Legal

Data Processing Addendum

How Lexnus processes personal data on behalf of customers. This is Appendix 1 to the Terms of Service.

Introduction

A. This DPA provides for the Controller and our respective obligations in relation to Personal Data processing. This DPA applies to all activities where we get in contact with Personal Data of the Controller including, but not limited to the Personal Data regarding the Controller's Users and other affected natural persons, in connection with the Platform, or other services provided to the Controller by us.

B. We are only allowed to process Personal Data in accordance with the Controller's documented instructions and in the Controller's interest.

C. Any reference made to "data protection laws" or similar in this DPA shall be understood to include, but not be limited to, the EU General Data Protection Regulation (2016/679) (the "GDPR"). If we're also providing services and/or products under this DPA to the Controller's Affiliates, or otherwise gain access to the Affiliate's data relating to identified or identifiable natural person(s) for the purposes of fulfilling the Main Agreement, such data shall be regarded as Personal Data and this DPA shall be applicable to our processing of such Personal Data. Such Affiliates have the same rights and obligations as the Controller under this DPA.

E. This DPA is an integral part of the Terms and/or any similar agreement executed between us and the Controller ("Main Agreement"). In the event of any conflict between the terms of the Main Agreement and the terms of this DPA, this DPA shall prevail with respect to the subject matter of this DPA.

1. Definitions

1.1 Affiliate

Affiliate shall mean, in this DPA, companies:

  • directly or indirectly owning or controlling the Controller;
  • under the same direct or indirect ownership or control as the Controller; or
  • directly or indirectly controlled by the Controller.

Control or ownership shall be understood to exist through direct or indirect ownership of fifty percent (50%) or more of the nominal value of the issued equity share capital or of fifty percent (50%) or more of the shares entitling the holders to vote for the election of the members of the board of directors or persons performing similar functions or the minimum share entitling to control prescribed in applicable legislation in such jurisdictions where the ownership of fifty percent (50%) or more would not be possible.

1.2 Processing

"Processing" shall have the meaning given to it under applicable data protection law and, for the purposes of this DPA, means the processing of Personal Data by us on behalf of the Controller in connection with the Main Agreement.

1.3 Data Subject

A Data Subject is a natural person whose Personal Data is being processed by us on behalf of the Controller under this DPA and the Main Agreement.

1.4 Instruction

We shall process Personal Data in accordance with the Controller's written instructions. The initial instructions are set forth in Sub-Appendix A to this DPA. Subject to the terms of this DPA, the Controller can change, amend or replace these initial instructions by single instructions in writing (of course, including in electronic form) at any time.

1.5 Personal Data

Personal Data means any information relating to an identified or identifiable natural person that is processed by us on behalf of the Controller under this DPA.

1.6 Personal Data Breach

Personal Data Breach is an accidental, unlawful or unauthorized destruction, loss, alteration, disclosure of or access to the Personal Data as well as any events endangering the security, confidentiality or integrity of the Personal Data.

2. Scope of Processing

2.1 We shall process Personal Data only on behalf of the Controller and according to the Controller's documented Instructions as set out in this Section 2, Sub-Appendix A (Instructions on processing Personal Data) and the Main Agreement, unless otherwise required by applicable data protection laws.

2.2 In addition to the Instructions set forth in Sub-Appendix A to this DPA, the Main Agreement and our performance thereof shall be the Controller's documented Instructions to us in respect of processing of Personal Data. The Parties may modify or supplement Sub-Appendix A during the term of the Main Agreement and this DPA by concluding an amendment to Sub-Appendix A, which shall be made in writing and which shall incorporate all of the substantive terms as set forth in Sub-Appendix A in an unchanged form. The Controller shall pay us reasonable compensation for all work and costs for us to accommodate such documented instructions by the Controller that are (1) not commercially reasonable to accommodate (for instance, instructions that would require the Platform – or the technology setup required to uphold the Controller's instructions – to be specially adapted for the Controller) and (2) are not generally expected and appropriate for the scope of services we offer. We may suggest new or amended instructions as reasonably required in the opinion of us (for instance, due to changes in the Platform or the Terms) and while it is the Controller's right to approve or reject such instructions, in case the Controller should not approve the instructions as suggested by us, section 11.4 shall apply.

3. Our obligations

3.1 As stated in section 2 above, we shall only collect, process or utilize Personal Data in accordance with the Instructions of the Controller and applicable laws and not for other own purposes or purposes of third parties. The Controller shall confirm any oral instructions in writing or via email. Where we believe that compliance with any Instructions by the Controller would result in a violation of applicable law on data protection, we shall immediately notify the Controller thereof.

3.2 Taking into account the costs of implementation, the state of the art, and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, we shall ensure, within our area of responsibility, the implementation and compliance with the agreed and appropriate technical and organizational measures, details of which are available from us upon request. In particular, we shall take such technical and organizational measures to protect the Personal Data against accidental, unlawful or unauthorized destruction, loss, alteration, disclosure and access as well as against other events that endanger the security, confidentiality or integrity of the Personal Data, including inter alia as appropriate:

(a) the pseudonymisation and encryption of Personal Data;

(b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;

(c) the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; and

(d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing.

For the avoidance of doubt, we may take other or additional measures as required due to new or amended legislation, or as a result of decisions by public authorities.

3.3 Upon the Controller's reasonable request, we shall provide information reasonably necessary to assist the Controller in demonstrating compliance with its obligations under applicable data protection law in relation to the Processing carried out by us under this DPA.

3.4 We shall inform the Controller without undue delay if we become aware (i) a material disruption affecting the Processing of Personal Data, (ii) a breach of this DPA or applicable data protection law in connection with the Processing of Personal Data, or (iii) any other circumstance that materially affects our ability to process Personal Data in accordance with this DPA or applicable data protection law.

3.5 All data storage media, if any, and all copies or reproductions thereof shall remain the property of the Controller. We shall at any time give information to the Controller relating to its Personal Data and materials. According to the Controller's individual orders, we shall be responsible for the erasure of test or excess data and materials in compliance with data protection requirements, except in certain cases, to be defined by the Controller, where storage and/or disclosure of the test or excess data shall be performed.

3.6 Personal Data shall primarily be processed within the European Economic Area ("EEA"). Where Personal Data is transferred to or processed in a country outside the EEA, we shall ensure that such transfer is made in accordance with applicable data protection law, including where applicable, on the basis of an adequacy decision or the European Commission's Standard Contractual Clauses together with any supplementary measures required by applicable law. The Controller's activation or use of an optional service involving an international transfer constitutes an Instruction to make such transfer in accordance with this Section.

3.7 Finally, if a Data Subject, public authority or third party requests information from us relating to the processing of Personal Data, we shall refer such request to the Controller and await the Controller's instructions.

4. Notification obligation

4.1 In case of a Personal Data Breach, we shall, without undue delay and, if possible, no later than 24 hours after having become aware of the Personal Data Breach, notify the Controller of the Personal Data Breach in writing. The notification shall, to the extent such information is available to us, contain all necessary information required for the Controller to be able to fulfill its reporting and disclosure obligations to the relevant public authority and Data Subjects.

4.2 We shall, without undue delay after becoming aware of any further details surrounding the Personal Data Breach, supplement the notification described above in Section 4.1 as well as provide the Controller with any other information relating to the respective Data Breach as reasonably requested by the Controller and available to us.

4.3 We will document any Personal Data Breaches, comprising the facts surrounding the breach, its effects and the remedial actions taken. This documentation must enable the supervisory authority to verify compliance with this Section 4. The documentation will only include information necessary for such purpose.

5. Confidentiality

5.1 Each Party shall keep confidential all material and information, including but not limited to Personal Data, marked as confidential or that should be understood to be confidential, regardless of whether personal, technical, financial or commercial and received in whatever form from the other Party ('Confidential Information'). A Party shall have the right to:

(i) use Confidential Information only for the purposes of this DPA and the Main Agreement;

(ii) copy Confidential Information only to the extent necessary for the purposes of this DPA and the Main Agreement; and

(iii) disclose Confidential Information only to those of its employees, subcontractors or advisors that need the Confidential Information for the purposes of this DPA and the Main Agreement. The disclosing Party is responsible for ensuring that the parties that receive Confidential Information comply with the terms relating to confidentiality agreed in this DPA.

5.2 The confidentiality obligation set out in this section 5 shall not, however, be applied to any material or information

(i) that was in the possession of the receiving Party prior to receipt of the same from the other Party without any obligation of confidentiality related thereto;

(ii) that is generally available or otherwise public, other than if it is public through a breach of this DPA or the Main Agreement on the part of the receiving Party;

(iii) that a Party has received from a third party without any obligation of confidentiality;

(iv) that a Party has independently developed without using any material or information received from the other Party;

(v) that a Party is obliged to disclose pursuant to Law or other order issued by a supervisory authority.

5.3 Each Party shall cease using Confidential Information received from the other Party promptly upon the termination of this DPA or the Main Agreement or when the respective Party no longer needs the Confidential Information in question for the purposes of this DPA and/or the Main Agreement and shall return or destroy the material in question (including all copies thereof). Each Party shall, however, be entitled to retain copies as and to the extent required by the applicable law.

5.4 Each Party guarantees the observance and proper performance of this DPA by its personnel and advisors to whom Confidential Information may be disclosed pursuant to this Clause 5.

5.5 The confidentiality obligations set out in this section 5 shall survive any termination or cancellation of this DPA or the Main Agreement.

6. Obligations of the Controller

6.1 The Controller warrants that all data used in the Service are collected, processed and utilized fairly and lawfully with respect to one or several of the legal grounds stipulated in the GDPR and other applicable law. Such requirements include, but are not limited to, the provision of information about processing of Personal Data to Data Subjects concerned.

6.2 Furthermore, the Controller shall inform us of the content and significance of applicable data protection law to the extent relevant for the processing of Personal Data carried out under this DPA as well as supervisory authorities' actions and decisions in respect of such processing of Personal Data. For the avoidance of doubt, and without prejudice to your right to instruct us on how to process Personal Data, we are not obligated to comply or take any measures due to such information as referred to in this section unless required by applicable data protection law.

7. Obligation to Assist

7.1 If the Controller, on the basis of applicable data protection laws, is obliged to answer to inquiries from Data Subjects on the collection, processing or utilization of Personal Data relating to such Data Subject, upon request of the Controller, we shall support the Controller in order to provide such information. We shall pass on such inquiries of affected Data Subjects to the Controller for answering these inquiries. We shall adequately support the Controller in this respect. Unless otherwise agreed in writing, the Controller shall adequately reimburse us for any reasonable costs incurred in connection with the fulfillment of the duties of this Section 7.

7.2 If the Controller, on the basis of applicable data protection laws, is obliged to erase or rectify Personal Data, we shall erase or rectify that Personal Data also from our data registers, upon the request of the Controller. Unless otherwise agreed in writing, the Controller shall adequately reimburse us for any reasonable costs incurred in connection with the fulfillment of the duties of this Section 7.

7.3 We shall assist the Controller also in the fulfillment of the Controller's other obligations under the applicable data protection laws.

8. Audits

8.1 Upon the Controller's reasonable request, we shall provide the Controller with information reasonably necessary to demonstrate our compliance with this DPA and applicable data protection law. Such information may include relevant documentation concerning our technical and organisational measures, security documentation, audit reports, certifications and responses to reasonable security or compliance questionnaires, where available.

8.2 The Controller shall primarily exercise its audit rights through the information and documentation provided under Section 8.1. If such information is reasonably insufficient to demonstrate our compliance with this DPA, or where an audit is required by applicable data protection law or based on reasonable evidence of material non-compliance with this DPA, the Controller may conduct an audit of our relevant processing activities.

Unless the circumstances reasonably require otherwise, such audit shall:

(i) be subject to at least thirty (30) days' prior written notice;

(ii) take place during normal business hours;

(iii) be limited in scope to systems, processes and information relevant to the Processing of Personal Data under this DPA;

(iv) be conducted in a manner that does not unreasonably interfere with our business operations or compromise the security, confidentiality, or rights of other customers or third parties; and

(v) where conducted by a third-party auditor, be performed by an independent auditor subject to appropriate confidentiality obligations.

We shall provide reasonable cooperation and assistance in connection with such audit. We shall not be required to disclose information that would compromise the security of our systems, disclose Personal Data or Confidential Information relating to other customers, or disclose our trade secrets, except to the extent required by applicable law or a competent supervisory authority.

8.3 Unless an audit identifies a material breach by us of this DPA or applicable data protection law, the Controller shall bear its own costs and reimburse us for reasonable costs incurred in connection with an audit that requires material assistance beyond the information and documentation ordinarily made available by us.

8.4 Nothing in this Section 8 shall restrict the rights or powers of a competent supervisory authority. We shall cooperate with and provide such information and access to a competent supervisory authority as required by applicable data protection law.

9. Subprocessors

9.1 Controller agrees that we may use sub-processors to fulfill our contractual obligations under this DPA and to provide certain services on our behalf. We shall inform Controller of the names of the sub-processors that are used and what kind of service the sub-processors performs, as well as the geographical location where their processing activities in respect of the Personal Data are performed. The current list of sub-processors is attached as Sub-Appendix B hereto. We will restrict the subprocessors' access to Personal Data only to what is necessary to maintain the Service (or other products/services provided by Lexnus to the Controller) and we will prohibit the subprocessors from accessing Personal Data for any other purpose. The Controller may object to the addition of new subprocessors.

9.2 We differentiate between Essential Subprocessors to Optional Sub-processors.

Essential Subprocessors are third-party subprocessors that provide critical infrastructure, functionality, or services without which the primary processing services would be significantly impaired or rendered inoperable. The use of Essential Subprocessors is mandatory and the Controller does not have the option to opt out from the utilization of these subprocessors for the delivery of the primary processing services.

Optional Subprocessors: are third-party subprocessors that provide supplementary or optional services, functionalities, or enhancements to the primary processing services. The use of Optional Subprocessors is not mandatory for the basic operation and delivery of the primary processing services. Controllers have the option to opt out from the utilisation of these subprocessors upon request, without compromising the core functions of the primary services.

9.3 We are liable for each Essential subprocessor's obligations regarding the processing of Personal Data.

9.4 We shall inform the Controller of any intended changes concerning the addition or replacement of other sub-processors that process Personal Data. Accordingly, we are giving the Controller the opportunity to object to such changes if there are objectively valid reasons for such objection and the Controller informs us of the objection within a reasonable time after being informed about the new sub-processors.

10. Liability

10.1 The Parties agree that the general principle of division of responsibility between the Parties under this DPA relating to fines and/or damages to the Data Subjects imposed by any relevant supervisory authority and/or competent court authorized to impose such fines or damages is based on the respective Party's need to fulfill its obligations under the applicable data protection laws and that any fines and/or damages to the Data Subjects imposed by a supervisory authority and/or competent court shall be paid by the Party that has failed in its performance of its legal obligations under the applicable data protection laws.

10.2 Lexnus shall indemnify and hold harmless the Data Controller upon the Data Controller's first demand insofar as third parties (Data Subjects in particular) make claims against Lexnus on the grounds of an infringement of their personal rights or of data protection law where such infringement is caused by actions of Lexnus in intentional or gross negligent violation of this DPA. The obligation to indemnify is – except in cases of willful intent or in relation to personal injuries or death – capped with the amount of fees paid by the Controller in the 12 months immediately before the infringing incidence.

11. Term and Termination

11.1 This DPA shall be concluded for an indefinite period of time, and shall automatically be terminated in case of termination of the Main Agreement for any reason. Either Party's right to terminate this DPA for cause shall remain unaffected.

11.2 If we materially breach our obligations under this DPA and fail to remedy such breach within thirty (30) days from the Controller's written notification of the breach to us, the Controller shall have the right to terminate the Main Agreement with immediate effect.

11.3 Upon termination of this Agreement for whatsoever reason, we shall give the Controller access to all data storage media and copies thereof as well as all Personal Data being in its possession to the Controller (by e.g. enabling the Controller to download documents including Personal Data) and shall thereafter delete any Personal Data stored with us. Personal Data contained in backups may be retained in accordance with our ordinary backup and disaster recovery procedures, provided that such Personal Data remains protected in accordance with this DPA and is not otherwise processed except as required by applicable law. Upon request of the Controller, we shall confirm compliance with such obligations in writing within four (4) weeks from such request.

11.4 If the Controller objects to our appointment of a subcontractor, or to our changes to the Service, and such objection prevents or significantly obstructs our ability to provide the Service, we have the right to terminate the Main Agreement with immediate effect. This also applies if the Controller's objection would entail costs to us that are unreasonably high in light of the compensation that the Controller will pay us under the Main Agreement. In case of termination under this clause 11.4, the Controller shall not be entitled to any refund of fees paid for the Service and we are relieved of any and all liability for any damages caused by our termination.

12. General Provisions

12.1 Amendments and additions to this DPA must be in writing. This also applies to a waiver of the requirement for this DPA.

12.2 Should one or more clauses of this DPA and or the Main Agreement be or become invalid and/or unenforceable, the validity of the other clauses of this DPA and the Main Agreement shall remain unaffected thereby. In such case, the Parties shall amend this agreement and amicably replace the invalid clauses.

12.3 Swedish law shall govern this DPA.

12.4 Any dispute, controversy or claim arising out of or in connection with this DPA, or the breach, termination or invalidity thereof, shall be finally settled by arbitration in accordance with the Rules of the Arbitration Institute of the Stockholm Chamber of Commerce for expedited arbitration procedure. The seat of arbitration shall be Stockholm, Sweden. The language to be used in the arbitral proceedings shall be English. This DPA shall be governed by the substantive law of Sweden.

Sub-Appendix A – Instructions on Processing Personal Data

In addition to what is set forth in the DPA and the Main Agreement, the Controller instructs us to process Personal Data in accordance with the instructions below:

PURPOSES OF THE PROCESSING

Lexnus provides a contract control and automation platform that enables the Controller to establish, manage and apply its legal policies and standards across its contracts and contracting processes.

Personal data is processed as necessary to provide the Platform and its functionality including to:

Create and administer User accounts and provide Users with access to the Platform;

Analyse contracts and other documents against the Controller's playbooks, approved clauses, policies and instructions, including to identify deviations, missing provisions and other issues;

Support the creation, review, management and execution of contracts and related contracting processes, including through integrations and artificial intelligence functionality made available through the Platform;

Provide, operate, maintain, secure and support the Platform and the services provided to the Controller; and

Otherwise process Personal Data as necessary to perform the Main Agreement in accordance with the Controller's documented instructions.

Personal data processed for these purposes may relate to the Controller's users, employees, representatives, advisers, consultants, contract counterparties and their representatives, and other natural persons whose Personal Data is contained in contracts, documents, or other information submitted to or processed through the Platform.

ARTIFICIAL INTELLIGENCE AND LARGE LANGUAGE MODELS

As part of providing the Platform, Lexnus may process Personal Data contained in contracts, documents and other information submitted to the Platform using artificial intelligence and large language model services ("AI Services). Such processing may include analysing, extracting, classifying, summarising and otherwise processing information in order to provide the AI-enabled functionality of the Platform.

The Controller instructs Lexnus to process Personal Data using the AI Services that form part of the standard functionality of the Platform and acknowledges that such processing may involve the transfer of Personal Data to the relevant subprocessor identified in Sub-Appendix B.

Where the Platform allows the Controller to select or activate an alternative or optional AI provider, the Controller's selection or activation of such provider constitutes an Instruction to Lexnus to process and transfer the relevant Personal Data using that provider. Optional AI providers will not process the Controller's Personal Data unless activated or selected by the Controller.

Lexnus shall only provide AI service providers with Personal Data to the extent necessary to provide the relevant functionality and shall ensure that such providers are engaged as subprocessors in accordance with Section 9 of this DPA.

Lexnus shall not use, or permit any AI services provider to use, Personal Data processed on behalf of the Controller to train or improve any general-purpose or provider-owned artificial intelligence or machine learning models, whether for the benefit of Lexnus, the AI service provider, or any third party.

MCP AND EXTERNAL AI SERVICES

The Platform may enable the Controller to connect Lexnus to third-party artificial intelligence platforms, applications or services through a Model Context Protocol ("MCP") connector or similar integration ("External AI Services").

Where the Controller enables or uses such connections, the Controller instructs Lexnus to make data available to the External AI Service in accordance with the Controller's actions, configurations and requests made through that service.

The Controller acknowledges that External AI Services are selected and controlled by the Controller and are not subprocessors engaged by Lexnus on the Controller's behalf. Once Personal Data has been transmitted to an External AI Service at the Controller's instruction, the processing of such Personal Data by the External AI Service is subject to the Controller's agreement and arrangements with the relevant provider.

The Controller is responsible for ensuring that it has an appropriate legal basis and any necessary agreements, permissions and safeguards for disclosure and processing of Personal Data through an External AI Service. Lexnus is not responsible for the External AI Service's subsequent processing, use, retention, disclosure or protection of Personal Data transmitted to it at the Controller's instruction.

For the avoidance of doubt, Lexnus' commitment not to use, or permit its AI subprocessors to use, Personal Data to train or improve general-purpose or provider-owned artificial intelligence or machine learning models does not apply to External AI Services selected and controlled by the Controller. The Controller is responsible for determining the terms under which such External AI Services process data made available through the MCP connector or other integrations.

TYPES OF PERSONAL DATA

Name, workplace, email address, phone number (if provided), activity on contracts and IP address are processed by default in order to set up User accounts and allow usage of the Platform.

As to contracts stored in the Platform, Personal Data included therein (and thereby processed by us) may vary depending on which type of document you upload. For example, name, email address and other information about your counterparties.

Please inform us about the types of Personal Data that you intend to upload to the platform, especially if you intend to enter any special categories of Personal Data, or Personal Data relating to criminal offences, as defined in Article 9 or 10 GDPR.

CATEGORIES OF DATA SUBJECTS

Your employees, who have User accounts, will per default be affected by the processing activities. Depending on the document your contracts you upload to the Platform, other categories might be: other employees advisors and consultants, your counterparties and their representatives that are mentioned in relation to your contracts, and other persons you mention in your contracts, which are processed through the Platform.

DURATION OF THE PROCESSING.

Personal Data that we process on your behalf will be processed until deleted through the Platform, or as per your instructions.

Sub-Appendix B – Sub-processors

Essential sub-processors

Sub-processors that the Controller is not able to opt out of.

ServiceCompany NameType of processingMeans of the transferLocation
Hosting and infrastructureClever CloudHosting and infrastructure services for the Platform, including application hosting, database services and object storage. Processes Customer Content, account information and other Personal Data processed through the Platform.N/A, processing within the EEAFrance
Encrypted file replication and backupOVHcloudCross-region replication of Customer Content for redundancy and disaster recovery. Contract files are stored as sealed ciphertext.N/A, processing within the EEAGermany
Transactional emailSweegoDelivery of transactional emails and notifications. Processes recipient email addresses, names and notification content.N/A, processing within the EEAFrance / Netherlands
Monitoring and observabilityBetter StackLogging, tracing, error monitoring, session replay and status services. Processes telemetry, application usage and UI replay data.N/A, processing within the EEACzech Republic
Artificial intelligence / LLMMistral AIDefault AI/LLM provider. Processes contract text and related information as necessary to provide AI-enabled functionality within the Platform. Personal Data is not provided for the purpose of training or improving the provider's general-purpose or provider-owned AI models.N/A, processing within the EEAFrance

Optional sub-processors

Optional Subprocessors provide functionality that is activated or used at the Controller's choice.

ServiceCompany NameType of ProcessingMeans of the transferLocation
Artificial intelligence / LLMAnthropicAlternative AI/LLM provider activated at the Controller's instruction. Processes contract text and related information as necessary to provide the AI-enabled functionality requested by the Controller. Personal Data is not provided for the purpose of training or improving the provider's general-purpose or provider-owned AI models.SCCUSA
Artificial intelligence / LLMOpenAIAlternative AI/LLM provider activated at the Controller's instruction. Processes contract text and related information as necessary to provide the AI-enabled functionality requested by the Controller. Personal Data is not provided for the purpose of training or improving the provider's general-purpose or provider-owned AI models.SCCUSA
Electronic signatureScriveElectronic signature services. Processes documents and Personal Data contained in or associated with documents that the Controller elects to send for signature.N/A, processing within the EEAEurope
Collaboration integrationSlackIntegration with a Slack workspace connected by the Controller through OAuth. Processes Personal Data made available through the integration as necessary to provide the functionality requested by the Controller.