Legal
Data Processing
Agreement.
You are the data controller for your clients' material. Leeside Labs Limited is your processor. This page sets out the Article 28 GDPR terms we work to, and how to get a signed copy for your file. Last reviewed September 2026.
Ask and it is yours
A signed DPA, back within 48 hours.
Email us with your practice or firm name and we will send an Article 28 agreement, executed on our side, for you to countersign. No account, no sales call, no charge. We will send a transfer impact assessment or answer a security questionnaire on the same terms.
Who is controller, and who is processor
The split matters more in a practice than in most businesses, because almost everything you dictate is somebody else’s personal data.
- You are the controller for the material you dictate, photograph, paste or upload — your clients, the other side, witnesses, figures, correspondence. You decide what goes in and why. We process it only to give the service back to you.
- We are the controller for your own account: your name and email, your professional role and practice name, billing records, and consent-gated analytics. That is our relationship with you, not your relationship with your client.
Nothing on this page changes the first line of that split. If we ever start processing your matter material for our own purposes, we would be a controller for it, and we would have to tell you and give you a basis to object. We do not, and the architecture is built so that we would have to change the product to start.
What the agreement commits us to
These are the Article 28(3) obligations, in the order the Regulation sets them out, and what each one means in practice here.
(a) We process only on your documented instructions
Your use of the service is the instruction. We do not mine your documents for our own purposes, we do not use them to train models — ours or anyone else’s — and if a law ever required us to process your material for some other reason, we would tell you before doing it unless that law forbids it.
(b) Everyone with access is under confidentiality
Access to production is limited to the people who run the service, all of whom are bound by confidentiality obligations that survive the engagement.
(c) We keep Article 32 security measures
Set out in full below, and we will describe any of them in more detail on request rather than hand you a certificate and call it an answer.
(d) Subprocessors, with notice and a right to object
You give general written authorisation for the subprocessors listed on our subprocessors page — six of them, of which two ever see matter content. We will give you advance notice of any addition or replacement, and you may object; if we cannot resolve the objection you may terminate without penalty for the remaining term. Every subprocessor is bound by data protection obligations no weaker than these, and we stay liable to you for what they do.
(e) We help you answer your clients
If a client of yours makes an access, rectification, erasure, restriction, portability or objection request, we help you answer it. Most of it you can do yourself inside the app; for anything you cannot, email us and we will do it within the time your own one-month deadline leaves you.
(f) We help with security, breaches and impact assessments
We notify you without undue delay after becoming aware of a personal data breach affecting your material, with what we know and what we are doing, so that you can meet your own Article 33 deadline. Where we are the controller, we notify the Data Protection Commission within 72 hours. We also help with a data protection impact assessment or prior consultation where the processing calls for one.
(g) We delete or return it when you are done
You can export at any time. On account deletion, all of it — audio recordings, scanned pages, transcripts, documents, workspace data — is permanently deleted within 30 days, unless EU or Irish law requires us to keep something (billing records, for seven years, which contain no matter content).
(h) We show our work
We make available the information needed to demonstrate compliance with these obligations: this page, the subprocessor register, our privacy policy, a transfer impact assessment, and completed security questionnaires. We will accommodate an audit or inspection at reasonable notice, once a year or whenever a supervisory authority requires one.
What we will not do is imply a certification we do not hold. Leeside Labs Limited is not ISO 27001 certified and holds no SOC 2 report today. We would rather tell you that plainly than let a badge on a page answer a question it does not answer.
Annex I
The processing, described
What a completed Annex I to the Standard Contractual Clauses would say, filled in for clerk&.
- Subject matter
- Provision of the clerk& dictation, drafting and document service.
- Duration
- For as long as your account is active, plus the deletion window described below. Billing records are kept for seven years under Irish Revenue and VAT law; they contain transaction metadata, never matter content.
- Nature and purpose
- Recording and transcribing dictation; generating, formatting and storing documents; classifying and filing them; resolving a recipient’s public office address; storage, search and retrieval on your instruction.
- Types of personal data
- Whatever appears in the material you dictate, photograph, paste or upload — typically client names and contact details, solicitor and firm details, matter references, court and hearing details, fee and settlement figures, and any personal data contained in the correspondence itself. Also your own account data: name, email, professional role, practice name, country and subscription state.
- Categories of data subject
- Your clients; opposing parties, witnesses and other individuals named in a matter; solicitors and other professionals you correspond with; and the members of your own workspace.
- Special category data
- Matter material may contain Article 9 data (for example health information in a personal-injury action) or Article 10 criminal-offence data. We process it as part of the document, on your instruction. You, as controller, are responsible for establishing the Article 9(2) or Article 10 basis.
Annex II
Technical and organisational measures
Article 32 GDPR. Specific enough to be checkable — and short enough to read.
Encryption in transit
TLS 1.3 on every connection between your device, our functions and every processor.
Encryption at rest
AES-256 across the database, both object stores, and backups.
Tenant isolation
Postgres row-level security scopes every read and write to your workspace. It is enforced by the database, not by application code that might forget.
Authenticated on every request
Microsoft OAuth sign-in with short-lived tokens. Every backend function verifies its caller — an authenticated user, or a verified webhook signature. Nothing reads your data anonymously.
Short-lived signed URLs
Audio recordings and uploaded documents are never public. They are reached only through workspace-scoped URLs that expire in minutes.
EEA-only processing
Every processor runs in an EEA region, with the single disclosed exception of the recipient-address lookup.
No training on your content
Contractual, not a policy statement: Google does not use Vertex AI prompts or responses to train its models, and neither do we.
Minimised logging
Operational logs carry request identifiers, timings and anonymised account identifiers — not dictation or document content. Retained no longer than seven days.
Least-privilege access
Production access is limited to the people who need it to run the service, over authenticated administrative interfaces, and is not used to read customer material except where you ask us to investigate something.
Separated environments
Development and production are separate projects with separate credentials. Customer data is not copied into development.
Deletion that actually deletes
Account deletion removes audio, scanned pages, transcripts, documents and workspace data across every store within 30 days, including from backups as they roll.
Analytics that cannot see matter content
Product analytics is opt-in, carries no dictation or document content, and is switched off entirely if you decline.
Annex III
Authorised subprocessors
The list you authorise when you sign. Each one's own data processing terms are linked.
Supabase
Supabase, Inc.
Database, authentication, backend functions, and storage for scanned pages and templates
EEA — Ireland
Matter content: yes
Their data processing termsGoogle Cloud
Google Cloud EMEA Ltd (Dublin)
All AI inference; object storage for audio recordings and uploaded documents; nightly database backups
EEA — Belgium and the EU multi-region
Matter content: yes
Their data processing termsVercel
Vercel, Inc.
Website and application hosting, CDN
EEA — Ireland
Matter content: no
Their data processing termsStripe
Stripe Payments Europe Ltd (Dublin)
Subscription billing and VAT calculation
EEA — Ireland
Matter content: no
Their data processing termsPostHog
PostHog, Inc.
Product analytics and session replay — consent-gated, off until you accept
EEA — Germany
Matter content: no
Their data processing termsBrevo
Sendinblue SAS
Transactional and notification email, workspace activity digest
EEA — France
Matter content: no
Their data processing terms
Microsoft is not on this list, and not in the register. Sign-in uses your own Microsoft tenant, which makes Microsoft an independent controller for your account rather than our processor — the reasoning is on the subprocessors page.
International transfers
All processing happens in the European Economic Area, with one disclosed exception: the recipient-address lookup, which sends a solicitor’s name — and nothing else — to a Google service that is not contractually EEA-resident. You can turn it off for your whole workspace.
Where a transfer to a third country does occur, it is governed by the 2021 Standard Contractual Clauses in the module appropriate to our role in that transfer, together with the supplementary measures in Annex II above. Several of our subprocessors are US-incorporated even though they process in the EEA; the CLOUD Act consequences of that, including the one we cannot mitigate, are set out honestly on the subprocessors page. A transfer impact assessment is available on request.
How this fits with our other terms
This page describes the agreement we offer and work to; the signed counterpart is the instrument. It sits alongside the terms of service, which govern the commercial relationship, and the privacy policy, which explains what we do with your own account data as controller. Where the signed agreement and this page differ, the signed agreement governs.
Questions, objections, and requests all go to the same place: hello@clerkand.com. Our supervisory authority is the Data Protection Commission in Ireland.
Put your AI clerk to work.
Free 14-day trial. No credit card. Five-minute setup. Whether you’re a sole practitioner or running a busy clerk’s room, clerk& earns its keep on the first fee note.
