Data Processing Addendum
Cedent AI, Inc. Version 1.0 · Effective September 1, 2026
This DPA is incorporated into and forms part of the Cedent AI Terms of Service between Cedent AI, Inc. (“Cedent”) and the law firm that accepts them (“Customer”). No signature is required — it takes effect automatically when Customer accepts the Terms and applies for as long as Cedent processes Matter Data.
Customers who require a countersigned copy for their own records or for a malpractice carrier may request one at legal@cedent.ai. We countersign on request at no charge and will not ask you to negotiate for it.
Capitalized terms not defined here have the meanings given in the Terms of Service.
1. Scope and Roles
1.1 What this DPA covers
This DPA governs Cedent’s processing of Customer Personal Data: all personal information contained in Matter Data, Calendar Data, and the time-entry ledger — that is, everything relating to Customer’s representation of its clients.
1.2 Roles
Customer is the controller and, under the CCPA, the “business.” Cedent is the processor and “service provider.” Cedent processes Customer Personal Data solely on Customer’s documented instructions and never for its own purposes.
1.3 What this DPA does not cover
- Account Data and website visitor data, for which Cedent is a controller — see the Privacy Policy.
- Payment data, for which Stripe, Inc. is an independent controller. Card numbers and payment credentials go directly to Stripe and never reach Cedent’s systems.
- Unsaved Scratchpad Content, which resides in the Authorized User’s browser and is never stored by Cedent. Cedent holds no copy and cannot export, delete, or certify deletion of it.
1.4 Customer’s responsibilities
Customer warrants that it has all rights, authority, and consents necessary to submit Customer Personal Data and to instruct the processing described here, including with respect to third parties whose information appears in a connected mailbox or calendar but who are not Customer’s clients — opposing parties, children, witnesses, and others. Cedent cannot assess this and does not.
2. Processing Instructions and Purpose Limitation
2.1 Documented instructions
Cedent will process Customer Personal Data only:
- (a) to provide, secure, maintain, and support the Service under the Terms;
- (b) as further instructed in writing by Customer, where consistent with the Service; and
- (c) where required by applicable law, subject to Section 8.
If Cedent believes an instruction violates applicable law, it will notify Customer and may suspend performance of that instruction.
2.2 Specific business purposes — stated specifically, not generically
As required by Cal. Code Regs. tit. 11, § 7051(a)(1), the business purposes are:
- Email and document ingestion — retrieving messages, attachments, and files from Connected Accounts and uploads.
- Text extraction and OCR — converting documents to machine-readable text.
- Matter organization — associating content with matters and building matter workspaces.
- Fact extraction, trust ranking, and chronology construction.
- Calendar ingestion and matter-association classification — retrieving every event on a connected calendar and classifying it (see the Privacy Policy, Section 6).
- Deadline computation — applying published statutes and rules to propose dates.
- Draft generation — correspondence, briefs, action briefs, and population of official court forms including FL-150 and FL-142.
- Missing-document identification.
- Draft time-entry generation and ledger maintenance.
- Outbound Actions at Customer’s direction — sending mail from Customer’s mailbox, writing calendar events, writing files to connected storage.
- Export and handover package generation.
- Security, abuse prevention, availability, and troubleshooting of the Service.
- Support, where an Authorized User requests assistance with specific content.
No other purpose is authorized.
2.3 Duration, categories, and subjects
Set out in Schedule 1.
3. CCPA Service Provider Certification
Cedent certifies that it understands the restrictions in this Section 3 and will comply with them. This Section is given for purposes of Cal. Civ. Code § 1798.140(ag) and Cal. Code Regs. tit. 11, § 7051.
Cedent will not:
- (a) sell or share Customer Personal Data, as “sell” and “share” are defined in the CCPA;
- (b) retain, use, or disclose Customer Personal Data for any purpose other than the specific business purposes in Section 2.2, including any commercial purpose of its own;
- (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between Cedent and Customer;
- (d) combine Customer Personal Data with personal information received from another source, or from another Customer, except as expressly permitted by Cal. Code Regs. tit. 11, § 7050(b);
- (e) use Customer Personal Data to train, fine-tune, evaluate, or improve any machine learning model — see Section 4; or
- (f) use Customer Personal Data to build or enhance any profile, audience, or advertising product.
Cedent will:
- (g) comply with all obligations applicable to it as a service provider under the CCPA and provide the same level of privacy protection the CCPA requires of a business;
- (h) notify Customer promptly, and in any event within five (5) business days, if it determines it can no longer meet its obligations under the CCPA or this DPA;
- (i) grant Customer the right to take reasonable and appropriate steps to ensure Cedent’s processing is consistent with Customer’s CCPA obligations (Section 9); and
- (j) grant Customer the right, on notice, to take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Data.
Customer discloses Customer Personal Data to Cedent only for the limited and specified business purposes in Section 2.2.
4. No Training — Binding Commitment
4.1 The commitment
Cedent will not use Customer Personal Data to train, fine-tune, evaluate, benchmark, or otherwise develop or improve any machine learning model, and will not permit any Subprocessor or model provider to do so.
4.2 Where inference happens
All AI inference performed by the Service runs on Amazon Bedrock within Amazon Web Services. Under Cedent’s terms with AWS, prompts and completions are not retained after a request is served and are not used to train or improve any model — whether AWS’s, a third-party model provider’s, or Cedent’s. No third-party model provider receives Customer Personal Data.
4.3 Scope note, stated precisely
Section 4.2 concerns model inference. Document text extraction and OCR are performed by Modal, and database hosting by Neon. These are disclosed Subprocessors (Schedule 3) bound by written terms at least as protective as this DPA, including the prohibition in Section 4.1. Cedent states this rather than claiming that no Matter Data ever leaves AWS, because that broader claim would not be accurate.
4.4 Survival and non-amendment
Section 4 survives termination indefinitely and may not be weakened as to Customer Personal Data already in the Service without Customer’s affirmative written opt-in. Continued use of the Service will never constitute consent to a weakening of this Section.
5. Confidentiality, Privilege, and Personnel
5.1 Treated as privileged by default
Cedent treats all Customer Personal Data as attorney-client privileged material and attorney work product, without distinguishing between sensitive and ordinary content.
5.2 Cedent’s undertaking
Cedent acts solely as Customer’s agent and service provider for the purpose of assisting Customer in rendering legal services to its clients. Cedent will not access, use, retain, or disclose Customer Personal Data except as necessary to provide the Service, as Customer directs, or as required by law under Section 8.
5.3 Privilege preservation
The arrangement is structured with the intention that Cedent’s access operates as an extension of Customer’s staff for the purpose of facilitating Customer’s provision of legal services, and does not waive the attorney-client privilege or work product protection. Cedent does not and cannot guarantee that any tribunal will so hold, and this is not legal advice to Customer. Cedent waives any right to assert that its receipt of Customer Personal Data waived any privilege or protection of Customer or Customer’s clients.
5.4 Personnel
Cedent ensures that personnel authorized to process Customer Personal Data are bound by written confidentiality obligations surviving employment, receive privacy and security training, and have access only on a least-privilege, need-to-know basis, with access logged.
5.5 No cross-firm access
Cedent maintains logical separation between Customer accounts and will not combine, commingle, or expose Customer Personal Data across firms.
6. Subprocessors
6.1 Authorization
Customer generally authorizes Cedent to engage Subprocessors, listed in Schedule 3 and maintained in versioned, dated form at cedent.ai/subprocessors.
6.2 Flow-down
Cedent will impose on each Subprocessor, by written contract, data protection obligations at least as protective as those in this DPA, including the no-training prohibition in Section 4.1 and the confidentiality obligations in Section 5. Cedent remains fully liable to Customer for each Subprocessor’s performance.
6.3 Change notice and objection
Cedent will give at least thirty (30) days’ advance notice before adding or replacing a Subprocessor that processes Customer Personal Data, by email to Customer’s Administrator and by publishing a new version of the list.
Customer may object on reasonable data-protection grounds within that thirty-day period. The parties will discuss in good faith. If Cedent cannot accommodate the objection, Customer may terminate the affected subscription without penalty and receive a pro-rata refund of prepaid unused fees, and Section 10 applies to the data.
7. Security and Incidents
7.1 Measures
Cedent implements and maintains the technical and organizational measures in Schedule 2, and will not materially reduce their overall protection during the term.
7.2 Incident notification
Cedent will notify Customer without undue delay and no later than seventy-two (72) hours after becoming aware of a Security Incident — a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data.
7.3 What the notice contains
To the extent known, and updated as investigation proceeds: the nature of the incident; the categories and approximate volume of data and number of individuals affected; whether the affected data included matter files, court-form financial data, or calendar content; likely consequences; measures taken and proposed; and a contact point.
7.4 Cooperation
Cedent will investigate, take reasonable steps to mitigate, and provide the information and cooperation Customer reasonably requires to meet its own notification obligations and its professional duty to inform affected clients. Cedent will not require Customer to await Cedent’s investigation before making its own required notifications.
7.5 No admission
Notice is not an acknowledgment of fault or liability.
8. Legal Process and Government Access
If Cedent receives a subpoena, warrant, court order, civil investigative demand, or other legal process seeking Customer Personal Data, Cedent will:
- (a) not produce Customer Personal Data unless and until legally compelled after the steps below;
- (b) notify Customer promptly and before any disclosure, unless legally prohibited — and if prohibited, seek authorization to notify and give notice at the earliest permitted moment;
- (c) where a nondisclosure obligation is imposed, seek to have it narrowed or lifted;
- (d) object on the grounds that the material is or may be privileged or work product, that Cedent is not the appropriate custodian, and that the demand should be directed to Customer as counsel of record; and
- (e) reasonably cooperate, at Customer’s expense, with Customer’s efforts to quash, limit, or obtain a protective order.
Cedent will not voluntarily disclose Customer Personal Data to law enforcement or any government authority.
9. Assistance, Diligence, and Audit
9.1 Individual rights requests
Because Customer is the controller, requests from Customer’s clients or third parties go to Customer. Cedent will not act on such a request directly, and will redirect the requester to Customer. Cedent will provide reasonable assistance, taking into account the nature of processing, to help Customer respond — including locating, exporting, correcting, or deleting specific records on Customer’s instruction.
9.2 Assessments
Cedent will provide reasonable assistance with Customer’s privacy impact assessments and vendor risk assessments relating to the Service.
9.3 Diligence materials
On request, and no more than once every twelve (12) months absent a Security Incident or a material change, Cedent will provide: this DPA; the current Security Schedule; the current versioned Subprocessor List; its SOC 2 report once issued; and reasonable written responses to a security questionnaire.
Cedent recognizes that its customers have an independent professional obligation under ABA Formal Opinion 512 and analogous state guidance to evaluate their AI vendors, and will not treat diligence requests as burdensome.
9.4 Audit
Where the materials in Section 9.3 are insufficient to demonstrate compliance, Customer may request an audit, on thirty (30) days’ notice, no more than once per year absent a Security Incident, during business hours, subject to confidentiality, conducted so as not to compromise other customers’ data, at Customer’s expense. Following a Security Incident affecting Customer, these frequency and cost limits do not apply.
10. Return and Deletion
10.1 Export window
On termination or expiration, Customer’s account remains accessible in a read-and-export state for thirty (30) days, so Customer can retrieve Customer Personal Data in a commercially reasonable machine-readable format at no additional charge.
Cedent will not condition export on payment of any amount, including undisputed past-due amounts. Cedent recognizes that Customer has independent obligations to its clients — including, in California, Rule of Professional Conduct 1.16(e)(1) — and will not obstruct Customer’s compliance with them.
10.2 Deletion on request, at any time
Customer may request deletion at any time — during the subscription, during the export window, or afterward — and Cedent will honor it. On written request Cedent will provide a certification of deletion.
10.3 Default deletion schedule
Absent an earlier request, following the thirty-day export window:
| Data | Production | Encrypted backups |
|---|---|---|
| Matter Data, Calendar Data, documents, Outputs | Within 30 days | Within 90 days |
| Email export archives (ZIP) | 14 days from generation | Within 90 days |
| Time-entry ledger | Within 30 days | Within 90 days |
10.4 Soft-delete — disclosed precisely
A document deleted by an Authorized User inside the Service is soft-deleted: removed from Customer’s view but retained by Cedent for thirty (30) days, so accidental deletion can be reversed. A soft-deleted document is not immediately destroyed. It remains encrypted, access-controlled, and subject to Sections 4 and 5 while retained. Customer may request immediate irreversible destruction of a specific document at privacy@cedent.ai.
10.5 Backups and legal holds
Deleted data persists in encrypted backups until rotated out, within 90 days, and is not restored to production after a deletion request. Cedent may retain data longer only where required by law or to preserve evidence under a litigation hold; such data stays subject to Sections 4, 5, and 8 and is deleted when the obligation lapses.
11. International Transfers
Cedent processes and stores all Customer Personal Data in the United States and does not transfer it outside the United States.
This DPA does not include GDPR Article 28 terms, Standard Contractual Clauses, or a UK Addendum, and Cedent makes no representation that the Service is suitable for processing personal data subject to the GDPR or UK GDPR. Customer is responsible for assessing lawfulness as to any non-U.S. individual appearing in Matter Data. Customers requiring such terms should contact legal@cedent.ai.
12. General
12.1 Precedence
In the event of conflict, this DPA prevails over the Terms of Service as to the processing of Customer Personal Data.
12.2 Liability
Each party’s liability under this DPA is subject to the limitations in the Terms of Service, except as those limitations cannot lawfully be applied.
12.3 Term
This DPA takes effect when Customer accepts the Terms and continues until Cedent has deleted all Customer Personal Data under Section 10. Sections 3, 4, 5, 8, and 10 survive termination.
12.4 Changes
Cedent may update this DPA on thirty (30) days’ notice, provided no update materially reduces the protections afforded to Customer Personal Data. A change weakening Section 4 (no training), Section 5 (confidentiality and privilege), or Section 8 (legal process) requires Customer’s affirmative opt-in as to data already in the Service.
Schedule 1 — Details of Processing
| Subject matter | Provision of the Cedent AI matter assistant |
| Duration | The subscription term, plus the retention periods in Section 10 |
| Nature | Ingestion, OCR and text extraction, storage, organization, AI classification and generation, deadline computation, court-form population, export, and outbound delivery at Customer’s direction |
| Purpose | The specific business purposes in Section 2.2 |
| Controller | Customer |
| Processor | Cedent AI, Inc. |
Categories of data subjects
Customer’s attorneys and staff; Customer’s clients; opposing parties; children and minors, including in custody matters; extended family members; witnesses; experts, evaluators, and custody evaluators; opposing and co-counsel; court personnel; and any individual appearing in a connected mailbox or calendar, including individuals unrelated to any matter.
Categories of personal data
Identifiers and contact details; family relationships and household composition; financial data — income, employment, expenses, assets, debts, accounts, tax information (FL-150, FL-142); property and real-estate records; health, medical, psychiatric, and substance-abuse information; allegations of abuse or domestic violence; immigration status; criminal history; communications content; calendar events including personal events; and any other content Customer submits.
Sensitive personal information
Customer Personal Data routinely includes categories treated as sensitive under the CCPA and other laws, including health data, precise financial account information, contents of communications, information concerning minors, sex life and sexual orientation, racial or ethnic origin, religious beliefs, and immigration status.
Cedent processes sensitive personal information only to perform the services in Section 2.2 and for no purpose that would trigger a consumer’s right to limit its use under Cal. Civ. Code § 1798.121.
Schedule 2 — Technical and Organizational Security Measures
1. Encryption
- In transit: TLS 1.3 for all connections, internal and external.
- At rest: AES-256 for all stored Customer Personal Data, including databases, object storage, and backups.
- Key management: AWS KMS, with rotation. Secrets in AWS Secrets Manager. No secrets in source or configuration files.
2. Access control
- Role-based access control; least privilege by default.
- MFA required for all Cedent personnel with production access. Human access to production is exclusively through AWS IAM Identity Center, with MFA enforced at every sign-in and device registration required. There are no human IAM users — the only IAM users are service principals.
- Customer authentication through Clerk, supporting MFA and SSO.
- Logical tenant separation; cross-firm access is prevented by design.
- Access reviewed at least quarterly; revoked within 24 hours of role change or departure.
- Production access to Customer Personal Data limited to personnel who require it, logged and reviewable.
3. Network and infrastructure
- Deployed on AWS in United States regions only.
- Private networking; no direct public database exposure; security groups least-privilege.
- Isolated environments. Staging and test environments never contain production Customer Personal Data.
4. Logging and monitoring
- Application logs to Axiom, retained 30 days. Logs pass through an allowlist scrubber before ingestion but still carry firm and matter identifiers, which is why the window is short rather than long.
- Infrastructure and administrative audit trail to AWS CloudTrail, retained 24 months — organization-wide, multi-region, with log-file integrity validation enabled.
- Authentication, authorization, and administrative actions logged.
- Alerting on anomalous access.
5. AI processing controls
- All inference on Amazon Bedrock inside AWS.
- Zero data retention by the inference layer beyond serving the request.
- No training or model improvement on Customer Personal Data, contractually prohibited at every layer.
- No third-party model provider receives Customer Personal Data.
6. Development and change management
- Peer code review; version control; separated environments.
- Dependency scanning and patching on a defined cadence.
- Least-privilege CI/CD credentials.
7. Personnel
- Written confidentiality agreements surviving employment.
- Security and privacy training at onboarding, including specific training on the handling of privileged material.
- Access revoked within 24 hours of departure.
8. Resilience
- Automated encrypted backups with defined rotation.
- Periodic restoration testing.
- Documented incident response plan with defined roles and escalation.
9. Vendor management
- Written DPAs with all Subprocessors processing Customer Personal Data.
- Security review before onboarding; no Subprocessor processes Customer Personal Data before its DPA is executed.
10. Compliance
- SOC 2 Type II in progress. Cedent will not represent that it holds certification before the report is issued.
- Controls designed against the Security and Confidentiality trust services criteria.
Current limitations, disclosed rather than omitted. As of this version: SOC 2 Type II is in progress, not complete; Cedent does not currently carry cyber liability or technology errors & omissions insurance; Sentry error monitoring is not enabled pending an executed DPA; and security responsibilities rest with a single individual, with no designated deputy or on-call rotation. These will be updated as they change, and Cedent will notify customers of material changes to this Schedule.
Schedule 3 — Subprocessor List
Version 1.1 — September 3, 2026 · Current version at cedent.ai/subprocessors
A. Subprocessors processing Customer Personal Data
| # | Subprocessor | Purpose | Location |
|---|---|---|---|
| 1 | Amazon Web Services, Inc. — ECS, S3, Bedrock, ElastiCache, KMS, Secrets Manager | Hosting, storage, all AI inference, caching, key and secret management | United States |
| 2 | Neon, Inc. | Database hosting | United States |
| 3 | Modal Labs, Inc. | Document text extraction and OCR | United States |
| 4 | Clerk, Inc. | Authentication and identity management | United States |
| 5 | Resend, Inc. | Platform notification email | United States |
| 6 | PostHog, Inc. | Product analytics | United States |
| 7 | Axiom, Inc. | Application and audit log ingestion | United States |
B. Not processing Customer Personal Data
| # | Party | Purpose | Note |
|---|---|---|---|
| 8 | Stripe, Inc. | Payments and subscription management | Independent controller for payment data. Card credentials go directly to Stripe and never reach Cedent’s systems |
| 9 | Netlify, Inc. | Marketing website hosting | cedent.ai marketing site only — no application data |
| 10 | Google LLC — Google Analytics 4 | Marketing website analytics | Marketing site only. Google Signals and Ads linkage disabled |
| 11 | PostHog, Inc. | Marketing website analytics | Marketing site only. No session recording. Already listed at #6 for product analytics — one provider, two separate uses |
C. Approved but not yet in production
Thirty days’ notice will be given before any of these begins processing Customer Personal Data.
| Party | Purpose | Status |
|---|---|---|
| Functional Software, Inc. (Sentry) | Application error monitoring | Not enabled. Pending DSN configuration and executed DPA |
| Clio (Themis Solutions Inc.) | Practice management synchronization | Not launched. Pending partner agreement review |
D. Removed
| Party | Reason | Removed |
|---|---|---|
| Railway Corp. | Used for staging and test environments only, never production. Does not process Customer Personal Data. Listed in error in the July 2026 privacy policy | v1.0 |
| Marker | Self-hosted software, not a third-party service, and used only in staging and development. Production document extraction runs entirely on Modal. Not a subprocessor | v1.0 |
Change log
| Version | Date | Change |
|---|---|---|
| 1.0 | September 1, 2026 | Initial versioned list. Added Stripe and Axiom; removed Railway and Marker; disclosed Sentry and Clio as pending |