Public Documentation

Lawie Docs

Legal and Policies

Data Processing Addendum

The execution framework for B2B processing of customer personal data.

Effective 2026-07-14 · Owner: Legal and Privacy

Requires completion and signature with the customer; this page is not an executed DPA.

Parties, instructions, and precedence

The executed DPA must identify the customer as controller, the Lawie contracting entity as processor, the underlying agreement, processing purpose and duration, data and data-subject categories, permitted regions, and special-category or criminal-offence data. It controls over conflicting agreement terms on data protection.

Lawie processes personal data only on documented customer instructions unless applicable law requires otherwise, and informs the customer of a conflicting instruction where legally permitted.

Confidentiality and security

  • Authorized personnel are bound by confidentiality obligations.
  • Technical and organizational measures cover identity and access, tenant isolation, encryption, logging, secure development, vulnerability management, recovery, incident response, and deletion.
  • Deployment-specific evidence and contractual commitments prevail over generic descriptions; no certification is implied by this page.

Subprocessors and transfers

The executed DPA must define authorized subprocessors, notice and objection periods, equivalent data-protection obligations, processing regions, and the lawful transfer mechanism for restricted transfers. The public register lists only vendors verified from executed agreements and deployed configuration.

Assistance and incidents

Taking account of the processing, Lawie reasonably assists with data-subject requests, security duties, DPIAs, and regulator consultation. Confirmed personal-data breaches are reported without undue delay with available information; statutory notifications remain the controller’s responsibility unless agreed otherwise.

Return, deletion, and audit

At termination or documented instruction, customer personal data is returned or deleted subject to legal holds, legal retention, and documented backup expiry. Audit rights, evidence access, frequency, confidentiality, costs, and remediation periods must be completed in the executed DPA.