For business customers

Data Processing Agreement

Version 1.0 · last updated 2026-08-05

Read it before you ask for it. This is our standard processor agreement for API and embedded-widget customers. It is published in full, including the parts that are not flattering — we hold no SOC 2 or ISO 27001, and section 5 says so rather than implying otherwise. If your legal team needs signature or their own paper, email support@ai-law-tracker.com.

Download the DPA

1. Roles and scope

This agreement applies where you (the "Customer") use the AI Law Tracker API, an embedded widget, or another service under a paid or free plan, and where in doing so AI Law Tracker ("ALT", "we") processes personal data on your behalf and on your documented instructions. For that processing you are the controller and we are the processor.

It does not apply to the public website. When someone visits ai-law-tracker.com, reads a page, posts a comment or requests an API key for themselves, ALT is the controller for that data and our privacy policy governs it, not this agreement.

Your order, plan selection and use of the service constitute your documented instructions. If you instruct us to do something we believe is unlawful, we will tell you and may suspend the affected processing rather than carry it out.

2. Subject matter, duration, nature and purpose

Subject matter: providing the AI Law Tracker service you have subscribed to — legal-record lookup, search, change feeds, webhooks and embedded widgets.

Duration: for as long as your plan is active, plus the deletion window in section 8.

Nature and purpose: hosting, transmitting, storing and returning data in order to operate the service, provide support, bill for it, and keep it secure and available.

Categories of data subjects: your personnel and any end users to whom you expose the service.

Categories of personal data: account and contact details (name, work email), API credentials in hashed form, request metadata (IP address, user agent, timestamps, endpoints called) and any content you or your users transmit through the service. We ask you not to send special-category data; the service is not designed for it.

3. Our obligations as processor

We process personal data only on your documented instructions, including for any transfer to a third country, unless a law we are subject to requires otherwise — in which case we will inform you before processing, unless that law forbids the notice.

Everyone we authorise to process the data is bound by a duty of confidentiality.

We implement the technical and organisational measures described in section 5.

We assist you, so far as is reasonable given the nature of the processing and the information available to us, with data subject requests, security-incident notifications, impact assessments and prior consultations.

We make available the information reasonably necessary to demonstrate compliance with this agreement, and we contribute to audits as described in section 7.

4. Sub-processors

You give general authorisation for us to engage the sub-processors listed below. Each is bound by data-protection obligations no less protective than this agreement, and we remain fully liable to you for their performance.

We will give you at least 30 days’ notice by email before adding or replacing a sub-processor. If you reasonably object on data-protection grounds within that period, we will work with you on an alternative; if none is workable, you may terminate the affected service and receive a pro-rated refund of prepaid fees.

Sub-processorPurposeProcessing location
Vercel Inc.Hosting, edge delivery and request logsUnited States / global edge
Supabase Inc.Managed Postgres databaseEuropean Union
ResendTransactional and outbound email deliveryUnited States
PolarPayments, invoicing and subscription managementUnited States / European Union
Google LLCAnalytics and advertising tags on the public website, loaded only where the visitor has consentedUnited States / global

5. Security measures

What we actually do, stated as measures rather than as a certification: all traffic is served over TLS; database access is restricted to service-role credentials with row-level security on publicly reachable tables; identifiers such as IP addresses and API keys are stored as irreversible keyed hashes rather than in plaintext; secrets are held in the hosting provider’s encrypted environment store and are not committed to source control; access to production systems is limited to the operator and protected by multi-factor authentication; data at rest is encrypted by our infrastructure providers.

What we do not claim: ALT holds no SOC 2, ISO 27001 or equivalent third-party audit, and this agreement does not represent that it does. We would rather you knew that before signing than after.

We review these measures as the service changes and will not reduce the overall level of security during the term.

6. Personal data breaches

We notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting data we process for you. The notice describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.

Where we cannot provide all of that at once, we send what we have and follow up as the picture becomes clear rather than waiting for a complete account.

7. Audit

On reasonable written notice, and no more than once in any twelve-month period unless a supervisory authority requires otherwise, we will answer a written security questionnaire and provide documentation reasonably necessary to demonstrate compliance with this agreement.

On-site audits are available where a supervisory authority requires one or following a personal data breach affecting your data, at your cost and subject to reasonable confidentiality and scheduling arrangements.

8. Return and deletion

On termination, and at your choice, we delete or return the personal data we process for you. Absent an instruction, we delete it within 30 days of termination.

Backups are deleted on their normal rotation, which completes within 90 days. Until then, backup copies remain subject to this agreement and are not accessed for any other purpose.

One exception, and it exists in your favour: an email address on our permanent suppression list stays there. Deleting it would mean losing the record of the fact that we must never contact that person again.

9. International transfers

Some sub-processors listed in section 4 process data in the United States and elsewhere outside the EEA and the UK. Where personal data is transferred out of the EEA or the UK, the transfer is made on the basis of the European Commission’s Standard Contractual Clauses (Decision 2021/914), including the UK International Data Transfer Addendum where the UK GDPR applies, which are incorporated into this agreement by reference.

For those transfers ALT acts as data exporter and the relevant sub-processor as data importer, on the module appropriate to the relationship. Where the Clauses conflict with this agreement, the Clauses prevail.

10. Data subject requests

If a data subject contacts us directly about data we process on your behalf, we will not respond substantively. We will refer them to you and let you know, promptly, that they got in touch.

We will assist you in responding, using the tooling and access available to us, at no additional charge for a reasonable volume of requests.

11. General

This agreement supplements our terms of service. Where it conflicts with them on the processing of personal data, this agreement prevails.

This is a template we publish so you can read it before you ask for it. If your legal team needs signature, changes or your own paper instead, email us and we will work from yours — publishing this does not mean it is take-it-or-leave-it.

This document is provided for information and is not legal advice.

Not legal adviceAI Law Tracker is not a law firm. This document describes the terms on which we process data for customers; it is not advice on your obligations, and you should have your own counsel review it before you rely on it.

See also: data & AI practices · privacy policy · terms · imprint