Legal

Data Processing Addendum

Last updated: July 13, 2026

This Data Processing Addendum governs the personal data FirmLaunch processes on behalf of partner law firms in connection with the Services.
01

Purpose and scope

This Data Processing Addendum ("DPA") supplements the Master Services Agreement or Order Form (the "Agreement") between the partner law firm ("Firm" or "Controller") and FirmLaunch ("FirmLaunch" or "Processor"). It governs FirmLaunch's processing of personal data on behalf of the Firm in connection with the Services. In the event of a conflict between this DPA and the Agreement with respect to personal data, this DPA controls.

02

Definitions

"Personal Data," "Processing," "Controller," "Processor," and "Personal Data Breach" have the meanings given under applicable data protection laws, including the California Consumer Privacy Act as amended by the CPRA ("CCPA") and comparable US state privacy laws. "Applicable Laws" means all data protection and privacy laws applicable to a party's processing under this DPA.

03

Roles of the parties

With respect to Personal Data delivered by FirmLaunch to the Firm as part of a signed retainer package, and any subsequent processing on the Firm's instructions, FirmLaunch acts as a Processor / service provider and the Firm acts as the Controller / business. FirmLaunch remains an independent Controller for its own website visitors and for pre-engagement advertising audiences prior to a Firm's engagement of the claimant.

04

Details of processing

  • Subject matter: provision of client acquisition, AI intake, qualification, appointment booking, document collection, and retainer delivery services.
  • Duration: the term of the Agreement plus retention required by law and professional-conduct rules.
  • Nature and purpose: intake and delivery of qualified personal injury matters to the Firm.
  • Types of Personal Data: identifiers, contact details, accident and injury details, insurance details, government identifiers voluntarily provided, call recordings and transcripts, and documents.
  • Categories of data subjects: prospective claimants, existing clients of the Firm, and Firm personnel.
05

Processor obligations

  • Process Personal Data only on documented instructions from the Firm, including as set out in the Agreement and this DPA.
  • Not sell Personal Data and not share it for cross-context behavioral advertising (as those terms are defined under the CCPA) except as necessary to provide the Services.
  • Not combine Personal Data received from the Firm with Personal Data received from other sources except as permitted by Applicable Laws.
  • Ensure personnel with access to Personal Data are subject to written confidentiality obligations.
  • Implement appropriate technical and organizational measures as described in our Security page.
  • Assist the Firm, taking into account the nature of the processing, in responding to data-subject rights requests, security assessments, and regulatory inquiries.
06

Subprocessors

The Firm authorizes FirmLaunch to engage subprocessors to provide the Services, subject to written agreements imposing data-protection obligations substantially similar to those in this DPA. A current list of subprocessors is available on request. FirmLaunch will provide notice of material changes to the subprocessor list and give the Firm a reasonable opportunity to object on data-protection grounds; if the objection cannot be resolved, either party may terminate the affected portion of the Services.

07

Data subject rights

Where FirmLaunch receives a request from a data subject relating to Personal Data processed on the Firm's behalf, FirmLaunch will forward the request to the Firm without undue delay and will not respond directly except to acknowledge receipt or as required by law. FirmLaunch will reasonably assist the Firm in fulfilling verified access, correction, deletion, portability, and opt-out requests.

08

Security measures

FirmLaunch maintains the administrative, technical, and physical safeguards described on our Security page, including encryption in transit and at rest, MFA on administrative accounts, least-privilege access, centralized logging, vulnerability management, and periodic third-party testing. FirmLaunch will not materially degrade these measures during the term.

09

Personal Data Breach notification

FirmLaunch will notify the Firm without undue delay after becoming aware of a confirmed Personal Data Breach affecting the Firm's Personal Data, and will provide information reasonably necessary for the Firm to meet its notification obligations under Applicable Laws. Notice of a breach is not an acknowledgment of fault or liability.

10

Audits and assessments

Upon reasonable prior written notice, and no more than once per twelve (12) month period unless required by a regulator or following a confirmed breach, FirmLaunch will make available to the Firm the information reasonably necessary to demonstrate compliance with this DPA. Audits are conducted during business hours, subject to confidentiality obligations, and must not unreasonably disrupt FirmLaunch's operations. FirmLaunch may satisfy audit requests through recent independent assessments, SOC reports, or completed security questionnaires.

11

International data transfers

FirmLaunch processes Personal Data primarily in the United States. If Personal Data is transferred internationally, the parties will cooperate in good faith to implement any transfer mechanisms required by Applicable Laws.

12

Return and deletion

Upon termination of the Services, FirmLaunch will, at the Firm's election, return or delete Personal Data processed on the Firm's behalf, except as required to be retained by Applicable Laws or professional-conduct rules. Backup copies are deleted in accordance with FirmLaunch's standard retention schedule.

13

Liability

Each party's liability under this DPA is subject to the limitations of liability set forth in the Agreement. Nothing in this DPA is intended to expand or limit the rights of data subjects under Applicable Laws.

14

How to execute

Firms that require a signed copy of this DPA may request one at legal@firmlaunch.co. This DPA is incorporated by reference into every Order Form and MSA unless expressly excluded.

Questions about this document? Contact legal@firmlaunch.co.