Data Processing Agreement (DPA)
This Data Processing Agreement (DPA) governs MXLEX's processing (as processor) on behalf of the firm (as controller) when using the service. It is governed by the LFPDPPP (Mexico), Ley 1581 de 2012 and Decreto 1377 de 2013 (Colombia), Ley 81 de 2019 and Decreto Ejecutivo 285 de 2021 (Panama), and art. 28 of the GDPR (EU), depending on the firm's country. It supplements the Terms of Service.
1. Roles and governing law
The firm is the controller of the matter content; MXLEX is the processor and processes that data only on documented instructions.
Governing law by the controller's country: LFPDPPP (Mexico), Ley 1581 de 2012 and Decreto 1377 de 2013 (Colombia), Ley 81 de 2019 and Decreto 285 de 2021 (Panama), and art. 28 of the GDPR (EU).
2. Subject matter, duration, and nature
Subject matter: provision of the MXLEX service. Duration: the term of the agreement. Nature and purpose: drafting, review, research, and management of legal documents for attorney review.
Data categories: identification and contact data, and any personal data (including, where applicable, sensitive data) contained in the documents the firm chooses to upload. Data subjects: the firm's clients and counterparties.
3. Processor obligations
Process data only on the controller's documented instructions.
Ensure the confidentiality of authorized personnel and not use matter content to train AI models.
Apply appropriate technical and organizational security measures (art. 32 of the GDPR and the security principle of the local laws); see the Security page.
Assist the controller with its obligations for security, breach notification, impact assessments, and responding to data-subject requests.
4. Sub-processors
The controller authorizes the sub-processors: Anthropic, AWS, and Supabase. MXLEX imposes equivalent protection obligations on each, maintains a current list, and notifies material changes with reasonable notice, allowing objection.
5. Breach notification
MXLEX will notify the controller without undue delay after becoming aware of a security breach affecting personal data, with the information reasonably available, so the controller can meet its notification duties (arts. 33 and 34 of the GDPR and equivalent duties in Mexico, Colombia, and Panama).
6. International transfers
Transfers outside the controller's country rely on valid mechanisms: GDPR standard contractual clauses under art. 46 where applicable, and the transfer provisions of the LFPDPPP, Ley 1581 and its Decreto 1377, and Ley 81 and its Decreto 285.
7. Return, deletion, and audit
On termination, and at the controller's choice, MXLEX will return or delete the matter content, except where legally required to retain it.
MXLEX will make available to the controller the information reasonably necessary to demonstrate compliance with this DPA, including its sub-processors' compliance reports where available.