Data Processing Agreement
Effective Date: May 1, 2025 · Aequitas Technologies LLC d/b/a Law Hired
This Data Processing Agreement (“DPA”) forms part of the Law Hired Terms of Service between Aequitas Technologies LLC d/b/a Law Hired (“Law Hired”, “Processor”) and the attorney or law firm using the Law Hired platform (“Controller”, “you”). This DPA governs the processing of personal data by Law Hired on behalf of the Controller.
1. Definitions
“Personal Data” means any information relating to an identified or identifiable natural person processed by Law Hired on behalf of the Controller in the course of providing the Law Hired platform and services.
“Processing” means any operation performed on Personal Data, including collection, recording, storage, retrieval, use, disclosure, or deletion.
“Data Subject” means the individual to whom the Personal Data relates, including the Controller’s clients, staff, and contacts whose information is stored on the platform.
“Sub-Processor” means any third party engaged by Law Hired to process Personal Data on the Controller’s behalf. Current Sub-Processors are listed in Schedule A.
“GDPR” means the General Data Protection Regulation (EU) 2016/679 and, where applicable, its UK equivalent (UK GDPR).
2. Scope and Purpose of Processing
Law Hired processes Personal Data solely for the purpose of providing the services described in the Terms of Service, including case management, client communication, document storage, billing, and related features. Law Hired does not process Personal Data for any purpose independent of the Controller’s instructions.
The categories of Personal Data processed include: names, email addresses, phone numbers, mailing addresses, case and matter details, billing and payment information (excluding raw payment credentials, which are processed by Stripe), and any other information the Controller uploads to the platform.
Processing activities are carried out in the United States. All servers and primary data infrastructure are located within the United States.
3. Controller's Instructions
Law Hired shall process Personal Data only in accordance with the Controller’s documented instructions, including those set out in this DPA and the Terms of Service. Law Hired will promptly inform the Controller if, in its reasonable opinion, an instruction infringes applicable data protection law.
The Controller represents that it has a lawful basis for processing the Personal Data it uploads to the platform and that it has provided appropriate notices to Data Subjects regarding such processing.
4. Confidentiality
Law Hired shall ensure that personnel authorized to process Personal Data have committed to confidentiality obligations. Law Hired personnel do not access client files, communications, case notes, or other matter content except as strictly necessary to provide technical support, and only with the Controller’s explicit consent.
5. Security Measures
Law Hired implements and maintains the following technical and organizational security measures:
✓
AES-256 encryption for all data at rest
✓
TLS 1.2 or higher encryption for all data in transit
✓
Row-level tenant isolation enforced at the database layer via Oracle Virtual Private Database (VPD), preventing cross-account data access
✓
Multi-factor authentication required for internal system access
✓
Access logging and audit trails for all production system access
✓
Regular dependency updates and security patch management
✓
Incident response procedures with defined escalation timelines
✓
Hosted on infrastructure from providers that hold their own SOC 2 Type II certifications (Law Hired is not itself SOC 2 certified)
Law Hired will not materially reduce the overall level of security provided under this DPA during the term of the Controller’s subscription.
6. Sub-Processors
The Controller authorizes Law Hired to engage the Sub-Processors listed in Schedule A below. Law Hired will notify the Controller of any intended addition or replacement of Sub-Processors by updating this DPA and providing 30 days’ notice via email. The Controller may object to a new Sub-Processor within that period; if the parties cannot resolve the objection, the Controller may terminate the subscription with a pro-rata refund.
Law Hired imposes data protection obligations on Sub-Processors equivalent to those in this DPA and remains liable to the Controller for the performance of Sub-Processors.
7. Data Subject Rights
Law Hired will assist the Controller in fulfilling Data Subject requests (access, rectification, erasure, portability, restriction, objection) within the technical capabilities of the platform. The Controller is responsible for responding to Data Subjects; Law Hired will provide reasonable technical assistance upon written request.
The platform provides an export of supported account records. Broader portability, return, or deletion requests require written scoping because documents, matter records, authentication data, audit evidence, backups, legal holds, and required financial records may follow different processes.
8. Data Breach Notification
Law Hired will notify the Controller of a confirmed Personal Data breach affecting the Controller’s data without unreasonable delay and within any deadline expressly required by applicable law or the parties’ signed order form. Available notification will describe the incident, affected data, likely consequences, and remediation steps.
The Controller is responsible for any required notifications to Data Subjects or supervisory authorities arising from a breach. Law Hired will cooperate with and assist the Controller in fulfilling those obligations.
9. Data Retention and Deletion
Upon termination, Law Hired will process a documented return or deletion request within its verified technical capabilities and subject to legal holds and applicable security, financial, tax, and professional-record obligations. The parties must document any required production-system or backup deadline in a signed order form; this public DPA does not promise unverified 30-day production or 90-day backup deletion.
10. International Data Transfers
Personal Data may be processed in the United States. A Controller requiring an EEA or UK transfer mechanism must obtain and execute the applicable transfer terms with Law Hired before transferring regulated Personal Data; Standard Contractual Clauses are not incorporated merely by viewing this page.
11. Audit Rights
The Controller may, upon 30 days’ written notice and no more than once per calendar year, request an audit of Law Hired’s data processing practices. Law Hired may satisfy this obligation by providing: (a) the most recent SOC 2 report published by its infrastructure providers, or (b) a written security questionnaire response. Where Law Hired has commissioned a third-party penetration test, it may also provide that summary; nothing in this section obliges Law Hired to commission one. On-site audits will be conducted at the Controller’s expense.
12. Liability
Each party’s liability under this DPA is subject to the limitations set out in the Law Hired Terms of Service. Nothing in this DPA limits either party’s liability to Data Subjects under applicable data protection law.
13. Governing Law
This DPA is governed by the laws of the State of Delaware, United States, without regard to conflict of law principles, except where GDPR or UK GDPR mandates a different governing law for specific provisions.
Schedule A — Authorized Sub-Processors
The following Sub-Processors are authorized as of the effective date of this DPA:
Supabase, Inc.
Purpose: Database hosting and backend infrastructure
Location: United States · Certification: SOC 2 Type II
Oracle Cloud Infrastructure (Oracle America, Inc.)
Purpose: Application hosting, compute, and object storage
Location: United States · Certification: SOC 2 Type II, ISO 27001
Stripe, Inc.
Purpose: Payment processing
Location: United States · Certification: PCI DSS Level 1
Execute This Agreement
By using the Law Hired platform, you agree to this DPA as part of the Law Hired Terms of Service. If you require a manually countersigned copy for your records — for example, to satisfy a state bar ethics opinion on cloud software — email us and we will return a signed PDF within 2 business days at no charge.
