Data Processing Agreement
UK GDPR Art. 28(3) controller-processor agreement for Avantwerk Legal AI. Sub-processors listed in Annex A; processing details in Annex B.
Parties
(1) The law firm, chambers, limited company, LLP, sole practice or legal department identified in the Order Form or trial-signup confirmation (the "Controller", "Customer", "you").
(2) Bennovate spółka z ograniczoną odpowiedzialnością, a company incorporated in the Republic of Poland, KRS 0000597272, NIP 7272799328, REGON 363700466, with its registered office at ul. Christiana Andersena 25, 94-118 Łódź, Poland, operating the Avantwerk Legal AI service (the "Processor", "Bennovate", "we").
Background
A. The Controller is an SRA-regulated law firm or other legal-services entity using the Avantwerk Legal AI service (the "Service") under a Trial or paid subscription governed by the Terms of Service.
B. In the course of providing the Service, Bennovate processes certain personal data on behalf of the Controller. The parties set out their respective data-protection obligations in accordance with UK GDPR Art. 28.
C. The Controller remains the controller (UK GDPR Art. 4(7)). Bennovate processes that data only as processor (UK GDPR Art. 4(8)).
D. Scope limitation. As described in Clause 2.3, this DPA covers only the narrow set of account-level personal data Bennovate processes on the Controller's behalf. It does not cover Matter Content, client data or privileged material, which remains on the Controller's own device and disk at all times (Local-First Architecture).
This DPA forms part of the Agreement. Capitalised terms not defined here have the meanings given in the Terms.
1. Definitions
| Term | Meaning |
|---|---|
| Agreement | The Terms of Service together with this DPA and any Order Form. |
| Controller | The Customer, being the party that determines the purposes and means of the processing described in this DPA. |
| Data Subject | An identified or identifiable natural person whose personal data is processed under this DPA. |
| IDTA | The International Data Transfer Agreement issued by the Information Commissioner under s.119A of the Data Protection Act 2018. |
| Personal Data | Information relating to an identified or identifiable natural person, as defined in UK GDPR Art. 4(1). |
| Personal Data Breach | A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data (UK GDPR Art. 4(12)). |
| Processing | Any operation or set of operations on personal data, as defined in UK GDPR Art. 4(2). |
| Processor | Bennovate. |
| Restricted Transfer | A transfer of personal data to a third country not covered by a UK adequacy instrument. |
| Sub-Processor | Any third party engaged by Bennovate to process personal data on behalf of the Controller. |
| UK GDPR | Regulation (EU) 2016/679 as retained in UK law by s.3 of the European Union (Withdrawal) Act 2018, as amended. |
2. Subject matter, nature, purpose and duration
2.1 Subject matter
Bennovate processes personal data relating to the Controller's fee-earners, billing contacts and technical contacts in the course of providing the Service.
2.2 Nature and purpose of processing
| Processing activity | Purpose |
|---|---|
| Creating and maintaining user accounts | Enabling authorised fee-earners to access the Service |
| Authentication and access logging | Security; audit trail; detection of unauthorised access |
| Recording subscription and billing data | Invoicing; payment processing; contract management |
| Sending transactional and service emails | Onboarding; account management; security notices; invoices |
| Processing e-signature workflows at onboarding | Executing engagement letters and DPAs |
| Providing customer support | Responding to queries and incidents |
2.3 Scope limitation — what is NOT processed
This DPA does not cover, and Bennovate does not process as a processor or otherwise:
- Matter Content — any case file, client document, privileged material, court paper, correspondence, witness statement or other legal work product belonging to the Controller or its clients. Matter Content is held exclusively on the Controller's own device and disk and never traverses Bennovate's infrastructure;
- End-client personal data — the personal data of the Controller's clients contained within Matter Content; or
- AI-processed matter extracts — position depends on subscription tier. On Starter and Practice plans (managed-key), Bennovate provisions and holds the API key for one or more managed-key AI Providers; those providers are Bennovate sub-processors and AI-processed matter extracts on those plans are within the scope of this DPA to the extent described at clause 6.5.1. The authoritative current list of managed-key AI Providers is Annex A to this DPA (rows marked "LIVE — managed-key"). On the Enterprise plan (BYOK), the Controller supplies its own API key; the AI Provider is the Controller's own processor under the Controller's direct contract with that provider, it is not a Bennovate sub-processor, and this DPA does not cover that processing chain. See clause 6.5.
2.4 Categories of data subjects
Fee-earners and solicitors at the Controller firm; billing contacts; technical contacts.
2.5 Categories of personal data
Name; job title; professional email address; SRA number; IP address (service logs); service-usage events; billing confirmation data.
Special-category data: none in scope. Bennovate instructs the Controller not to transmit special-category data (UK GDPR Art. 9) through the Service except where strictly necessary and disclosed in advance.
2.6 Duration
Processing continues for the duration of the subscription (including any Trial period) and for such further period as is required by applicable law or as set out in the retention table in the Privacy Notice. On termination, Clause 9 governs deletion and return.
3. Controller's instructions and compliance
3.1 Documented instructions. Bennovate shall process personal data only on documented instructions from the Controller. The Controller's instructions are set out in this DPA and in the Terms. Any additional instructions must be given in writing and signed by an authorised representative of the Controller.
3.2 Notification of unlawful instructions. If Bennovate considers that any instruction infringes the UK GDPR or other applicable data-protection law, Bennovate shall immediately notify the Controller in writing. Bennovate shall not be obliged to follow any instruction that it reasonably considers to be unlawful.
3.3 Controller's obligations. The Controller warrants that it: (a) is the controller of the personal data and has all necessary rights, consents and lawful bases; (b) has complied with its own transparency obligations; (c) has assessed and is satisfied that the processing is compatible with its own GDPR compliance; (d) will promptly notify Bennovate of any changes in applicable law materially affecting this DPA.
4. Confidentiality — UK GDPR Art. 28(3)(b)
Bennovate shall ensure that persons authorised to process personal data under this DPA are bound by appropriate obligations of confidentiality — whether statutory, contractual or otherwise — and that they process personal data only as necessary for the performance of the Service.
5. Security — UK GDPR Art. 28(3)(c) and Art. 32
5.1 General obligation
Bennovate shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, having regard to: (a) the state of the art; (b) the cost of implementation; (c) the nature, scope, context and purposes of processing; (d) the risk of varying likelihood and severity to the rights and freedoms of natural persons.
5.2 Minimum security measures
- TLS 1.2 or higher encryption for all data in transit between the Controller's browser and Bennovate's servers;
- encryption of the Controller's BYOK key at rest in browser-side IndexedDB — the key is never transmitted to Bennovate's servers;
- server-side access controls and role-based restrictions on account data;
- logging of access events with tamper-evident audit chain;
- fail2ban or equivalent brute-force protection on authenticated endpoints;
- regular vulnerability scanning and dependency auditing;
- a documented incident-response procedure consistent with the timelines in Clause 7.
5.3 Security review
Bennovate maintains a Security Review Package available to the Controller for audit purposes. The Controller acknowledges that Bennovate's security posture is that of a sole-operator software company at the current stage of operation, and that ISO 27001 certification and SOC 2 Type II reports are planned but not yet obtained.
6. Sub-processors — UK GDPR Art. 28(3)(d) and Art. 28(2)
6.1 General authorisation. The Controller provides general written authorisation for Bennovate to engage the sub-processors listed in Annex A. Bennovate shall impose data-protection obligations on each sub-processor no less protective than those in this DPA, by written contract.
6.2 Changes to sub-processors. Bennovate shall give the Controller not less than 30 days' written notice before engaging a new sub-processor or materially changing the scope of an existing engagement. Notice shall be given by email to the billing contact address and by a prominent notice within the Service.
6.3 Controller's right to object. Within 14 days of receiving notice under Clause 6.2, the Controller may object in writing, stating the data-protection grounds. If the parties cannot resolve the objection within the notice period, the Controller may terminate the Agreement with immediate effect, with a pro-rated refund of prepaid fees for the unexpired subscription period. If the Controller does not object within 14 days, the Controller is deemed to have accepted the change.
6.4 Liability for sub-processors. Bennovate remains liable to the Controller for the performance of sub-processors' obligations under this DPA to the same extent as if Bennovate were performing those obligations directly.
6.5 AI Provider — managed-key and BYOK positions.
6.5.1 Starter and Practice plans (managed-key). On these plans Bennovate provisions and holds the API key for one or more managed-key AI Providers. Each such provider is thereby engaged by Bennovate as a sub-processor within the meaning of UK GDPR Art. 28(2) and is subject to the sub-processor obligations in clauses 6.1 to 6.4 (general authorisation; change notice; right to object; Bennovate's liability). The authoritative current list of managed-key AI Providers is Annex A to this DPA, which Bennovate maintains as its published sub-processor register; rows are marked to indicate whether each AI Provider is live on managed-key plans or anticipated under BYOK only. Adding a managed-key AI Provider to that register constitutes engaging a new sub-processor for the purposes of clause 6.2: Bennovate will give not less than 30 days' written notice before that provider is first used, and the Controller's right to object under clause 6.3 applies. The change is a register update and a notice — it does not require amendment of this DPA. As at the date of this DPA, the live managed-key AI Providers are: Anthropic PBC (SP-02 — USA — live); and Amazon Web Services EMEA SARL (SP-17 — EU/EEA — live; inference does not leave the EEA). Each managed-key AI Provider is contractually prohibited from using data submitted to it to train its models. Token usage is billed to Bennovate and charged to the Controller as part of the subscription fee.
6.5.1.1 Two distinct pre-egress controls. Before any call reaches the AI Provider, two separate controls apply. They answer different duties and neither substitutes for the other:
- The privilege gate — an egress control evaluated on every outbound call, before the call is made, against the classification of the material and the destination. Its effect differs by destination, and Bennovate states the difference rather than describing the strongest case:
- To the AI Provider, in England & Wales: a warn-and-log control with the Controller's override. Material classified as privileged, and material not yet classified, raises a blocking prompt naming the destination and the effect; the call proceeds only if the Controller's fee-earner confirms it, and that confirmation is written to the matter's audit record. It is not withheld absolutely. This is deliberate: legal professional privilege belongs to the client and is the client's to waive, so the decision is the solicitor's to take and to record, not Bennovate's to take away.
- To the Controller's CRM and to outbound email: an absolute block. Material classified as privileged, and material not yet classified, does not leave the device to those destinations, and there is no override.
- On a matter outside England & Wales: an absolute block to every external destination, including the AI Provider. In each of the other markets Bennovate serves, the professional-secrecy duty is absolute and the client cannot waive it as against third parties — so on those matters the gate withholds privileged and unclassified material with no override available to anyone, including the fee-earner. Each of those markets has its own data-processing agreement, in its own language, stating its own duty and the statute that imposes it; this agreement governs England & Wales.
- Client-side pseudonymisation — for the disclosable material that does leave, the identifiers in Bennovate's published taxonomy (party and person names, addresses and postcodes, national, tax and company identifiers, dates of birth, bank details, and court or matter references, per market) are replaced with stable tokens in the Controller's browser before egress. This addresses data minimisation under UK GDPR Art. 5(1)(c).
6.5.1.2 Pseudonymisation, not anonymisation. The substitution at 6.5.1.1(b) is reversible: the token-to-value mapping is generated in the Controller's browser, is used there to restore the real values in the returned draft, and is never transmitted to Bennovate, to the AI Provider or to any other recipient. The material is therefore pseudonymised within the meaning of UK GDPR Art. 4(5). It remains personal data, it remains within the scope of the UK GDPR, and it continues to require a lawful basis. It is not anonymised and Bennovate does not represent it as anonymised.
6.5.1.3 Stated limits. The pseudonymisation pass is a text function. It does not act on content inside an image, screenshot or scanned page, and it does not act on special-category facts written as prose that carry no identifier pattern. Bennovate publishes the full class list, the classes loaded for England and Wales, and the stated gaps at Annex C — PII taxonomy register to this DPA, which is generated from the same source the product's tokeniser compiles from. The Controller must not treat either control as a substitute for its own professional judgment on what may be sent.
6.5.2 Enterprise plan (BYOK). Where the Controller uses the BYOK mechanism, the Controller supplies its own API key. That key is stored in the browser's IndexedDB and is never transmitted to Bennovate's servers. The Controller's chosen AI Provider is the Controller's own processor under the Controller's direct contract and DPA with that provider. It is not a Bennovate sub-processor for the purposes of this DPA or UK GDPR Art. 28. Matter content submitted to the AI Provider via BYOK is processed under the Controller's own relationship with the AI Provider, and token usage is billed to the Controller directly by that AI Provider. The Controller is responsible for its own UK GDPR compliance in that processing chain, including any applicable restricted transfer obligations under s.119A DPA 2018.
7. Data subject rights assistance — UK GDPR Art. 28(3)(e)
Bennovate shall, taking into account the nature of processing, assist the Controller by appropriate technical and organisational measures, in responding to requests from data subjects exercising their rights under UK GDPR Chapter III (Arts. 15–22: access, rectification, erasure, restriction, portability, objection, automated decision-making).
Specifically:
- Bennovate shall notify the Controller within 5 working days of receiving a data-subject rights request directed to Bennovate that relates to data processed under this DPA;
- Bennovate shall provide the Controller with information it reasonably requires to respond, within 15 working days of the Controller's written request;
- Bennovate shall not respond substantively to a data-subject rights request on the Controller's behalf without the Controller's prior written instruction, except where required to do so by law.
8. Assistance with Art. 32–36 obligations — UK GDPR Art. 28(3)(f)
Bennovate shall assist the Controller in ensuring compliance with:
- Art. 32 — security obligations, by maintaining the measures in Clause 5 and providing the Controller with relevant technical information on request;
- Art. 33 — Personal Data Breach notification to the ICO: Bennovate shall notify the Controller without undue delay and in any event within 48 hours of becoming aware of a Personal Data Breach affecting data processed under this DPA. Notification shall include: (i) the nature of the breach including categories and approximate numbers of data subjects and records affected; (ii) the name and contact details of the DPO; (iii) the likely consequences; (iv) measures taken or proposed to mitigate effects. The Controller is responsible for notifying the ICO within the 72-hour window under UK GDPR Art. 33(1);
- Art. 34 — communication of a breach to affected data subjects, by providing the Controller with information needed to assess whether notification is required and to draft it;
- Art. 35 — DPIA: Bennovate shall, on request, provide relevant technical information to assist the Controller in completing a DPIA in respect of the processing described in this DPA;
- Art. 36 — prior consultation: where a DPIA indicates a high residual risk that requires prior consultation with the ICO, Bennovate shall cooperate with the Controller to the extent the consultation relates to Bennovate's processing.
9. Deletion and return of data — UK GDPR Art. 28(3)(g)
9.1 On termination. On expiry or termination of the Agreement for any reason, Bennovate shall, at the Controller's election:
- delete all personal data processed under this DPA within 30 days of the termination date; or
- return all personal data to the Controller in a structured, commonly used and machine-readable format within 30 days, after which Bennovate shall delete all copies.
9.2 Legal retention exceptions. Bennovate may retain personal data beyond the period in Clause 9.1 to the extent retention is required by applicable law (including accounting and tax obligations). In such cases Bennovate shall: (a) notify the Controller of the data retained and the legal basis; (b) cease all processing for any purpose other than compliance; (c) delete the data as soon as the legal obligation ceases.
9.3 Matter content not affected. Matter Content on the Controller's own device and disk is unaffected by termination — it was never held by Bennovate.
10. Audit rights — UK GDPR Art. 28(3)(h)
10.1 Bennovate's obligation. Bennovate shall make available to the Controller all information necessary to demonstrate compliance with UK GDPR Art. 28 and shall allow for and contribute to audits and inspections conducted by the Controller or a third-party auditor mandated by the Controller.
10.2 Practical audit procedure.
- The Controller shall give Bennovate at least 30 days' written notice of an audit request, specifying scope and proposed dates.
- Audits shall be conducted during normal business hours and shall not unreasonably disrupt Bennovate's operations.
- The Controller may inspect: documentation of Bennovate's security policies and procedures; sub-processor list; DPA and security review documents; and relevant logs — subject to Bennovate redacting third-party confidential information.
- The Controller shall not audit more than once per 12-month period unless: (i) a Personal Data Breach has occurred; (ii) the ICO requires it; or (iii) the Controller has reasonable grounds to suspect a material breach of this DPA.
- The Controller shall bear its own costs of any audit. Bennovate may charge a reasonable fee for management time beyond one day.
- Where a recent third-party audit report is available (e.g. ISO 27001 certification), Bennovate may satisfy the audit obligation by making that report available, subject to confidentiality.
11. International transfers
11.1 Transfer mechanism. Where Bennovate (or a sub-processor) transfers personal data outside the UK that is not covered by UK adequacy regulations, Bennovate shall ensure the transfer is subject to one of:
- the International Data Transfer Agreement (IDTA) under s.119A DPA 2018; or
- the UK Addendum to EU Standard Contractual Clauses; or
- another mechanism approved by the ICO.
11.2 Transfer impact assessment. Where a restricted transfer takes place, Bennovate shall have conducted or make available the results of a transfer impact assessment (TIA). Where the TIA identifies a risk that cannot be mitigated, Bennovate shall notify the Controller and not proceed without written consent.
11.3 Current transfer positions:
| Sub-processor | Destination | Mechanism |
|---|---|---|
| Hetzner Online GmbH | Germany (EEA) | UK adequacy regulations |
| CRM provider | USA | UK Addendum / IDTA |
| Payment processor | USA | UK Addendum / IDTA |
| Transactional email provider | USA | UK Addendum / IDTA |
12. Term
This DPA is co-terminous with the Agreement. It comes into force on the Effective Date and terminates automatically when the Agreement terminates, subject to the survival provisions at Clause 9.
13. Governing law and jurisdiction
This DPA is governed by the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales.
14. Order of precedence
In the event of any conflict between this DPA and the Terms of Service on data-protection matters, this DPA prevails. In the event of any conflict between this DPA and any applicable standard contractual clauses (IDTA or UK Addendum) incorporated by reference, the standard contractual clauses prevail.
Annex A — Authorised Sub-Processors
| # | Sub-processor | Role | Data processed | Jurisdiction | Mechanism |
|---|---|---|---|---|---|
| SP-01 | Hetzner Online GmbH | VPS hosting | Server logs, access logs, static SPA bundle, signed-document store | Germany (EU/EEA) | UK adequacy (EEA) |
| SP-02 | Anthropic PBC (Starter and Practice plans — managed-key only) | LLM provider (Claude API): AI processing for fee-earners on plans where Bennovate provisions and holds the API key; prompts pass the fail-closed privilege gate, then client-side pseudonymisation (UK GDPR Art. 4(5) — reversible; the mapping is held in the Controller's browser and never transmitted), before egress; data not used for model training | Per-call prompts and matter extracts explicitly submitted by the fee-earner on those plans | USA | Anthropic DPA + EU Standard Contractual Clauses (Module 2) incorporated by UK Addendum / IDTA |
| SP-03 | HighLevel Inc. (GoHighLevel — CRM) | Firm-level metadata, subscription stage, billing routing | Firm name, contact email, subscription tier, billing confirmation | USA | UK Addendum / IDTA |
| SP-04 | Documenso (community edition, self-hosted on our VPS) | Engagement letter and DPA e-signing | Name, email, signed document | Germany (our VPS) | Not a third-party transfer |
| SP-06 | Stripe Inc. (payment processing) | Subscription payment processing | Payment confirmation data — no card numbers | USA | UK Addendum / IDTA |
| SP-09 | Mailgun Technologies, Inc. (a Sinch company — transactional email) | Sending onboarding, account and invoice emails | Name, email address | USA | UK Addendum / IDTA |
| SP-10 | Twilio Inc. (SMS notifications) | SMS one-time codes and account alerts | Mobile phone numbers of firm contacts | USA | UK Addendum / IDTA |
| SP-12 | Google Ireland Ltd (Google Workspace / Gmail) | Bennovate's operational business email and calendar — firm onboarding and support correspondence; firm contact metadata only; no matter content; no privileged material transmitted or stored | Name, email address, phone number of firm contacts | Ireland (EU); possible onward transfer to Google LLC (USA) | Google Workspace Data Processing Amendment + EU Standard Contractual Clauses + EU–US Data Privacy Framework; UK Addendum / IDTA for UK-side restricted transfers |
| SP-13 | Microsoft Ireland Operations Ltd (Microsoft 365 / OneDrive) | Bennovate's operational document storage and office productivity — firm operational documents and contact data; no customer matter content; no privileged material transmitted or stored | Name, email address, firm operational document metadata of firm contacts | Ireland (EU), EU Data Boundary; possible onward transfer to Microsoft Corp (USA) | Microsoft Products and Services Data Protection Addendum + EU Standard Contractual Clauses + EU Data Boundary commitment; UK Addendum / IDTA for UK-side restricted transfers |
| SP-14 | OpenAI, L.L.C. (OpenAI API) — PLANNED — BYOK only; not in use on any managed-key plan as at the date of this DPA | Anticipated LLM provider (OpenAI API) for fee-earners on the Enterprise plan using the BYOK mechanism. Under BYOK the Controller supplies its own API key; OpenAI is the Controller's own processor under the Controller's direct contract (clause 6.5.2) and is not a Bennovate sub-processor in respect of matter content. Listed here to give advance visibility; any transition to a managed-key arrangement will be notified under clause 6.2 before first use. | None under Bennovate's sub-processor relationship. Matter content under BYOK is processed under the Controller's own contract with OpenAI. | USA | Not applicable under current BYOK position. IDTA / UK Addendum will apply on any future managed-key transition; Controller is responsible for its own transfer compliance under clause 6.5.2 in the interim. |
| SP-15 | Google Ireland Ltd (Gemini API) — PLANNED — BYOK only; not in use on any managed-key plan as at the date of this DPA. Distinct from SP-12 (Google Workspace — Bennovate's operational email and calendar). | Anticipated LLM provider (Gemini API) for fee-earners on the Enterprise plan using the BYOK mechanism. Under BYOK the Controller supplies its own API key; Google Ireland Ltd (Gemini API) is the Controller's own processor under the Controller's direct contract (clause 6.5.2) and is not a Bennovate sub-processor in respect of matter content. Listed here to give advance visibility; any transition to a managed-key arrangement will be notified under clause 6.2 before first use. | None under Bennovate's sub-processor relationship. Matter content under BYOK is processed under the Controller's own contract with Google. | Ireland (EU/EEA); possible onward transfer to Google LLC (USA) | Not applicable under current BYOK position. UK adequacy (EEA) + UK Addendum / IDTA for any onward transfer to Google LLC (USA) + EU–US Data Privacy Framework will apply on any future managed-key transition; Controller is responsible for its own transfer compliance under clause 6.5.2 in the interim. |
| SP-16 | Microsoft Ireland Operations Ltd (Azure OpenAI Service) — PLANNED — BYOK only; not in use on any managed-key plan as at the date of this DPA. Distinct from SP-13 (Microsoft 365 / OneDrive — Bennovate's operational use). | Anticipated LLM provider (Azure OpenAI Service) for fee-earners on the Enterprise plan using the BYOK mechanism. Under BYOK the Controller supplies its own API key and selects the Azure region; Microsoft Ireland Operations Ltd is the Controller's own processor under the Controller's direct contract (clause 6.5.2) and is not a Bennovate sub-processor in respect of matter content. Listed here to give advance visibility; any transition to a managed-key arrangement will be notified under clause 6.2 before first use. Note: the applicable transfer mechanism on any managed-key transition depends on the Azure region selected. | None under Bennovate's sub-processor relationship. Matter content under BYOK is processed under the Controller's own contract with Microsoft. | Region chosen by the Controller. Ireland (EU/EEA) where an EU/EEA Azure region is selected; otherwise determined by the Controller's chosen region. | Not applicable under current BYOK position. On any managed-key transition: UK adequacy (EEA) where an EU/EEA Azure region is selected; IDTA / UK Addendum where a non-EU/EEA region is selected. Under current BYOK arrangement, transfer compliance is the Controller's own responsibility under clause 6.5.2. |
| SP-17 | Amazon Web Services EMEA SARL (Amazon Bedrock, EU region) — LIVE — managed-key | LLM provider (Amazon Bedrock, inference locked to AWS EU region): AI processing for fee-earners on Starter and Practice plans where Bennovate provisions and holds the API key; prompts pass the fail-closed privilege gate and client-side pseudonymisation (UK GDPR Art. 4(5) — reversible; the mapping is held in the Controller's browser and never transmitted) before egress; inference remains in the EEA; data not used for model training. | Per-call prompts and matter extracts explicitly submitted by the fee-earner on managed-key plans, following the same pre-egress controls as SP-02. | EU/EEA — inference does not leave the EEA. Contracting entity: Amazon Web Services EMEA SARL, registered in Luxembourg. | No restricted transfer (inference remains in EEA; UK adequacy regulations apply; AWS EMEA SARL is the processing entity). AWS Data Processing Addendum + EU Standard Contractual Clauses (intra-EEA processing); UK Addendum applied to the Bennovate–AWS EMEA SARL service relationship. |
AI Providers — managed-key and BYOK positions. On Starter and Practice plans, the managed-key AI Providers are those rows marked "LIVE — managed-key" in this Annex: currently SP-02 (Anthropic PBC) and SP-17 (Amazon Web Services EMEA SARL — Amazon Bedrock, EU region). Both are Bennovate sub-processors covered by clauses 6.1–6.4. Rows marked "PLANNED — BYOK only" (SP-14, SP-15, SP-16) identify providers anticipated for use by Controllers on the Enterprise plan BYOK mechanism; under BYOK the Controller's chosen AI Provider is the Controller's own processor for matter content and is not a Bennovate sub-processor. See clause 6.5. Any transition of a listed BYOK provider to managed-key — or the addition of any further managed-key AI Provider to this register — constitutes engaging a new sub-processor under clause 6.2 and requires a 30-day notice before first use; it is a register update, not a DPA amendment.
Numbering. The SP- identifiers above are those of Bennovate's master sub-processor register, so that one row can be matched across this DPA, the register itself and every market's contract. The identifiers are therefore not contiguous here. Four rows of the master register are deliberately not reproduced in this Annex, because none of them processes personal data of the Controller or of its data subjects under this DPA: SP-05 (Gitea, self-hosted source-code remote — code only, no customer data); SP-07 (Let's Encrypt, the TLS certificate authority — no personal data in scope); SP-08 (Cloudflare, authoritative DNS only — no proxying, no traffic inspection, no payload); and SP-11 (Google Ireland Ltd, GA4 web analytics on the marketing websites only, never in the application — pre-listed in the master register under the Clause 6.2 notice procedure and not yet activated). Change record. No sub-processor has ever been removed from this Annex — the gap is the omission described above, not a deletion. The identifiers themselves were renumbered on 31 July 2026: until that date this Annex used its own local sequence, and the rows now read SP-02 Anthropic PBC (was SP-06), SP-03 HighLevel Inc. (was SP-02), SP-04 Documenso (was SP-05), SP-06 Stripe Inc. (was SP-03), SP-09 Mailgun Technologies, Inc. (was SP-04) and SP-10 Twilio Inc. (was SP-07). SP-01, SP-12 and SP-13 are unchanged. A Controller holding a copy signed before that date should read it against this mapping; the vendors, their roles and the transfer mechanisms are the same in both. Should any of those four begin to process personal data under this DPA, it is added to this Annex under the same identifier and the Clause 6.2 notice applies. SP-14 to SP-17 (OpenAI, L.L.C.; Google Ireland Ltd — Gemini API; Microsoft Ireland Operations Ltd — Azure OpenAI Service; and Amazon Web Services EMEA SARL — Amazon Bedrock) were added on 14 August 2026 to reflect the product's five-provider AI routing capability: SP-14, SP-15 and SP-16 are listed as BYOK-only anticipated providers; SP-17 is a live managed-key provider (Amazon Bedrock, EU region).
Sub-processor additions and changes are subject to the 30-day notice procedure in Clause 6.2.
Annex B — Processing Details Summary (UK GDPR Art. 30 record)
| Element | Detail |
|---|---|
| Subject matter | Account management; authentication; billing; e-signing at onboarding; customer support |
| Duration | Subscription term + legal retention periods |
| Nature | Collection, storage, access, use, disclosure to sub-processors, deletion |
| Purpose | Providing the Service under the Agreement |
| Type of personal data | Name, professional email, job title, SRA number, IP address, service usage events, billing confirmation |
| Categories of data subjects | Fee-earners and solicitors; billing contacts; technical contacts of the Controller firm |
| Controller | The law firm identified in the Order Form |
| Processor | Bennovate spółka z ograniczoną odpowiedzialnością |
| Sub-processors | As listed in Annex A |
Annex C — PII taxonomy register
This Annex is the register referred to at clause 6.5.1.3. It is generated from the product's taxonomy source and re-rendered whenever a class changes, so the published list and the code cannot diverge.
59 classes across 5 live markets, 19 of which load in an England-and-Wales matter, and 9 stated gaps.
Classes loaded in an England-and-Wales matter
| Token | Class | Example |
|---|---|---|
[[NAME_n]] | Party and person names | Jan Kowalski |
[[ADDRESS_n]] | Street address | 12 Bedford Road |
[[EMAIL_n]] | Email address | j.kowalski@example.pl |
[[VATID_n]] | VAT registration number | GB123456789 |
[[DOB_n]] | Date of birth * | Date of birth: 14 May 1974 |
[[IBAN_n]] | IBAN | GB29NWBK60161331926819 |
[[NHS_n]] | NHS number | 943 476 5919 |
[[NI_n]] | National Insurance number | QQ 12 34 56 C |
[[POSTCODE_n]] | Postcode | SW1A 1AA |
[[AMOUNT_n]] | Monetary amount | £12,500.00 |
[[UTR_n]] | Unique Taxpayer Reference * | UTR 1234567890 |
[[SORTCODE_n]] | Sort code | 40-47-84 |
[[CRN_n]] | Company number * | Company number 12236697 |
[[ACCOUNT_n]] | Bank account number * | Account number 12345678 |
[[DRIVINGLICENCE_n]] | Driving licence number | MORGA657054SM9IJ |
[[PASSPORT_n]] | Passport number | 123456789 |
[[CASEREF_n]] | Claim or matter reference * | Claim No: KB-2024-001234 |
[[CARD_n]] | Payment card number | 4111 1111 1111 1111 |
[[PHONE_n]] | Telephone number | +48 22 123 45 67 |
The other live markets
| Market | Class | Classes loaded |
|---|---|---|
| Polska | Adres (ulica i numer) · Numer VAT UE · Data urodzenia · Kod pocztowy · PESEL · REGON · Numer KRS · NIP · Numer księgi wieczystej · Numer paszportu · Dowód osobisty · Sygnatura akt | 18 |
| Deutschland | Anschrift (Straße und Hausnummer) · Umsatzsteuer-Identifikationsnummer · Geburtsdatum · Postleitzahl (PLZ) · Steuerliche Identifikationsnummer · Steuernummer · Handelsregisternummer · Rentenversicherungsnummer · Personalausweisnummer · Aktenzeichen | 16 |
| España | Domicilio (calle y número) · NIF-IVA (número de operador intracomunitario) · Fecha de nacimiento · DNI · NIE · CIF · Código postal · Número de la Seguridad Social · Número de pasaporte · Número de procedimiento / expediente | 16 |
| Nederland | Adres (straat en huisnummer) · Btw-identificatienummer · Geboortedatum · Burgerservicenummer (BSN) · Postcode · KvK-nummer · Paspoortnummer · Zaaknummer / kenmerk | 14 |
Stated gaps — what the pass does not reach
| Gap | What it means |
|---|---|
| Anything inside an image, screenshot or scanned page | The pass is a text function. Pixels are not reached; the product warns at the point of upload. |
| Voice-dictation clean-up, the one route told the names on purpose | The pass exists so dictated words come back spelled correctly, which it does by telling the model the matter's own vocabulary alongside the transcript. Tokenising that payload would remove the only thing that makes it work. The same privilege gate, transport and audit ledger apply; Verbatim mode sends nothing at all. |
| Special-category facts written as prose | A sentence describing treatment carries Art. 9 data with no identifier shape to match. The privilege gate, not this pass, governs whether it may leave. |
| A nine-digit business number is labelled as a passport or BSN token | Same shape, no way to separate them without a label. The value IS tokenised; only the class name is coarser than it should be. |
| Eleven-digit and ten-digit identifiers share shapes across markets | In a market-scoped call the right class is loaded. In an unscoped call priority decides the label. No value escapes untokenised either way. |
| A person who is neither a matter party nor titled | Tokenised only where the person is a known party on the file or carries a title. A greedy capitalised-word matcher would shred the surrounding legal prose. |
| A date of birth written with no label next to it | The class fires on the label. Claiming every bare date would take the breach, hearing and limitation dates with it. Identifiers that encode a date of birth have their own classes and are always tokenised. |
| Citations of published case law are deliberately not tokenised | A neutral citation is public law, not the client. The case-reference classes are label-anchored for that reason, so a client's own reference written bare is missed. |
| Markets not yet live have no classes | France, Italy, Belgium and Ireland are absent. They get authored by that market's counsel when the market opens, not guessed now. |
* Label-anchored. The class fires on the label written next to the value; the same value written bare in a sentence is not reached. Stated here rather than left to be discovered.
The substitution is reversible and is therefore pseudonymisation under UK GDPR Art. 4(5), not anonymisation. The mapping is generated in the Controller's browser, used there, and never transmitted. Several classes are label-anchored: they fire on the label written next to the value, and a value written bare is not reached — the date-of-birth and case-reference gaps below state where.