal data breach affecting personal data processed under this DPA.
8.2 Our notification will describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where the information is not all available at once, we will provide it in phases without undue further delay.
8.3 We will not notify any supervisory authority or data subject about a breach affecting your personal data without first consulting you, unless legally required to do so. As Controller, that notification is your decision and your obligation.
8.4 We will provide reasonable assistance with your obligations under Articles 32 to 36, including data protection impact assessments and prior consultation, taking into account the nature of processing and the information available to us.
9. Deletion or return of data (Article 28(3)(g))
9.1 At the end of the provision of the Services, we will, at your choice, delete or return all personal data processed on your behalf, and delete existing copies, unless law requires us to retain it.
9.2 Absent a written instruction from you, we will delete in accordance with the retention periods in the Privacy Policy.
9.3 You may delete uploaded documents at any time using the Services.
9.4 Backups. Deleted personal data may persist in encrypted backups for a limited period before being overwritten in the ordinary cycle. It remains subject to this DPA until then and is not restored into active use.
10. Audits and information (Article 28(3)(h))
10.1 We will make available to you the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
10.2 Practical arrangements, which reflect that we are a very small organisation:
(a) we will first respond to a reasonable written information request, and expect that to satisfy most audits; (b) an on-site or remote inspection may be requested no more than once in any twelve-month period, unless required by a supervisory authority or following a personal data breach affecting your data; (c) at least thirty (30) days' written notice is required; (d) audits must occur during business hours, must not unreasonably disrupt operations, and are subject to confidentiality; (e) an auditor must not be a competitor of ours; (f) you bear your own costs, and our reasonable costs, of any inspection beyond a written information request; (g) we may withhold information whose disclosure would breach a duty owed to another customer, compromise the security of the Services, or disclose another customer's data.
10.3 We hold no third-party security certifications and no third-party audit report is available. We say so plainly; see the Security document.
11. International transfers
11.1 We are established in India, which is not the subject of an adequacy decision under Article 45.
11.2 Where we process personal data transferred from the European Economic Area, the United Kingdom or Switzerland, the transfer is made under the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914, which are incorporated into this DPA by reference:
(a) Module Two (controller to processor) applies where you are a controller; (b) Module Three (processor to processor) applies where you are a processor acting for another controller; (c) for the United Kingdom, the ICO's International Data Transfer Addendum applies to those clauses; (d) for Switzerland, references are adapted accordingly.
11.3 For the purposes of the clauses: you are the data exporter, we are the data importer; the details in section 2 of this DPA populate Annex I; the measures in our Security document populate Annex II; and the list in Sub-processors populates Annex III.
11.4 Docking clause / optional clauses. The optional clause on docking applies. Where the clauses require a choice of supervisory authority or governing law, the law and authority of the EEA Member State in which you are established apply, or Ireland where you are not established in the EEA.
11.5 Where the clauses conflict with the rest of this DPA, the clauses prevail.
⚠️ FOR REVIEW: the Standard Contractual Clauses require completed annexes and, in practice, a documented transfer impact assessment covering Indian government access powers. See
../reference/EU-COMPLIANCE-REQUIREMENTS.md§1.4. This DPA should not be signed with a customer until that assessment exists and the annexes are completed.
12. Liability
12.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except to the extent Data Protection Law prohibits limiting it.
12.2 Nothing in this DPA limits a data subject's rights, or either party's liability to a supervisory authority.
13. General
13.1 This DPA prevails over the Terms of Service to the extent of any conflict concerning the processing of personal data on your behalf.
13.2 If any provision is invalid or unenforceable, the rest continues in force.
13.3 This DPA terminates automatically when we stop providing the Services to you, save for provisions which by their nature survive.
13.4 We may update this DPA where required by a change in Data Protection Law, or to reflect a change in the Services, provided the update does not reduce your protection.
14. Contact
Naman Kedia A-20 Geetanjali Enclave, New Delhi 110017, India namankedia@geppetto.work