Introduction
Welcome to Jude, an artificial intelligence (AI) driven multi-purpose workspace platform for legal professionals (Platform).
Jude is owned and operated by Jude Platform Limited. In this DPA, “Jude”, “we”, “our” or “us” refers to Jude Platform Limited. “You” or “your” refers to the Law Firm that a User represents. “Party” refers to either your or us and “parties” refers to both you and us.
All Services provided by Jude to you via the Platform are provided under our terms of service (available at https://jude.law/terms) (as amended from time to time, including by any applicable Regional Terms) (Terms). In providing the Platform and/or the Services, Jude will process Personal Data on your behalf. You act as a Controller of that Personal Data and you appoint Jude as your Processor.
For those Law Firms whom we consider are required by Applicable Data Privacy Laws to have a written data processing agreement, this document comprises the DPA provided for in clause 7.2 of the Terms. It sets out the terms on which Jude processes Personal Data on your behalf and forms part of, and is incorporated into, the contract formed by the Terms (Contract). If there is any conflict between this DPA and the Terms in relation to the processing of Personal Data, this DPA prevails.
1. Definitions and interpretation
Some words used in this DPA have specific meanings. Those words are set out in clause 14.
This DPA was last updated on 4th August 2026
2. Roles of the parties
2.1 The parties acknowledge that, for the purposes of Applicable Data Privacy Laws in respect of Law Firm Personal Data, the Law Firm is the Controller and Jude is the Processor.
2.2 In respect of Account Data, Jude acts as an independent Controller and will process Account Data in accordance with its Privacy Policy (available at https://jude.law/privacy) and Applicable Data Privacy Laws. Account Data is not subject to the processor obligations in this DPA.
2.3 You warrant and undertake that:
you have complied, and will continue to comply, with Applicable Data Privacy Laws in respect of Your Personal Data, including establishing a lawful basis for the processing contemplated by the Contract and providing all notices and obtaining all consents or authorisations required;
you are entitled to transfer, or provide access to, Your Personal Data to us for processing in accordance with this DPA; and
- all instructions to us will comply with Applicable Data Privacy Laws.
2.4 You acknowledges that you and your Users, and not Jude, are responsible for determining whether the Platform is appropriate for the storage and processing of any Special Category Data or other information subject to specific regulation or heightened professional obligations (including information subject to legal professional privilege), and for your own compliance with any professional conduct rules applicable to you.
3. Processing on documented instructions
3.1 We will process Your Personal Data only on and in accordance with your documented instructions, including with regard to any Restricted Transfer, unless required to process it otherwise by Applicable Law to which Jude is subject, in which case Jude will (to the extent permitted by that law) inform you of that legal requirement before processing.
3.2 The parties agree that the Contract (including this DPA), together with your configuration of, and use of the ordinary features of, the Platform, constitute your complete documented instructions to Jude as at the date of this DPA. Additional or alternative instructions must be agreed between the parties in writing.
3.3 Jude will promptly inform you if, in our opinion, an instruction from you infringes Applicable Data Privacy Laws. We are not obliged to undertake a legal review of your instructions and this clause does not affect your responsibility for your own instructions.
3.4 The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subjects are as set out in Schedule 1.
3.5 Without limiting clause 3.1, we will not use Your Personal Data to train, fine-tune or otherwise improve any artificial intelligence or machine learning model (whether Jude’s own or a third party’s) and will ensure that all large language model endpoints used in the provision of the Platform and/or the Services are configured so that Your Personal Data submitted to them is not used for model training.
4. Personnel and confidentiality
4.1 Jude will ensure that all persons it authorises to process Your Personal Data:
are subject to binding obligations of confidentiality in respect of that data (whether contractual or statutory);
process it only as necessary to provide access to the Platform and/or the Services and in accordance with this DPA; and
receive appropriate training on data protection and information security.
4.2 Jude will restrict access to Your Personal Data to those personnel who require access for the purposes of providing access to the Platform and/or the Services, applying the principle of least privilege.
5. Security
5.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks to Data Subjects, Jude will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the UK GDPR, including at a minimum the measures described in Schedule 2 (Security Measures).
5.2 Jude may update the Security Measures from time to time, provided that no update materially reduces the overall level of protection afforded to Your Personal Data.
5.3 You are responsible for your own secure use of the Platform and the Services, including the management of your Users’ credentials, your access-control and authentication settings (including any single sign-on integration) and the security of data in transit to the point of ingestion by the Platform.
6. Sub-processors
6.1 You provide Jude with general written authorisation to engage Sub-processors to process Your Personal Data, subject to this clause 6. You expressly approve the Sub-processors listed in Schedule 3 as at the date of this DPA.
6.2 Jude will maintain a current list of its Sub-processors in the Privacy Policy and will give you at least 30 days’ prior written notice (which may be given by email to your nominated contact or by updating the Privacy Policy and notifying subscribed customers) of the addition or replacement of any Sub-processor.
6.3 If you have reasonable grounds relating to data protection to object to a new Sub-processor, you may notify Jude in writing within 14 days of Jude’s notice, setting out those grounds. The parties will discuss the objection in good faith. If Jude cannot reasonably accommodate the objection (including by making available a reasonable alternative means of providing the Platform and/or the Services without the new Sub-processor), you may terminate the affected Services on written notice without penalty (but without refund of prepaid fees except as required by law or provided in the Contract).
6.4 Jude will:
enter into a written contract with each Sub-processor imposing data protection obligations that provide at least the same level of protection for Your Personal Data as this DPA, to the extent applicable to the services provided by that Sub-processor; and
remain fully liable to you for the performance of each Sub-processor’s obligations.
7. Assistance with Data Subject rights
7.1 Taking into account the nature of the processing, Jude will assist you, by appropriate technical and organisational measures and insofar as this is possible, in fulfilling your obligations to respond to requests from Data Subjects exercising their rights under the UK GDPR (including access, rectification, erasure, restriction, portability and objection).
7.2 The parties anticipate that the self-service features of the Platform will ordinarily enable you to respond to Data Subject requests without further assistance from Jude. If Jude receives a request directly from a Data Subject relating to Your Personal Data, it will (to the extent legally permitted) promptly notify you and will not respond to the request other than to direct the Data Subject to you, unless required by law.
7.3 Jude may charge you a reasonable fee for assistance under clause 7.1 that exceeds the self-service functionality of the Platform, calculated at Jude’s then-current rates, except where the need for assistance arises from Jude’s breach of this DPA.
8. Personal Data Breach
8.1 Jude will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Your Personal Data.
8.2 Jude’s notification will, to the extent the information is available to Jude, describe:
the nature of the breach, including where possible the categories and approximate numbers of Data Subjects and records concerned;
- the likely consequences of the breach;
the measures taken or proposed to address the breach and mitigate its possible adverse effects; and
- a contact point for further information.
Information may be provided in phases as it becomes available.
8.3 Jude will take reasonable steps to contain and remediate the breach and will provide you with reasonable assistance and information to enable you to meet your own obligations under Articles 33 and 34 of the UK GDPR (including notification to the Information Commissioner and communication to Data Subjects, each of which remains your responsibility).
8.4 Jude will not make any public statement or notification to any regulator or Data Subject concerning a Personal Data Breach affecting Your Personal Data that identifies you without your prior written consent, unless required by law.
9. DPIAs and prior consultation
9.1 Taking into account the nature of the processing and the information available to it, Jude will provide reasonable assistance to you with any data protection impact assessment, and any prior consultation with the Information Commissioner, that you are required to carry out under Articles 35 or 36 of the UK GDPR in relation to the processing of Your Personal Data by Jude. Clause 7.3 applies to assistance under this clause.
10. International transfers
10.1 Your Personal Data will be hosted at rest within Ireland, as described in Schedule 1. Jude will not transfer Your Personal Data outside the European Union except:
to New Zealand, being a country covered by UK adequacy regulations under Article 45 of the UK GDPR, for the purposes of platform administration, support and operation by Jude personnel;
- to the Sub-processors and in the locations set out in Schedule 3; or
- with your prior written authorisation.
10.2 Jude will not make any Restricted Transfer to a country not covered by UK adequacy regulations unless it has first put in place a valid transfer mechanism under Chapter V of the UK GDPR (such as the ICO’s International Data Transfer Contract or the UK Addendum to the EU Standard Contractual Clauses) together with any supplementary measures reasonably required, and will provide evidence of that mechanism to you on request.
10.3 If any transfer mechanism relied on under this clause 10 is invalidated or superseded, the parties will cooperate in good faith to put in place a valid alternative mechanism promptly.
11. Return and deletion of Your Personal Data
11.1 At any time during the term of the Contract, you may, through the Platform and/or the Services or by written request, require the deletion of specified Your Personal Data, and Jude will comply within 30 days of the request.
11.2 On termination or expiry of the Contract, Jude will, at your election (to be notified in writing within 30 days of termination or expiry):
return to you all Your Personal Data in a commonly used, machine-readable format; and/or
- delete all Your Personal Data,
and in either case will delete all remaining copies of Your Personal Data within 60 days of termination or expiry, unless and to the extent that applicable law requires continued storage, in which case Jude will isolate the retained data, protect it in accordance with this DPA, and process it for no other purpose.
11.3 If you make no election under clause 11.2 within the period stated, Jude will delete all Your Personal Data in accordance with clause 11.2(b).
11.4 Deletion under this clause 11 includes deletion from Sub-processor systems, and may be effected by rendering the data irrecoverable in the ordinary course of Jude’s and its Sub-processors’ backup-expiry cycles, provided that backups are protected in accordance with this DPA pending expiry.
12. Audit and information rights
12.1 Jude will make available to you all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 of the UK GDPR, and will allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you, in accordance with this clause 12.
12.2 The parties agree that Jude will first satisfy its obligations under clause 12.1 by making available, on written request no more than once in any 12-month period:
its then-current security documentation, including summaries of the Security Measures, penetration test summaries and (once obtained) certifications or audit reports such as ISO 27001 certification or SOC 2 reports; and
written responses to your reasonable information-security and data protection questionnaires.
12.3 If the information provided under clause 12.2 is not reasonably sufficient to demonstrate compliance, or where an audit is required by a supervisory authority or following a Personal Data Breach affecting Your Personal Data, you (or its mandated auditor, which must not be a competitor of Jude) may conduct a remote (desktop) audit of Jude’s relevant records, systems documentation and policies, subject to:
at least 30 days’ written notice (except following a Personal Data Breach);
- reasonable confidentiality undertakings;
- conduct during business hours with minimal disruption; and
no access to data of Jude’s other customers or to information that would compromise Jude’s security.
12.4 Each party bears its own costs of an audit, except that Jude may charge reasonable costs of assistance for any audit beyond the first in any 12-month period, unless the audit reveals material non-compliance by Jude.
13. Liability
13.1 Each party’s liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability in the Contract, except that nothing in the Contract or this DPA limits either party’s liability to a Data Subject under Article 82 of the UK GDPR.
14. How to read this DPA
Headings are provided only to make this DPA easier to read and understand. Clause and Schedule references are to this DPA unless stated otherwise.
We have provided some examples in this DPA to help explain what we mean. Where we have provided examples, or where we say “include”, “includes” or “including” or similar, the examples given may not be all possible examples.
Words which are defined in the Terms have the same meanings in this DPA. However, some other words used in this DPA have specific meanings and we have set these out below. Any words which are the same retain meanings given to them in the Terms, but if those words are given a different meaning in this DPA (including in clause 14), then that meaning prevails.
- Account Data means Personal Data relating to your relationship with Jude, including the names and contact details of your Users and administrators, billing and payment information, support communications and usage and telemetry data relating to your use of the Platform and/or the Services, in respect of which Jude acts as an independent Controller.
- Applicable Data Privacy Laws means all laws applicable to the processing of Personal Data under this DPA, including (i) the UK GDPR and the DPA 2018 (each as amended from time to time, including by the Data (Use and Access) Act 2026); and (ii) to the extent applicable, the Privacy Act 2020 (New Zealand).
- Contract has the meaning given to it in the Introduction section on the first page of this DPA.
- Personal Data, Personal Data Breach, Processor, processing (and process), Special Category Data, Controller and Data Subject have the meanings given to them (or to equivalent terms) in the UK GDPR.
- Restricted Transfer means a transfer of Your Personal Data which is subject to Chapter V of the UK GDPR, being a transfer to a country, territory or international organisation which is not the subject of UK adequacy regulations under Article 45 of the UK GDPR.
- Security Measure has the meaning given to it in clause 5.1
- Sub-processor means any third party appointed by or on behalf of Jude to process Your Personal Data.
- VPC means virtual private cloud.
- Your Personal Data means any Personal Data processed by Jude on your behalf in connection with the provision of the Platform and/or the Services, as described in Schedule 1, but excluding Account Data.
15. Term and general
15.1 This DPA takes effect on the date the Contract takes effect (or, if later, the date you first make Your Personal Data available to Jude) and continues until Jude ceases to process Your Personal Data, notwithstanding termination or expiry of the Contract.
15.2 Jude may update this DPA from time to time to reflect changes in the Applicable Data Privacy Laws or in the Platform, the Services or the Terms, provided that no update materially reduces the protection afforded to Your Personal Data, and will give you reasonable prior notice of material updates.
15.3 If any provision of this DPA is held invalid or unenforceable, it will be modified to the minimum extent necessary to make it valid and enforceable, and the remainder of this DPA will be unaffected.
15.4 This DPA is governed by the same laws which govern the Terms, and the parties submit to the jurisdiction of the same courts as set out in the Terms, provided that nothing in this clause deprives a Data Subject of any right to bring proceedings in accordance with the UK GDPR.
Schedule 1 — Your Personal Data and description of processing
Subject matter: The processing of Your Personal Data by Jude in the course of providing the Platform and/or the Services under the Contract.
Duration: The term of the Contract plus any post-termination period contemplated by clause 11.
Nature and purpose of processing: Hosting, storage, retrieval, indexing (including vector indexing), optical character recognition and document extraction, analysis (including by means of large language models on non-training endpoints), display, transmission, and deletion of Your Personal Data, in each case for the purpose of providing, securing, supporting and maintaining the Platform and/or the Services in accordance with the Contract.
Categories of Data Subjects: Data Subjects whose Personal Data is contained in Content uploaded to or processed through the Platform and/or the Services by you, which may include: your clients and prospective clients; counterparties and opposing parties; witnesses; beneficiaries and other persons connected with client matters; your partners, employees and contractors; and other third parties referred to in matter documents and correspondence.
Categories of Personal Data: Names, contact details, identification and verification documents, matter and case details, correspondence, financial information, and any other Personal Data contained in documents and Content you submit to the Platform. You, not Jude, determine the Content submitted.
Special Category Data and criminal offence data: Given the nature of legal matters, Content submitted by you may incidentally include Special Category Data (for example, health information or data revealing racial or ethnic origin, in matters such as family, employment, immigration or personal injury) and criminal offence data. The Platform does not require such data, and it is processed only as part of the Content which you choose to submit.
Location of processing: If you are domiciled in the United Kingdom, Your Personal Data is hosted at rest in a VPC on Amazon Web Services infrastructure located in Dublin, Ireland. Large language model inference is performed within EU regions only. Administration and support access may occur from New Zealand, being a country covered by UK adequacy regulations. Sub-processor locations are set out in Schedule 3.
Schedule 2 — Security Measures
Jude implements and maintains, at a minimum, the following technical and organisational measures:
- Network isolation: The Platform is hosted within a VPC, with a single database holding multiple Law Firms as independent tenants which are protected through authorisation controls.
- Encryption: All Your Personal Data is encrypted in transit using industry-standard TLS protocols and encrypted at rest.
- Access control: Access to Your Personal Data is governed by role-based access controls applying the principle of least privilege. Federated single sign-on is available to customers via Microsoft and Google, enabling your own identity provider policies (including multi-factor authentication and conditional access) to govern access to the Platform and/or the Services.
- AI processing safeguards: Large language model processing is performed via non-consumer, non-training endpoints - Your Personal Data is not used to train or improve any model. Where technically feasible, processing of Content is performed within Jude’s VPC rather than through external processing pipelines.
- Logging and monitoring: System activity is logged and monitored, with error tracking configured so that private information is anonymised or hidden.
- Organisational measures: Jude personnel are subject to confidentiality obligations and receive security training. Jude maintains a documented incident response plan and an information security management programme aligned with ISO/IEC 27001, in respect of which certification is currently being pursued.
- Resilience: Data is backed up within the same geographic region as primary hosting. Jude maintains measures to ensure ongoing availability and the ability to restore access to Your Personal Data in a timely manner following an incident.
Schedule 3 — Approved Sub-processors
| Sub-processor | Role | Your Personal Data processed | Location |
|---|---|---|---|
| Amazon Web Services New Zealand Limited (our AWS contracting party) and its AWS affiliates, including Amazon Web Services, Inc. (including AWS Bedrock) | Cloud infrastructure and hosting; managed LLM inference (Bedrock) | All Your Personal Data (hosting); document content submitted for AI processing (Bedrock) | Dublin, Ireland (hosting at rest and backups); EU regions only (Bedrock inference, including cross-region inference within the EU geography) |
| Auth0 (Okta, Inc.) | Authentication | User email, name, password credentials | Dublin, Ireland and Frankfurt, Germany |
| Reducto, Inc. | OCR and document extraction | Document contents during extraction, automatically deleted within a maximum of 24 hours (purge jobs run every 12 hours); no backups or long-term archives, and no persisted logs or cache containing Your Personal Data | EU only, under Reducto’s EU data residency configuration. Reducto engages onward sub-processors for EU-region compute and storage, restricted to EU-region execution; the current list is maintained at trust.reducto.ai |
| Turbopuffer, Inc. | Vector storage / AI search and retrieval | Components of documents uploaded by you | Frankfurt, Germany |