This Data Processing Agreement ("DPA") forms part of and is subject to the Juris Terms of Service (the "Agreement") between the subscribing law firm or legal practice (the "Firm") and Kwata Team, an Alberta sole proprietorship and operator of the Juris service. It sets out how Kwata Team processes personal data contained in the Firm's materials when the Firm uses Juris. If there is a conflict between this DPA and the Agreement on personal-data processing, this DPA governs.
1. Roles
For all personal data the Firm submits to or generates within Juris ("Firm Personal Data"), the Firm is the controller and Juris is the processor, acting solely on the Firm's documented instructions. The Firm determines the purposes and means of processing; Juris processes only to provide the service.
2. Scope and instructions
Juris processes Firm Personal Data only to provide, maintain, secure, and support the service; as further instructed by the Firm through its use of the service's features; and as required by law, in which case Juris will inform the Firm unless legally prohibited. The Firm's use of the service, together with this DPA and the Agreement, is its complete and documented instructions.
3. Purpose limitation
- ·Never training data. Firm Personal Data is never used to train, fine-tune, or improve any AI model, whether ours or a third party's. It is used only to perform the task the Firm asked for, inside the Firm's account.
- ·Never sold. Firm Personal Data is never sold, rented, or disclosed to advertisers or data brokers.
- ·Account isolation. Firm Personal Data is walled off from every other customer account.
4. Confidentiality and security
Persons authorized to process Firm Personal Data are bound by confidentiality. Juris maintains technical and organizational measures to protect Firm Personal Data, described in Schedule A. The Firm remains responsible for its own access credentials, device security, and user administration.
5. Subprocessors
The Firm grants Juris general authorization to engage the subprocessors listed by function in Schedule B. Juris imposes data-protection obligations on each subprocessor that are materially consistent with this DPA and remains responsible for their performance. Juris will give the Firm at least 30 days' notice before adding or replacing a subprocessor; if the Firm objects on reasonable data-protection grounds, the parties will discuss in good faith, and failing resolution the Firm may terminate the affected service and receive a pro-rated refund of prepaid, unused fees.
6. International transfers
Juris will maintain a lawful basis for any cross-border processing it performs and will provide, on request, a description of the safeguards in place. Where a Firm is subject to a data-protection regime requiring specific transfer instruments, the parties will agree those instruments in a written addendum.
7. Assistance and data-subject requests
Taking into account the nature of the processing, Juris will reasonably assist the Firm to respond to individuals exercising their rights (access, correction, deletion, portability) and to meet the Firm's own security, breach-notification, and impact-assessment obligations. Juris forwards to the Firm, without undue delay, any such request it receives directly and does not respond to the individual except to confirm the request was forwarded. The Firm, as controller, is responsible for responding to individuals and for any regulatory notifications.
8. Security-incident notification
Juris will notify the Firm of a security incident affecting Firm Personal Data without undue delay, and in any event within 72 hours of becoming aware, describing the nature of the incident, the categories of data affected, the likely consequences, and the measures taken or proposed. The Firm, as controller, determines whether the incident triggers a reporting obligation and makes any such report; Juris's notice is not an admission of fault or liability.
9. Audit and evidence of compliance
On the Firm's written request, no more than once in any 12-month period, Juris will make available documentation reasonably necessary to demonstrate compliance with this DPA, including a description of its security measures and written responses to a reasonable set of security questions. Where documentation is insufficient for a specific regulatory requirement, the parties will agree in advance on a limited, scoped audit at the Firm's expense, on at least 30 days' notice, conducted so as not to compromise other customers' data or Juris's security. Juris does not currently hold a SOC 2 or ISO 27001 report; if one exists, providing it satisfies this section.
10. Return and deletion
The Firm may export its complete data at any time through the self-serve export feature. On termination, Juris will delete Firm Personal Data within 30 days unless retention is required by law. Deletion removes stored files, search-index vectors, and database records, not merely database rows, and Juris will confirm deletion in writing on request.
11. Retention is the Firm's responsibility
The Firm, not Juris, holds the professional and legal duty to retain client files and records for the periods required by its governing law society, limitation statutes, and other applicable law. Those periods commonly exceed any period for which the Firm keeps an account active with Juris. The Firm meets that duty by exporting and retaining its own copy. Juris retains an account while it is active and may permanently delete it on the Firm's request or after a documented period of inactivity, following advance notice; the Firm is responsible for keeping a current contact email and for exporting anything it must retain before an account is deleted.
12. Firm responsibilities
- ·The Firm has a lawful basis and any necessary consents to submit the Firm Personal Data it chooses to submit and to instruct the processing described here.
- ·The Firm is solely responsible for what it inputs, for classifying documents (including the privileged-document flag), for supervising and verifying all output, and for all professional decisions made using the service.
- ·The Firm remains the professional of record and the decision-maker for every matter; Juris provides tools, not legal advice or a legal opinion.
13. Liability, warranties, and technology risk
All liability, limitation of liability, disclaimer of warranties, force majeure, and indemnification arising out of or related to this DPA and the service are governed exclusively by the corresponding provisions of the Agreement (the Juris Terms of Service), which apply equally to this DPA. This DPA does not create, increase, or vary either party's liability beyond what the Agreement provides.
Without limiting that, the Firm acknowledges that the service uses artificial intelligence and other technology that can produce inaccurate, incomplete, or fabricated output and can be interrupted or unavailable; that the Firm is responsible for independently verifying all output before relying on it or filing it; and that the Firm remains the sole decision-maker for every matter.
14. Term, precedence, and general
This DPA takes effect when the Firm accepts the Agreement and continues while Juris processes Firm Personal Data. On any conflict about personal-data processing, this DPA governs, then the Agreement; on any conflict about liability, warranties, force majeure, indemnification, or risk allocation, the Agreement governs. This DPA is governed by the laws of the Province of Alberta and the applicable laws of Canada. If any provision is unenforceable, the rest remains in effect.
Schedule A — Security measures
- ·Isolation: each Firm's data sits in a dedicated database schema, a dedicated search-index collection, and storage segregated by account.
- ·Encryption: files, extracted text, and search-index text are encrypted at rest under a key unique to the Firm; all connections use current TLS.
- ·Not zero-knowledge: the service decrypts transiently to read, analyze, and serve. Access is limited to providing the service, is application-mediated, and is logged.
- ·Privileged-document exclusion: documents the Firm flags as privileged are excluded from all AI processing at the data layer.
- ·Access and audit: application-mediated reads; an audit log records document views and downloads, privilege-flag changes, and access grants and revocations; two-factor authentication available.
- ·Deletion and backups: deletion removes files, vectors, and records; encrypted backups support recovery.
- ·Alignment: designed and operated in alignment with PIPEDA and the Alberta Personal Information Protection Act. No third-party security certification is held today.
Schedule B — Subprocessors (by function)
- ·Managed cloud hosting provider — compute, database, and file storage that run the service.
- ·Enterprise AI model provider — the language-model processing that powers analysis and drafting, under a no-training commitment.
- ·Transactional email delivery provider — account, notification, and document-forwarding email.
- ·Global edge content-delivery network — secure, faster delivery of the application to the browser.
Each is bound by data-protection obligations materially consistent with this DPA. A current function-level list is available on request; named-vendor detail is available under confidentiality to a Firm conducting formal due diligence.
Annex 1 — Nature of the processing
- ·Subject matter and duration: provision of the Juris service, for the term of the Agreement and until deletion.
- ·Nature and purpose: storing, organizing, analyzing, searching, and drafting from the Firm's case materials, solely to provide the service. Never used to train AI, never sold.
- ·Data subjects: the Firm's clients and other individuals named in the Firm's matters.
- ·Categories of data: identifying and contact information, matter and case details, and the contents of documents the Firm submits. The Firm controls what it submits.