Support

Data Processing Addendum

Effective date: August 6, 2026

This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Terms of Service and, where applicable, the EULA (together, the "Agreement") between Handled. ("Handled.," "we," or "us") and the customer that accepts the Agreement ("Customer," "you," or "your"). Handled Legal Technologies, LLC, a Nevada limited liability company doing business as Handled., is referred to throughout the Agreement as "Handled." It governs Handled.'s processing of Personal Information contained in Customer's case files and related data on Customer's behalf. If there is a conflict between this DPA and the rest of the Agreement with respect to processing of Personal Information, this DPA controls. Capitalized terms not defined here have the meanings in the Agreement.

Effective date: August 6, 2026, or, if later, the date Customer accepts the Agreement.

1. Definitions

"Applicable Privacy Law" means U.S. state privacy and data-protection laws applicable to the processing under this DPA, including the California Consumer Privacy Act as amended (the "CCPA"), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, and comparable state laws.

"Personal Information" (or "Personal Data") means information within Customer Data that identifies, relates to, or could reasonably be linked with a particular individual or household, as defined by Applicable Privacy Law.

"Customer Data" means the case information and other content Customer or its authorized users enter, import, synchronize, back up, or export through the Service.

"Business," "Controller," "Service Provider," "Processor," "Contractor," "Consumer," "Sell," "Share," "Process/Processing," and "Sensitive Personal Information" have the meanings given under Applicable Privacy Law.

"Subprocessor" means a third party engaged by Handled. to process Personal Information on Handled.'s behalf in connection with the Service.

"Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Information that Handled. processes on Customer's behalf.

2. Roles of the Parties

With respect to Personal Information within Customer Data, Customer is the Business/Controller and Handled. is the Service Provider/Processor, processing solely on Customer's behalf and under Customer's documented instructions. With respect to the limited account, authentication, license, device, billing, and support information Handled. determines the purposes and means of processing for, Handled. acts as a Business/Controller under its Privacy Policy; that processing is outside the scope of this DPA. Customer is responsible for the accuracy, quality, and legality of Customer Data and for having the rights and authorizations necessary for Handled. to process it as contemplated by the Agreement.

3. Scope and Details of Processing

Subject matter: provision of the litigation case-management Service.

Duration: the term of the Agreement, plus the deletion/return periods in Section 10.

Nature and purpose: hosting, storing, transmitting, synchronizing, protecting, and otherwise processing Personal Information only as reasonably necessary to operate, secure, support, and provide the Service Customer selects, and to comply with law. For Free and Solo, case content remains in the local encrypted database on Customer devices; for Pro, Handled. additionally maintains a protected online copy that Handled. cannot read.

Types of Personal Information: as determined and supplied by Customer within case files, which may include names and contact details of clients, opposing parties, witnesses, and counsel; matter and court information; and, incidentally, categories of Sensitive Personal Information that Customer chooses to include.

Categories of individuals: Customer's clients and other individuals whose information appears in Customer's matters; Customer's authorized users.

4. Customer Instructions

Handled. will process Personal Information only: (a) on Customer's documented instructions, including as set out in the Agreement and this DPA and as given through Customer's use of the Service; and (b) as required by applicable law, in which case Handled. will, where legally permitted, inform Customer of that requirement before processing. Handled. will inform Customer if, in Handled.'s reasonable opinion, an instruction infringes Applicable Privacy Law.

5. Service-Provider / Processor Restrictions

Handled. will not, with respect to Personal Information processed on Customer's behalf:

  • Sell or Share the Personal Information;
  • retain, use, or disclose it for any purpose other than the business purposes specified in the Agreement and this DPA, including for any commercial purpose other than providing the Service, except as permitted by Applicable Privacy Law;
  • retain, use, or disclose it outside the direct business relationship between the parties;
  • combine it with personal information Handled. receives from or on behalf of any other person, or collects from its own interaction with any consumer, except as Applicable Privacy Law permits a service provider to do to perform a business purpose; or
  • use it for advertising, to train machine-learning or artificial-intelligence models, or for unrelated product development.

Handled. certifies that it understands the restrictions in this Section and will comply with them. Handled. will provide the same level of privacy protection to the Personal Information as is required of Customer by Applicable Privacy Law. Customer may take reasonable and appropriate steps under Section 9 to help ensure Handled. uses the Personal Information consistent with Customer's obligations, and to stop and remediate unauthorized use.

6. Confidentiality

Handled. will ensure that personnel authorized to process Personal Information are bound by appropriate confidentiality obligations and are informed of the confidential and, where applicable, privileged nature of the information. Because most Pro case content is protected such that Handled. cannot read it, Handled.'s personnel have no routine access to that content.

7. Security

Handled. will implement and maintain reasonable administrative, technical, and physical safeguards appropriate to the nature of the Personal Information, designed to protect it from unauthorized or unlawful access, destruction, use, modification, or disclosure. These include, as applicable: encryption of the local database using a key held in the operating-system credential store; device-side protection of Pro case content before upload, with Handled. not holding the decryption key; access controls requiring an authorized account seat and current license; and the additional measures described in the Privacy Policy.

8. Subprocessors

Customer provides general authorization for Handled. to engage Subprocessors to process Personal Information in connection with the Service. Handled.'s current Subprocessors are Supabase (authentication and storage), Lemon Squeezy (billing/merchant of record), Resend (invitation email), Netlify (website hosting), and GitHub (release-file hosting). Handled. will: (a) impose on each Subprocessor, by written contract, data-protection obligations no less protective than those in this DPA; (b) remain responsible for each Subprocessor's performance of those obligations; and (c) give Customer notice of an intended addition or replacement of a Subprocessor, by email to the account's registered email address, with a reasonable opportunity to object on reasonable data-protection grounds before the new Subprocessor begins processing Personal Information. Customer may also request the then-current Subprocessor list at any time by emailing [email protected].

9. Assistance to Customer

Taking into account the nature of the processing and the information available to Handled., Handled. will provide reasonable assistance to Customer to enable Customer to:

  • Respond to consumer/data-subject requests. Handled. will not respond to a request it receives directly from an individual regarding Personal Information Handled. processes on Customer's behalf, except to direct the individual to Customer or as Customer instructs; and Handled. will, through appropriate technical and organizational measures, help Customer access, correct, delete, or provide a portable copy of Personal Information in Handled.'s possession, to the extent Handled. is technically able (noting that Handled. cannot read protected Pro case content).
  • Meet security, breach-notification, and, where applicable, assessment obligations under Applicable Privacy Law, taking into account the information available to Handled.
  • Demonstrate compliance. Make available to Customer, on reasonable request, information reasonably necessary to demonstrate Handled.'s compliance with this DPA.

Handled. will respond in writing to a reasonable request from Customer for information necessary to demonstrate compliance with this DPA. Handled. does not currently offer an on-site audit or a formal third-party audit program; a written response to a reasonable request is Handled.'s compliance-demonstration mechanism under this DPA.

10. Return and Deletion

On termination or expiration of the Agreement, or on Customer's earlier written request, Handled. will, at Customer's choice, delete or return the Personal Information it processes on Customer's behalf, unless retention is required by law. Consistent with the Service's design and the Privacy Policy: local case information remains under Customer's control on Customer devices and is not deleted by Handled.; the protected Pro online copy and obsolete access or recovery records are deleted within 30 days after Customer leaves Pro; copies in provider backups expire through the provider's ordinary backup lifecycle; and Handled. may retain limited records for up to seven years where reasonably needed for legal, billing, tax, security, fraud-prevention, or dispute purposes or as required by law, subject to the protections of this DPA for as long as retained.

11. Security-Incident Notification

Handled. will notify Customer without undue delay after becoming aware of a Security Incident affecting Personal Information Handled. processes on Customer's behalf, and will provide information reasonably available to Handled. to help Customer meet its own notification obligations. Because Handled. cannot read protected Pro case content, a Security Incident affecting only that protected content may have limited practical impact on intelligible Personal Information; Handled. will nonetheless provide the notice this Section requires. Handled.'s notification is not an acknowledgment of fault or liability.

12. Sensitive Information and Special Categories

Customer controls whether Customer Data includes Sensitive Personal Information. Handled. processes any such information solely to provide the Service on Customer's behalf and subject to the restrictions in Section 5. Customer is responsible for determining whether its inclusion of such information, and its own handling of clients' privileged and confidential material, complies with Applicable Privacy Law and Customer's professional obligations.

13. Liability; Order of Precedence

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. This DPA does not limit any liability that Applicable Privacy Law does not permit to be limited. Except as expressly modified here, the Agreement remains in full force. This DPA controls over the rest of the Agreement only with respect to the processing of Personal Information on Customer's behalf.

14. Governing Law

This DPA is governed by the law specified in the Agreement, except that Applicable Privacy Law governs the interpretation of terms and obligations it defines, and mandatory law controls where it cannot be waived.

15. Acceptance

Customer accepts this DPA by accepting the Agreement. No separate signature is required for this DPA to be effective.