Skip to content
Docket Build

Legal

Data Processing Addendum

This addendum forms part of the agreement between Docket Build, Inc. and the customer, and governs our processing of personal data contained in client documents. Section 6 contains the model training exclusion — it is a contractual obligation, not a policy statement.

Last updated 1 May 2026

01Roles

The customer is the controller (or, where the customer is itself a processor for its clients, the processor) in respect of personal data contained in documents uploaded to the service. Docket Build is the processor and acts only on the customer's documented instructions.

The agreement, this addendum and the customer's configuration of the service constitute the complete documented instructions. We will notify the customer if we believe an instruction infringes applicable data protection law.

02Subject matter and duration

ElementDetail
Subject matterAssembly of immigration petition packets from customer-supplied documents
DurationThe term of the agreement, plus the retention period configured by the customer
Nature and purposeClassification, compliance checking, evidentiary mapping, pagination, Bates numbering, indexing, drafting, cross-checking and export
Categories of data subjectBeneficiaries, petitioners, dependants, declarants, witnesses and firm personnel
Categories of personal dataIdentity, contact, immigration status, employment, education, financial and, in humanitarian matters, special category data

03Confidentiality of personnel

Personnel authorised to process customer content are bound by written confidentiality obligations, receive annual data protection and security training, and are subject to background checks before production access is granted. Access is granted on a least-privilege basis and reviewed quarterly.

04Security measures

  • AES-256 encryption at rest with envelope encryption and per-tenant data keys, rotated on a 90-day schedule.
  • TLS 1.3 in transit with HSTS enforced.
  • Isolated tenant storage; no shared buckets and no cross-tenant context at inference time.
  • Matter-scoped role-based access control, with SSO/SAML and SCIM available on the Scale tier.
  • Comprehensive audit logging of every document action, exportable by the customer.
  • Annual third-party penetration testing and continuous vulnerability management.
  • Documented business continuity and disaster recovery plan with tested failover.

05Subprocessors

The customer authorises the subprocessors listed on our subprocessors page. We impose data protection obligations on each subprocessor at least as protective as those in this addendum, and we remain liable for their performance.

We will give at least thirty days' notice before adding or replacing a subprocessor. The customer may object on reasonable data protection grounds within that period, in which case the parties will work in good faith to resolve it; if no resolution is possible, the customer may terminate the affected service without penalty.

06Model training exclusion

Docket Build will not use customer content — including client documents, firm work product, cover-letter templates, exhibit indexes and any derivative of them — to train, fine-tune, evaluate or benchmark any machine learning model, whether our own or a third party's.

This obligation applies to pre-training, fine-tuning, reinforcement learning, evaluation datasets and any human review programme. It is not subject to an opt-out, is not conditioned on tier, and survives termination of the agreement. Compliance with this control is tested as part of our SOC 2 Type II examination.

07Data subject requests

Taking into account the nature of the processing, we will assist the customer by appropriate technical and organisational measures in fulfilling its obligation to respond to data subject requests. Where we receive a request directly, we will not respond substantively and will forward it to the customer without undue delay.

08Personal data breach

We will notify the customer without undue delay and in any event within twenty-four hours of confirming a personal data breach affecting their content. Notification will describe the nature of the breach, categories and approximate volume of data affected, likely consequences and measures taken. A written incident report follows within five business days, and a post-incident review is available on request.

09Deletion and return

The customer configures retention. Source uploads default to deletion 180 days after packet export; matter-level retention is available on the Scale tier. On termination, we delete customer content in accordance with the configured retention period, and in any event within ninety days, except where retention is required by law.

We will issue a certificate of destruction on request for any specific document, matter or account.

10Audit

We will make available all information reasonably necessary to demonstrate compliance with this addendum, including our current SOC 2 Type II report, penetration test summary and hosting attestation under NDA. Where a customer's regulatory obligations require an on-site audit, we will accommodate one no more than annually, on reasonable notice and at the customer's cost.

11International transfers

Where processing involves transfer of personal data out of the EEA, the UK or Switzerland, the parties incorporate the applicable Standard Contractual Clauses, with Docket Build as data importer, together with a documented transfer impact assessment. Customers may select US or India data residency, and document processing remains within the selected region.

Contact

Docket Build, Inc., Plot No. 5, Road No. 5, Mahindra Hills East Marredpally, Nehrunagar, Hyderabad, Secunderabad, Telangana, 500026, India. Email privacy@docketbuild.com, telephone +91 (080) 4123-7700.

Docket Build is legal technology software designed for use by licensed attorneys and legal professionals. Docket Build does not provide legal advice, does not practice law, and does not create an attorney–client relationship. All legal theories, filings, and petitions must be reviewed and approved by a qualified attorney.