Scope of this page: it explains how data-processing terms are agreed with LawAOS and which documents carry the commitments. It is not itself the agreement. Terms are agreed per deployment and signed by both parties.
A data processing agreement sets out how LawAOS handles the personal data a firm places in its workspace: the purposes of the processing, the security measures, the service providers involved, how long data is kept, how it is returned or deleted, and what happens if something goes wrong. Firms with regulatory obligations usually need one before onboarding.
The firm decides what goes into its workspace and why: which matters, which clients, which documents. LawAOS processes that content to provide the Service the firm configured, and for nothing else. Customers retain their rights in workspace content, and LawAOS does not sell firm content, use it for third-party advertising, or use it to train LawAOS-owned models.
The agreement references the public documents rather than restating them, so there is one version of each commitment:
- Security measures: the controls on the Security page and in section 4 of the Privacy Policy.
- Retention, export and deletion: section 5 of the Privacy Policy.
- Data subject rights: section 6 of the Privacy Policy.
- AI-assisted features: section 8 of the Privacy Policy, and the provider terms the firm selects.
- Confidentiality and the Service: section 10 of the Terms of Service.
LawAOS uses providers for hosting, authentication, communications, payment processing, support, and the AI features a firm configures. Each receives only the data needed for the service it provides, under its own contract and configuration (Privacy Policy, section 3). The agreement lists the providers in use at signing and sets out how the firm is told when that list changes.
The primary application database is currently hosted in the Asia-Pacific (Sydney) region. Other providers may process operational, authentication, communications, payment, support, or configured AI data in additional regions under their service configuration (Privacy Policy, section 10). Where a transfer mechanism or a residency requirement applies, it is addressed in the agreement before onboarding, not after.
Use the request button below, or write to office@lawaos.com with the firm’s name and the jurisdiction the review is for. Tell us if the firm needs an NDA first, a named-provider list, or a specific regulator’s wording; the reply comes from the engineering team, which is also who answers the security review.
Ready to start? Send the request and we will reply with the next step. We aim to answer within one business day.
