LawyerDeskBook a demo

Data processing addendum

The addendum governing LawyerDesk's processing of personal data on behalf of customers, pursuant to GDPR, UK GDPR, CCPA, and DPDP.

  • Last updatedApril 18, 2026
  • Document04 of 08
  • JurisdictionIndia, courts at Bengaluru

01 Roles of the parties

Customer is the Controller of personal data processed via LawyerDesk. LawyerDesk acts as Processor, and our sub-processors act as sub-processors.

02 Scope and purpose

LawyerDesk processes personal data only to provide the service, to comply with documented customer instructions, and as required by law. We do not process personal data for our own purposes.

03 Security measures

We maintain technical and organizational measures appropriate to the risk, including encryption in transit and at rest, access controls, pseudonymization where practical, regular security testing, and business continuity planning. See our Security page for detail.

04 Sub-processors

We use a limited, vetted list of sub-processors for infrastructure, observability, and support. The current list is at /legal/subprocessors. We notify customers of material changes and offer a reasonable objection window.

05 International transfers

Cross-border transfers rely on Standard Contractual Clauses, UK IDTA, or equivalent safeguards. Customers may specify primary data residency at provisioning.

06 Assistance and audits

We assist Customer in responding to data subject requests and, where feasible, in meeting obligations under articles 32-36 GDPR. Customers may audit our compliance annually, subject to confidentiality and reasonable notice.

LawyerDesk Advocacy Private Limited · Data processing addendum· last updated April 18, 2026 · https://lawyerdesk.ai/legal/dpa

Questions about this document?

Our legal team replies within two business days.

legal@lawyerdesk.ai