Legal

Data Processing Addendum

Version 1.0 · Effective date: January 1, 2026 · Last updated: January 1, 2026


This Data Processing Addendum ("DPA") forms part of the Lextiff Terms of Service ("Agreement") entered into between Canvas Chrome Designs, the developer and operator of Lextiff ("Processor," "Lextiff," "we," "our," or "us"), and the Customer identified in the applicable subscription agreement, order form, or Terms of Service ("Controller," "Customer," "you," or "your").

This DPA governs the Processing of Personal Data by Lextiff on behalf of the Customer in connection with the Services.

Where this DPA conflicts with the Terms of Service regarding the Processing of Personal Data, this DPA shall prevail to the extent of that conflict.

1. Purpose

The purpose of this DPA is to establish the rights and obligations of the parties regarding the Processing of Personal Data by Lextiff while providing the Services.

The parties intend this DPA to satisfy applicable contractual requirements under applicable privacy and data protection laws, including, where applicable:

  • United States federal privacy laws;
  • applicable U.S. state privacy laws;
  • the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA);
  • the Virginia Consumer Data Protection Act (VCDPA);
  • the Colorado Privacy Act (CPA);
  • the Connecticut Data Privacy Act (CTDPA);
  • the Utah Consumer Privacy Act (UCPA);
  • and, where applicable, the European Union General Data Protection Regulation (GDPR), the UK GDPR, and other applicable privacy laws.

2. Definitions

"Controller" means the party that determines the purposes and means of Processing Personal Data.

"Processor" means the party Processing Personal Data on behalf of the Controller.

"Personal Data" means any information relating to an identified or identifiable natural person processed by Lextiff on behalf of the Customer through the Services.

"Processing" means any operation performed upon Personal Data including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, restriction, deletion, and destruction.

"Customer Data" means all information uploaded, submitted, stored, transmitted, or otherwise processed through the Services by or on behalf of Customer. Customer Data may include Personal Data.

"Data Subject" means the identified or identifiable individual to whom Personal Data relates.

"Security Incident" means an actual or reasonably confirmed unauthorized access, acquisition, disclosure, alteration, destruction, or loss of Customer Personal Data. A Security Incident does not include unsuccessful attempts or activities that do not compromise Personal Data, including but not limited to port scans, firewall blocks, unsuccessful login attempts, denial-of-service attempts that do not result in unauthorized disclosure, vulnerability scans, or malware quarantined prior to affecting Customer Data.

"Subprocessor" means any third party authorized by Lextiff to Process Personal Data while providing the Services.

"Services" means the cloud-based Lextiff legal practice management platform together with associated applications, APIs, integrations, documentation, customer support, and related services.

"Applicable Data Protection Laws" means all laws governing the Processing of Personal Data applicable to the parties under this DPA.

3. Scope

This DPA applies whenever Lextiff Processes Personal Data on behalf of Customer while providing the Services.

This DPA applies to all Customer accounts regardless of subscription plan unless a separate negotiated agreement expressly supersedes this DPA.

4. Relationship of the Parties

The parties acknowledge and agree that:

  • Customer acts as the Controller (or Processor acting on behalf of another Controller where applicable).
  • Lextiff acts solely as a Processor.
  • Customer determines what Personal Data is collected, why it is processed, who may access it, and how long it should be retained.
  • Lextiff determines only the technical means reasonably necessary to provide the Services.

Nothing in this DPA transfers ownership of Customer Data to Lextiff.

5. Customer Instructions

Lextiff shall Process Personal Data only:

  • pursuant to the Agreement;
  • pursuant to this DPA;
  • according to Customer's documented instructions;
  • as configured by Customer through the Services;
  • where required by applicable law.

If applicable law requires Processing beyond Customer's instructions, Lextiff shall notify Customer before such Processing unless prohibited by law.

If Lextiff reasonably believes that a Customer instruction violates applicable law, Lextiff may suspend the relevant Processing and notify Customer.

6. Customer Responsibilities

Customer represents and warrants that:

  • it has all necessary legal rights to provide Personal Data to Lextiff;
  • all required notices have been provided to Data Subjects;
  • all required consents have been obtained where necessary;
  • Personal Data is collected lawfully;
  • Personal Data is accurate to the best of Customer's knowledge;
  • Customer's Processing complies with applicable law.

Customer remains solely responsible for:

  • determining the lawful basis for Processing;
  • responding to Data Subject requests unless otherwise agreed;
  • complying with attorney ethical obligations;
  • complying with court rules;
  • complying with HIPAA where applicable;
  • managing user permissions;
  • disabling accounts of former employees;
  • maintaining endpoint security within its organization.

7. Nature and Purpose of Processing

Lextiff Processes Personal Data solely for purposes including:

  • hosting the Services;
  • authenticating users;
  • managing law firm accounts;
  • storing legal documents;
  • organizing case files;
  • processing client intake information;
  • facilitating secure communications;
  • generating reports;
  • providing document storage;
  • maintaining audit logs;
  • supporting workflow automation;
  • enabling AI-assisted productivity features, where offered;
  • providing customer support;
  • maintaining backups;
  • improving reliability and security of the Services;
  • complying with applicable law.

Lextiff shall not Process Customer Personal Data for advertising purposes.

Lextiff shall not sell Customer Personal Data.

Lextiff shall not use Customer Personal Data to build marketing profiles.

8. Categories of Personal Data

Depending upon Customer's use of the Services, Lextiff may Process categories of Personal Data including:

Client Information

  • names; addresses; telephone numbers; email addresses; dates of birth; driver's license information; government-issued identification where provided by Customer.

Medical Information

  • injury descriptions; treatment records; diagnoses; provider information; prescriptions; medical expenses; rehabilitation records; imaging reports.

Insurance Information

  • policy numbers; claim numbers; adjuster information; insurer correspondence.

Legal Information

  • pleadings; litigation documents; evidence; witness information; attorney notes; case timelines; settlement documents; trust accounting records.

Employment Information

  • employer details; payroll records; wage information; employment history.

Financial Information

  • settlement allocations; liens; expenses; invoices; payment history.

Technical Information

  • IP addresses; browser information; authentication logs; audit logs; device identifiers; security events.

9. Categories of Data Subjects

Personal Data may relate to:

  • attorneys; law firm employees; clients; prospective clients; witnesses; medical providers; experts; insurers; opposing parties; vendors; consultants; contractors; authorized users.

10. Confidentiality

Lextiff shall ensure that all personnel authorized to Process Customer Personal Data are subject to appropriate confidentiality obligations. Such obligations may arise through employment agreements, contractor agreements, confidentiality agreements, company policies, or applicable law.

Access to Customer Personal Data shall be limited to personnel who require such access to perform their assigned responsibilities in connection with providing or supporting the Services. Lextiff shall implement internal access controls designed to prevent unauthorized personnel from accessing Customer Personal Data.

Confidentiality obligations shall survive termination of employment, engagement, and this DPA.

11. Technical and Organizational Security Measures

Lextiff shall implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.

Security measures are designed taking into account the nature of the Services, the categories of Personal Data processed, the risks presented by Processing, the state of available technology, implementation costs, and industry best practices.

While no security program can eliminate every risk, Lextiff is committed to maintaining safeguards appropriate to the Services and the information entrusted to it.

12. Encryption

Where appropriate and technically feasible, Lextiff employs encryption technologies to protect Customer Personal Data. These measures may include:

  • Transport Layer Security (TLS) for data transmitted over public networks;
  • encryption of stored data using industry-accepted encryption standards where applicable;
  • encrypted backups;
  • encryption of secrets, credentials, and API keys using secure key management practices.

Encryption keys are managed using appropriate administrative and technical safeguards intended to reduce the risk of unauthorized access.

13. Authentication and Access Control

Lextiff implements controls designed to ensure that only authorized individuals may access Customer Personal Data. Depending on the Services used, these controls may include:

  • role-based access controls (RBAC);
  • least-privilege access principles;
  • unique user accounts;
  • password hashing using industry-accepted algorithms;
  • session management controls;
  • authentication logging;
  • account lockout protections;
  • optional multi-factor authentication where available.

Customer is responsible for configuring user permissions appropriate to its organization and promptly removing access for users who no longer require it.

14. Logging and Monitoring

Lextiff maintains logging and monitoring capabilities designed to support security, operational integrity, and incident response. Depending on the Services, logs may include:

  • authentication events; account activity; administrative actions; document access events; system errors; infrastructure events; API requests; security alerts.

Logs are used to investigate security incidents, troubleshoot technical issues, detect suspicious activity, improve platform reliability, and satisfy compliance and auditing requirements where applicable.

Access to logs is restricted to authorized personnel with a legitimate business need.

15. Vulnerability Management

Lextiff maintains a security program intended to identify and remediate vulnerabilities affecting the Services. This program may include software updates, security patches, dependency management, vulnerability scanning, code reviews, security testing, and monitoring of publicly disclosed vulnerabilities.

Security updates are deployed based on risk, operational impact, and availability.

16. Backup and Disaster Recovery

Lextiff maintains commercially reasonable backup and disaster recovery procedures designed to reduce the risk of data loss and improve service resilience. Such measures may include encrypted backups, redundant storage, geographically resilient infrastructure where appropriate, periodic restoration testing, disaster recovery planning, and infrastructure monitoring.

Customer acknowledges that no backup or disaster recovery process can guarantee the prevention of all data loss. Customers are encouraged to maintain independent copies of critical records where appropriate.

17. Physical Security

Where Lextiff utilizes third-party cloud infrastructure providers, physical security of data centers is managed by those providers. Such providers are generally responsible for implementing measures including facility access controls, surveillance, environmental controls, redundant power, fire suppression, hardware disposal procedures, and visitor management.

Lextiff evaluates cloud providers based on appropriate security and operational standards.

18. Customer Security Responsibilities

Customer acknowledges that information security is a shared responsibility. Customer agrees to maintain strong passwords, protect authentication credentials, configure user permissions appropriately, remove access for former personnel without unnecessary delay, secure devices used to access the Services, maintain appropriate antivirus and endpoint protection, promptly report suspected unauthorized access, and comply with applicable privacy and security laws.

Lextiff is not responsible for security incidents resulting primarily from Customer's failure to maintain reasonable security practices.

19. Subprocessors

Customer grants Lextiff general authorization to engage Subprocessors as reasonably necessary to provide the Services. Subprocessors may perform services including cloud hosting, secure storage, email delivery, SMS delivery, payment processing, infrastructure monitoring, authentication, customer support, backup services, analytics, and artificial intelligence features requested by the Customer.

Before engaging a Subprocessor, Lextiff shall take reasonable steps to ensure that the Subprocessor is contractually required to provide protections for Personal Data that are substantially similar to those required under this DPA. Lextiff remains responsible for the performance of its Subprocessors with respect to their Processing activities on behalf of Lextiff, to the extent required by applicable law.

A current list of Subprocessors is published on the Lextiff Subprocessor List and updated from time to time.

20. Artificial Intelligence Processing

Lextiff does not currently offer AI-assisted features. Should such features be introduced in the future, this section will govern their Processing of Customer Personal Data, and Customers will be notified in accordance with Section 36 (Changes to this DPA).

21. Privacy by Design

Lextiff seeks to incorporate privacy and security considerations into the design, development, and operation of the Services. Where appropriate, Lextiff considers data minimization, least-privilege access, secure default configurations, logging and accountability, confidentiality, integrity, availability, and resilience.

Privacy and security practices may evolve over time as technology, legal requirements, and industry standards develop.

22. Assistance with Data Subject Requests

To the extent required by Applicable Data Protection Laws, Lextiff shall provide reasonable assistance to Customer in responding to verified requests from Data Subjects concerning Personal Data processed through the Services, including rights to access, correct, delete, restrict, object to Processing, or receive Personal Data in a portable format where required by law.

Where technically feasible, Customer may fulfill many such requests directly through the administrative features of the Services.

If Lextiff receives a request directly from a Data Subject relating to Customer Data, Lextiff will, unless prohibited by law, promptly notify Customer and direct the requester to Customer. Lextiff will not respond directly to such requests except as required by applicable law or authorized by Customer.

23. Government and Law Enforcement Requests

If Lextiff receives a subpoena, court order, search warrant, or other legally binding request from a governmental authority seeking access to Customer Personal Data, Lextiff shall, unless prohibited by applicable law, promptly notify Customer of the request, provide Customer with a copy of the request where legally permitted, and provide reasonable cooperation to allow Customer to seek protective relief or otherwise respond to the request.

Lextiff will disclose only the Personal Data reasonably required to comply with the applicable legal obligation.

Nothing in this section requires Lextiff to challenge or refuse a lawful governmental request where doing so would violate applicable law.

24. Security Incidents and Personal Data Breaches

Lextiff maintains incident response procedures designed to identify, investigate, contain, mitigate, and remediate Security Incidents affecting Customer Personal Data.

Upon becoming aware of a confirmed Security Incident involving Customer Personal Data, Lextiff shall, without undue delay and taking into account the information reasonably available at the time, notify the affected Customer; describe the nature of the Security Incident; identify, where reasonably known, the categories of Personal Data affected; describe the likely consequences of the Security Incident, if reasonably known; describe measures taken or proposed to address the Security Incident; and provide updates as additional material information becomes available.

The timing and content of notifications may be affected by the need to investigate the incident, prevent further harm, preserve evidence, or comply with applicable law.

Notification of a Security Incident shall not constitute an admission of fault or liability by Lextiff.

25. Incident Response

Lextiff maintains a documented incident response process designed to detect potential security events, assess severity and scope, contain and mitigate incidents, investigate root causes, restore affected systems, and implement corrective actions where appropriate.

Following a material Security Incident, Lextiff may review and enhance its security controls to reduce the likelihood of similar incidents.

26. HIPAA and Protected Health Information

Some Customers may process information that constitutes Protected Health Information ("PHI") under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"). Customer is solely responsible for determining whether its use of the Services is subject to HIPAA or other healthcare privacy laws.

Where required by applicable law and agreed by the parties, Customer and Lextiff may enter into a separate Business Associate Agreement ("BAA"). This DPA does not itself constitute a Business Associate Agreement.

Unless a BAA has been fully executed, Customer shall not rely upon this DPA as satisfying HIPAA Business Associate requirements, and Lextiff does not assume the legal obligations of a HIPAA Business Associate solely by virtue of providing the Services.

Where a BAA is in effect, the terms of that BAA shall govern the Processing of PHI to the extent of any conflict with this DPA.

27. Cross-Border Data Transfers

Customer acknowledges that Personal Data may be processed and stored in jurisdictions where Lextiff or its authorized Subprocessors operate.

Where cross-border transfers of Personal Data are subject to Applicable Data Protection Laws, Lextiff will implement appropriate safeguards reasonably designed to support lawful transfers, which may include:

  • contractual safeguards;
  • Standard Contractual Clauses (SCCs) where required by law;
  • transfer mechanisms recognized under Applicable Data Protection Laws; or
  • other lawful transfer mechanisms available at the time of transfer.

28. Data Return and Deletion

Upon expiration or termination of the Agreement, Customer may request an export of Customer Data in a commercially reasonable and commonly used electronic format, subject to the terms of the Agreement.

Following the applicable data retention period described in the Terms of Service, Lextiff shall delete Customer Personal Data from active production systems, or anonymize such data where deletion is not reasonably practicable.

Customer acknowledges that encrypted backup copies containing Customer Personal Data may remain within secure backup systems for a limited period before being overwritten or securely deleted in accordance with Lextiff's backup retention schedule.

Where Applicable Data Protection Laws require continued retention of certain information, Lextiff may retain such information only for the period and purposes required by law.

29. Compliance Assistance

Taking into account the nature of the Processing and the information available to Lextiff, Lextiff shall provide reasonable assistance to Customer in meeting obligations under Applicable Data Protection Laws where such assistance is necessary and reasonably requested. Such assistance may relate to security documentation, regulatory inquiries concerning the Services, privacy assessments, incident investigations, responses to supervisory authorities, and documentation concerning technical and organizational measures.

Lextiff may charge reasonable fees for assistance that exceeds routine support obligations or requires significant additional resources.

30. Audits

Upon reasonable written request and subject to appropriate confidentiality obligations, Lextiff shall make available information reasonably necessary to demonstrate compliance with this DPA. Lextiff may satisfy such requests by providing independent audit reports, security certifications, compliance documentation, security questionnaires, summaries of technical and organizational measures, or other relevant documentation, where available.

Where such documentation is insufficient to satisfy a legal requirement applicable to Customer, the parties may mutually agree upon a reasonable audit process that minimizes disruption to Lextiff's operations, protects the confidentiality of other customers, preserves the security of the Services, and is conducted during normal business hours upon reasonable advance notice.

Unless otherwise required by law or agreed in writing, Customer shall bear its own costs associated with any audit.

31. Records of Processing

Lextiff maintains records of its Processing activities to the extent required by Applicable Data Protection Laws. Such records may include categories of Processing activities, categories of Personal Data processed, categories of recipients, categories of Subprocessors, applicable retention practices, and descriptions of technical and organizational safeguards.

32. Cooperation with Supervisory Authorities

Where required by Applicable Data Protection Laws, Lextiff shall cooperate with competent supervisory or regulatory authorities regarding its obligations as a Processor, taking into account the confidentiality of Customer Data and the rights of other customers.

33. Limitation of Liability

Except as expressly provided in this DPA, each party's liability arising out of or relating to this DPA shall be subject to the limitations and exclusions of liability contained in the Lextiff Terms of Service.

Nothing in this DPA shall exclude or limit liability to the extent such limitation is prohibited by applicable law.

Where Applicable Data Protection Laws impose direct obligations on either party, each party remains responsible for complying with its own statutory obligations.

34. Term and Termination

This DPA becomes effective on the earlier of the Effective Date stated above, the date Customer first uses the Services, or the effective date of the applicable Agreement.

This DPA remains in force for as long as Lextiff Processes Personal Data on behalf of Customer.

Termination of the Agreement automatically terminates this DPA, except for provisions that by their nature are intended to survive termination, including:

  • confidentiality;
  • data deletion obligations;
  • audit rights;
  • liability provisions;
  • dispute resolution;
  • governing law.

35. Order of Precedence

In the event of any conflict between this DPA, the Terms of Service, the Privacy Policy, or any executed Business Associate Agreement (BAA), the following order of precedence shall apply with respect to the Processing of Personal Data:

  1. Executed Business Associate Agreement (where applicable)
  2. This Data Processing Addendum
  3. Terms of Service
  4. Privacy Policy

Except as expressly modified by this DPA, the Terms of Service remain in full force and effect.

36. Changes to this DPA

Lextiff may update this DPA from time to time to reflect changes in applicable law, improve security practices, introduce new Services, update Subprocessors, or reflect operational improvements.

Where material changes are made, Lextiff will provide notice by email, in-application notification, or publication on the Lextiff website.

Unless otherwise required by law, revised versions become effective on the date specified in the updated DPA. Continued use of the Services after the effective date constitutes acceptance of the revised DPA.

37. Governing Law

This DPA shall be governed by the governing law and dispute resolution provisions contained in the Lextiff Terms of Service, unless otherwise agreed in writing by the parties.

Annex I — Details of Processing

Controller: Customer (Law Firm or Organization)

Processor: Canvas Chrome Designs (Lextiff)

Subject Matter: Processing of Personal Data necessary for providing the Lextiff legal practice management platform and related Services.

Nature of Processing:

Collection, storage, organization, retrieval, hosting, transmission, backup, encryption, indexing, searching, deletion, secure disposal.

Purpose of Processing:

Provide the Services; authenticate users; manage legal matters; store documents; facilitate communications; support workflow automation; provide customer support; improve platform reliability and security; comply with legal obligations.

Duration: For the duration of the Customer's subscription and any applicable post-termination retention period described in the Agreement.

Categories of Data Subjects:

Attorneys, law firm employees, legal assistants, paralegals, firm administrators, clients, prospective clients, witnesses, medical providers, insurers, experts, vendors, contractors.

Categories of Personal Data:

Contact information, identification information, case information, medical information, insurance information, financial information, settlement information, communications, authentication logs, audit logs, uploaded documents.

Special Categories of Data:

Where Customer elects to upload such information: Protected Health Information (PHI), medical records, treatment records, disability information, injury information, and other sensitive information processed by Customer.

Annex II — Technical and Organizational Measures

Organizational Security

Confidentiality obligations for personnel; security awareness training; role-based responsibilities; documented security policies.

Identity and Access Management

Unique user accounts; role-based access controls; least-privilege principles; authentication controls; password protection; optional multi-factor authentication where available.

Encryption

Encrypted communications using TLS; encryption of stored data where applicable; encrypted backups; secure key management practices.

Infrastructure Security

Secure cloud hosting; network segmentation where appropriate; infrastructure monitoring; vulnerability management; patch management.

Logging and Monitoring

Authentication logging; audit trails; security event monitoring; operational monitoring; incident investigation support.

Availability

Redundant infrastructure where appropriate; automated backups; disaster recovery procedures; restoration testing.

Secure Development

Secure software development practices; change management; testing prior to production deployment; dependency management; remediation of identified vulnerabilities.

Incident Response

Documented incident response procedures; investigation processes; containment measures; customer notification where required.

Annex III — Authorized Subprocessors

A current, maintained list of Lextiff's authorized Subprocessors — including their category and purpose — is published separately so it can be kept up to date without requiring changes to this DPA.

View the Subprocessor List →

Contact Information

Questions regarding this Data Processing Addendum may be directed to:

Privacy Team, Lextiff (Operated by Canvas Chrome Designs)

Email: privacy@lextiff.com

Security: security@lextiff.com

Website: https://www.lextiff.com