This Data Processing Agreement ("DPA") is entered into by and between Batesly, Inc., a Delaware corporation ("Processor" or "Batesly"), and the entity identified in the Master Service Agreement ("Controller" or "Customer").
This DPA is incorporated into and forms part of the Master Service Agreement (the "MSA") between Batesly and Customer. This DPA applies to the extent that Batesly processes Personal Data on behalf of Customer in connection with the Services.
In the event of a conflict between this DPA and the MSA, this DPA shall control with respect to the processing of Personal Data.
1. DEFINITIONS
Capitalized terms not defined herein shall have the meanings set forth in the MSA. The following definitions apply to this DPA:
"Applicable Data Protection Law" means all laws and regulations applicable to the processing of Personal Data under this DPA, including, as applicable: (a) the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA"); (b) other U.S. state privacy laws; and (c) any other applicable data protection or privacy laws.
"Data Subject" means an identified or identifiable natural person whose Personal Data is processed.
"Personal Data" means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a Data Subject, and that is processed by Batesly on behalf of Customer in connection with the Services. For purposes of the CCPA, Personal Data includes "Personal Information" as defined therein.
"Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure, or destruction.
"Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed by Batesly in connection with the Services.
"Subprocessor" means any third party engaged by Batesly to process Personal Data on behalf of Customer.
2. ROLES AND SCOPE OF PROCESSING
2.1 Roles of the Parties
For purposes of this DPA: (a) Customer is the Controller of Personal Data; and (b) Batesly is the Processor of Personal Data, processing Personal Data on behalf of and under the instructions of Customer.
2.2 Customer's Processing Instructions
Customer instructs Batesly to process Personal Data as necessary to provide the Services in accordance with the MSA and this DPA. Customer's instructions are documented in Annex 1 (Description of Processing). Customer may provide additional written instructions consistent with this DPA, provided that Batesly is not obligated to follow instructions that would violate Applicable Data Protection Law.
2.3 Details of Processing
The subject matter, nature, purpose, duration, types of Personal Data, and categories of Data Subjects are described in Annex 1.
2.4 Customer Obligations
Customer represents and warrants that: (a) it has provided all necessary notices and obtained all necessary consents, permissions, and rights to enable Batesly to lawfully process Personal Data as contemplated by this DPA; (b) its instructions to Batesly comply with Applicable Data Protection Law; and (c) it has the right to transfer Personal Data to Batesly for processing.
3. BATESLY'S DATA PROCESSING OBLIGATIONS
3.1 Processing Limitations
Batesly shall:
(a) Process Personal Data only on behalf of and in accordance with Customer's documented instructions, unless required by law to process Personal Data for other purposes (in which case, Batesly shall inform Customer of such legal requirement before processing, unless prohibited by law);
(b) Not sell, share, or use Personal Data for any purpose other than providing the Services, including not using Personal Data for targeted advertising;
(c) Not retain, use, or disclose Personal Data outside the direct business relationship with Customer;
(d) Process Personal Data only to the extent necessary to provide the Services.
3.2 Confidentiality
Batesly shall ensure that persons authorized to process Personal Data have committed to confidentiality obligations or are under an appropriate statutory obligation of confidentiality.
3.3 Security Measures
Batesly shall implement and maintain appropriate technical and organizational security measures designed to protect Personal Data against Security Incidents, as described in Annex 2 (Security Measures). Batesly shall regularly test, assess, and evaluate the effectiveness of these measures.
3.4 Security Incident Response
Upon becoming aware of a Security Incident, Batesly shall:
(a) Notify Customer without undue delay and in any event within seventy-two (72) hours;
(b) Provide Customer with sufficient information to enable Customer to meet any obligations to notify Data Subjects or regulatory authorities;
(c) Cooperate with Customer's reasonable requests regarding the Security Incident;
(d) Take reasonable steps to mitigate the effects and minimize any damage resulting from the Security Incident.
Notification shall include, to the extent known: (i) a description of the nature of the Security Incident; (ii) the categories and approximate number of Data Subjects and records concerned; (iii) the likely consequences; and (iv) measures taken or proposed to address the Security Incident.
3.5 Data Subject Requests
Batesly shall, taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures in responding to requests from Data Subjects to exercise their rights under Applicable Data Protection Law (including rights of access, rectification, erasure, restriction, portability, and objection). If Batesly receives a request directly from a Data Subject, Batesly shall promptly notify Customer and shall not respond to the request directly except to acknowledge receipt, unless legally required to do so.
3.6 Assistance with Compliance
Batesly shall provide reasonable assistance to Customer in ensuring compliance with Customer's obligations regarding: (a) security of processing; (b) notification of Security Incidents to supervisory authorities and Data Subjects; (c) data protection impact assessments; and (d) prior consultation with supervisory authorities, in each case taking into account the nature of processing and information available to Batesly.
4. SUBPROCESSORS
4.1 Authorized Subprocessors
Customer authorizes Batesly to engage the Subprocessors listed in Annex 3 (Subprocessor List) to process Personal Data on Customer's behalf. Batesly shall enter into written agreements with each Subprocessor that impose data protection obligations no less protective than those in this DPA.
4.2 Changes to Subprocessors
Batesly shall notify Customer at least thirty (30) days before engaging any new Subprocessor or replacing an existing Subprocessor. Customer may object to the engagement of a new Subprocessor by providing written notice to Batesly within fifteen (15) days of receiving notice, stating reasonable grounds for the objection. If Customer objects, the parties shall work in good faith to resolve Customer's concerns. If resolution is not possible, Customer may terminate the affected Services with no penalty by providing written notice within thirty (30) days of Batesly's notice.
4.3 Subprocessor Liability
Batesly shall remain liable to Customer for the performance of its Subprocessors' obligations under this DPA.
5. DATA TRANSFERS AND LOCATION
5.1 Processing Location
Personal Data will be processed in the United States. Batesly's primary infrastructure is hosted on Railway in U.S. regions.
5.2 Future International Transfers
If Customer requires processing of Personal Data subject to the European Union General Data Protection Regulation (GDPR) or United Kingdom data protection laws, the parties shall execute the then-current Standard Contractual Clauses (SCCs) approved by the European Commission or UK authorities, as applicable, which shall be incorporated into this DPA by reference.
6. AUDIT AND INSPECTION
6.1 Audit Information
Upon Customer's written request, and subject to reasonable confidentiality obligations, Batesly shall make available to Customer information necessary to demonstrate compliance with this DPA, including: (a) Batesly's then-current security documentation; (b) Batesly's own SOC 2 report once completed, and summaries of Subprocessors' third-party audit reports or certifications (such as SOC 2), where available; and (c) responses to reasonable written questions.
6.2 On-Site Audits
Customer may, upon at least thirty (30) days' prior written notice and no more than once per year (unless required by a regulatory authority or following a Security Incident), conduct an audit or inspection of Batesly's processing activities, or appoint a qualified third-party auditor (subject to confidentiality obligations) to do so. Such audits shall: (a) be conducted during normal business hours; (b) not unreasonably interfere with Batesly's operations; (c) comply with Batesly's security and confidentiality requirements; and (d) be at Customer's expense, unless the audit reveals a material breach of this DPA by Batesly.
7. DATA RETENTION AND DELETION
7.1 Retention During Subscription
Batesly shall retain Personal Data for the duration of the MSA and as necessary to provide the Services, unless otherwise instructed by Customer or required by law.
7.2 Deletion Upon Termination
Upon termination or expiration of the MSA, and subject to Customer's data export rights under the MSA, Batesly shall delete or return all Personal Data within the timeframes specified in the MSA (ninety (90) days for production systems; one hundred eighty (180) days for backup systems), unless retention is required by Applicable Data Protection Law. Batesly shall certify deletion in writing upon Customer's request.
7.3 Retention for Legal Obligations
Notwithstanding the foregoing, Batesly may retain Personal Data to the extent required by Applicable Data Protection Law, provided that Batesly shall: (a) process such Personal Data only as necessary to comply with such legal obligations; (b) maintain the confidentiality and security of such Personal Data; and (c) delete such Personal Data when retention is no longer required.
8. CCPA-SPECIFIC PROVISIONS
To the extent that Batesly processes Personal Data subject to the CCPA:
8.1 Service Provider Status
Batesly is a "Service Provider" as defined by the CCPA. Batesly shall not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than providing the Services, including for commercial purposes other than providing the Services; (c) retain, use, or disclose Personal Data outside the direct business relationship with Customer; or (d) combine Personal Data received from Customer with Personal Data received from other sources, except as permitted by the CCPA.
8.2 Certification
Batesly certifies that it understands and will comply with the restrictions set forth in this Section 8.
8.3 Assistance with CCPA Rights
Batesly shall assist Customer in responding to verifiable consumer requests to exercise rights under the CCPA, including requests to know, delete, correct, and opt-out.
9. GENERAL PROVISIONS
9.1 Governing Law
This DPA shall be governed by the laws specified in the MSA.
9.2 Limitation of Liability
Each party's liability under this DPA shall be subject to the limitations of liability set forth in the MSA.
9.3 Term
This DPA shall remain in effect for the duration of the MSA and for as long as Batesly processes Personal Data on behalf of Customer.
9.4 Amendments
This DPA may be amended by Batesly upon thirty (30) days' notice to Customer to reflect changes in Applicable Data Protection Law. Material changes that adversely affect Customer shall not apply to the then-current Subscription Term without Customer's consent.
9.5 Entire Agreement
This DPA, together with the MSA and its annexes, constitutes the entire agreement between the parties with respect to the processing of Personal Data.
ANNEX 1: DESCRIPTION OF PROCESSING
1. Subject Matter and Purpose of Processing
Batesly processes Personal Data to provide the Services described in the MSA, including: matter management, document management and storage, search and retrieval, collaboration features, AI-powered document intelligence, optional Google Calendar sync, and related functionality.
2. Duration of Processing
Processing will continue for the duration of the MSA, plus any post-termination retention period specified in the MSA or required by law.
3. Nature of Processing
Collection, storage, organization, retrieval, use, disclosure (to Authorized Users and authorized external parties), and deletion of Personal Data as necessary to provide the Services.
4. Categories of Data Subjects
Personal Data may relate to the following categories of Data Subjects:
(a) Customer's employees, contractors, and other personnel;
(b) Customer's clients and their personnel;
(c) Opposing parties, witnesses, and other individuals referenced in legal matters;
(d) Individuals whose Personal Data is contained in documents uploaded to the Services.
5. Types of Personal Data
The Services may process the following types of Personal Data:
(a) Identifiers: names, email addresses, phone numbers, mailing addresses, government identifiers (e.g., SSN, passport numbers) if contained in uploaded documents;
(b) Professional information: job titles, employers, professional affiliations;
(c) Account information: usernames, login credentials (hashed), access logs;
(d) Communications: emails and correspondence stored in the Services;
(e) Document content: any Personal Data contained in documents uploaded by Customer;
(f) Usage data: activity logs, IP addresses, device information;
(g) Calendar data: for users who connect a Google account, calendar list and event details (such as title, time, location, and attendees) for the calendars they select.
6. Sensitive Personal Data
Customer may upload documents containing sensitive Personal Data, including but not limited to: health information, financial information, Social Security numbers, and information related to legal proceedings. Customer is responsible for ensuring appropriate legal basis and safeguards for processing such data.
ANNEX 2: TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
Batesly implements the following technical and organizational security measures to protect Personal Data:
1. Encryption
(a) Encryption at rest: AES-256 encryption for all stored data (object storage and managed database);
(b) Encryption in transit: TLS 1.2 or higher for all data transmission;
(c) Key management through a managed key management service.
2. Access Controls
(a) Role-based access control (RBAC) for all users;
(b) Multi-factor authentication (MFA) support;
(c) Unique user accounts with strong password requirements;
(d) Automatic session timeouts;
(e) Matter-level and document-level permission controls;
(f) Ethical wall/conflict screening capabilities.
3. Infrastructure Security
(a) Hosting on Railway and Amazon Web Services, whose infrastructure is SOC 2 Type II certified. Batesly's own SOC 2 Type II audit is in progress;
(b) Logical tenant isolation (multi-tenant architecture with strict data segregation);
(c) Network security controls including firewalls and security groups;
(d) Regular vulnerability scanning and patching.
4. Audit and Monitoring
(a) Immutable audit logging of all system actions;
(b) Access logging and monitoring;
(c) Alerting for suspicious activities;
(d) Log retention for the duration of subscription plus seven (7) years.
5. Data Backup and Recovery
(a) Automated daily backups;
(b) Point-in-time recovery capability;
(c) Backup encryption;
(d) Documented disaster recovery procedures.
6. Personnel Security
(a) Background checks for personnel with access to systems;
(b) Confidentiality agreements for all personnel;
(c) Security awareness training;
(d) Access provisioning and de-provisioning procedures.
7. Incident Response
(a) Documented incident response procedures;
(b) Designated incident response team;
(c) 72-hour breach notification commitment.
8. Certifications and Assessments
(a) Batesly's own SOC 2 Type II certification is in progress. Batesly's infrastructure providers, Railway and Amazon Web Services, are already SOC 2 Type II certified;
(b) Annual penetration testing by qualified third party;
(c) Regular security assessments.
ANNEX 3: AUTHORIZED SUBPROCESSORS
The following Subprocessors are authorized to process Personal Data on behalf of Customer as of the Last Updated date above.
Customer may subscribe to Subprocessor update notifications at: compliance@batesly.io
| Subprocessor | Purpose | Location | Data Types |
|---|---|---|---|
| Railway | Cloud infrastructure, hosting, data storage, compute | United States | All Customer Data |
| Amazon Web Services (Bedrock) | AI-powered document intelligence features via Anthropic Claude models hosted in AWS (optional) | United States | Processed in-region; no retention for model training |
| Google Workspace | Business email services | United States | Email communications |
| Stripe | Payment processing | United States | Billing contact info, payment data |
| Resend | Transactional email delivery | United States | Email address and message content |
| Customer.io | Customer communications and marketing email | United States | Contact info and engagement events |
| Google Analytics | Website analytics | United States | Website usage data and device info |
| Google (Calendar API) | Optional calendar sync for users who connect Google | United States | Calendar list and event details for selected calendars |
| ChartMogul | Subscription analytics | EU/Germany | Account metadata, usage metrics |
| Scytale | SOC 2 compliance automation | United States | Security/compliance metadata |
ANNEX 4: STANDARD CONTRACTUAL CLAUSES
[Reserved for Future Use]
This Annex is reserved for Standard Contractual Clauses (SCCs) for international data transfers. If Customer requires processing of Personal Data subject to the European Union General Data Protection Regulation (GDPR) or United Kingdom data protection laws, the parties shall execute the then-current SCCs approved by the European Commission or UK authorities, which shall be attached to this Annex and incorporated by reference.
To request execution of SCCs, please contact: compliance@batesly.io