Skip to content

Data Processing

HAQQ's data processing agreement is not a separate document. It is Book III of the Terms of Service, and this page is a readable map of it — what HAQQ does with a firm's data, in which role, and under which commitments.

Who is the controller and who is the processor

The roles are not fixed across the platform. They depend on the subscription and on which processing activity is in question, and Book III §B splits them three ways.

Controller and processor roles, per Book III §B
SituationControllerHAQQ's role
Business Subscription — data the firm puts into the platformThe Customer. The firm determines the purposes and means of processing.Processor, acting on the Customer's documented instructions.
Personal Subscription — account, billing, usage, fraud, support, compliance dataHAQQ.Controller.
Personal Subscription — third-party personal data the subscriber uploadsThe Personal Subscriber, for that data.Processor for that data.
HAQQ's own billing, accounting, tax, fraud prevention, sanctions compliance, security monitoring, legal claims, product administration and corporate governanceHAQQ, independently.Independent controller.

Which privacy laws attach is a separate question from where the data is hosted. §C is explicit that residency sets the default hosting location, while the law that applies also turns on where the data subject is, where the controller or processor is established, which markets the service is offered into, and the nature of the data. The Terms name the GDPR, UK GDPR, UAE PDPL, KSA PDPL, Oman PDPL, the Kuwait CITRA Data Privacy Protection Regulation, Bahrain PDPL and Lebanon Law No. 81 of 2018 as examples, illustratively rather than exhaustively.

What gets processed

§E lists ten categories. Most of a law firm's exposure sits in one of them — case and matter files — and that is the category the firm itself controls the contents of.

Categories of data processed, per Book III §E
CategoryWhat it covers
Identity dataNames, titles, professional and account identifiers, and government-issued identifiers where required.
Contact dataEmail addresses, phone numbers, addresses, organisation details.
Professional dataJob title, firm, bar membership, licences, practice areas, credentials, role.
Case and matter filesLegal documents, contracts, pleadings, memoranda, evidence, correspondence, discovery material, exhibits, court documents, matter notes, tasks, hearings.
CRM dataClient and contact records, relationship history, billing data, timekeeping, notes, interaction logs.
Authentication dataUsernames, hashed passwords, tokens, MFA factors, session identifiers.
System metadataIP addresses, device identifiers, browser and OS data, logs, timestamps, IP- or device-derived location, diagnostics, activity trails.
Billing and payment-interface dataInvoices, subscriptions, transaction references, payment status, tax and billing profile data. Full card data is handled by the payment partner or a PCI-DSS compliant processor, not by HAQQ.
Support dataTickets, chat content, screenshots, diagnostic files, reproduction steps, logs.
Derived dataAnonymised and aggregated telemetry, usage metrics, performance and reliability analytics, security diagnostics — none of it identifying a customer, user, client or data subject.

What HAQQ does not do with it

Two commitments in the Terms are worth reading as one, because together they are the answer to the question most firms actually ask. §B states that HAQQ's internal product development does not involve training, fine-tuning or improving AI models on customer data, matter data, prompts, outputs or user content. Book V §E goes further and states that HAQQ does not use customer data, matter data, prompts, AI inputs, AI outputs, user content, client data or support data to train, fine-tune, improve or update any foundation model, cross-customer model, third-party model or competing product. Both carve out the same single exception: a separately signed written agreement in which the customer expressly agrees, where that use is lawful.

Book V §E also draws the line the phrase “AI processing” usually blurs. Retrieval, indexing, search, summarisation, drafting assistance, classification, extraction, contextual prompting and permission-aware generation inside the customer's own tenant are processing, and they are authorised. Model training is a different act and is not. What HAQQ may keep is irreversibly anonymised, aggregated telemetry for performance, reliability, abuse, latency, capacity and security — which by definition carries no customer content and identifies no data subject. How this behaves in the product is on AI settings, and the isolation boundary it sits inside is on Data Architecture.

Obligations on each side

§I lists what HAQQ owes as processor and §J lists what the customer owes as controller. They are written as a pair and neither works without the other.

Processor and controller obligations, per Book III §§I-J
HAQQ, as processor (§I)The customer, as controller (§J)
Process personal data only on the customer's documented instructions, unless required by law.Collect, use, submit and process data lawfully.
Bind authorised personnel to confidentiality.Provide the notices and obtain the consents, client authorisations and professional approvals the use requires.
Implement the technical and organisational measures set out in the agreement.Configure permissions, access rights, retention settings and product features appropriately.
Assist with data subject requests, taking the nature of the processing into account.Respond to data subject requests where the customer is controller.
Notify confirmed personal data breaches under §P.Notify HAQQ promptly of suspected incidents affecting the products or the data.
Assist with data protection impact assessments and regulator consultations where required and reasonably necessary.Maintain security for its own systems, devices, credentials and users.
Make available the information reasonably necessary to demonstrate compliance, subject to confidentiality, security and proportionality.Comply with professional secrecy, privilege, court, bar and client-consent obligations.
Return, delete, anonymise or render inaccessible personal data under §Q, and impose equivalent obligations on subprocessors.Indemnify HAQQ for claims arising from its own unlawful processing or breach, subject to Book XIV.

Subprocessors

§L is a general authorisation: the customer authorises HAQQ to engage subprocessors, which may include cloud hosting, infrastructure, storage, analytics, payment-interface, communications, support, AI infrastructure, identity and security providers. HAQQ commits to selecting them with reasonable diligence, to written agreements imposing protections no less protective than the applicable law requires, and to remaining responsible for their acts and omissions to the extent the law and the agreement require.

A customer may object in good faith to a new subprocessor within fifteen (15) days of notice. The objection has to identify a reasonable legal, security, confidentiality, professional-responsibility or regulatory basis. If it cannot be resolved, HAQQ may make commercially reasonable alternative arrangements, or the customer may terminate the affected product or processing activity only — not the whole subscription — without penalty, paying undisputed fees accrued up to that point.

Where data is processed, and how it crosses borders

§N offers regional data residency where available, and hosts in-region by default where that is expressly committed in an order form, an official proposal or the platform configuration. Cross-border transfers may still occur where they are necessary for support, security, billing, subprocessor services, redundancy, legal compliance or operating the service at all.

Where the applicable law requires a transfer mechanism, the Terms permit reliance on adequacy decisions, Standard Contractual Clauses, UK addenda, equivalent contractual safeguards, supplementary measures, explicit consent, necessity for performance of a contract, or the establishment or defence of legal claims. Where required, HAQQ will perform or rely on transfer impact assessments and supplementary safeguards — encryption, pseudonymisation, access controls, contractual commitments and legal-environment assessment.

Security measures

§M commits HAQQ to technical and organisational measures appropriate to the risk, and lists what those may include.

  • Encryption in transit and at rest.
  • Role-based access controls, least-privilege access, and periodic access reviews.
  • Tenant isolation.
  • Logging and monitoring, and vulnerability management.
  • Incident response procedures, and backup and disaster recovery measures.
  • Personnel confidentiality obligations, security training, secure development practices.
  • Physical and environmental security through the hosting providers.
  • Penetration testing, assessments, audits or certification reviews where applicable, and customer-managed encryption keys where available on the subscription tier.

Data subject rights

§K commits HAQQ to facilitating rights requests as the applicable law requires: access, correction, deletion, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority. Requests go to info@haqq.ai, or another address HAQQ designates.

Where HAQQ is processor rather than controller — which is the normal case for a business subscription — it may refer the request to the customer and act on the customer's documented instructions, unless the law requires it to answer directly. HAQQ may require reasonable identity verification, and may reject or charge for repetitive, manifestly unfounded, excessive or unlawful requests where the law permits.

Breach notification

A personal data breach, in §P's definition, is a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to customer personal data processed by HAQQ.

The notice carries, to the extent known, the nature of the breach, the categories and approximate number of affected data subjects and records, the likely consequences, the measures taken or proposed, a contact point, and mitigation recommendations — in phases, as the picture fills in. Security alerts, unsuccessful attacks, blocked intrusion attempts and routine vulnerability reports run through the incident response programme instead; they do not automatically constitute breach notice.

Deciding whether regulators, courts, professional bodies, clients or data subjects have to be told is the customer's call, unless HAQQ has a direct legal obligation of its own. HAQQ assists where required. Each party bears its own breach-management costs unless the breach is primarily caused by the other party's breach of the agreement or of the law.

Retention, export and deletion

§Q sets out what happens after a subscription ends. The carve-outs matter as much as the periods: legal hold, tax law, audit, sanctions screening, anti-money-laundering obligations, a court order, a professional obligation or a separately executed agreement can each extend any of it.

What happens to data after termination, per Book III §Q
StagePeriodWhat happens
Export window90 days from termination or expiryThe customer retrieves its data.
Deletion from productionA commercially reasonable period after the export window closesData is deleted, anonymised or rendered inaccessible in active production systems — subject to legal, regulatory, security, backup, disaster recovery, billing, audit, dispute and compliance retention obligations.
Encrypted backups and disaster recovery archivesUp to 1 year from terminationData may persist. Longer only where law, a litigation hold, a security investigation, disaster recovery integrity or immutable-backup architecture requires it. Backups are not restored to production except for disaster recovery, security, continuity, legal compliance or investigation — and if restored, deletion or anonymisation is re-applied.
Derived dataIndefiniteRetained only where irreversibly anonymised or aggregated, so that it is not personal data under the applicable law.
Confirmation of deletionOn written requestHAQQ may provide reasonable confirmation, subject to confidentiality, security, legal and technical limits.

Audit and compliance evidence

§O grades access to evidence by who is asking. Business subscribers may request reasonable compliance evidence about HAQQ's security, confidentiality and processing obligations. Enterprise subscribers, regulated customers and customers under a specific legal or regulatory audit obligation may request additional audit materials or procedures, subject to confidentiality, security, proportionality, availability, scope and applicable fees.

Evidence normally arrives as executive summaries, certifications, audit summaries, security white papers, trust-centre materials, policy summaries or completed questionnaires. Full audit reports and penetration-test detail may require a mutual NDA and may be redacted to protect security, confidentiality, privilege or third-party rights.

On-site or remote audits are the exception, not the default: permitted only where written materials cannot satisfy a mandatory legal or regulatory obligation, limited in scope, no more than once a year unless the law requires more, with at least sixty (60) days' notice, during normal business hours, without disrupting operations, and conducted by independent auditors bound by confidentiality.

The processing schedule

§R is the annex a data protection officer looks for — the Article 28(3)-shaped description of the processing, in ten rows.

Data processing schedule, per Book III §R
ItemWhat the Terms state
Subject matterProcessing customer personal data in order to provide, secure, support, maintain, improve and administer the products and related services under the agreement, order forms, official proposals and statements of work.
DurationThe term of the subscription or service, plus any post-termination retention, export, backup, legal, regulatory, audit, dispute or compliance period described in the agreement.
Nature and purposeHosting, storage, retrieval, transmission, indexing, access control, authentication, encryption, support, troubleshooting, billing, analytics on anonymised and aggregated telemetry, AI-assisted retrieval and generation, document processing, matter management, client communication, payment-interface support, migration, integration and security monitoring.
Categories of data subjectsCustomers, authorised users, account owners, administrators, employees, contractors, lawyers, legal-service clients, counterparties, witnesses, court personnel, suppliers, contacts, prospective clients, listed professionals, bar association members, end customers, partner personnel, and anyone whose data appears in customer data.
Categories of personal dataIdentity, contact, authentication, professional, account, CRM, billing, matter and case-file data, legal documents, communications, metadata, logs, usage data, payment-interface data, KYC or intake data, and anything else the customer submits.
Sensitive dataMay be processed where the customer submits it in connection with legal matters, intake, professional workflows, evidence, litigation, family, criminal, health-related, financial or employment matters. The customer is responsible for the legal basis and safeguards.
SubprocessorsEngaged as described in §L; the current list or equivalent information made available through the Platform, Trust Center, written request or contractual schedule.
Technical and organisational measuresEncryption in transit and at rest, tenant isolation, access controls, role-based permissions, logging, monitoring, vulnerability management, incident response, backup and disaster recovery controls, personnel confidentiality, training, physical security and audit procedures.
TransfersGoverned by §N; may rely on adequacy decisions, SCCs, UK addenda, equivalent contractual safeguards, supplementary measures or other lawful mechanisms.
Deletion or returnReturn, export, deletion, anonymisation, backup retention and certification of deletion are governed by §Q and Book XIV.

What this page cannot answer

The four questions below are the ones a procurement or compliance review asks that Book III does not currently answer. They are recorded rather than guessed at.

Data Architecture covers the isolation boundary — how workspace data is separated and who inside a firm can reach it. The HAQQ security page carries the platform-level guarantees and is kept current there rather than duplicated here. The binding text of everything on this page is Book III of the Terms of Service.

Tópicos relacionados

Esta página foi útil?