Data Processing Agreement (DPA)

Between: Navarro Hernandez, P.L. ("Processor") and the law firm customer ("Controller") Effective: On acceptance of Terms of Service

⚠ LEGAL REVIEW REQUIRED — DPA template. Counsel review essential before publication. Particularly: confirm sub-processor flow-through clauses match current vendor contracts.

1. Definitions

"Customer Data" means data the Controller uploads or enters into Trial Commander, including client information, matter details, time entries, trust records, and documents.

"Data Protection Laws" means applicable laws governing privacy and data protection, including Florida Statutes § 501.171, Florida Bar Rule 4-1.6(e), HIPAA (where applicable), GDPR, CCPA, and their successors.

"Security Incident" means unauthorized access, use, disclosure, alteration, or destruction of Customer Data.

"Sub-processor" means any third party that processes Customer Data on behalf of the Processor.

2. Roles

The Controller determines the purposes and means of processing Customer Data. The Processor processes Customer Data only on the Controller's documented instructions to provide the Service.

3. Processor Obligations

The Processor:

3.1 Processes only on instruction. We process Customer Data only to provide the Service as described in our Terms and Privacy Policy, or as otherwise instructed in writing. We do not use Customer Data for our own purposes, training AI models, advertising, or resale.

3.2 Personnel confidentiality. All employees and contractors with access to Customer Data are bound by confidentiality obligations that survive termination of their engagement.

3.3 Security. We maintain appropriate technical and organizational measures:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Field-level encryption for privileged data
  • Access controls with MFA for privileged access
  • Tamper-evident audit logs
  • Regular security testing and dependency scanning
  • Incident response procedures with documented recovery time objectives
  • Background checks and security training for personnel

3.4 Sub-processors. We engage sub-processors (listed in § 7) subject to data protection obligations equivalent to those in this DPA. We are liable for sub-processor compliance.

3.5 Data subject requests. If a data subject contacts us directly, we will forward the request to the Controller and not respond ourselves (except to acknowledge receipt and direct them to the Controller).

3.6 Assistance. We assist the Controller in complying with data protection law, including by:

  • Providing audit logs and access records
  • Responding to security questionnaires (annually, or on reasonable request)
  • Notifying of breach within 72 hours
  • Cooperating with regulator inquiries

3.7 Audits. Upon 30 days' written notice and subject to confidentiality, the Controller may audit our compliance with this DPA no more than once per year, during business hours, at Controller's expense. We may satisfy this by providing current SOC 2 Type II or ISO 27001 reports where available.

3.8 Deletion on termination. On termination of the Service, we delete Customer Data per the schedule in the Privacy Policy (30 days after cancellation, with up to 90-day backup retention).

4. Controller Obligations

The Controller:

4.1 Lawful basis. Has a lawful basis for processing Customer Data and has obtained necessary consents or authorizations from data subjects (clients, third parties mentioned in matters).

4.2 Accuracy. Is responsible for the accuracy, legality, and content of Customer Data.

4.3 Client notification. Is responsible for notifying clients about the use of cloud software, including AI features, as required by Florida Bar Rule 4-1.6(e) and ABA Formal Opinion 512.

4.4 Instructions. Issues instructions to the Processor that comply with data protection law. If Processor believes an instruction violates law, it will inform Controller and not act on the instruction.

4.5 Appropriate use. Uses the Service consistent with Florida Bar rules and does not use it to circumvent trust account, confidentiality, or other regulatory requirements.

5. Security Incidents

5.1 We will notify the Controller within 72 hours of confirming a Security Incident affecting their data, via:

  • Email to the firm admin contact on file
  • Detailed incident report within 7 days

5.2 The notification will include (to extent known):

  • Nature and scope of the incident
  • Categories and approximate volume of data affected
  • Likely consequences
  • Measures taken or proposed to address it
  • Contact for more information

5.3 We will provide reasonable cooperation in the Controller's own breach-notification obligations.

6. International Transfers

If Customer Data is transferred out of EEA/UK:

  • We rely on the European Commission's Standard Contractual Clauses (2021 Module 2, Controller-to-Processor)
  • Or UK ICO International Data Transfer Addendum where applicable

7. Sub-processors

Current authorized sub-processors:

Sub-processorPurposeData CategoryLocationCertifications
Clerk Inc.AuthenticationUser identity, sessionUSASOC 2 Type II
Stripe Inc.Payment processingBilling infoUSAPCI-DSS Level 1, SOC 2
Anthropic PBCAI processing (no model training on customer data; limited or zero retention per the AI Disclosure)Matter content for AI featuresUSASOC 2 Type II
Postmark (AC PM LLC)Transactional emailRecipient infoUSASOC 2 Type II
Sentry (Functional Software, Inc.)Error monitoringStack traces (PII scrubbed)USASOC 2 Type II
Cloudflare, Inc. (R2)File storageUploaded documentsUSASOC 2 Type II
Upstash Inc.Rate limiting / RedisIP, hashed user IDsUSA
Microsoft Corporation (Azure)Application hosting and databaseAll Customer DataUSA (East US 2 — Virginia)SOC 2 Type II, ISO 27001, HITRUST

Notice of Changes. We maintain this list at https://www.trialcommander.com/sub-processors. Material changes require 30 days' notice. Controllers may object within 14 days; we will work to address concerns or offer cancellation with pro-rated refund.

8. HIPAA Considerations

For Controllers representing clients in medical malpractice or other matters involving Protected Health Information (PHI):

  • A separate Business Associate Agreement (BAA) must be executed
  • Additional safeguards apply (see HIPAA Addendum)
  • Not available on the TRIAL tier; requires Complete or Enterprise subscription

9. Term and Survival

This DPA takes effect on acceptance of Terms and remains in force as long as Processor holds Customer Data. Obligations regarding deletion, audit log retention, and breach notification survive termination.

10. Liability

Liability under this DPA is subject to the limitations in the Terms of Service, except where data protection law prohibits such limitation.

11. Contact


Template version 1.0 — requires counsel review before publication.