42B AI, Inc. DATA PROCESSING ADDENDUM
Last Updated: September 10, 2026
This Data Processing Addendum ("DPA") is entered into between 42B AI, Inc., a Delaware corporation ("Processor" or "42B"), and the customer identified in the applicable Order Form or Terms of Service acceptance ("Controller" or "Customer"), and forms part of the Terms of Service or other master agreement between the parties governing Customer's use of the Service (the "Principal Agreement"). Capitalized terms not defined here have the meaning given in the Principal Agreement.
This DPA takes effect automatically, by reference, upon Customer's acceptance of the Terms of Service (for self-serve Customers) or execution of the applicable Order Form (for negotiated Customers). No separate signature is required. A Customer that requires a countersigned copy for its own records or vendor review process may request one, using the signature block at the end of this DPA.
1. Definitions
- (a) “Data Protection Laws” means applicable U.S. federal and state laws governing the privacy, security, and processing of personal data, including without limitation the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”) and other applicable state comprehensive privacy laws.
- (b) “Controller” means the party that determines the purposes and means of processing Personal Data (Customer); “Processor” means the party that processes Personal Data on a Controller's behalf (42B) — used here for clarity of roles, consistent with how these terms are used across U.S. state privacy laws, regardless of the specific statutory label (e.g., “business”/“service provider” under the CCPA).
- (c) “Personal Data,” “Processing,” and “Personal Data Breach” have their ordinary meanings under applicable Data Protection Laws.
- (d) “Sub-processor” means any processor engaged by 42B to process Personal Data on Customer's behalf.
2. Roles of the Parties
As between the parties, Customer is the Controller and 42B is the Processor of Personal Data contained in Customer Data (e.g., names, roles, hours, and rates of Customer's outside counsel personnel appearing in uploaded invoices and guidelines). Each party will comply with the obligations applicable to its role under Data Protection Laws.
3. Scope of Processing
42B will process Personal Data only: (a) on Customer's documented instructions, including as set out in the Principal Agreement and this DPA, unless required to do otherwise by law (in which case 42B will inform Customer before processing, unless prohibited from doing so); and (b) as described in Annex I.
4. Processor Obligations
- (a) Confidentiality. 42B will ensure that personnel authorized to process Personal Data are subject to a duty of confidentiality.
- (b) Security. 42B will implement the technical and organizational measures described in Annex II, taking into account the state of the art, costs of implementation, and the risk to Data Subjects.
- (c) Sub-processors. Customer authorizes 42B to engage the Sub-processors listed in Annex III. 42B will notify Customer at least 30 days before adding a new Sub-processor by updating Annex III or the subprocessor list referenced in 42B's Privacy Policy, and Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, Customer may terminate the affected Service and, upon request, may receive a pro-rata refund of any prepaid, unused fees for the terminated portion. 42B remains liable for Sub-processor performance to the same extent as for its own acts.
- (d) Assistance. 42B will provide reasonable assistance to Customer, at Customer's expense for anything beyond standard platform functionality, with: (i) responding to Data Subject requests; (ii) Customer's data protection impact assessments; and (iii) Customer's obligations to notify Personal Data Breaches to supervisory authorities and affected individuals.
- (e) Breach Notification. 42B will notify Customer without undue delay upon becoming aware, of a Personal Data Breach affecting Customer's Personal Data, except where delayed at the legal request of law enforcement or governmental authority investigating the matter, and will provide information reasonably available to help Customer meet its own notification obligations.
- (f) Deletion or Return. On termination of the Principal Agreement, 42B will, at Customer's election, delete or return all Personal Data, and delete existing copies, unless retention is required by law.
- (g) Audit Rights. 42B will make available information reasonably necessary to demonstrate compliance with this DPA, including via a summary of a recent third-party security audit or certification (e.g., SOC 2), and will permit and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, on reasonable notice and subject to confidentiality, no more than once per year absent a Personal Data Breach or regulatory requirement.
5. Liability
Each party's liability arising out of this DPA is subject to the limitation of liability set out in the Principal Agreement.
6. Term
This DPA remains in effect for as long as 42B processes Personal Data on Customer's behalf under the Principal Agreement.
ANNEX I. Details of Processing
Subject Matter and Duration
Provision of the 42B outside counsel guideline and invoice compliance Service, for the duration of the Principal Agreement.
Nature and Purpose of Processing
Hosting, storage, and AI-assisted analysis of uploaded outside counsel guidelines and invoices to generate a compliance rules engine and invoice-review output for Customer's use.
Categories of Data Subjects
Customer's outside counsel personnel and other individuals named in uploaded invoices or guidelines (e.g., timekeepers).
Categories of Personal Data
Name, professional role/title (e.g., Partner, Associate), years of experience, hours worked, billing rate, and narrative descriptions of work performed, as they appear in uploaded invoices and guidelines. No special category data is intentionally collected.
Frequency of Transfer
Continuous, for as long as Customer uses the Service.
Sources of Data
All data - Data Subjects, Personal Data, all invoice and outside counsel guideline information - is delivered either explicitly by Customer or at Customer’s express request and authority.
ANNEX II. Technical and Organizational Security Measures
- (a) Encryption of Personal Data in transit (TLS) and at rest.
- (b) Access controls limiting access to Personal Data to personnel who need it, with unique credentials and, where available, multi-factor authentication.
- (c) Logical separation of Customer Data by account.
- (d) Confidentiality obligations for personnel with access to Personal Data.
- (e) Regular backups and a documented incident-response process.
ANNEX III. Authorized Sub-processors
| Sub-Processor | Manages | Location |
|---|---|---|
| Stripe, Inc. | Payment processing | United States |
| Google LLC | Google Workspace email, calendar, chat | United States |
| Microsoft Corporation | Azure hosting | United States |
| Google LLC | AI model provider | United States |
This DPA takes effect automatically, by reference, upon Customer's acceptance of the Terms of Service (for self-serve Customers) or execution of the applicable Order Form (for negotiated Customers). No separate signature is required. A Customer that requires a countersigned copy for its own records or vendor review process may request one, using the signature block below.
IN WITNESS WHEREOF, the parties have caused this DPA to be executed by their duly authorized representatives.
42B.ai, Inc.
Name: __________________________
Title: ___________________________
Date: ___________________________
Signature: _______________________
[COUNTERPARTY LEGAL NAME]
Name: __________________________
Title: ___________________________
Date: ___________________________
Signature: _______________________