Last updated September 13, 2026
1. Scope and roles
This Data Processing Addendum (DPA) applies where YourLegalAid processes personal information on behalf of a subscriber or organizational customer (Controller) in providing the Services. Controller determines the purposes and means of processing Controller Personal Information. YourLegalAid acts as Processor for that processing and follows documented Controller instructions except where applicable law requires otherwise.
Activities performed by YourLegalAid for its own independent purposes—such as billing, fraud prevention, account administration, legal compliance, and defence of legal claims—are outside the processor role to the extent YourLegalAid independently determines those purposes and applicable law permits the processing.
Product improvement is not automatically treated as processor activity. Reuse of Controller Personal Information for product improvement, model training, fine-tuning, evaluation, or other independent purposes requires a separate lawful basis and must not contradict the governing agreement, Privacy Policy, or enterprise commitments.
2. Processing instructions
YourLegalAid will:
- process Controller Personal Information only to provide the Services and perform documented instructions;
- notify Controller if, in YourLegalAid's reasonable view, an instruction would violate applicable privacy law, unless law prohibits that notice;
- ensure personnel authorized to process Controller Personal Information are bound by confidentiality obligations; and
- not sell Controller Personal Information or use it for unrelated advertising purposes.
3. Security
YourLegalAid will maintain administrative, technical, and organizational safeguards appropriate to the sensitivity, volume, context, and risks of the processing. Specific controls—such as encryption standards, MFA coverage, penetration-testing frequency, certifications, monitoring, and vulnerability management—are contractual commitments only where they have been verified and stated in an applicable Security Schedule or agreement.
4. Security incidents
A Security Incident means unauthorized access to, acquisition of, disclosure of, alteration of, loss of, or destruction of Controller Personal Information that triggers response obligations under the agreement or applicable law. YourLegalAid will notify Controller without undue delay after confirming a Security Incident affecting Controller Personal Information and will provide reasonably available information to assist Controller with its legal obligations.
No fixed 24-hour notification commitment applies unless expressly stated in an executed agreement that is supported by the operational incident-response process.
5. Service providers and subprocessors
Controller authorizes YourLegalAid to use service providers necessary to provide the Services, subject to this DPA and any notice or objection process in the applicable enterprise agreement. YourLegalAid will impose data-protection obligations appropriate to the services they perform. The public Service Provider list identifies currently verified integrations; a customer-specific subprocessor schedule may supplement that list.
6. Cross-border processing
Where Controller Personal Information is processed outside the province or country in which it was collected, YourLegalAid will implement safeguards required by applicable law, including contractual measures and privacy-impact assessments where required. For Quebec personal information, applicable cross-border assessment requirements will be addressed before the transfer where required by law.
7. Data-subject requests
Taking into account the nature of the processing, YourLegalAid will provide reasonable assistance to Controller in responding to valid privacy-rights requests where the relevant information is processed on Controller's behalf and Controller cannot reasonably fulfil the request without that assistance. If YourLegalAid receives a request relating primarily to Controller Personal Information, it may refer the requester to Controller unless law requires otherwise.
8. Retention, return, and deletion
Controller Personal Information will be retained only as necessary to provide the Services and satisfy documented legal, security, backup, and dispute-preservation requirements. At termination, and subject to applicable law and agreed backup cycles, YourLegalAid will delete or return Controller Personal Information as specified in the applicable agreement or documented Controller instruction.
Data in backups may remain until the applicable backup rotation expires, provided it is protected from ordinary production use and deleted or overwritten in the normal cycle.
9. Audit and compliance information
On reasonable written request, YourLegalAid will provide information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, and privilege restrictions. Any contractually permitted audit must be proportionate, coordinated to minimize disruption, and subject to reasonable security and confidentiality requirements. Cost allocation is governed by the applicable agreement and law.
10. Liability and priority
Liability under this DPA is subject to the liability provisions of the governing agreement unless that agreement expressly states otherwise or applicable law prohibits the limitation. If this DPA conflicts with the governing agreement on processing of Controller Personal Information, this DPA controls to the extent of that conflict.
Schedule 1 — Processing details
Subject matter
Provision of the YourLegalAid software, legal-information, document, research, AI-enabled, collaboration, and related support services selected by Controller.
Duration
For the term of the applicable agreement, plus any limited retention period necessary for deletion, backup rotation, legal compliance, or dispute preservation.
Nature and purpose
Processing may include collection, receipt, hosting, storage, organization, retrieval, transmission, generation, transformation, analysis, deletion, and support activities necessary to provide the contracted Services.
Categories of data subjects
- Controller personnel and authorized users;
- clients or prospective clients of Controller;
- parties, witnesses, and other persons referenced in legal matters;
- landlords, tenants, applicants, or respondents;
- individuals referenced in uploaded documents or public records; and
- support contacts and administrators.
Categories of personal information
- identity and contact information;
- account and authentication information;
- legal-matter facts and procedural information;
- uploaded document contents;
- correspondence and notes;
- immigration or employment information;
- public-record information;
- support communications and device/security logs; and
- other information intentionally submitted by Controller or its users.
Sensitive information
Controller determines whether it will submit sensitive information. Possible categories include legal allegations, immigration information, financial information, government identifiers, health information, information about minors, and other highly sensitive personal information.
Service-specific details
Processing locations, retention and deletion rules, active subprocessors, and any restrictions on AI processing, training or reuse, data location, export, logging, or support access must be specified in the applicable agreement, order form, security schedule, or written instructions accepted by YourLegalAid.
Contact
Use the Contact page for DPA or enterprise privacy enquiries. See the Privacy Policy and Legal Centre for related documents.