Cedent AI
Legal

Data Processing Addendum

Cedent AI, Inc. Version 1.0 · Effective September 1, 2026


This DPA is incorporated into and forms part of the Cedent AI Terms of Service between Cedent AI, Inc. (“Cedent”) and the law firm that accepts them (“Customer”). No signature is required — it takes effect automatically when Customer accepts the Terms and applies for as long as Cedent processes Matter Data.

Customers who require a countersigned copy for their own records or for a malpractice carrier may request one at legal@cedent.ai. We countersign on request at no charge and will not ask you to negotiate for it.

Capitalized terms not defined here have the meanings given in the Terms of Service.


1. Scope and Roles

1.1 What this DPA covers

This DPA governs Cedent’s processing of Customer Personal Data: all personal information contained in Matter Data, Calendar Data, and the time-entry ledger — that is, everything relating to Customer’s representation of its clients.

1.2 Roles

Customer is the controller and, under the CCPA, the “business.” Cedent is the processor and “service provider.” Cedent processes Customer Personal Data solely on Customer’s documented instructions and never for its own purposes.

1.3 What this DPA does not cover

  • Account Data and website visitor data, for which Cedent is a controller — see the Privacy Policy.
  • Payment data, for which Stripe, Inc. is an independent controller. Card numbers and payment credentials go directly to Stripe and never reach Cedent’s systems.
  • Unsaved Scratchpad Content, which resides in the Authorized User’s browser and is never stored by Cedent. Cedent holds no copy and cannot export, delete, or certify deletion of it.

1.4 Customer’s responsibilities

Customer warrants that it has all rights, authority, and consents necessary to submit Customer Personal Data and to instruct the processing described here, including with respect to third parties whose information appears in a connected mailbox or calendar but who are not Customer’s clients — opposing parties, children, witnesses, and others. Cedent cannot assess this and does not.


2. Processing Instructions and Purpose Limitation

2.1 Documented instructions

Cedent will process Customer Personal Data only:

  • (a) to provide, secure, maintain, and support the Service under the Terms;
  • (b) as further instructed in writing by Customer, where consistent with the Service; and
  • (c) where required by applicable law, subject to Section 8.

If Cedent believes an instruction violates applicable law, it will notify Customer and may suspend performance of that instruction.

2.2 Specific business purposes — stated specifically, not generically

As required by Cal. Code Regs. tit. 11, § 7051(a)(1), the business purposes are:

  1. Email and document ingestion — retrieving messages, attachments, and files from Connected Accounts and uploads.
  2. Text extraction and OCR — converting documents to machine-readable text.
  3. Matter organization — associating content with matters and building matter workspaces.
  4. Fact extraction, trust ranking, and chronology construction.
  5. Calendar ingestion and matter-association classification — retrieving every event on a connected calendar and classifying it (see the Privacy Policy, Section 6).
  6. Deadline computation — applying published statutes and rules to propose dates.
  7. Draft generation — correspondence, briefs, action briefs, and population of official court forms including FL-150 and FL-142.
  8. Missing-document identification.
  9. Draft time-entry generation and ledger maintenance.
  10. Outbound Actions at Customer’s direction — sending mail from Customer’s mailbox, writing calendar events, writing files to connected storage.
  11. Export and handover package generation.
  12. Security, abuse prevention, availability, and troubleshooting of the Service.
  13. Support, where an Authorized User requests assistance with specific content.

No other purpose is authorized.

2.3 Duration, categories, and subjects

Set out in Schedule 1.


3. CCPA Service Provider Certification

Cedent certifies that it understands the restrictions in this Section 3 and will comply with them. This Section is given for purposes of Cal. Civ. Code § 1798.140(ag) and Cal. Code Regs. tit. 11, § 7051.

Cedent will not:

  • (a) sell or share Customer Personal Data, as “sell” and “share” are defined in the CCPA;
  • (b) retain, use, or disclose Customer Personal Data for any purpose other than the specific business purposes in Section 2.2, including any commercial purpose of its own;
  • (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between Cedent and Customer;
  • (d) combine Customer Personal Data with personal information received from another source, or from another Customer, except as expressly permitted by Cal. Code Regs. tit. 11, § 7050(b);
  • (e) use Customer Personal Data to train, fine-tune, evaluate, or improve any machine learning model — see Section 4; or
  • (f) use Customer Personal Data to build or enhance any profile, audience, or advertising product.

Cedent will:

  • (g) comply with all obligations applicable to it as a service provider under the CCPA and provide the same level of privacy protection the CCPA requires of a business;
  • (h) notify Customer promptly, and in any event within five (5) business days, if it determines it can no longer meet its obligations under the CCPA or this DPA;
  • (i) grant Customer the right to take reasonable and appropriate steps to ensure Cedent’s processing is consistent with Customer’s CCPA obligations (Section 9); and
  • (j) grant Customer the right, on notice, to take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Data.

Customer discloses Customer Personal Data to Cedent only for the limited and specified business purposes in Section 2.2.


4. No Training — Binding Commitment

4.1 The commitment

Cedent will not use Customer Personal Data to train, fine-tune, evaluate, benchmark, or otherwise develop or improve any machine learning model, and will not permit any Subprocessor or model provider to do so.

4.2 Where inference happens

All AI inference performed by the Service runs on Amazon Bedrock within Amazon Web Services. Under Cedent’s terms with AWS, prompts and completions are not retained after a request is served and are not used to train or improve any model — whether AWS’s, a third-party model provider’s, or Cedent’s. No third-party model provider receives Customer Personal Data.

4.3 Scope note, stated precisely

Section 4.2 concerns model inference. Document text extraction and OCR are performed by Modal, and database hosting by Neon. These are disclosed Subprocessors (Schedule 3) bound by written terms at least as protective as this DPA, including the prohibition in Section 4.1. Cedent states this rather than claiming that no Matter Data ever leaves AWS, because that broader claim would not be accurate.

4.4 Survival and non-amendment

Section 4 survives termination indefinitely and may not be weakened as to Customer Personal Data already in the Service without Customer’s affirmative written opt-in. Continued use of the Service will never constitute consent to a weakening of this Section.


5. Confidentiality, Privilege, and Personnel

5.1 Treated as privileged by default

Cedent treats all Customer Personal Data as attorney-client privileged material and attorney work product, without distinguishing between sensitive and ordinary content.

5.2 Cedent’s undertaking

Cedent acts solely as Customer’s agent and service provider for the purpose of assisting Customer in rendering legal services to its clients. Cedent will not access, use, retain, or disclose Customer Personal Data except as necessary to provide the Service, as Customer directs, or as required by law under Section 8.

5.3 Privilege preservation

The arrangement is structured with the intention that Cedent’s access operates as an extension of Customer’s staff for the purpose of facilitating Customer’s provision of legal services, and does not waive the attorney-client privilege or work product protection. Cedent does not and cannot guarantee that any tribunal will so hold, and this is not legal advice to Customer. Cedent waives any right to assert that its receipt of Customer Personal Data waived any privilege or protection of Customer or Customer’s clients.

5.4 Personnel

Cedent ensures that personnel authorized to process Customer Personal Data are bound by written confidentiality obligations surviving employment, receive privacy and security training, and have access only on a least-privilege, need-to-know basis, with access logged.

5.5 No cross-firm access

Cedent maintains logical separation between Customer accounts and will not combine, commingle, or expose Customer Personal Data across firms.


6. Subprocessors

6.1 Authorization

Customer generally authorizes Cedent to engage Subprocessors, listed in Schedule 3 and maintained in versioned, dated form at cedent.ai/subprocessors.

6.2 Flow-down

Cedent will impose on each Subprocessor, by written contract, data protection obligations at least as protective as those in this DPA, including the no-training prohibition in Section 4.1 and the confidentiality obligations in Section 5. Cedent remains fully liable to Customer for each Subprocessor’s performance.

6.3 Change notice and objection

Cedent will give at least thirty (30) days’ advance notice before adding or replacing a Subprocessor that processes Customer Personal Data, by email to Customer’s Administrator and by publishing a new version of the list.

Customer may object on reasonable data-protection grounds within that thirty-day period. The parties will discuss in good faith. If Cedent cannot accommodate the objection, Customer may terminate the affected subscription without penalty and receive a pro-rata refund of prepaid unused fees, and Section 10 applies to the data.


7. Security and Incidents

7.1 Measures

Cedent implements and maintains the technical and organizational measures in Schedule 2, and will not materially reduce their overall protection during the term.

7.2 Incident notification

Cedent will notify Customer without undue delay and no later than seventy-two (72) hours after becoming aware of a Security Incident — a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data.

7.3 What the notice contains

To the extent known, and updated as investigation proceeds: the nature of the incident; the categories and approximate volume of data and number of individuals affected; whether the affected data included matter files, court-form financial data, or calendar content; likely consequences; measures taken and proposed; and a contact point.

7.4 Cooperation

Cedent will investigate, take reasonable steps to mitigate, and provide the information and cooperation Customer reasonably requires to meet its own notification obligations and its professional duty to inform affected clients. Cedent will not require Customer to await Cedent’s investigation before making its own required notifications.

7.5 No admission

Notice is not an acknowledgment of fault or liability.


If Cedent receives a subpoena, warrant, court order, civil investigative demand, or other legal process seeking Customer Personal Data, Cedent will:

  • (a) not produce Customer Personal Data unless and until legally compelled after the steps below;
  • (b) notify Customer promptly and before any disclosure, unless legally prohibited — and if prohibited, seek authorization to notify and give notice at the earliest permitted moment;
  • (c) where a nondisclosure obligation is imposed, seek to have it narrowed or lifted;
  • (d) object on the grounds that the material is or may be privileged or work product, that Cedent is not the appropriate custodian, and that the demand should be directed to Customer as counsel of record; and
  • (e) reasonably cooperate, at Customer’s expense, with Customer’s efforts to quash, limit, or obtain a protective order.

Cedent will not voluntarily disclose Customer Personal Data to law enforcement or any government authority.


9. Assistance, Diligence, and Audit

9.1 Individual rights requests

Because Customer is the controller, requests from Customer’s clients or third parties go to Customer. Cedent will not act on such a request directly, and will redirect the requester to Customer. Cedent will provide reasonable assistance, taking into account the nature of processing, to help Customer respond — including locating, exporting, correcting, or deleting specific records on Customer’s instruction.

9.2 Assessments

Cedent will provide reasonable assistance with Customer’s privacy impact assessments and vendor risk assessments relating to the Service.

9.3 Diligence materials

On request, and no more than once every twelve (12) months absent a Security Incident or a material change, Cedent will provide: this DPA; the current Security Schedule; the current versioned Subprocessor List; its SOC 2 report once issued; and reasonable written responses to a security questionnaire.

Cedent recognizes that its customers have an independent professional obligation under ABA Formal Opinion 512 and analogous state guidance to evaluate their AI vendors, and will not treat diligence requests as burdensome.

9.4 Audit

Where the materials in Section 9.3 are insufficient to demonstrate compliance, Customer may request an audit, on thirty (30) days’ notice, no more than once per year absent a Security Incident, during business hours, subject to confidentiality, conducted so as not to compromise other customers’ data, at Customer’s expense. Following a Security Incident affecting Customer, these frequency and cost limits do not apply.


10. Return and Deletion

10.1 Export window

On termination or expiration, Customer’s account remains accessible in a read-and-export state for thirty (30) days, so Customer can retrieve Customer Personal Data in a commercially reasonable machine-readable format at no additional charge.

Cedent will not condition export on payment of any amount, including undisputed past-due amounts. Cedent recognizes that Customer has independent obligations to its clients — including, in California, Rule of Professional Conduct 1.16(e)(1) — and will not obstruct Customer’s compliance with them.

10.2 Deletion on request, at any time

Customer may request deletion at any time — during the subscription, during the export window, or afterward — and Cedent will honor it. On written request Cedent will provide a certification of deletion.

10.3 Default deletion schedule

Absent an earlier request, following the thirty-day export window:

DataProductionEncrypted backups
Matter Data, Calendar Data, documents, OutputsWithin 30 daysWithin 90 days
Email export archives (ZIP)14 days from generationWithin 90 days
Time-entry ledgerWithin 30 daysWithin 90 days

10.4 Soft-delete — disclosed precisely

A document deleted by an Authorized User inside the Service is soft-deleted: removed from Customer’s view but retained by Cedent for thirty (30) days, so accidental deletion can be reversed. A soft-deleted document is not immediately destroyed. It remains encrypted, access-controlled, and subject to Sections 4 and 5 while retained. Customer may request immediate irreversible destruction of a specific document at privacy@cedent.ai.

Deleted data persists in encrypted backups until rotated out, within 90 days, and is not restored to production after a deletion request. Cedent may retain data longer only where required by law or to preserve evidence under a litigation hold; such data stays subject to Sections 4, 5, and 8 and is deleted when the obligation lapses.


11. International Transfers

Cedent processes and stores all Customer Personal Data in the United States and does not transfer it outside the United States.

This DPA does not include GDPR Article 28 terms, Standard Contractual Clauses, or a UK Addendum, and Cedent makes no representation that the Service is suitable for processing personal data subject to the GDPR or UK GDPR. Customer is responsible for assessing lawfulness as to any non-U.S. individual appearing in Matter Data. Customers requiring such terms should contact legal@cedent.ai.


12. General

12.1 Precedence

In the event of conflict, this DPA prevails over the Terms of Service as to the processing of Customer Personal Data.

12.2 Liability

Each party’s liability under this DPA is subject to the limitations in the Terms of Service, except as those limitations cannot lawfully be applied.

12.3 Term

This DPA takes effect when Customer accepts the Terms and continues until Cedent has deleted all Customer Personal Data under Section 10. Sections 3, 4, 5, 8, and 10 survive termination.

12.4 Changes

Cedent may update this DPA on thirty (30) days’ notice, provided no update materially reduces the protections afforded to Customer Personal Data. A change weakening Section 4 (no training), Section 5 (confidentiality and privilege), or Section 8 (legal process) requires Customer’s affirmative opt-in as to data already in the Service.



Schedule 1 — Details of Processing

Subject matterProvision of the Cedent AI matter assistant
DurationThe subscription term, plus the retention periods in Section 10
NatureIngestion, OCR and text extraction, storage, organization, AI classification and generation, deadline computation, court-form population, export, and outbound delivery at Customer’s direction
PurposeThe specific business purposes in Section 2.2
ControllerCustomer
ProcessorCedent AI, Inc.

Categories of data subjects

Customer’s attorneys and staff; Customer’s clients; opposing parties; children and minors, including in custody matters; extended family members; witnesses; experts, evaluators, and custody evaluators; opposing and co-counsel; court personnel; and any individual appearing in a connected mailbox or calendar, including individuals unrelated to any matter.

Categories of personal data

Identifiers and contact details; family relationships and household composition; financial data — income, employment, expenses, assets, debts, accounts, tax information (FL-150, FL-142); property and real-estate records; health, medical, psychiatric, and substance-abuse information; allegations of abuse or domestic violence; immigration status; criminal history; communications content; calendar events including personal events; and any other content Customer submits.

Sensitive personal information

Customer Personal Data routinely includes categories treated as sensitive under the CCPA and other laws, including health data, precise financial account information, contents of communications, information concerning minors, sex life and sexual orientation, racial or ethnic origin, religious beliefs, and immigration status.

Cedent processes sensitive personal information only to perform the services in Section 2.2 and for no purpose that would trigger a consumer’s right to limit its use under Cal. Civ. Code § 1798.121.



Schedule 2 — Technical and Organizational Security Measures

1. Encryption

  • In transit: TLS 1.3 for all connections, internal and external.
  • At rest: AES-256 for all stored Customer Personal Data, including databases, object storage, and backups.
  • Key management: AWS KMS, with rotation. Secrets in AWS Secrets Manager. No secrets in source or configuration files.

2. Access control

  • Role-based access control; least privilege by default.
  • MFA required for all Cedent personnel with production access. Human access to production is exclusively through AWS IAM Identity Center, with MFA enforced at every sign-in and device registration required. There are no human IAM users — the only IAM users are service principals.
  • Customer authentication through Clerk, supporting MFA and SSO.
  • Logical tenant separation; cross-firm access is prevented by design.
  • Access reviewed at least quarterly; revoked within 24 hours of role change or departure.
  • Production access to Customer Personal Data limited to personnel who require it, logged and reviewable.

3. Network and infrastructure

  • Deployed on AWS in United States regions only.
  • Private networking; no direct public database exposure; security groups least-privilege.
  • Isolated environments. Staging and test environments never contain production Customer Personal Data.

4. Logging and monitoring

  • Application logs to Axiom, retained 30 days. Logs pass through an allowlist scrubber before ingestion but still carry firm and matter identifiers, which is why the window is short rather than long.
  • Infrastructure and administrative audit trail to AWS CloudTrail, retained 24 months — organization-wide, multi-region, with log-file integrity validation enabled.
  • Authentication, authorization, and administrative actions logged.
  • Alerting on anomalous access.

5. AI processing controls

  • All inference on Amazon Bedrock inside AWS.
  • Zero data retention by the inference layer beyond serving the request.
  • No training or model improvement on Customer Personal Data, contractually prohibited at every layer.
  • No third-party model provider receives Customer Personal Data.

6. Development and change management

  • Peer code review; version control; separated environments.
  • Dependency scanning and patching on a defined cadence.
  • Least-privilege CI/CD credentials.

7. Personnel

  • Written confidentiality agreements surviving employment.
  • Security and privacy training at onboarding, including specific training on the handling of privileged material.
  • Access revoked within 24 hours of departure.

8. Resilience

  • Automated encrypted backups with defined rotation.
  • Periodic restoration testing.
  • Documented incident response plan with defined roles and escalation.

9. Vendor management

  • Written DPAs with all Subprocessors processing Customer Personal Data.
  • Security review before onboarding; no Subprocessor processes Customer Personal Data before its DPA is executed.

10. Compliance

  • SOC 2 Type II in progress. Cedent will not represent that it holds certification before the report is issued.
  • Controls designed against the Security and Confidentiality trust services criteria.

Current limitations, disclosed rather than omitted. As of this version: SOC 2 Type II is in progress, not complete; Cedent does not currently carry cyber liability or technology errors & omissions insurance; Sentry error monitoring is not enabled pending an executed DPA; and security responsibilities rest with a single individual, with no designated deputy or on-call rotation. These will be updated as they change, and Cedent will notify customers of material changes to this Schedule.



Schedule 3 — Subprocessor List

Version 1.1 — September 3, 2026 · Current version at cedent.ai/subprocessors

A. Subprocessors processing Customer Personal Data

#SubprocessorPurposeLocation
1Amazon Web Services, Inc. — ECS, S3, Bedrock, ElastiCache, KMS, Secrets ManagerHosting, storage, all AI inference, caching, key and secret managementUnited States
2Neon, Inc.Database hostingUnited States
3Modal Labs, Inc.Document text extraction and OCRUnited States
4Clerk, Inc.Authentication and identity managementUnited States
5Resend, Inc.Platform notification emailUnited States
6PostHog, Inc.Product analyticsUnited States
7Axiom, Inc.Application and audit log ingestionUnited States

B. Not processing Customer Personal Data

#PartyPurposeNote
8Stripe, Inc.Payments and subscription managementIndependent controller for payment data. Card credentials go directly to Stripe and never reach Cedent’s systems
9Netlify, Inc.Marketing website hostingcedent.ai marketing site only — no application data
10Google LLC — Google Analytics 4Marketing website analyticsMarketing site only. Google Signals and Ads linkage disabled
11PostHog, Inc.Marketing website analyticsMarketing site only. No session recording. Already listed at #6 for product analytics — one provider, two separate uses

C. Approved but not yet in production

Thirty days’ notice will be given before any of these begins processing Customer Personal Data.

PartyPurposeStatus
Functional Software, Inc. (Sentry)Application error monitoringNot enabled. Pending DSN configuration and executed DPA
Clio (Themis Solutions Inc.)Practice management synchronizationNot launched. Pending partner agreement review

D. Removed

PartyReasonRemoved
Railway Corp.Used for staging and test environments only, never production. Does not process Customer Personal Data. Listed in error in the July 2026 privacy policyv1.0
MarkerSelf-hosted software, not a third-party service, and used only in staging and development. Production document extraction runs entirely on Modal. Not a subprocessorv1.0

Change log

VersionDateChange
1.0September 1, 2026Initial versioned list. Added Stripe and Axiom; removed Railway and Marker; disclosed Sentry and Clio as pending