DATA PROCESSING AGREEMENT
Addendum to the Initio Terms of Service
Slipstream Automation LLC
Effective Date: August 31, 2026
1. Parties and Recitals
This Data Processing Agreement ("DPA") is entered into by and between:
Data Controller ("Controller"): The subscribing attorney or law firm identified in the Initio Terms of Service (the "Subscriber").
Data Processor ("Processor"): Slipstream Automation LLC, an Oregon limited liability company, operator of the Initio client intake automation platform.
RECITALS
WHEREAS, the Controller has subscribed to the Initio client intake automation platform (the "Service") pursuant to the Terms of Service;
WHEREAS, in the course of providing the Service, the Processor will process Personal Information on behalf of the Controller;
WHEREAS, the parties wish to ensure that such processing is conducted in compliance with Applicable Law, including the Oregon Consumer Privacy Act (OCPA), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and the General Data Protection Regulation (GDPR) to the extent applicable; and
WHEREAS, this DPA sets forth the parties' obligations with respect to the processing of Personal Information in connection with the Service;
NOW, THEREFORE, in consideration of the mutual obligations set forth herein, the parties agree as follows:
2. Definitions
Capitalized terms used in this DPA have the meanings assigned to them in the Initio Terms of Service and Privacy Policy, unless otherwise defined herein. Additional definitions:
"Data Breach" means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Information transmitted, stored, or otherwise processed by the Processor or its Sub-Processors.
"Data Subject" means the identified or identifiable natural person to whom Personal Information relates, including End-Clients and Recorded Parties.
"Documented Instructions" means the processing instructions provided by the Controller to the Processor as set forth in this DPA, the Terms of Service, and any subsequent written instructions agreed upon by both parties.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to processors established in third countries, as adopted by the European Commission or other competent authority.
"Technical and Organizational Measures" or "TOMs" means the security measures implemented by the Processor to protect Personal Information, as described in Annex B.
3. Scope and Purpose of Processing
3.1 Scope
This DPA applies to all processing of Personal Information carried out by the Processor on behalf of the Controller in connection with the provision of the Service.
3.2 Purpose of Processing
The Processor shall process Personal Information solely for the following purposes: (a) to provide the Service as described in the Terms of Service; (b) to automate client intake workflows, including lead capture, communication sequencing, appointment scheduling, payment processing, document generation, and data collection on behalf of the Controller; (c) to generate AI-powered communications (including automatically sent inquiry response emails) and intake analysis summaries on behalf of the Controller using third-party artificial intelligence services (currently Anthropic's Claude); (d) to generate engagement letters and related legal documents on behalf of the Controller using third-party document automation services (currently PandaDoc); (e) to transmit Personal Information to and from the Controller's designated Sub-Processors as necessary to perform the Service; (f) to comply with Applicable Law; and (g) to screen the names of prospective End-Clients against the Recorded Parties associated with the Controller, in order to identify potential conflicts of interest for the Controller's review.
3.3 Categories of Data Subjects
The categories of Data Subjects whose Personal Information is processed under this DPA include: (a) prospective clients of the Controller who initiate the intake process; (b) current clients of the Controller whose information is processed through the Service; and (c) Recorded Parties — individuals whom the Controller records in or uploads to the Service for conflict-screening purposes. Recorded Parties may include individuals who have never interacted with the Service and have no relationship with the Processor, including the Controller's former clients and parties adverse to the Controller's clients.
3.4 Types of Personal Information
The types of Personal Information processed under this DPA are set forth in Annex A and include, without limitation: full name, email address, phone number, mailing address, date of birth, marital status, spouse and dependent information, legal matter descriptions, financial information, health and medical information, electronic signature data, and information specific to the Data Subject's case type and the Controller's practice area.
For a Recorded Party, in that capacity, the only Personal Information processed is Recorded Party Information as defined in the Terms of Service: the party's name, a normalized form of that name used for matching, a role, an optional relationship label, and internal references recording how the record entered the Service. No contact details, legal matter descriptions, financial information, health information, or other special-category information is processed about a Recorded Party in that capacity.
3.5 Duration
Processing shall continue for the duration of the Controller's subscription to the Service and for the period necessary to complete data retrieval and deletion in accordance with Section 11 of this DPA and Section 14 of the Terms of Service.
4. Obligations of the Processor
4.1 Processing on Documented Instructions
The Processor shall process Personal Information only on the basis of the Controller's Documented Instructions, unless required to do otherwise by Applicable Law. If Applicable Law requires processing beyond the Controller's instructions, the Processor shall inform the Controller of that requirement before processing, unless the law prohibits such notification on important grounds of public interest.
4.2 Confidentiality
The Processor shall ensure that all personnel authorized to process Personal Information have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. The Processor shall not disclose Personal Information to any third party except as authorized by this DPA, the Terms of Service, or the Controller's written instructions.
4.3 Security
The Processor shall implement and maintain the Technical and Organizational Measures described in Annex B. The Processor shall regularly assess the effectiveness of these measures and update them as necessary to ensure an appropriate level of security, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risk to the rights and freedoms of Data Subjects.
4.4 Sub-Processor Management
The Processor's obligations regarding Sub-Processors are set forth in Section 5 of this DPA.
4.5 Cooperation with Data Subject Requests
The Processor shall, taking into account the nature of the processing, assist the Controller by implementing appropriate technical and organizational measures, insofar as possible, for the fulfilment of the Controller's obligation to respond to requests from Data Subjects exercising their rights under Applicable Law, as further detailed in Section 8.
4.6 Assistance with Compliance
The Processor shall assist the Controller in ensuring compliance with the Controller's obligations regarding security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of processing and the information available to the Processor.
4.7 Deletion and Return
Upon termination of the Service and following the Data Retrieval Period specified in the Terms of Service, the Processor shall, at the Controller's choice, delete or return all Personal Information to the Controller, and delete existing copies unless Applicable Law requires retention or one of the exceptions in Sections 11.4 through 11.6 applies. The Processor shall certify in writing that deletion has been completed upon the Controller's request.
4.8 Audit Rights
The Processor's obligations regarding audits are set forth in Section 10 of this DPA.
5. Sub-Processor Management
5.1 Approved Sub-Processors
The Controller hereby provides general written authorization for the Processor to engage Sub-Processors for the processing of Personal Information. The current list of approved Sub-Processors is set forth in Annex C.
5.2 Obligations Imposed on Sub-Processors
The Processor shall: (a) impose data protection obligations on each Sub-Processor by way of a written agreement that provides at least the same level of protection as this DPA; (b) remain fully liable to the Controller for the performance of each Sub-Processor's obligations; and (c) conduct reasonable due diligence on each Sub-Processor's data protection practices.
5.3 Notification of Changes
The Processor shall notify the Controller via email at least thirty (30) days prior to engaging any new Sub-Processor or replacing an existing Sub-Processor. The notification shall include the name of the Sub-Processor, the processing activities to be performed, and the location of processing.
5.4 Right to Object
The Controller may object to the engagement of a new or replacement Sub-Processor by providing written notice to the Processor within fifteen (15) days of receiving the notification described in Section 5.3. If the Controller objects on reasonable grounds, the parties shall negotiate in good faith to resolve the objection. If the parties are unable to resolve the objection within thirty (30) days, the Controller may terminate the subscription in accordance with Section 14 of the Terms of Service as its sole remedy.
5.5 AI Sub-Processing
The Processor engages Anthropic (Claude API) to perform automated text analysis and content generation as part of the Service. Data transmitted to Anthropic includes inquiry text and intake form submissions, which may contain sensitive Personal Information including legal matter details, financial information, family information, and health information. AI processing is performed solely to generate the automated inquiry response email that the Service sends to the prospective End-Client on the Controller's behalf, and to generate intake analysis summaries for the Controller's review. The Processor has confirmed that, under Anthropic's Commercial Terms of Service, prompts and responses submitted through the API are not used to train Anthropic's models. Under Anthropic's published data-retention terms for commercial API use, inputs and outputs are deleted from Anthropic's systems within thirty (30) days by default, except where longer retention is required to enforce Anthropic's usage policy or to comply with legal obligations. The Processor shall notify the Controller promptly if the AI provider's data use terms change in a manner that materially affects the processing of Personal Information.
6. Data Security Measures
The Processor shall implement and maintain the Technical and Organizational Measures (TOMs) described in Annex B. These measures are designed to protect Personal Information against Data Breaches and to ensure a level of security appropriate to the risk, taking into account:
- (a)The state of the art of available security technologies;
- (b)The costs of implementing security measures;
- (c)The nature, scope, context, and purposes of processing;
- (d)The risk of varying likelihood and severity for the rights and freedoms of Data Subjects; and
- (e)The sensitivity of the Personal Information processed, including the potential presence of legally privileged information and health-related information.
The Processor shall review and update the TOMs periodically and upon the occurrence of any material change in the processing activities or risk environment.
7. Data Breach Procedures
7.1 Detection and Investigation
The Processor shall implement reasonable measures to detect Data Breaches promptly. Upon becoming aware of a suspected or confirmed Data Breach, the Processor shall immediately investigate the incident to determine its nature, scope, and potential impact.
7.2 Notification
The Processor shall notify the Controller of any confirmed Data Breach without undue delay and in any event within seventy-two (72) hours of becoming aware of the breach. The notification shall include, to the extent known at the time:
- (a)A description of the nature of the Data Breach, including the categories and approximate number of Data Subjects and Personal Information records affected;
- (b)The name and contact details of the Processor's point of contact;
- (c)A description of the likely consequences of the Data Breach;
- (d)A description of the measures taken or proposed to be taken to address the Data Breach, including measures to mitigate its adverse effects; and
- (e)Any other information required by Applicable Law.
7.3 Ongoing Cooperation
Following the initial notification, the Processor shall: (a) continue to investigate the Data Breach and provide supplemental information as it becomes available; (b) cooperate with the Controller in complying with any breach notification obligations under Applicable Law; (c) take all reasonable steps to contain and remediate the Data Breach; and (d) preserve evidence related to the Data Breach for potential regulatory or legal proceedings.
7.4 No Unauthorized Notifications
The Processor shall not notify any third party, regulatory authority, or Data Subject of a Data Breach without the prior written consent of the Controller, except where required to do so by Applicable Law. In such cases, the Processor shall inform the Controller of the legal requirement and provide the Controller with a copy of the notification before it is issued, to the extent practicable.
8. Data Subject Rights
8.1 Processor's Obligations
The Processor shall, taking into account the nature of the processing, assist the Controller by implementing appropriate technical and organizational measures for the fulfilment of the Controller's obligation to respond to Data Subject requests exercising their rights under Applicable Law, including rights of access, rectification, erasure, restriction, portability, and objection.
8.2 Forwarding Requests
If the Processor receives a request directly from a Data Subject regarding Personal Information processed under this DPA, the Processor shall promptly forward the request to the Controller and shall not respond to the Data Subject directly without the Controller's prior written authorization, unless required by Applicable Law.
8.3 Technical Capabilities
The Processor shall maintain the capability to search, export, correct, and delete specific Data Subject records within its systems and shall assist the Controller in fulfilling Data Subject requests within ten (10) business days of receiving the Controller's instruction. As of the Effective Date these operations are performed manually by Processor personnel; the Processor does not provide a self-service export, correction, or deletion interface, and the ten-business-day commitment reflects an operational undertaking rather than an automated one.
8.4 Costs
If the Processor incurs material costs in assisting the Controller with Data Subject requests beyond what is reasonably required for the initial response, the parties shall agree in good faith on the allocation of such costs before proceeding.
9. Cross-Border Data Transfers
9.1 General Principle
The Processor shall not transfer Personal Information to a country or territory outside the United States without ensuring that adequate safeguards are in place, as required by Applicable Law.
9.2 Transfer Mechanisms
Where Personal Information is transferred outside the United States (including transfers to Sub-Processors located in or processing data in third countries), the Processor shall implement appropriate transfer mechanisms, which may include: (a) Standard Contractual Clauses adopted by the European Commission; (b) adequacy determinations; (c) binding corporate rules; or (d) other transfer mechanisms recognized under Applicable Law.
9.3 Notification
The Processor shall notify the Controller prior to any new cross-border transfer of Personal Information not previously identified in Annex C and shall provide the Controller with information regarding the transfer mechanism and safeguards in place.
10. Audit Rights
10.1 Right to Audit
The Controller shall have the right to verify the Processor's compliance with this DPA. The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance and shall allow for and contribute to audits, including inspections, conducted by the Controller or an independent auditor mandated by the Controller.
10.2 Audit Procedures
Audits shall be conducted: (a) upon reasonable written notice of at least thirty (30) days; (b) during normal business hours; (c) no more frequently than once per twelve (12) month period, unless a Data Breach has occurred or the Controller has reasonable grounds to believe the Processor is not in compliance with this DPA; and (d) in a manner that does not unreasonably disrupt the Processor's business operations.
10.3 Third-Party Certifications
The Processor may satisfy audit requests by providing the Controller with: (a) relevant third-party audit reports or certifications (such as SOC 2 Type II or ISO 27001), to the extent available; (b) written responses to the Controller's reasonable compliance questionnaires; or (c) summaries of the Processor's security testing and assessment results, provided that such alternatives reasonably demonstrate compliance with this DPA.
As of the Effective Date, the Processor does not hold SOC 2 Type II, ISO 27001, or equivalent third-party certifications. The Processor relies on the security certifications maintained by its Sub-Processors (as noted in Annex C) and its own Technical and Organizational Measures (Annex B) to demonstrate compliance. The Processor will notify the Controller if and when third-party certifications are obtained.
10.4 Costs
Each party shall bear its own costs in connection with audits. If an audit reveals material non-compliance by the Processor, the Processor shall bear the reasonable costs of the audit and shall promptly remediate the non-compliance at its own expense.
11. Term and Termination
11.1 Effective Date
This DPA shall become effective on the date the Controller first subscribes to the Service and shall remain in effect for the duration of the Controller's subscription, plus the period necessary to complete data retrieval and deletion as described herein.
11.2 Termination
This DPA shall terminate automatically upon termination of the Terms of Service. Sections 2, 4.2, 4.7, 7, 10, 11.4, 11.5, 11.6, and 12 shall survive termination.
11.3 Data Return and Deletion
Upon termination of the Controller's subscription: (a) the Controller shall have thirty (30) days to request retrieval of Personal Information by contacting the Processor at admin@slipstream.works (the "Data Retrieval Period"); (b) the Processor shall provide the data in a machine-readable format (JSON for structured data; original format for documents stored in S3), assembled manually by Processor personnel; (c) following the Data Retrieval Period, the Processor shall initiate deletion of all Personal Information from its systems and Sub-Processors' systems; (d) deletion shall be completed within thirty (30) days of initiation; and (e) the Processor shall, upon request, provide written certification of deletion. Deletion under this Section is subject to the exceptions in Sections 11.4 (legal retention), 11.5 (refund-ban identifiers), and 11.6 (deferred Sub-Processor cleanup).
The Processor does not operate an automated retention or deletion process as of the Effective Date; deletion is initiated and tracked manually by Processor personnel upon the Controller's request.
11.4 Exceptions to Deletion
The Processor may retain Personal Information to the extent and for the duration required by Applicable Law, provided that the Processor: (a) limits processing of such retained data to the purposes required by law; (b) maintains the confidentiality and security of such data; and (c) deletes the data promptly upon expiration of the legal retention requirement. Payment records may be retained for up to seven (7) years to satisfy tax and accounting obligations.
11.5 Identifiers Retained After Refund
The Service provides a sixty (60) day money-back guarantee under which an eligible Controller's firm may receive a refund of subscription fees. Where a refund is approved, the Controller's subscription is terminated and all attorney user accounts on the firm are deactivated, but the Controller's firm record is not deleted: it is preserved as a tombstone, marked refund-banned, to enforce the prohibition on re-subscription after a refund. All End-Client Data continues to be deleted in accordance with Section 11.3; the preserved record relates to the Controller (the Subscriber), not to any End-Client.
Following deletion of End-Client Data under Section 11.3, the Processor retains, indefinitely, a minimal set of identifiers associated with the original subscription: (a) the email address of the firm owner; (b) the authentication-account identifier issued to the firm owner by the Processor's authentication Sub-Processor (Clerk); and (c) the firm record itself, marked as refund-banned. The Processor uses these identifiers solely to enforce the one-refund-per-firm prohibition and does not use them to contact the former firm owner, deliver marketing communications, or for any other purpose. The Processor's position is that this retention is permitted under the enforcement-of-agreement and dispute-resolution exceptions to deletion recognized under the Oregon Consumer Privacy Act and the CCPA/CPRA. This behavior is described in further detail in Section 9.5 of the Privacy Policy.
11.6 Deferred Sub-Processor Cleanup
As of the Effective Date, the deletion process under Section 11.3 covers Personal Information stored in the Processor's primary data systems (Supabase, Amazon S3) and Sub-Processors the Processor can deprovision through an automated pathway. The following Sub-Processor data is not auto-deleted on subscription termination and is cleaned up manually on a deferred basis: (a) the Controller's scheduling user account and any associated appointment records held in the Processor's self-hosted Cal.com instance; and (b) the Controller's partner account and any associated payment records held by Confido Legal. The Processor will deprovision both on written request to admin@slipstream.works as part of the Section 11.3 deletion process. This behavior is described in further detail in Section 9.6 of the Privacy Policy.
12. Liability
12.1 General
The liability of each party under this DPA shall be subject to the limitations of liability set forth in the Terms of Service, except as provided in Section 12.2.
12.2 Carve-Outs
The limitation of liability set forth in Section 12 of the Terms of Service shall not apply to: (a) the Processor's breach of its obligations under Section 4.2 (Confidentiality) of this DPA; (b) the Processor's breach of Section 7 (Data Breach Procedures) of this DPA; (c) the Processor's indemnification obligations under Section 13.2 of the Terms of Service; or (d) damages arising from the Processor's gross negligence or willful misconduct in connection with the processing of Personal Information.
12.3 Allocation
Each party shall be liable for damages caused by processing that violates its obligations under this DPA or Applicable Law. The Processor shall be liable for damages caused by processing that does not comply with the Controller's Documented Instructions or this DPA, except to the extent that the Processor demonstrates it is not in any way responsible for the event giving rise to the damage.
13. CCPA Service Provider Provisions
To the extent that the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), applies to the processing of Personal Information under this DPA, the following provisions shall apply:
- (a)The Processor is a "service provider" as defined under the CCPA/CPRA with respect to Personal Information processed on behalf of the Controller.
- (b)The Processor shall not sell or share (as those terms are defined under the CCPA/CPRA) Personal Information received from the Controller.
- (c)The Processor shall not retain, use, or disclose Personal Information for any purpose other than the business purposes specified in this DPA and the Terms of Service, or as otherwise permitted by the CCPA/CPRA.
- (d)The Processor shall not combine Personal Information received from the Controller with Personal Information received from or on behalf of another person or entity, or collected from the Processor's own interaction with Data Subjects, except as expressly permitted by the CCPA/CPRA for the performance of the business purposes specified in this DPA.
- (e)The Processor shall comply with the CCPA/CPRA and shall provide the same level of privacy protection for Personal Information as is required by the CCPA/CPRA.
- (f)The Processor shall notify the Controller if it determines that it can no longer meet its obligations under the CCPA/CPRA.
- (g)The Controller shall have the right to take reasonable and appropriate steps to ensure that the Processor uses Personal Information in a manner consistent with the Controller's obligations under the CCPA/CPRA, including the audit rights set forth in Section 10.
Annex A: Details of Processing
A.1 Categories of Data Subjects
- (a)Prospective clients of the Controller who initiate the client intake process through the Service.
- (b)Current clients of the Controller whose information is processed through the Service.
- (c)Recorded Parties — individuals whom the Controller records in or uploads to the Service for conflict-screening purposes, including individuals who have never interacted with the Service and have no relationship with the Processor, and including the Controller's former clients and parties adverse to the Controller's clients.
A.2 Types of Personal Information Processed
| Category | Specific Data Elements |
|---|---|
| Identity Data | Full name, date of birth |
| Contact Data | Email address, phone number, mailing address |
| Family Data | Marital status, spouse information, dependent/children information |
| Legal Matter Data | Description of legal matter, facts and circumstances relevant to potential representation, case type, practice area |
| Financial Data | Financial information relevant to the legal matter or fee arrangements |
| Health Data | Health and medical information relevant to personal injury, family law, or other applicable practice areas |
| Scheduling Data | Appointment dates, times, preferences |
| Communication Data | Email correspondence content generated through the Service's automated workflows |
| Document Data | Engagement letter content, electronic signature data, signed documents |
| Payment Data | Payment amounts, payer names, trust account routing information |
| Voluntarily Provided Data | Any other information voluntarily provided by the Data Subject through the intake process |
| Conflict-Screening Data | Party name, normalized name used for matching, role (client, prospect, adverse party, or related party), optional relationship label |
Not every category above applies to every category of Data Subject. For a Recorded Party who is not also a prospective or current client of the Controller, Conflict-Screening Data is the only category processed.
A.3 Processing Activities
- (a)Collection of End-Client information through automated intake forms;
- (b)Storage of End-Client records in the Processor's database infrastructure (Supabase) with multi-tenant isolation;
- (c)Automated email communication on behalf of the Controller via transactional email provider (Resend);
- (d)Scheduling of consultation appointments via self-hosted scheduling platform (Cal.com);
- (e)Processing of retainer and fee payments via IOLTA-compliant payment processor (Confido Legal), routed to the Controller's designated trust account;
- (f)Automated analysis of inquiry text and intake form submissions using artificial intelligence (Anthropic's Claude) to generate inquiry response emails sent automatically to prospective End-Clients on the Controller's behalf, and consultation preparation summaries for the Controller's review;
- (g)Generation of engagement letters and related legal documents via document automation provider (PandaDoc), including collection of electronic signatures from both the Controller and Data Subjects;
- (h)Storage of matter documents and generated files in cloud storage (AWS S3);
- (i)Transmission of data between Sub-Processors as necessary to execute intake workflows; and
- (j)Generation of aggregated and anonymized analytics data (excluding AI-generated content derived from End-Client Data);
- (k)Screening of the names of prospective End-Clients against the Recorded Parties associated with the Controller, by deterministic name comparison performed within the Processor's own systems, to identify potential conflicts of interest for the Controller's review; and
- (l)Where the screening described in paragraph (k) identifies a potential match, transmission of the matched Recorded Party's name, role, and relationship label to the artificial intelligence Sub-Processor (Anthropic's Claude) as part of the intake analysis described in paragraph (f). A Recorded Party's name is transmitted only where it matches a name on a submitted intake form; names that do not match are not transmitted.
A.4 Retention Periods
Personal Information is retained for the duration of the Controller's active subscription to provide the Service. Upon termination of the subscription, the Controller has thirty (30) days to request data retrieval. Following the Data Retrieval Period, the Processor shall complete deletion of all Personal Information within thirty (30) days, in accordance with Section 11.3. Payment records may be retained for up to seven (7) years to satisfy tax and accounting obligations.
Recorded Party Information is retained on the same basis and is subject to the same retrieval and deletion process. The Controller may delete an individual Recorded Party record, or an entire uploaded batch of them, from the Service at any time. Recorded Party Information is not deleted automatically on termination; as with all other Personal Information, deletion is initiated and tracked manually by Processor personnel, as described in Section 11.3.
Two exceptions to the deletion of End-Client Data apply, both described in Section 11 of this DPA: (a) where the Controller's firm has received a refund under the Service's money-back guarantee, a minimal set of Controller (not End-Client) identifiers and the refund-banned firm record are retained indefinitely to enforce the one-refund-per-firm prohibition (Section 11.5); and (b) the Cal.com scheduling account and Confido Legal partner account are deprovisioned manually on written request rather than automatically on termination (Section 11.6).
Annex B: Technical and Organizational Measures
B.1 Access Controls
- (a)Role-based access control (RBAC) limiting data access to authorized personnel with a legitimate need-to-know;
- (b)Multi-tenant data isolation enforced at the database level using row-level security (RLS) policies on Supabase, ensuring that each Controller's data is logically separated and inaccessible to other Controllers or their personnel;
- (c)Unique user credentials for all personnel with access to processing systems;
- (d)Multi-factor authentication (MFA) for administrative access to Sub-Processor accounts;
- (e)Authentication and session management for Subscriber dashboard access via Clerk, an industry-standard authentication provider;
- (f)Regular review and revocation of access rights upon personnel changes; and
- (g)Principle of least privilege applied to all system access.
B.2 Encryption
- (a)Encryption of Personal Information in transit using TLS 1.2 or higher;
- (b)Encryption of Personal Information at rest where supported by Sub-Processors, including AES-256 encryption in AWS S3 and encryption at rest provided by Supabase; and
- (c)Secure key management practices.
B.3 Monitoring and Logging
- (a)Structured error logging to a dedicated error tracking system, with email alerts for critical and high-severity events and daily digest summaries;
- (b)Logging of access to systems containing Personal Information;
- (c)Monitoring of system logs for suspicious activity; and
- (d)Retention of the audit trail — the append-only record of actions taken through the Service, which the Processor's database privileges prevent from being altered or deleted — for a minimum of twelve (12) months.
The error and diagnostic logs described in (a) are operational records rather than an audit trail, and are subject to a shorter retention schedule: entries that have been triaged and closed are deleted ninety (90) days afterward; errors reported by Subscriber and visitor browsers are deleted after thirty (30) days regardless of status; and the volume of browser-reported errors is capped, with the most recent entries retained when that cap is exceeded. Entries recording an unresolved error are not deleted on any schedule.
B.4 Incident Response
- (a)Documented incident response plan for Data Breaches;
- (b)Designated incident response personnel;
- (c)Notification procedures as described in Section 7 of this DPA; and
- (d)Post-incident review and remediation process.
B.5 Personnel Security
- (a)Confidentiality obligations for all personnel with access to Personal Information;
- (b)Training on data protection and handling of sensitive information; and
- (c)Prompt revocation of access upon termination of employment or engagement.
As of the Effective Date, the Processor is a sole-founder operation. All data access is limited to the founder. This minimizes the personnel attack surface. The measures described above will scale as the organization grows.
B.6 Sub-Processor Security
- (a)Due diligence review of Sub-Processor security practices prior to engagement;
- (b)Contractual data protection obligations imposed on all Sub-Processors;
- (c)Periodic review of Sub-Processor compliance; and
- (d)Selection of Sub-Processors that maintain industry-recognized security certifications where available (see Annex C for current certification status).
B.7 Business Continuity
- (a)Regular backups of critical system configurations and database data;
- (b)Reliance on Sub-Processors' disaster recovery and business continuity capabilities (including AWS infrastructure redundancy and Supabase's backup and recovery features); and
- (c)Documented procedures for restoring service availability following disruption.
Annex C: Approved Sub-Processors
The following Sub-Processors are approved as of the Effective Date of this DPA:
| Sub-Processor | Function | Data Processed | Location | Security Certifications |
|---|---|---|---|---|
| Supabase | Database hosting (Postgres with Row Level Security) | All application data, multi-tenant isolated via firm-level scoping | Cloud-hosted (US) | SOC 2 Type II |
| Clerk | Authentication and session management | Subscriber credentials, session tokens | Cloud-hosted (US) | SOC 2 Type II |
| Resend | Transactional email delivery | Email addresses, names, message content | Cloud-hosted (US) | SOC 2 Type II |
| Confido Legal | IOLTA-compliant payment processing | Payment amounts, payer names, trust account routing data | Cloud-hosted (US) | SOC 2 Type II; annual PCI-DSS audits |
| PandaDoc | Document generation and e-signatures | Engagement letter content, signer names, signature data | Cloud-hosted (US) | SOC 2 Type II |
| Cal.com | Scheduling and appointment booking | Names, emails, phone numbers, appointment data | Self-hosted on Render (US); appointment data stays within the Processor's infrastructure unless the Controller connects an external calendar (see note below) | N/A (self-hosted) |
| AWS (Amazon S3) | Document and file storage | Matter documents, generated files | US regions | SOC 2 Type II, ISO 27001 |
| Anthropic (Claude API) | AI text processing — email generation and intake analysis | Inquiry text, intake form data (may include legal matter details, financial, family, and health information) | Cloud-hosted (US) | SOC 2 Type II, ISO 27001 |
| Render | API and scheduling hosting | All API traffic in transit | Cloud-hosted (US) | SOC 2 Type II |
| Vercel | Frontend hosting (CDN) | Static assets only — no Personal Information at rest | CDN (global edge, US origin) | SOC 2 Type II |
Controller-Connected Calendars
The scheduling platform is operated by the Processor on its own infrastructure. The Controller may, at its option, connect an external calendar account (for example Microsoft Outlook or Google Calendar) so that consultations appear on the Controller's own calendar. Where the Controller does so, appointment data — including the Data Subject's name, the appointment time, and any details carried in the booking title — is synchronized to that calendar provider at the Controller's direction and under the Controller's own account with that provider. That provider is not engaged by the Processor and is not a Sub-Processor under this DPA; the Controller is responsible for the terms governing its own calendar account. A Controller that does not connect an external calendar has no such transfer.
Infrastructure Underlying Named Sub-Processors
Each Sub-Processor named above operates on infrastructure it procures itself, which in some cases includes a content-delivery and network-protection layer sitting in front of its hosting. The Processor's API and scheduling hosting is fronted in this way by its hosting Sub-Processor. These underlying providers are engaged by the named Sub-Processor rather than by the Processor, and are covered by that Sub-Processor's own obligation, imposed under Section 5.2, to bind its providers to equivalent data protection terms. They are accordingly not enumerated separately in this Annex, and the Processor's liability for them runs through the named Sub-Processor under Section 5.2(b).
Relationship to the Privacy Policy Sub-Processor List
The Privacy Policy (Section 7) lists two additional third-party services, Stripe and PostHog, that do not appear in this Annex.
Stripe processes the Controller's own subscription-billing information (the Subscriber's billing identifiers and payment-method metadata), for which the Processor acts as a Data Controller rather than as a Data Processor on the Controller's behalf.
PostHog processes two data streams, neither of which contains End-Client Data or Recorded Party Information: (a) aggregate, anonymous traffic measurement on the Processor's own public marketing pages, and (b) usage analytics covering the Controller's own use of the Service — the Subscriber's account activity on the authenticated surfaces, never the content of any End-Client record. The Service's analytics instrumentation is configured so that End-Client Data cannot reach the analytics service: it is not loaded on any surface End-Clients use, automatic event and element capture is disabled, session recording is disabled at the project level, and transmitted URLs are stripped to an approved parameter set. Recorded Party Information is likewise never transmitted: the Service's analytics events carry no party name, role, or relationship label, and the automatic capture that would otherwise read them from the page is disabled. For both streams the Processor acts as a Data Controller in respect of its own marketing website and its own Subscriber relationships, not as a Data Processor on the Controller's behalf.
Because this Annex governs only the Sub-Processors that process End-Client Data or Recorded Party Information on the Controller's documented instructions, both services are disclosed in the Privacy Policy's broader Section 7 inventory but are outside the scope of this Annex. Neither Stripe nor PostHog processes either category, and neither engagement triggers the Sub-Processor notification requirements of Section 5.3.
Update Mechanism
Changes to the Sub-Processor list shall be communicated to the Controller in accordance with Section 5.3 of this DPA. The Controller may subscribe to Sub-Processor change notifications by contacting the Processor at admin@slipstream.works. This Annex shall be updated to reflect any approved changes.