Data Processing Agreement
Version 1.0 · Effective 20 September 2026
This Data Processing Agreement (DPA) forms part of the Terms & Conditions. Capitalised terms not defined here have the meaning given in those Terms.
1. Roles
1.1 The Customer determines the purposes and means of processing personal information contained in Customer Data. Solicia processes that information only on the Customer's documented instructions, to provide, secure and support the Service, and to comply with law.
1.2 The Agreement, authorised-user actions, documented support requests and lawful written instructions consistent with the Service constitute the Customer's documented instructions. Solicia will tell the Customer if it believes an instruction breaches applicable privacy law.
1.3 Each party complies with the privacy law applicable to it, including the Privacy Act 1988 (Cth) where applicable.
2. Processing details
| Subject matter | Provision, security, support and backup of the Customer-specific Solicia Service |
|---|---|
| Duration | The Agreement term and the deletion periods in clause 11 of the Terms |
| Nature and purpose | Receiving, storing, analysing and generating documents and correspondence in response to Customer instructions |
| Data subjects | Customer users and employees, and clients, counterparties, witnesses, advisers and other persons appearing in submitted matter content |
| Categories of data | Identity and contact details, email metadata and content, documents, matter information, authentication and audit data, and any sensitive or privileged information the Customer chooses to submit |
3. Solicia's obligations
3.1 Solicia ensures that personnel authorised to process Customer Data are bound by confidentiality obligations.
3.2 Solicia maintains the security measures in clause 6.
3.3 Solicia assists the Customer, taking into account the nature of the processing and the information available to it, with access, correction and deletion requests, privacy impact assessments, regulator enquiries and security incident obligations.
3.4 Solicia notifies the Customer's nominated contact within 24 hours after becoming aware of an incident that may materially affect the security of Customer Data, including a credible suspected incident, and provides reasonable assistance and a written report after containment.
3.5 Solicia does not sell Customer Data and does not use Customer Data to train general-purpose AI models.
3.6 On termination, Solicia returns or deletes Customer Data in accordance with clause 11 of the Terms.
4. Subprocessors
4.1 The Customer gives general authorisation for Solicia to engage subprocessors. The current list is published at solicia.ai/legal/subprocessors.
4.2 Solicia imposes data protection obligations on each subprocessor that are materially equivalent to those in this DPA, and remains responsible for their performance.
4.3 Solicia gives at least 30 days' notice of a material new subprocessor where practicable. The Customer may object on reasonable data-protection grounds, in which case the parties will seek a practical alternative, and either may terminate the affected Service if none is reasonably available.
5. Location of processing
5.1 Customer Data is stored in the region assigned to the Customer's organisation and confirmed in the Agreement.
5.2 Limited processing may occur outside that region:
- AI inference. Prompts and responses may be processed transiently within the data zone that the region belongs to. No Customer Data is retained outside the region for Solicia.
- Network delivery. Public application traffic passes through a global network security and delivery layer. It is processed in transit only, and no Customer Data is stored at rest outside the region.
- Web research. A sanitised search query may be sent to a search provider outside the region. Documents, mailbox content and system access are never provided. Web research can be disabled for an organisation on request.
5.3 These are the locations at which processing occurs. They are not a representation that every network packet remains within the region.
6. Security measures
Solicia maintains administrative, technical and organisational measures proportionate to the Service, including:
- encryption of Customer Data in transit using current industry-standard protocols, and encryption at rest;
- private network access to managed data services, with public access to storage disabled;
- named administrative identities with multi-factor authentication, least-privilege access and periodic access review;
- optional single sign-on for Customer users, and organisation-level multi-factor authentication enforcement;
- tenant-scoped application access controls, with audit logging, monitoring and threat detection;
- a controlled change workflow with immutable deployments, secrets scanning, dependency review and documented remediation targets;
- point-in-time database recovery, independent immutable backups held in the same region, object versioning with soft delete, and periodic restore testing;
- a documented incident response process, including the notification and reporting commitments in clause 3.4.
Solicia reviews these measures at least annually and may change them, provided the change does not materially reduce the level of protection.
7. Audit
The Customer's audit rights are set out in clause 10 of the Terms.
8. Precedence
If this DPA conflicts with the Terms in relation to the processing of personal information, this DPA prevails.