Skip to content

Legal

Data Processing
Agreement.

You are the data controller for your clients' material. Leeside Labs Limited is your processor. This page sets out the Article 28 GDPR terms we work to, and how to get a signed copy for your file. Last reviewed September 2026.

Ask and it is yours

A signed DPA, back within 48 hours.

Email us with your practice or firm name and we will send an Article 28 agreement, executed on our side, for you to countersign. No account, no sales call, no charge. We will send a transfer impact assessment or answer a security questionnaire on the same terms.

Who is controller, and who is processor

The split matters more in a practice than in most businesses, because almost everything you dictate is somebody else’s personal data.

  • You are the controller for the material you dictate, photograph, paste or upload — your clients, the other side, witnesses, figures, correspondence. You decide what goes in and why. We process it only to give the service back to you.
  • We are the controller for your own account: your name and email, your professional role and practice name, billing records, and consent-gated analytics. That is our relationship with you, not your relationship with your client.

Nothing on this page changes the first line of that split. If we ever start processing your matter material for our own purposes, we would be a controller for it, and we would have to tell you and give you a basis to object. We do not, and the architecture is built so that we would have to change the product to start.

What the agreement commits us to

These are the Article 28(3) obligations, in the order the Regulation sets them out, and what each one means in practice here.

(a) We process only on your documented instructions

Your use of the service is the instruction. We do not mine your documents for our own purposes, we do not use them to train models — ours or anyone else’s — and if a law ever required us to process your material for some other reason, we would tell you before doing it unless that law forbids it.

(b) Everyone with access is under confidentiality

Access to production is limited to the people who run the service, all of whom are bound by confidentiality obligations that survive the engagement.

(c) We keep Article 32 security measures

Set out in full below, and we will describe any of them in more detail on request rather than hand you a certificate and call it an answer.

(d) Subprocessors, with notice and a right to object

You give general written authorisation for the subprocessors listed on our subprocessors page — six of them, of which two ever see matter content. We will give you advance notice of any addition or replacement, and you may object; if we cannot resolve the objection you may terminate without penalty for the remaining term. Every subprocessor is bound by data protection obligations no weaker than these, and we stay liable to you for what they do.

(e) We help you answer your clients

If a client of yours makes an access, rectification, erasure, restriction, portability or objection request, we help you answer it. Most of it you can do yourself inside the app; for anything you cannot, email us and we will do it within the time your own one-month deadline leaves you.

(f) We help with security, breaches and impact assessments

We notify you without undue delay after becoming aware of a personal data breach affecting your material, with what we know and what we are doing, so that you can meet your own Article 33 deadline. Where we are the controller, we notify the Data Protection Commission within 72 hours. We also help with a data protection impact assessment or prior consultation where the processing calls for one.

(g) We delete or return it when you are done

You can export at any time. On account deletion, all of it — audio recordings, scanned pages, transcripts, documents, workspace data — is permanently deleted within 30 days, unless EU or Irish law requires us to keep something (billing records, for seven years, which contain no matter content).

(h) We show our work

We make available the information needed to demonstrate compliance with these obligations: this page, the subprocessor register, our privacy policy, a transfer impact assessment, and completed security questionnaires. We will accommodate an audit or inspection at reasonable notice, once a year or whenever a supervisory authority requires one.

What we will not do is imply a certification we do not hold. Leeside Labs Limited is not ISO 27001 certified and holds no SOC 2 report today. We would rather tell you that plainly than let a badge on a page answer a question it does not answer.

Annex I

The processing, described

What a completed Annex I to the Standard Contractual Clauses would say, filled in for clerk&.

Subject matter
Provision of the clerk& dictation, drafting and document service.
Duration
For as long as your account is active, plus the deletion window described below. Billing records are kept for seven years under Irish Revenue and VAT law; they contain transaction metadata, never matter content.
Nature and purpose
Recording and transcribing dictation; generating, formatting and storing documents; classifying and filing them; resolving a recipient’s public office address; storage, search and retrieval on your instruction.
Types of personal data
Whatever appears in the material you dictate, photograph, paste or upload — typically client names and contact details, solicitor and firm details, matter references, court and hearing details, fee and settlement figures, and any personal data contained in the correspondence itself. Also your own account data: name, email, professional role, practice name, country and subscription state.
Categories of data subject
Your clients; opposing parties, witnesses and other individuals named in a matter; solicitors and other professionals you correspond with; and the members of your own workspace.
Special category data
Matter material may contain Article 9 data (for example health information in a personal-injury action) or Article 10 criminal-offence data. We process it as part of the document, on your instruction. You, as controller, are responsible for establishing the Article 9(2) or Article 10 basis.

Annex II

Technical and organisational measures

Article 32 GDPR. Specific enough to be checkable — and short enough to read.

Encryption in transit

TLS 1.3 on every connection between your device, our functions and every processor.

Encryption at rest

AES-256 across the database, both object stores, and backups.

Tenant isolation

Postgres row-level security scopes every read and write to your workspace. It is enforced by the database, not by application code that might forget.

Authenticated on every request

Microsoft OAuth sign-in with short-lived tokens. Every backend function verifies its caller — an authenticated user, or a verified webhook signature. Nothing reads your data anonymously.

Short-lived signed URLs

Audio recordings and uploaded documents are never public. They are reached only through workspace-scoped URLs that expire in minutes.

EEA-only processing

Every processor runs in an EEA region, with the single disclosed exception of the recipient-address lookup.

No training on your content

Contractual, not a policy statement: Google does not use Vertex AI prompts or responses to train its models, and neither do we.

Minimised logging

Operational logs carry request identifiers, timings and anonymised account identifiers — not dictation or document content. Retained no longer than seven days.

Least-privilege access

Production access is limited to the people who need it to run the service, over authenticated administrative interfaces, and is not used to read customer material except where you ask us to investigate something.

Separated environments

Development and production are separate projects with separate credentials. Customer data is not copied into development.

Deletion that actually deletes

Account deletion removes audio, scanned pages, transcripts, documents and workspace data across every store within 30 days, including from backups as they roll.

Analytics that cannot see matter content

Product analytics is opt-in, carries no dictation or document content, and is switched off entirely if you decline.

Annex III

Authorised subprocessors

The list you authorise when you sign. Each one's own data processing terms are linked.

  • Supabase

    Supabase, Inc.

    Database, authentication, backend functions, and storage for scanned pages and templates

    EEA — Ireland

    Matter content: yes

    Their data processing terms
  • Google Cloud

    Google Cloud EMEA Ltd (Dublin)

    All AI inference; object storage for audio recordings and uploaded documents; nightly database backups

    EEA — Belgium and the EU multi-region

    Matter content: yes

    Their data processing terms
  • Vercel

    Vercel, Inc.

    Website and application hosting, CDN

    EEA — Ireland

    Matter content: no

    Their data processing terms
  • Stripe

    Stripe Payments Europe Ltd (Dublin)

    Subscription billing and VAT calculation

    EEA — Ireland

    Matter content: no

    Their data processing terms
  • PostHog

    PostHog, Inc.

    Product analytics and session replay — consent-gated, off until you accept

    EEA — Germany

    Matter content: no

    Their data processing terms
  • Brevo

    Sendinblue SAS

    Transactional and notification email, workspace activity digest

    EEA — France

    Matter content: no

    Their data processing terms

Microsoft is not on this list, and not in the register. Sign-in uses your own Microsoft tenant, which makes Microsoft an independent controller for your account rather than our processor — the reasoning is on the subprocessors page.

International transfers

All processing happens in the European Economic Area, with one disclosed exception: the recipient-address lookup, which sends a solicitor’s name — and nothing else — to a Google service that is not contractually EEA-resident. You can turn it off for your whole workspace.

Where a transfer to a third country does occur, it is governed by the 2021 Standard Contractual Clauses in the module appropriate to our role in that transfer, together with the supplementary measures in Annex II above. Several of our subprocessors are US-incorporated even though they process in the EEA; the CLOUD Act consequences of that, including the one we cannot mitigate, are set out honestly on the subprocessors page. A transfer impact assessment is available on request.

How this fits with our other terms

This page describes the agreement we offer and work to; the signed counterpart is the instrument. It sits alongside the terms of service, which govern the commercial relationship, and the privacy policy, which explains what we do with your own account data as controller. Where the signed agreement and this page differ, the signed agreement governs.

Questions, objections, and requests all go to the same place: hello@clerkand.com. Our supervisory authority is the Data Protection Commission in Ireland.

Put your AI clerk to work.

Free 14-day trial. No credit card. Five-minute setup. Whether you’re a sole practitioner or running a busy clerk’s room, clerk& earns its keep on the first fee note.

Also on your phone

Download on the App StoreGet it on Google Play