Legal
Data Processing Agreement
Effective August 11, 2026
- Version
- 2026-08-11
- SHA-256
- 3d2fc88bb5fc6e2c720b5b68783d8ace487a9f7261ea09931ca85f262e8771af
How this agreement applies
This Data Processing Agreement (the "DPA") is incorporated into the BetterDocket Terms of Service and applies automatically to every Firm that uses the Service. No signature is required. A countersigned copy is available on request at legal@betterdocket.com for Firms that need one for their vendor file.
"BetterDocket," "we," and "us" mean Product Advantage LLC, a Delaware limited liability company doing business as BetterDocket. Capitalized terms not defined here have the meaning given in the Terms.
Definitions
Customer Data — the case, client, document, message, and related content a Firm and its invited Clients submit to the Service, as defined in the Terms.
Personal Information — information within Customer Data that identifies or is reasonably capable of being associated with an individual, including a Firm's Clients and Firm Members.
Security Incident — a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Data in our systems or a subprocessor's systems. It does not include unsuccessful attempts, pings, port scans, failed log-in attempts, denial-of-service attempts, or similar events that do not compromise Customer Data.
Subprocessor — a third party we engage that processes Customer Data on our behalf.
Roles
The Firm is the controller and, where applicable, the "business" with respect to Customer Data. BetterDocket is the processor and, where applicable, the "service provider."
The Firm determines the purposes and means of processing. We process Customer Data only on the Firm's documented instructions, which consist of the Terms, this DPA, and the Firm's and its authorized users' use of the Service's features. We will notify the Firm if we believe an instruction violates applicable law, and may suspend the affected processing.
Service provider commitments (CCPA/CPRA)
BetterDocket:
- will not sell or share Customer Data as those terms are defined in the California Consumer Privacy Act;
- will not retain, use, or disclose Customer Data for any purpose other than the specific business purposes set out in the Terms and this DPA, including not for its own commercial purpose, and not outside the direct business relationship between BetterDocket and the Firm, except as permitted by the CCPA;
- will not combine Customer Data with personal information it receives from or on behalf of another person, or collects from its own interactions with a consumer, except as permitted by the CCPA;
- certifies that it understands and will comply with the restrictions in (1) through (3);
- will comply with applicable CCPA obligations and provide the same level of privacy protection required of the Firm; and
- grants the Firm the right, on notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Data.
The Firm may notify us if it determines we are using Customer Data in an unauthorized manner, and we will promptly remediate.
Other state privacy laws
Where the Firm is subject to a comparable state privacy law that uses different terminology — including the Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana laws — the parties intend for BetterDocket to act as the "processor" and for this DPA to satisfy the corresponding contractual requirements.
Subprocessors
The Firm authorizes us to engage the subprocessors below to process Customer Data. Each is bound by a written agreement imposing data-protection obligations no less protective in substance than this DPA to the extent applicable to that subprocessor's processing.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Hosted Postgres database, authentication, object storage | United States |
| Vercel | Application hosting and delivery | United States |
| Amazon Web Services (S3 Glacier Flexible Retrieval) | Cold storage of archived and pending-deletion Case packages | United States |
| Stripe | Payment processing and usage metering. Stripe acts as an independent controller for payment data. | United States |
| Resend | Transactional email delivery — recipient address and notification content only | United States |
| PostHog | Product analytics and masked session replay | United States |
| Sentry | Application error monitoring — error messages, stack traces, and normalized page addresses | United States |
| OpenAI | AI-assisted suggestion generation | United States |
PostHog configuration. Session replay is configured to mask all text and form inputs and to block images, video, canvas, frames, and embedded content. We do not intentionally transmit Case, Client, document, message, or task identifiers or user-entered content to PostHog.
Sentry configuration. Sentry receives a report when the application fails. A report carries the error message, the stack trace, and the page address with record identifiers replaced by a placeholder. Session replay is not enabled in Sentry. We do not intentionally transmit Case, Client, document, message, or task content to Sentry: request and response bodies, cookies, request headers, query strings, and the text of anything clicked or typed are removed before a report is sent. An error message produced by our own code may in principle quote a value it was processing, which is why this is described as what we do not intentionally send rather than as a guarantee.
OpenAI arrangement. We transmit limited Case information to OpenAI's API only when a user invokes an AI-assisted feature. Three controls apply to that processing:
- We have executed OpenAI's Data Processing Addendum.
- Our OpenAI organization is enrolled in Zero Data Retention. Under that arrangement OpenAI does not retain request or response content, including for abuse and misuse monitoring.
- We additionally set the no-retention flag (
store: false) on every API call, independently of the organization-level setting.
OpenAI states that it does not use data submitted through its API to train its models. Content is still transmitted to and processed by OpenAI in order to produce the output the user asked for.
These are the controls we have put in place and the commitments OpenAI has made to us. As stated in the Terms, we do not warrant a third party's conduct. A Firm that would rather not use AI-assisted features at all can contact us at support@betterdocket.com to have them disabled for the Firm's account.
Not subprocessors of Customer Data
The following are used only on our public marketing website and never receive Customer Data:
- RB2B / Retention.com — business-visitor identification on betterdocket.com marketing pages. It is not present in the firm application or the client portal.
- The internal Slack or Microsoft Teams workspace to which those visitor signals are delivered.
These are described in our privacy notice, where BetterDocket acts as a controller, and are outside the scope of this DPA.
Change notice
We will give at least thirty (30) days' notice before engaging a new subprocessor for Customer Data, by email to Firm account administrators and by updating this page. A Firm may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the Firm's exclusive remedy is to terminate the affected Service and receive a refund of prepaid, unused base fees. We may engage a replacement subprocessor immediately where necessary to maintain or restore the Service or to address a security or legal risk, with notice as soon as practicable.
Security measures
We will implement and maintain administrative, technical, and physical safeguards designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, and unauthorized disclosure or access, appropriate to the nature of the data and to our size, complexity, and stage of development. Annex A describes the measures in place as of the effective date of this DPA.
Annex A is descriptive. It describes our current implementation. It is not a warranty, a certification, or a commitment to maintain any specific control. We may change, replace, or remove individual measures as the Service, its providers, and the threat environment evolve, provided that we will not make a change that materially degrades the overall security of the Service during a Firm's subscription term. We will update Annex A when our practices materially change.
Known limitations. Annex A includes an express statement of capabilities we do not currently provide. The Firm acknowledges it has reviewed those limitations and has determined the Service is appropriate for the information it chooses to place in it.
Security incident notification
We will notify the Firm of a Security Incident affecting the Firm's Customer Data without undue delay, and in any event within five (5) business days after we confirm that a Security Incident has occurred.
Contents. The notice will include the information then reasonably available: the nature of the incident, the categories and approximate volume of Customer Data involved, the likely consequences, the measures taken or proposed, and a contact point. We will supplement as further information becomes available. An initial notice is not an acknowledgment of fault or liability.
Scope of our role. The Firm is responsible for determining whether an incident triggers any notification obligation to its clients, to individuals, to any regulator, or to any bar authority, and for making those notifications. We will not notify the Firm's clients or any regulator on the Firm's behalf, and will not do so without the Firm's prior written consent unless required by law. We will provide reasonable cooperation and information the Firm needs to meet its own obligations.
Notice address. Notice will be sent to the Firm's account administrators. The Firm is responsible for maintaining a current address and for designating a security contact if it wants notice sent elsewhere.
Audit
We do not offer on-site audits, direct inspection of our systems or facilities, or Firm-conducted penetration or vulnerability testing. Instead, on reasonable written request no more than once per twelve-month period, we will:
- provide our then-current security description (Annex A) and our published security page;
- provide the security documentation, certifications, or reports our infrastructure subprocessors make available to us and that we are permitted to share;
- complete a reasonable written security questionnaire, using our standard responses where they address the question; and
- make a knowledgeable representative available for one videoconference of up to one hour to answer questions about this DPA and Annex A.
Information provided under this section is our Confidential Information. If a Firm is required by a supervisory authority to conduct an audit we cannot accommodate, the Firm's exclusive remedy is to terminate. If we later obtain a SOC 2 Type II or comparable report, providing that report will satisfy this section in full.
Return and deletion
During the term, the Firm may export its Customer Data at any time using the Service's export features.
On termination or expiration, we will make Customer Data available for export for thirty (30) days, after which we may delete it. On the Firm's written request within that period, we will provide a machine-readable export.
The following apply during and after the term and reflect our actual implementation:
- Deleting a Case removes it from the Service immediately and stops usage charges at the next daily usage snapshot. The Case is retained as a checksum-verified cold-storage package for thirty (30) days and is then permanently destroyed, including both the cold-storage object and the underlying database records. Destruction is irreversible.
- Archiving a Case packages the Case's files into cold storage and removes them from primary storage only after a checksum-verified upload. Archived Cases remain readable to the Firm and to Clients with access. Restoring an archived or deleted Case requires retrieval from cold storage and typically takes several hours.
- Deleted documents and folders are retained in the Case's Trash for ninety (90) days and are then permanently destroyed.
- Backups and logs cycle on their own schedules and are not individually purged on request. Residual copies remain subject to the Confidentiality section until overwritten in the ordinary course.
- We may retain Customer Data where required by law or by a legal hold, and will continue to protect it under this DPA for as long as it is retained.
Certification. On written request following completion of deletion, we will provide written confirmation of deletion, subject to the residual-copy and legal-retention exceptions above.
Prohibited data
The Firm will not submit to the Service, and will instruct its Firm Members and Clients not to submit: protected health information subject to HIPAA; cardholder data or full payment-card numbers; biometric or genetic identifiers; consumer report information subject to the FCRA; classified, export-controlled, or ITAR-regulated information; information about an individual the Firm knows to be under 13; or any personal data subject to the GDPR, the UK GDPR, or comparable non-US law.
We do not maintain a HIPAA compliance program, are not a Business Associate, and will not enter a Business Associate Agreement. Our systems are not designed for, and have not been assessed against, HIPAA, PCI DSS, GLBA safeguards, CJIS, or FedRAMP. We have no liability arising from prohibited data a Firm submits, and the Firm will indemnify us against claims arising from it.
The Firm acknowledges that the Service is a general-purpose client-communication tool and that the Firm chooses what to place in it. We do not inspect, classify, or filter Customer Data for prohibited categories, and our access controls do not vary by data sensitivity. Marking a Case as restricted is an access-control feature; it is not a data-classification or encryption tier.
Geographic scope
The Service is designed for and offered to law firms established in and operating from the United States, and Customer Data is stored and processed in the United States.
We do not offer Standard Contractual Clauses, a UK International Data Transfer Addendum, an EU or UK representative under Article 27, data residency, or any GDPR-specific commitment, and we do not act as a processor under the GDPR or the UK GDPR. The Firm must not use the Service to process personal data subject to those laws. If a Firm requires GDPR terms, it should not subscribe; contact us and we will tell you honestly whether that has changed.
Confidentiality
Confidentiality of Customer Data. We will treat all Customer Data as the Firm's Confidential Information, will hold it in strict confidence, and will not access, use, or disclose it except (a) as necessary to provide, secure, and support the Service under the Terms and this DPA, (b) to subprocessors bound by written confidentiality obligations at least as protective, (c) with the Firm's direction or written consent, or (d) as required by law, subject to Compelled Disclosure below.
Standard of care. We will protect Customer Data with at least the degree of care we use for our own most sensitive confidential information, and in no event less than reasonable care.
Acknowledgment of the Firm's professional obligations. We acknowledge that Customer Data may include information relating to the representation of the Firm's clients that the Firm is obligated to protect under ABA Model Rule 1.6 and its state counterparts, including Rule 4-1.6 of the Rules Regulating The Florida Bar, and may include material protected by the attorney-client privilege or the work-product doctrine. We will not knowingly take any action that would waive, or that is intended to waive, any privilege or protection applicable to Customer Data, and the parties intend that our access to Customer Data as a service provider does not constitute a waiver of any privilege or protection.
Personnel. We will limit access to Customer Data to personnel who need it to perform under the Terms, will bind each such person to written confidentiality obligations surviving the end of their engagement, and will ensure those obligations survive termination of this DPA.
Compelled disclosure. If we receive a subpoena, court order, warrant, civil-investigative demand, or other legal process seeking Customer Data, we will, unless legally prohibited:
- promptly notify the Firm before disclosing, and in any event give the Firm a reasonable opportunity to object or to seek a protective order;
- not voluntarily produce Customer Data and, where the request is directed at the Firm's clients' information, direct the requesting party to the Firm as the appropriate custodian;
- reasonably cooperate at the Firm's expense with the Firm's lawful efforts to limit or quash; and
- disclose only the minimum required.
If prohibited from notifying, we will use lawful efforts to obtain a waiver of the prohibition.
Duration. These obligations continue for as long as we retain any Customer Data and survive termination indefinitely with respect to Customer Data, notwithstanding any general confidentiality term elsewhere in the Terms.
Individual rights requests
Taking into account the nature of the processing, we will provide reasonable assistance to the Firm in responding to a verifiable request from an individual, primarily through the Service's self-service export and deletion features.
We will not respond directly to a request from a Firm's Client or a Firm Member regarding Customer Data. We will refer the requester to the Firm unless required by law.
General
Order of precedence. This DPA controls over the Terms as to the processing of Customer Data only. In all other respects the Terms control.
Liability. Each party's liability under this DPA is subject to the exclusions and limitations in the Terms, and all claims under the Terms and this DPA are aggregated under a single cap.
Term. This DPA is coterminous with the Terms and continues for as long as we retain Customer Data.
Governing law and disputes. As stated in the Terms.
Changes. We may update this DPA as our practices and providers change. Every published version remains available at its own permanent address together with the SHA-256 hash of its text. Material changes follow the notice process in the Terms.
Annex A — Security measures as of August 7, 2026
This annex is a description of our current implementation, not a warranty. It mirrors our public security page and carries the same limitations without softening them.
Measures in place
- Encryption in transit. The Service is served over HTTPS/TLS in production.
- Encryption at rest. Our hosted infrastructure providers state that they encrypt data stored on their platforms. This is their representation, not an independently verified control of ours.
- Authenticated product access. Firm and client application access requires an authenticated account. API access tokens are verified before we build the user's firm or client context.
- Database-level authorization. Row-level security policies scope product reads and writes to the relevant Firm, Client, and Case relationships. Restricted Cases limit firm-side access to assigned Firm Members plus firm owners and admins.
- Document storage. Case documents are stored in a private bucket, and storage policies apply the same Case access checks used for application data. Firm logos are intentionally public so they can appear in client emails.
- Server-side credentials. Privileged service credentials are kept on the API server rather than shipped to browsers or native applications. Automated services use them for limited operational functions such as invitations, subscriptions, webhooks, and scheduled jobs.
- Activity records. We record activity events for many material product changes. These records support product history and accountability, but they are not a comprehensive log of every application or infrastructure action.
- Cold-storage integrity. Case packages written to cold storage are verified by checksum before the primary copies are removed.
- Production access. At present, one BetterDocket operator has direct privileged access to the production database, through an individual account protected by multi-factor authentication.
- AI provider retention. OpenAI processing is covered by an executed Data Processing Addendum and by Zero Data Retention, and every API call additionally carries the no-retention flag. See the OpenAI arrangement above.
Capabilities we do not currently provide
- No completed SOC 2 or ISO certification, and no formal, independently audited security program.
- No completed independent application penetration test.
- No HIPAA compliance program and no Business Associate Agreements.
- No multi-factor authentication for firm or client product accounts.
- No end-to-end encryption. Authorized application services, the operator described above, and infrastructure providers can process data when necessary to provide the Service.
- No contractual uptime commitment and no guarantee of uninterrupted availability or recovery.
- No published fixed retention schedule covering every category of product data beyond the timelines stated in Return and Deletion above.
- No data residency, sovereign storage, or region selection.
No internet transmission, storage system, or access control can guarantee complete security. These practices reduce risk; they do not eliminate it.
Contact
Security questions and vulnerability reports: security@betterdocket.com. Please do not include passwords or sensitive Case content in an initial email.
Previous versions
- Data Processing Agreement — effective August 26, 2026
- Data Processing Agreement — effective August 19, 2026
- Data Processing Agreement — effective August 17, 2026
- Data Processing Agreement — effective August 16, 2026
- Data Processing Agreement — effective August 12, 2026
- Data Processing Agreement — effective August 9, 2026
- Data Processing Agreement — effective August 7, 2026