Data Processing Addendum

Effective Date: 2026-07-04

This Data Processing Addendum ("DPA") is incorporated into the BriefBank Terms of Service (Terms §3.1) and applies whenever Juris Intelligence, Inc. ("Company") processes Customer Personal Data on a customer's behalf. For self-serve customers it takes effect on acceptance of the Terms; no separate signature is required. Where the Terms and this DPA conflict as to Personal Data, this DPA controls.

1. Roles and scope

"Customer Personal Data" means Personal Data contained in Customer Content or Derived Data processed on Customer's behalf. Customer is the controller/business; Company is the processor/service provider/contractor (a subprocessor if Customer is itself a processor). Company-controlled account, billing, support, usage, and legal records are governed by the Privacy Policy, not this DPA.

2. Processing instructions

Company will process Customer Personal Data only to provide, secure, support, and operate BriefBank, on Customer's documented instructions (the Terms, product settings, AI-feature use, and this DPA) and applicable law. Company will not train or fine-tune AI models on Customer Personal Data.

3. Confidentiality and security

Personnel authorized to process Customer Personal Data are subject to confidentiality obligations. Company maintains the technical and organizational measures in Annex II and the Security Overview.

4. Subprocessors

Customer grants general authorization to use the subprocessors in the Subprocessor List. Company imposes written data-protection terms on subprocessors consistent with this DPA, remains responsible for their processing, and provides at least 30 days' advance notice of new subprocessors with an objection right (Terms §3.5).

5. Data-subject requests and assistance

Company will reasonably assist Customer with data-subject requests, security obligations, DPIAs, and prior consultations, taking into account the nature of processing and information available to Company. Company may redirect a requester who contacts it directly to Customer.

6. Security incidents

Company will notify Customer of a confirmed personal-data breach involving Customer Personal Data without undue delay, in accordance with Terms §3.7, with information reasonably available to support Customer's obligations.

7. Deletion or return

Upon Customer request or termination, Company will delete Customer Personal Data unless legally required to retain it. Paid-tier deletion requests complete within 30 days; Free-tier account closure triggers prompt deletion. Deletion purges associated database rows and embeddings (original uploaded file bytes are not retained); backups follow the ordinary cycle. Export/return is provided where the Service offers it or as separately agreed.

8. Audits and information

Company will make available information reasonably necessary to demonstrate compliance (the Security Overview, subprocessor information, and reasonable questionnaire responses). Any audit must be reasonable, on advance notice, under confidentiality, and must not compromise other customers, security, or trade secrets.

9. CPRA service-provider/contractor terms

Company will not: sell or share Customer Personal Data; retain, use, or disclose it outside the business purposes in the Agreement; retain, use, or disclose it for a commercial purpose other than providing BriefBank; or combine it with personal data from other sources except as CPRA permits. Company certifies it understands and will comply with these restrictions and will notify Customer if it can no longer comply. Customer may take reasonable steps to stop and remediate unauthorized processing.

10. International transfers

BriefBank is currently offered to customers in the United States only, and Customer Content is stored at rest in the United States. This DPA does not presently rely on EU Standard Contractual Clauses or the UK IDTA because Company does not offer the Service in the EEA or UK.

If Company makes the Service available to EEA or UK customers in the future, the EU Standard Contractual Clauses (Module Two where Customer is controller and Company is processor; Module Three where Customer is a processor and Company is subprocessor, with Clause 9 general written authorization and 30 days' notice) and the UK IDTA or UK Addendum, as appropriate, will be incorporated by an updated version of this DPA before such availability, with Annexes I–III below serving as the SCC Annexes. Onward transfers to subprocessors use appropriate safeguards.

11. Order of precedence

For Customer Personal Data, this DPA controls over conflicting Terms provisions (consistent with Terms §15.2). The Terms otherwise remain in effect.


Annex I — Processing details

Annex II — Security measures

Encryption in transit and at rest; dual-database row-level security keyed on org_id; managed-identity/AAD service authentication; fail-closed authorization; Azure Key Vault for secrets; audit logging; least-privilege access; subprocessor DPAs and diligence; event-driven deletion of database rows and embeddings (original uploaded file bytes are not retained); and incident notification per Terms §3.7. See the Security Overview.

Annex III — Subprocessors

The current Subprocessor List, incorporated by reference.