Legal

Data Processing Addendum

This addendum forms part of the agreement when dashboardWISE processes personal data on a customer’s behalf.

Last updated 25 August 2026

On this page

Application and Acceptance

This Data Processing Addendum (“DPA”) forms part of the Terms of Service, an Order Form, or another written agreement governing the customer’s use of the dashboardWISE services (the “Agreement”). It applies to the extent dashboardWISE LLC processes Customer Personal Data on the customer’s behalf.

This DPA becomes effective when the customer accepts the Agreement or when the parties otherwise agree to it. A person accepting this DPA for a customer represents that the person has authority to bind that customer and, where the customer acts for another controller, has authority to give the instructions described here.

This DPA does not govern personal data for which dashboardWISE determines the purposes and means of processing, such as business contact, billing, website, security, and service-improvement data described in the Privacy Policy. That processing is governed by the Privacy Policy and applicable law.

Definitions

“Applicable Data Protection Law” means the privacy, data protection, and data security laws that apply to the processing of Customer Personal Data under the Agreement, including, where applicable, the EU GDPR, UK GDPR, the UK Data Protection Act 2018, and United States state privacy laws.

“Customer Personal Data” means personal data contained in Customer Data that dashboardWISE processes on the customer’s behalf to provide the services. It does not include data for which dashboardWISE acts as an independent controller.

“EU GDPR” means Regulation (EU) 2016/679. “UK GDPR” has the meaning given in section 3(10) of the UK Data Protection Act 2018. “SCCs” means the standard contractual clauses in the Annex to European Commission Implementing Decision (EU) 2021/914.

“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner and laid before Parliament under section 119A of the Data Protection Act 2018, as amended or replaced.

“Security Incident” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data processed by dashboardWISE. It excludes unsuccessful attempts or activities that do not compromise Customer Personal Data, including unsuccessful log-in attempts, scans, pings, and denial-of-service attacks.

“Controller,” “processor,” “data subject,” “personal data,” “processing,” “supervisory authority,” and “subprocessor” have the meanings given by Applicable Data Protection Law. “Including” means “including without limitation.”

Roles and Scope

The customer is a controller of Customer Personal Data, or a processor acting on a controller’s behalf. dashboardWISE is respectively a processor or subprocessor. Each party will comply with Applicable Data Protection Law in performing its role.

dashboardWISE will process Customer Personal Data only to provide, secure, support, and maintain the services in accordance with the Agreement, this DPA, the customer’s documented use and configuration of the services, and other documented instructions accepted by dashboardWISE. Annex I describes the subject matter, duration, nature, purpose, data subjects, and data categories.

dashboardWISE will promptly inform the customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law. It may suspend the affected processing until the parties agree on a lawful instruction, without being required to perform legal analysis on the customer’s behalf.

Customer Instructions

The Agreement, this DPA, the customer’s authorised product settings, its use of available features and integrations, and its written support requests are the customer’s complete documented instructions at the effective date. Additional instructions must be consistent with the Agreement and technically and organisationally feasible.

dashboardWISE may process Customer Personal Data as required by applicable law. Before doing so, it will inform the customer of that legal requirement unless the law prohibits notice on important grounds of public interest.

If an additional instruction requires material work beyond the services, dashboardWISE may charge reasonable fees or require the parties to agree on scope, timing, and costs before performing it.

Customer Obligations

The customer is responsible for the lawfulness, fairness, accuracy, quality, and scope of Customer Personal Data and its instructions. The customer will establish a valid legal basis, provide required notices, obtain required consents or authorisations, and respect data subject rights before directing dashboardWISE to process Customer Personal Data.

The customer will use the services only in accordance with Applicable Data Protection Law, the Agreement, and the Acceptable Use Policy. It will not provide Customer Personal Data that dashboardWISE is not permitted to process or direct dashboardWISE to process data in a way that violates a person’s rights.

The customer determines whether the services, their configuration, and the safeguards in this DPA are appropriate for its processing, including any professional secrecy, legal privilege, retention, residency, or sector-specific duties. The customer remains responsible for account administration, authorised-user access, connected-service permissions, and its own systems and credentials.

Confidentiality and Personnel

dashboardWISE will ensure that persons authorised to process Customer Personal Data are subject to confidentiality obligations or an appropriate statutory duty of confidentiality and process the data only as necessary for their assigned responsibilities.

Access is limited according to role and need. dashboardWISE is responsible for the compliance of its authorised personnel with the obligations in this DPA while they process Customer Personal Data.

Security

Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, as well as the risk to individuals, dashboardWISE will maintain appropriate technical and organisational measures designed to protect Customer Personal Data against a Security Incident. The current measures are described in Annex II and on the Security page.

dashboardWISE may update its measures as technology, risk, and the services change, provided that the overall security of the services is not materially reduced during the term. No method of transmission, storage, or security is completely secure, and this section does not create an absolute guarantee against every incident.

Security Incidents

dashboardWISE will notify the customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. Notice will be sent to the customer’s account, security, or administrative contact unless another contact has been agreed.

To the extent known and reasonably available, notice will describe the nature of the Security Incident, the categories of affected data and data subjects, the likely consequences, measures taken or proposed, and a contact for follow-up. dashboardWISE may provide information in phases as the investigation develops and will take reasonable steps to contain, investigate, and mitigate the Security Incident.

dashboardWISE will reasonably cooperate with the customer’s legally required notifications. The customer remains responsible for deciding whether to notify a supervisory authority, data subjects, clients, or other parties unless Applicable Data Protection Law assigns that duty directly to dashboardWISE. Notice is not an admission of fault or liability.

Data Subject Requests

Taking into account the nature of the processing, dashboardWISE will provide appropriate technical and organisational assistance, insofar as reasonably possible, for the customer to respond to requests to exercise rights of access, correction, deletion, restriction, portability, objection, or rights relating to automated decision making.

If dashboardWISE receives a request relating to Customer Personal Data directly from a data subject, it will not respond substantively except on the customer’s documented instructions or as required by law. Where legally permitted, dashboardWISE will direct the requester to the customer or notify the customer of the request.

Compliance Assistance

Taking into account the nature of processing and the information available to dashboardWISE, dashboardWISE will reasonably assist the customer with obligations under Articles 32 through 36 of the EU GDPR and equivalent requirements under Applicable Data Protection Law. This includes relevant security information, Security Incident response, data protection impact assessments, and prior consultation with supervisory authorities.

dashboardWISE will provide information reasonably available to it but is not required to obtain legal advice for the customer, prepare the customer’s legal filings, or disclose information that would compromise another customer, security, privilege, or a third party’s confidentiality. Material assistance beyond ordinary service operation may be subject to reasonable, pre-agreed fees, except to the extent required because dashboardWISE breached this DPA.

Subprocessors

The customer gives dashboardWISE general written authorisation to engage the subprocessors identified in Annex III and on the Subprocessors page. dashboardWISE will enter into a written agreement with each subprocessor that imposes data protection obligations no less protective in substance than the obligations applicable to that subprocessor’s processing under this DPA.

dashboardWISE remains responsible for each subprocessor’s performance of those obligations to the same extent it would be responsible if performing the relevant processing itself, subject to the Agreement. dashboardWISE will assess a subprocessor’s ability to protect Customer Personal Data before appointment and require an appropriate transfer mechanism where necessary.

dashboardWISE will provide at least 15 days’ advance notice before a new subprocessor begins materially processing Customer Personal Data. The customer may object during that period on reasonable, documented data protection grounds. The parties will work in good faith to address the objection, including by using a commercially reasonable alternative where available.

If no reasonable solution is available, either party may terminate only the affected service by written notice. dashboardWISE will refund prepaid fees for the terminated service covering the period after termination. This is the customer’s exclusive remedy for a subprocessor objection. Where an emergency replacement is reasonably necessary to preserve security, availability, or legal compliance, dashboardWISE may appoint the replacement first and provide notice without undue delay afterward.

Return and Deletion

During the term, the customer may retrieve Customer Personal Data through available service export functions. At the customer’s choice following termination or expiry, dashboardWISE will return or delete Customer Personal Data and delete existing copies, unless applicable law requires retention. If the customer does not communicate a choice, dashboardWISE may delete the data after a commercially reasonable retrieval period.

Customer Personal Data may remain in encrypted backups, immutable security records, or disaster-recovery systems until overwritten or deleted through ordinary retention cycles. While retained, residual data remains subject to this DPA, is isolated from ordinary use, and will be restored only when reasonably necessary for disaster recovery, security investigation, or legal compliance.

dashboardWISE may retain records necessary to demonstrate compliance, resolve disputes, enforce the Agreement, or meet legal obligations, provided those records are limited and protected under applicable confidentiality and security requirements.

Information and Audits

dashboardWISE will make available information reasonably necessary to demonstrate compliance with Article 28 of the EU GDPR, the UK GDPR, and this DPA. The parties will ordinarily use current security documentation, policies, summaries, and written responses before requesting an on-site or technical audit.

If that information is reasonably insufficient, the customer may conduct an audit once in any 12-month period. That limit does not apply following a Security Incident affecting the customer, where the customer has credible evidence of material non-compliance, or where a supervisory authority requires an audit.

An audit must be proportionate, limited to processing covered by this DPA, conducted during normal business hours on reasonable advance notice, and designed to avoid unreasonable disruption. The customer must use an independent auditor that is not a competitor of dashboardWISE and is bound by confidentiality. Audits may not expose another customer’s data, security-sensitive information, source code, privileged material, or information dashboardWISE is legally prohibited from disclosing.

The customer bears its audit costs and will reimburse reasonable costs incurred by dashboardWISE, unless the audit identifies a material breach of this DPA by dashboardWISE. Nothing in this section limits a supervisory authority’s lawful powers.

United States Privacy Terms

To the extent United States state privacy law applies to Customer Personal Data, dashboardWISE acts as a processor, service provider, or contractor, as those terms are defined by applicable law. The customer’s disclosure of Customer Personal Data is solely for the limited and specified business purposes described in the Agreement, this DPA, and Annex I.

dashboardWISE will not sell Customer Personal Data, share it for cross-context behavioural advertising, process it for targeted advertising, or retain, use, or disclose it outside the direct business relationship with the customer or for a purpose other than the limited and specified purposes in this DPA, except as permitted by applicable law. dashboardWISE will not combine Customer Personal Data with personal data received from another person or collected from its own interaction with an individual except as permitted by applicable law to provide the services.

dashboardWISE will not use Customer Personal Data to train a general-purpose artificial intelligence model for its independent benefit. It may use deidentified or aggregated information only where it has taken reasonable measures to prevent association with a person or customer, publicly commits to maintain the information in deidentified form, and does not attempt to reidentify it.

dashboardWISE certifies that it understands and will comply with the restrictions in this section. It will notify the customer if it determines that it can no longer meet an applicable obligation. The customer may take reasonable and appropriate steps to verify, discontinue, and remediate unauthorised use, subject to the audit safeguards in this DPA.

International Transfers

Customer Personal Data may be processed in the United States, where the dashboardWISE production environment is hosted, and may be accessed by authorised dashboardWISE personnel in Pakistan for service operation and support. Subprocessors may process data in the locations identified on the Subprocessors page. The customer authorises those transfers subject to this DPA.

Each party will use a lawful transfer mechanism for a restricted transfer under Applicable Data Protection Law. Where required, the SCCs and UK Addendum are incorporated as described below. If another valid transfer mechanism applies, including an adequacy decision, the parties may rely on that mechanism for as long as it remains valid.

On reasonable request, dashboardWISE will provide information reasonably available to support the customer’s transfer impact assessment. dashboardWISE will consider whether applicable law or practice prevents it from complying with the relevant transfer terms and will notify the customer if it can no longer comply.

Where legally permitted, dashboardWISE will review government demands for Customer Personal Data, seek to narrow demands that are overbroad or unlawful, challenge them where there are reasonable grounds, and notify the customer before disclosure. dashboardWISE will disclose only the data it is legally required to disclose and will document requests as required by the applicable transfer terms.

EU Standard Contractual Clauses

For a transfer of Customer Personal Data governed by the EU GDPR that is not otherwise subject to an adequate transfer mechanism, the SCCs are incorporated into this DPA by reference and completed as follows.

  • Module Two applies where the customer is a controller and dashboardWISE is a processor. Module Three applies where the customer is a processor and dashboardWISE is a subprocessor.
  • Clause 7, the optional docking clause, applies. In Clause 9(a), Option 2, general written authorisation, applies, with the notice period stated in the Subprocessors section of this DPA.
  • The optional language in Clause 11 does not apply. In Clause 17, Option 1 applies and the governing law is the law of Ireland. Under Clause 18(b), the courts of Ireland have jurisdiction.
  • Annex I of this DPA completes Annex I.A and Annex I.B of the SCCs. The competent supervisory authority under Annex I.C is determined under Clause 13. Where Clause 13 permits the parties to identify a supervisory authority and no other authority is mandated, the Irish Data Protection Commission is identified.
  • Annex II of this DPA completes Annex II of the SCCs. Annex III of this DPA completes Annex III of the SCCs.

For Module Three, the customer warrants that its controller has authorised dashboardWISE as a subprocessor and the customer will provide information required under Clause 8.3 to that controller. dashboardWISE may give required subprocessor notices to the customer, and the customer is responsible for forwarding them to its controller where required.

The signatures or other binding acceptance of the Agreement are treated as signatures to the SCCs. The SCCs terminate only as permitted by their terms or when the relevant transfer no longer requires them.

UK Addendum

For a restricted transfer governed by the UK GDPR that is not otherwise subject to an adequate transfer mechanism, the UK Addendum is incorporated into this DPA and completed as follows.

  • Table 1 identifies the customer as exporter and dashboardWISE as importer, using the party details and key contacts in Annex I.
  • Table 2 identifies the approved EU SCCs as the SCCs completed in the EU Standard Contractual Clauses section of this DPA, including the applicable Module Two or Module Three selections.
  • Table 3 is completed by Annexes I, II, and III of this DPA.
  • In Table 4, both the importer and exporter may end the UK Addendum as permitted by section 19 of its Mandatory Clauses.

The Mandatory Clauses in Part 2 of the UK Addendum apply. References in the SCCs to the EU, Member State law, and supervisory authorities are interpreted for UK restricted transfers as required by the UK Addendum.

Priority, Liability and Third-Party Rights

If there is a conflict concerning processing of Customer Personal Data, the order of priority is: the applicable SCCs or UK Addendum; this DPA; then the Agreement. An Order Form changes this DPA only if it expressly identifies the provision being changed and is signed by authorised representatives of both parties.

The exclusions and limitations of liability in the Agreement apply to this DPA, and liability arising under this DPA is aggregated with liability under the Agreement rather than creating a separate or additional cap. Nothing limits liability or data subject rights to the extent a limitation is prohibited by Applicable Data Protection Law, the SCCs, or the UK Addendum.

Except for data subjects entitled to enforce rights under the SCCs or UK Addendum and any supervisory authority with mandatory enforcement powers, this DPA creates no rights for third-party beneficiaries. A person may not recover more than once for the same loss.

Annex I — Processing Details

Data Exporter. The customer identified in the Agreement or applicable Order Form. Its address, contact details, and activities relevant to the transfer are those stated in the Agreement or customer account. The exporter’s role is controller under Module Two or processor under Module Three. The customer’s authorised account contact is the transfer contact unless it identifies another contact in writing.

Data Importer. dashboardWISE LLC, 8 The Green STE A, Dover, Kent County, DE 19901, United States. Email: support@dashboardwise.com. The importer provides law-firm analytics, reporting, integrations, synchronisation, automation, account administration, security, and support. Its role is processor under Module Two or subprocessor under Module Three.

Subject Matter and Purpose. Processing Customer Personal Data to provide, secure, maintain, and support the dashboardWISE services in accordance with documented customer instructions. Processing may include receiving, accessing, collecting, importing, storing, structuring, organising, normalising, matching, analysing, calculating, retrieving, displaying, exporting, transmitting, synchronising, restricting, backing up, and deleting data.

Frequency and Duration. Processing is continuous or intermittent according to the customer’s use, connected-service sync schedules, support requests, and service operation. It continues for the term of the Agreement and the limited period necessary for return, deletion, backups, security, dispute resolution, and legal compliance.

Data Subjects. Customer personnel and authorised users; current and prospective clients; contacts; matter participants; counterparties; lawyers and other professionals; employees, contractors, and service providers; payors and payment recipients; and other individuals represented in records the customer directs dashboardWISE to process.

Personal Data. Names, business and personal contact details, account and role information, user identifiers, matter and client records, practice areas, work and time entries, billing and payment records, expenses, trust transaction information, engagement and status data, communications and notes, connected-service identifiers, authentication and access records, device and network data, and operational metadata.

Sensitive Data. The standard service does not require special-category or criminal-conviction data. Customer-connected legal records may nevertheless contain information about health, race or ethnicity, religion, political views, trade-union membership, sexual life or orientation, biometric or genetic data, criminal allegations or convictions, government identifiers, financial accounts, precise location, or other sensitive data. Safeguards include encryption, firm-scoped access, role and permission controls, confidentiality, logging, and customer-controlled source permissions. The customer will limit sensitive data to what is lawful and necessary.

Locations and Retention. Customer Personal Data is hosted in the customer’s assigned regional service cell: AWS us-west-1 (Oregon) for the United States service or AWS eu-west-2 (London) for the United Kingdom service. Authorised dashboardWISE personnel may access data from Pakistan. Subprocessor locations are described in Annex III and on the Subprocessors page. Retention is determined by the Agreement, customer configuration and instructions, the Return and Deletion section, backup cycles, and applicable law.

Supervisory Authority. The competent supervisory authority is determined under Clause 13 of the SCCs based on the data exporter’s establishment, representative, or affected data subjects. The parties identify the Irish Data Protection Commission only where Clause 13 permits a contractual selection and no other authority is mandated.

Annex II — Technical and Organisational Measures

dashboardWISE applies measures appropriate to the services and risk. The measures below describe the current production design and may evolve in accordance with the Security section.

  • Identity and Access. Account authentication, protected sessions, short-lived verification codes, optional two-factor authentication, server-derived firm scoping, and role and permission checks for customer users.
  • Encryption. TLS for public service traffic; encrypted production database, object storage, and backups; and AES 256 GCM encryption for connected-service credentials and authenticator secrets.
  • Network and Infrastructure. An isolated database network, service security groups, restricted ingress through AWS CloudFront and the application load balancer, and service-specific infrastructure permissions.
  • Secrets. Production secrets and parameters are stored outside source code using AWS-managed secret and parameter services, with access limited by scoped service identities.
  • Tenant Separation. Firm, provider-source, permission, reporting-time-zone, and data-generation scope are derived and enforced through the service request path.
  • Service Resilience. Encrypted backups, deletion protection, queue isolation, bounded retries, health checks, operational monitoring, and documented recovery and deployment procedures.
  • Application and Integration Security. Provider webhook validation, origin controls, rate limiting, encrypted integration credentials, controlled token rotation, software review, automated checks, and scoped production deployment identities.
  • Detection and Response. Operational and security logging, failure handling, monitoring alarms, investigation, and incident containment and remediation procedures.
  • Confidentiality and Disposal. Need-based access, confidentiality obligations, customer export capability, active-data deletion, and protected residual backup data pending ordinary expiration.

These measures do not represent certification under any external security standard unless dashboardWISE expressly identifies a current certification in writing.

Annex III — Approved Subprocessors

The current approved subprocessors for Customer Personal Data are listed below. The Subprocessors page provides the maintained public list and current location details.

  • Amazon Web Services, Inc. Cloud hosting, database, object storage, queues, content delivery, monitoring, and transactional infrastructure. Primary region: United States us-west-1 (Oregon) or United Kingdom eu-west-2 (London), according to the customer’s assigned service cell. Data depends on customer use and may include all Customer Personal Data hosted in the service.
  • Axiom, Inc. Operational logging and service observability. Data is limited through logging design and may include request metadata, masked contact data, technical identifiers, and error context. Current processing location is identified on the Subprocessors page.

PostHog, Inc., Polar Software, Inc., and Cal.com, Inc. may process analytics, billing, subscription, tax, or scheduling information for dashboardWISE’s own business purposes and are described in the Privacy Policy and Subprocessors page. They are not treated as Customer Data subprocessors unless they process Customer Personal Data on the customer’s behalf.

Customer-selected connected services, including Clio Manage and Smokeball, are independently chosen and authorised by the customer. They are not dashboardWISE-appointed subprocessors merely because the customer directs dashboardWISE to exchange data with them.

Contracting entity

dashboardWISE LLC

Registered address

8 The Green STE ADover, Kent County, DE 19901United States

Legal contact

support@dashboardwise.com

State of Delaware, United States