Know what your firm knows — instantly

Discover what your firm can achieve when every lawyer has instant access to your full institutional knowledge.

DeepJudge AG
Data Processing Addendum

Version 1.1 – May 2026

This Data Processing Addendum, including any annexes, exhibits, or appendices (“DPA”) forms part of the Agreement or any other agreement about the delivery of contracted services (“Agreement”) between DeepJudge AG (“DeepJudge”) and Customer, which are parties to that Agreement, to reflect the parties’ agreement about the Processing of Customer Personal Data (as those terms are defined below). This DPA is effective on the Effective Date of the Agreement, unless this DPA is separately executed, in which case it is effective on the date of the last signature. In the event of any conflict between this DPA and the Agreement, the provisions of this DPA will control with respect to the subject matter of Processing Customer Personal Data.

All capitalized terms not defined herein shall have the meaning set forth in the Agreement or in Applicable Data Protection Law. 

1. Definitions.

  1. Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. “Control,” for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity. 
  1. Applicable Data Protection Law” means any applicable laws, rules, regulations, and governmental requirements relating to the privacy, confidentiality, or security of Personal Data, as they may be amended or otherwise updated from time to time, including, without limitation, the General Data Protection Regulation 2016/679 (“GDPR”) and supplementing data protection law of the European Union Member States, the United Kingdom's Data Protection Act 2018 and the GDPR as saved into United Kingdom law by virtue of Section 3 of the United Kingdom's European Union (Withdrawal) Act 2018 (“UK GDPR”), the Swiss Federal Data Protection Act (“Swiss DPA”), and the California Consumer Privacy Act (“CCPA”) of 2018.
  1. Controller” (or “Business” as used in Applicable Data Protection Law) means the entity which determines the purpose and means of the Processing of Personal Data. 
  1. Controller Affiliate” means an Affiliate of Customer which is permitted to use the Services pursuant to the Agreement between DeepJudge and Customer but has not signed its own agreement with DeepJudge. 
  1. Customer Personal Data” means the Personal Data that Customer or a Controller Affiliate provides under the Agreement for DeepJudge to Process on behalf of Customer or Controller Affiliate in connection with the Services. Customer Personal Data does not include information that is anonymized.
  1. Data Subject” means an identified or identifiable person to whom Personal Data relates. 
  1. Data Subject Request means a request from Data Subjects seeking to exercise their rights under Applicable Data Protection Law.
  1. “​​Personal Data” (which will include “Personal Information” as used in Applicable Data Protection Law) has the meaning as defined under Applicable Data Protection Law. 
  1. Process,” “Processing,” and “Processed” will have the meaning as defined under Applicable Data Protection Law.
  1. Processor” (or “Service Provider” as used in Applicable Data Protection Law) means the entity engaged to Process Personal Data on behalf of the Controller. 
  1. Restricted Country” means (i) where the GDPR applies, a country outside of the European Economic Area (“EEA”) not subject to an adequacy determination by the European Commission; (ii) where the Swiss Federal Act on Data Protection of June 19, 1992, applies, a country outside Switzerland which has not been recognized to provide an adequate level of protection by the Federal Data Protection and Information Commissioner; and (ii) countries that do not qualify for the adequacy regulations under Section 17A of the UK GDPR. 
  1. Restricted Transfer” means, (i) where the GDPR applies, a transfer of Personal Data from the EEA to a Restricted Country; (ii) where the Swiss Federal Act on Data Protection of June 19, 1992, applies, a transfer of Personal Data from Switzerland to a Restricted Country; and (iii) transfers covered by Chapter V of the UK GDPR. 
  1. Security Breach” means a breach of security that leads to the loss or unauthorized access, use, alteration, or acquisition of (including authorized internal access to) Customer Personal Data. 
  1. Sell” and “Share” will have the meaning as defined under Applicable Data Protection Law.
  1. Standard Contractual Clauses” or “SCCs” means (i) where the GDPR applies, the clauses annexed to the European Commission’s Implementing Decision 2021/914 of June 4, 2021 for the transfer of Personal Data to third countries; and (ii) where the UK GDPR applies, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under Section 119A(1) Data Protection Act 2018 (“UK IDTA”) (in each case, as updated, amended or superseded from time to time).
  1. Subprocessor” means any Processor engaged by DeepJudge to assist in fulfilling its obligations with respect to providing the Services. For purposes of this DPA, Subprocessor includes subcontracted Service Providers or Contractors as defined under Applicable Data Law.

2. Role of the Parties.
 

The parties acknowledge and agree to the following: (i) Customer is the Controller of Customer Personal Data and (ii) DeepJudge is the Processor of Customer Personal Data. 

3. Scope and Responsibility.

  1. Each Party represents that it will comply with its respective obligations under Applicable Data Protection Law. Customer represents and warrants that it has obtained any necessary consents or otherwise has a lawful basis to provide Personal Data to DeepJudge for Processing in accordance with the Agreement and this DPA, and its instructions to DeepJudge do and shall comply with Applicable Data Protection Law. Customer will notify DeepJudge if the Data Subject withdraws consent.
  1. DeepJudge will ensure that: (i) all personnel authorized to Process Customer Personal Data are made aware of the confidential nature of Customer Personal Data and have committed themselves to confidentiality (e.g., by confidentiality agreements) or are under an appropriate statutory obligation of confidentiality; (ii) access to Customer Personal Data is restricted only to those personnel who require it for the purposes of fulfilling DeepJudge’s obligations under the Agreement; (iii) reasonable and appropriate steps are taken to help ensure that any Customer Personal Data provided to it is Processed in a manner consistent with Applicable Data Protection Laws and (iv), upon notice, it takes reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.
  1. DeepJudge will promptly notify Customer if it believes or confirms that it cannot follow the instructions of Customer or meet its obligations under the Agreement or Applicable Data Protection Law for any reason, unless it is prohibited by applicable law from making such notification.
  1. DeepJudge will Process the Customer Personal Data solely to provide the Services to Customer, to carry out its obligations under the Agreement, and in accordance with the Customer’s written instructions unless doing so would otherwise violate Applicable Data Protection Law. DeepJudge will not, nor will it permit any Subprocessor to: (i) Sell or Share any of Customer Personal Data; (ii) Process Customer’s Personal Data for any purpose other than for the business purpose of performing the Services and fulfilling its obligations under the Agreement (or as otherwise permitted by Applicable Data Protection Law); (iii) retain, use, or disclose Customer Personal Data outside of the direct business relationship between the parties as defined in the Agreement; or (iv) combine Customer Personal Data with Personal Data that it receives from, or on behalf of, another person or persons or that it collects from its own consumer interaction.

4. Cooperation.

DeepJudge will reasonably cooperate with and assist Customer with meeting its Applicable Data Protection Law obligations and will immediately notify Customer if it receives any complaint, notice, or communication that relates to Customer’s compliance with Applicable Data Protection Law. 

5. Subprocessors. 

  1. DeepJudge is authorized to engage Subprocessors to Process the Customer Personal Data as necessary to carry out its obligations under the Agreement as set forth in Annex 3. DeepJudge will conduct reasonable due diligence on each Subprocessor to ensure each Subprocessor is capable of providing the level of data protection required by this DPA. DeepJudge will enter into a written agreement with each Subprocessor that imposes no less restrictive terms as those contained in this DPA. DeepJudge is responsible for the acts and omissions of its Subprocessors in connection with Processing of Customer Personal Data under the Agreement.
  1. At least thirty (30) days prior to the date on which any new Subprocessor shall commence Processing Customer Personal Data, DeepJudge will notify Customer to give Customer an opportunity to object to the engagement of a new Subprocessor on reasonable grounds relating to the protection of Customer Personal Data. If Customer objects to the engagement of a new Subprocessor, the parties will discuss Customer’s concerns in good faith to find a commercially reasonable resolution. If no such resolution can be reached, DeepJudge will, in its sole discretion, either not appoint the new Subprocessor or permit Customer to suspend or terminate the Service affected by such change in accordance with the termination provisions of the Agreement without liability to either party (but without prejudice to any fees incurred by Customer prior to suspension or termination).

6. Data Security.

  1. DeepJudge shall maintain appropriate technical and organizational measures with regard to Customer Personal Data and to ensure an appropriate level of security, including, but not limited to, the “Security Measures” set out in Annex 2.
  1. Customer acknowledges that the Security Measures are subject to technical progress and development and that DeepJudge may update or modify the Security Measures from time to time, provided that such updates and modifications do not degrade or diminish the overall security of the Services.

7. Security Breaches.

In the event of a confirmed Security Breach (at DeepJudge or at a Subprocessor of DeepJudge), DeepJudge shall, without undue delay, but in any event within seventy-two (72) hours of discovery, inform Customer of the Security Breach and take such steps as DeepJudge in its sole discretion deems necessary and reasonable to remediate such violation. In the event of such a Security Breach, DeepJudge shall, taking into account the nature of the Processing and the information available to DeepJudge, provide Customer with reasonable cooperation and assistance necessary for Customer to comply with its obligations under Applicable Data Protection Law with respect to notifying (i) the relevant Supervisory Authority and/or (ii) Data Subjects affected by such Personal Data Breach without undue delay.

8. Data Subject Requests.

As between the parties, Customer will have sole discretion and responsibility in responding to the rights asserted by any individual in relation to Customer Personal Data under Applicable Data Protection Law. DeepJudge will forward to Customer without undue delay any Data Subject Request received by DeepJudge or any Subprocessor. Processor shall not be responsible for directly responding to Data Subject Requests. 

9. Audits.

DeepJudge shall, upon written request, either provide information regarding its compliance in the form of third-party certifications and audits reports on its security, privacy and architecture or respond with industry standard written audit questionnaires, provided that the purpose of such audit is to verify that DeepJudge is Processing Personal Data in accordance with its obligations under the DPA. Such audit may be carried out by Customer or an inspection body composed of independent members and in possession of required professional certificates or qualifications that bind said body to a duty of confidentiality, and for the avoidance of doubt, no access to any part of DeepJudge’s information technology systems, data hosting sites or centers, or its infrastructure will be permitted. Only to the extent that such audit of DeepJudge’s third-party certifications, audit reports and/or industry standard written audit questionnaires cannot reasonably demonstrate DeepJudge’s compliance with its obligations under the DPA, may Customer or an inspection body composed of independent members elected by Customer that is bound by a duty of confidentiality conduct an audit of DeepJudge. Any audit shall: (i) be conducted at the expense of Customer; (ii) be conducted under mutually agreed notice, scope and duration; (iii) exclude any internal accounting or financial information, trade secret, data or information of any other DeepJudge customer (including its end users), or any information that in DeepJudge’s reasonable opinion could compromise the security of its systems or premises or cause DeepJudge to be in breach of its obligations under Applicable Data Protection Law or its security, confidentiality, or privacy obligations to any other DeepJudge customer or third-party; and (iv) be limited to once per calendar year. 

10. International Data Transfers.

DeepJudge will only transfer Customer Personal Data across international borders and between jurisdictions in accordance with Applicable Data Protection Law. The parties agree that when the transfer of Customer Personal Data from Customer to DeepJudge is a Restricted Transfer, such transfer shall be subject to Standard Contractual Clauses, which shall be deemed incorporated by reference and form an integral part of this DPA. Appendix A hereto provides additional details as required by Annexes 1 and 2 of the SCCs. In the event of a conflict between this DPA and the SCCs, the provisions of the SCCs will control.

11. Disposal and Return.

Upon request, and except as required by Applicable Data Protection Law, each DeepJudge will promptly destroy or return to Customer, and upon request, confirm such destruction of, all of Customer Personal Data in its possession, on its systems, or held by Subprocessors in its behalf. Any such Customer Personal Data so retained will remain subject to the terms of the Agreement. 

12. DeepJudge contact/representative.

Please contact legal@deepjudge.ai regarding any questions or issues related to this DPA

Appendum A

Annex 1 - Details of Processing

A. List of Parties

Data exporter(s): 

The individual or entity that has entered into the Agreement with data importer for the provision of the products and services as described in the Agreement and/or applicable Order Form. 

Activities relevant to the data transferred under these Clauses: Uploading, transmitting, and otherwise processing the data through products or services of Processor.

Role (controller/processor): Controller

Data importer(s): 

Name: DeepJudge AG
Address: Militärstrasse 36, 8004 Zürich Switzerland 
Contact: Data Protection Officer, jacqueline@deepjudge.ai

Activities relevant to the data transferred under these Clauses: Providing services upon request to customers

Role (controller/processor): Processor

B. Description of Transfer

Categories of data subjects whose personal data is transferred

Controller may submit Personal Data while using the Services, the extent of which is determined and controlled by Controller in its sole discretion, and which may include, but is not limited to Personal Data relating to the following categories of Data Subjects:

  • Customer Contacts
  • Other end users including Customer employees, contractors, collaborators, customers, prospects, suppliers, and subcontractors. 
  • Other individuals attempting to communicate with or transfer Personal Data to Customer end users.
Categories of personal data transferred

Controller may submit Personal Data to the Services, the extent of which is determined and controlled by Controller in Controller’s sole discretion, and which may include but is not limited to the following categories of Personal Data:

  • Contact information 
  • Any other Personal Data submitted by, sent to, or received by Controller, or its end users
Sensitive data transferred (if applicable) and applied restrictions or safeguards

Data Exporter may upload Customer Data which may include special categories of Personal Data, the extent of which is determined and controlled by the Data Exporter in its sole discretion. Any such special categories of Personal Data shall be protected by applying the security measures described in Annex 2.

Frequency of the transfer

Continuous

Nature of the Processing

Personal Data will be Processed in accordance with the Agreement (including this DPA) and may be subject to the following Processing activities:

  • Storage and other Processing necessary to provide, maintain and improve the Services provided to Customer.
Purpose of the transfer and further processing

Data Importer will Process Personal Data as necessary to provide the Services pursuant to the Agreement, as further specified in the Order Form, and as further instructed by Data Exporter in its use of the Services.

Period for which Personal Data will be retained

Subject to this DPA, Data Importer will Process Personal Data for the duration of the Agreement, unless otherwise agreed in writing.

C. Competent Supervisory Authority

For the purposes of the Standard Contractual Clauses, the supervisory authority that shall act as competent supervisory authority is either (i) where Customer is established in an EU Member State, the supervisory authority responsible for ensuring Customer's compliance with the GDPR; (ii) where Customer is not established in an EU Member State but falls within the extra-territorial scope of the GDPR and has appointed a representative, the supervisory authority of the EU Member State in which Customer's representative is established; or (iii) where Customer is not established in an EU Member State but falls within the extra-territorial scope of the GDPR without having to appoint a representative, the supervisory authority of the EU Member State in which the Data Subjects are predominantly located. In relation to Personal Data that is subject to the UK GDPR or Swiss DPA, the competent supervisory authority is the UK Information Commissioner or the Swiss Federal Data Protection and Information Commissioner (as applicable).

Annex 2 - Security Measures

DeepJudge has implemented the following security measures to protect Customer Data, ensure proper security regulations, and mitigate potential risks: 

Measure Description
Pseudonymisation and/or Encryption of Personal Data DeepJudge maintains Customer Data encrypted in transit with TLS 1.2 (or later) and at rest with AES 256-bit encryption (or equivalent).
Ongoing Confidentiality, Integrity, Availability and Resilience The infrastructure for the Services may span multiple fault-tolerant clusters in geographic zones physically separated from one another; a variety of tools and processes are in place to maintain high availability and resiliency.
Restoration of Availability and Access to Personal Data Backups of non-redundant Customer Data are performed on a regular schedule and recovery testing is periodically conducted.
Regular Testing, Assessing and Evaluating Technical and Organisational Measures DeepJudge maintains an enterprise-wide security program that includes administrative, organizational, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of Customer Data. DeepJudge conducts periodic reviews of its security program.
User Identification and Authorisation DeepJudge enforces password and multi-factor authentication requirements. Access rights are promptly removed with personnel termination. DeepJudge operates under the principle of least privilege which ensures that only those with a business need to access a system or data are authorized and utilizes role-based access controls (RBAC) to provision and control access.
Protection of Data During Transmission DeepJudge maintains Customer Data encrypted in transit with TLS 1.2 (or later).
Protection of Data During Storage DeepJudge maintains Customer Data encrypted with AES-256 bit encryption (or equivalent).
Events Logging DeepJudge maintains application and infrastructure event logs. Events logs are managed centrally and contextually by the security team.
System Configuration DeepJudge maintains a change management policy with approval processes applicable to pre-production. Hardened security configuration and vulnerability fixes are used in the production environment. Pre-production and production environments are segregated. DeepJudge leverages tools to minimize security exposure including essential built-in security features such as containerization, locked-down firewalls, and audit logging.
Internal IT and IT Security Governance and Management The security program at DeepJudge includes administrative, organizational, technical, and physical safeguards reasonably designed to protect the confidentiality, integrity, and availability of Customer Data taking into account the nature of the services provided by DeepJudge and Applicable Data Protection Law. DeepJudge maintains information security and privacy policies considering these aspects. These policies are approved by management, regularly reviewed, and made available to all employees.
Certification/Assurance of Processes and Products DeepJudge performs annual penetration testing and is audited regularly. DeepJudge's security controls are audited for SOC 2 Type II compliance.
Data Minimisation DeepJudge customers determine the data sent to the Services and control the amount of data processed for minimisation purposes. DeepJudge deletes the Customer Data at Customer's request in accordance with the DPA in place with its customers.
Data Quality DeepJudge customers determine the data sent to the Services. DeepJudge deletes the Customer Data at Customer's request in accordance with the DPA in place with its customers.
Limited Data Retention DeepJudge deletes the Customer Data at Customer's request in accordance with the DPA in place with its customers.
Accountability DeepJudge employs multiple controls to ensure high visibility and enforcement of change management policies to ensure accountability, including comprehensive system logs, code reviews, infrastructure as code, and filtering requests through a centralized ticketing solution.
Data Portability and Erasure DeepJudge deletes the Customer Data at Customer's request in accordance with the DPA in place with its customers.
Transfers to Subprocessors DeepJudge Subprocessors pursuant to the DPA with its customers enter into written agreements with DeepJudge requiring them to abide by terms consistent with the requirements of the DPA with DeepJudge's customers.

Annex 3 - Subprocessors

Subprocessor Purpose Legal Name/Address Location
Microsoft Azure AI Provider and cloud infrastructure Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18 D18 P521, Ireland Customer Selected
Google Cloud Platform AI Provider and cloud infrastructure Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland Customer Selected
Amazon Web Services AI Provider and cloud infrastructure Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855, Luxembourg Customer Selected
Intercom Customer support Intercom R&D Unlimited Company, 124 St Stephen's Green, Dublin 2, D02 C628 European Union
Gong Customer support Gong.io, Inc., 201 Spear Street, 13th Fl., San Francisco, CA 94105 European Union