Data Processing Agreement

Last updated: July 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Attest Law (“Attest”) and the law firm that uses the services (“Firm”). It governs our handling of the client case data the Firm entrusts to us. Where this DPA conflicts with the Terms, this DPA controls for matters of data protection.

1. Roles

The Firm determines the purposes and means of processing its client case data and is the controller of that data. Attest is a processor and, for purposes of the California Consumer Privacy Act as amended (“CCPA”), a service provider. The Firm remains responsible for its own professional and ethical obligations to its clients, including confidentiality and privilege.

2. Scope of processing

We process Firm data only to provide the services and only on the Firm’s documented instructions, which include the Terms, this DPA, and the Firm’s use of product features. The subject matter is the provision of immigration casework software; the duration is the term of the Firm’s account; the data subjects are the Firm’s personnel and its clients; and the data includes case documents, questionnaire responses, contact details, and immigration matter details.

3. Service provider restrictions

We will not sell or share Firm data as those terms are defined by the CCPA. We will not retain, use, or disclose Firm data for any purpose other than performing the services, and specifically not for our own commercial purposes, not outside the direct business relationship with the Firm, and not by combining Firm data with data from another source except as permitted for a service provider. We certify that we understand and will comply with these restrictions.

4. No AI training

Firm data is not used to train, fine-tune, or otherwise improve any artificial intelligence model, whether ours or a third party’s. Content sent to a model provider is processed to answer the request in front of it and is not retained by that provider for model improvement.

5. Confidentiality

We treat Firm data as confidential. Personnel with access are bound by confidentiality obligations, and access is limited to those who need it to operate or support the services. We recognize that Firm data may be subject to attorney-client privilege and the work-product doctrine, and our handling of it is not intended to waive either.

6. Security

We maintain technical and organizational measures appropriate to the sensitivity of the data, including encryption in transit and at rest, per-firm isolation enforced at the database level, hashed portal-link and API-key storage, and an append-only audit log of uploads, AI runs, and approvals. Our current practices are described on our security page.

7. Subprocessors

The Firm authorizes us to engage the subprocessors named on our subprocessor list. Each subprocessor is bound by written terms no less protective than this DPA for the data it handles. We will update that list before a new subprocessor begins processing Firm data, and we remain responsible for our subprocessors’ performance.

8. Security incidents

We will notify the Firm without undue delay after becoming aware of a breach of security leading to the unauthorized disclosure of, or access to, Firm data. The notice will describe what we know, what we are doing about it, and what the Firm may need to do — including what the Firm needs in order to meet its own notification obligations. We will cooperate with the Firm’s reasonable investigation.

9. Assistance and data subject requests

If we receive a request from an individual about data we process for the Firm, we will not respond to it directly except to direct the requester to the Firm, and we will pass the request along. We will provide reasonable assistance to the Firm in responding, including through the access, export, and deletion tools in the product.

10. Return and deletion

The Firm may export its data at any time during the term. On termination, or on request, we delete Firm data from primary systems promptly and from backups on a fixed schedule, except where retention is required by law. Deletion requests can be sent to [email protected].

11. Location of processing

Firm data is processed in the United States. We do not currently offer processing in other regions. If the Firm requires terms for international transfers, contact us before sending data that would depend on them.

12. Audit and diligence

On reasonable request, and no more than once a year absent a security incident, we will provide the information reasonably necessary for the Firm to confirm our compliance with this DPA — including answering a security questionnaire. A SOC 2 program is planned; we will make the report available when we have one rather than implying we have one now.

13. Changes

If we materially change this DPA, we will provide notice through the services or by email before it takes effect.

14. Contact

To request a countersigned copy of this DPA, or to raise a data protection question, write to [email protected] or send us your questionnaire.