- Trust Center
- Security
- Assist Mi Legal Data Processing Addendum
Trust Center / Security
enterpriseAssist Mi Legal Data Processing Addendum
Enterprise data-processing terms defining controller and processor roles, processing instructions, confidentiality, safeguards, subprocessors, breach notice, audits, retention, and deletion.
- Version
- starter-2026-06
- Effective
- July 31, 2026
- Last updated
- August 2, 2026
# Assist Mi Legal Data Processing Addendum
Version 1.0
Effective Date: August 1, 2026
This Data Processing Addendum ("DPA") forms part of the Assist Mi
Legal Terms of Service, Enterprise Agreement, or other governing
agreement between Customer and Assist Mi Legal.
This DPA applies whenever Assist Mi Legal processes Personal
Data on behalf of Customer.
## 1. Definitions
Customer
The organization subscribing to the Services.
Controller
The entity that determines the purposes and means of processing
Personal Data.
Processor
The entity processing Personal Data on behalf of a Controller.
Personal Data
Information relating to an identified or identifiable individual.
Processing
Any operation performed on Personal Data, including collection,
storage, organization, retrieval, disclosure, transmission, deletion, or
destruction.
Subprocessor
A third party engaged by Assist Mi Legal to support delivery of the
Services.
## 2. Roles
Customer acts as Controller of Personal Data submitted to the
Services.
Assist Mi Legal acts as Processor of such Personal Data.
Assist Mi Legal will process Personal Data only:
To provide the Services
To comply with documented Customer instructions
To satisfy legal obligations
## 3. Processing Activities
Processing may include:
Storage
Retrieval
Search
Organization
Workflow automation
AI-assisted processing
Reporting
Synchronization
Security monitoring
Processing is limited to activities reasonably necessary to provide
the Services.
## 4. Customer Instructions
Customer instructs Assist Mi Legal to process Personal Data as
necessary to:
Deliver Services
Maintain Services
Support integrations
Perform authorized workflows
Deliver AI-powered functionality
Additional documented instructions may be provided by Customer.
## 5. Confidentiality
Assist Mi Legal shall ensure that personnel authorized to process
Personal Data are subject to appropriate confidentiality obligations.
## 6. Security Measures
Assist Mi Legal shall maintain commercially reasonable
administrative, technical, and organizational safeguards designed
to protect Personal Data.
Examples may include:
Access controls
Authentication controls
Encryption in transit
Encryption at rest where applicable
Audit logging
Monitoring
Backup procedures
Security review processes
No system can guarantee absolute security.
## 7. Subprocessors
Customer authorizes Assist Mi Legal to engage Subprocessors as
reasonably necessary to provide Services.
Subprocessors may include providers supporting:
Cloud hosting
Authentication
Email delivery
Monitoring
Infrastructure
AI processing
Customer support
Assist Mi Legal shall maintain responsibility for Subprocessor
compliance consistent with this DPA.
## 8. AI Service Providers
Customer acknowledges that AI-powered functionality may utilize
third-party AI providers.
Such providers may process Customer data solely to provide
requested functionality.
Use of AI functionality remains subject to:
Terms of Service
AI Use Policy
Applicable agreements
## 9. International Transfers
Customer acknowledges that Personal Data may be processed in
jurisdictions where Assist Mi Legal or its service providers operate.
Assist Mi Legal shall take commercially reasonable measures to
support lawful transfers where required.
## 10. Security Incidents
Assist Mi Legal shall notify Customer without unreasonable delay
upon becoming aware of a confirmed Security Incident affecting
Personal Data processed on behalf of Customer.
Notification may include:
Nature of incident
Categories of affected information
Known impact
Mitigation efforts
Recommended actions
Notification does not constitute an admission of fault or liability.
## 11. Assistance
Where reasonably feasible, Assist Mi Legal will provide information
necessary to assist Customer in responding to:
Access requests
Deletion requests
Correction requests
Applicable privacy obligations
## 12. Audits
Customer may request reasonable information regarding Assist Mi
Legal's security practices.
Assist Mi Legal may satisfy such requests through:
Security documentation
Compliance reports
Questionnaires
Certifications
Customer audits shall be reasonable in scope and frequency.
## 13. Data Retention
Customer controls retention of Customer data subject to platform
functionality and legal obligations.
Assist Mi Legal may retain information:
As required by law
For security purposes
For backup purposes
For dispute resolution
## 14. Return and Deletion
Upon termination of Services and subject to applicable legal
requirements:
Customer may request export of Customer data.
Assist Mi Legal will delete or render inaccessible Customer
data within a commercially reasonable period.
Certain information may be retained as required by law or
operational necessity.
## 15. Liability
Liability arising under this DPA shall be governed by the liability
provisions contained within the governing agreement.
## 16. Order of Precedence
In the event of conflict:
1. Enterprise Agreement or MSA
2. This DPA
3. Terms of Service
## 17. Acceptance
Execution of the governing agreement or continued use of
Enterprise Services constitutes acceptance of this DPA.