Last updated 18 September 2026
This Data Processing Agreement (DPA) forms part of the Terms of Service between Legal Pandas Ltd (AskPanda, we, us) and the Customer. It sets out the terms required by Article 28 of the UK GDPR that apply whenever we process personal data on the Customer's behalf. It applies automatically to every subscription. A countersigned copy is available on request from support@legalpandas.com.
1.1 Data Protection Law means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and, where applicable to the Customer, the EU GDPR, in each case as amended.
1.2 Client Enquiry Data means personal data contained in enquiries, correspondence, contacts and related records that the Customer or its Authorised Users submit to the Service or that the Service captures for the Customer, as described in Annex 1.
1.3 Sub-processor means a third party we engage to process Client Enquiry Data.
1.4 Controller, processor, data subject, personal data, personal data breach and processing have the meanings given in Data Protection Law. Other capitalised terms have the meanings given in the Terms of Service.
2.1 The Customer is the controller of Client Enquiry Data and we are its processor. Where the Customer acts as a processor for another controller, the Customer warrants that it has that controller's authority to appoint us as a sub-processor on these terms.
2.2 The subject matter, duration, nature and purpose of the processing, and the categories of data subjects and personal data, are described in Annex 1.
2.3 We act as an independent controller, not as the Customer's processor, for the account details of Authorised Users and for our own business records, as described in our Privacy Policy .
3.1 The Customer is responsible for the accuracy and lawfulness of Client Enquiry Data, for having a lawful basis for its processing, and for providing enquirers with the privacy information required by Data Protection Law, including that the Customer uses software incorporating artificial intelligence to organise enquiries.
3.2 The Customer's instructions to us are these terms, the Terms of Service, and the settings and actions its Authorised Users take within the Service. The Customer will not instruct us to process data in a way that breaches Data Protection Law.
We will:
5.1 The Customer gives general written authorisation for us to engage the Sub-processors listed in Annex 3.
5.2 We will give the Customer at least 30 days' notice by email to its account contact before adding or replacing a Sub-processor. The Customer may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees.
5.3 We will impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and we remain fully liable to the Customer for each Sub-processor's performance.
6.1 The Service allows the Customer to access, correct, export and delete Client Enquiry Data directly, which will normally be sufficient to respond to data subject requests.
6.2 If a data subject contacts us directly about Client Enquiry Data we will not respond substantively but will forward the request to the Customer within 3 business days and provide reasonable assistance.
7.1 We will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Client Enquiry Data. The notice will describe the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. We may provide information in phases as it becomes available.
7.2 We will cooperate with the Customer and take reasonable steps to contain and remedy the breach. We will not notify a data subject or regulator of a breach involving Client Enquiry Data without the Customer's agreement unless the law requires us to.
8.1 During the subscription the Customer may delete records at any time within the Service, and may export its Client Enquiry Data in a structured, commonly used format.
8.2 On termination or expiry the Customer may export its Client Enquiry Data for 30 days. We will then delete all Client Enquiry Data, including copies held by Sub-processors, within a further 60 days, and confirm deletion in writing on request. Data in backups is overwritten in the ordinary backup cycle and is not restored except to recover the Service, in which case this DPA continues to apply.
8.3 We may retain data only where and for as long as the law requires, and it will remain protected by this DPA.
9.1 On request, no more than once a year unless required by a regulator or following a breach, we will provide the Customer with the information reasonably necessary to demonstrate compliance with this DPA, including summaries of our security measures and Sub-processor arrangements.
9.2 If that information is insufficient, the Customer or an independent auditor bound by confidentiality may audit our relevant processing on at least 30 days' written notice, during business hours, without disrupting the Service or accessing other customers' data. Each party bears its own costs.
10.1 We store Client Enquiry Data, including backups, in the United Kingdom in the AWS London region. Some Sub-processors listed in Annex 3 process data in the European Union or the United States.
10.2 We will not transfer Client Enquiry Data outside the UK except to a country covered by UK adequacy regulations, or under an appropriate safeguard recognised by Data Protection Law, such as the UK Extension to the EU-US Data Privacy Framework, the ICO's International Data Transfer Agreement, or the ICO Addendum to the EU Standard Contractual Clauses. We will provide copies of the relevant safeguards on request.
11.1 Each party's liability under this DPA is subject to the exclusions and limitations in the Terms of Service, except that nothing limits either party's liability to a data subject under Data Protection Law.
11.2 This DPA takes effect when the Customer first uses the Service and continues for as long as we process Client Enquiry Data. Clauses 4(e), 8 and 11 survive termination, and clause 10 continues to apply for as long as we hold any Client Enquiry Data.
11.3 If this DPA conflicts with the Terms of Service on a data protection matter, this DPA prevails. We may update this DPA to reflect changes in law or in the Service on 30 days' notice; changes that reduce the Customer's protections require its agreement.
11.4 This DPA is governed by the law of England and Wales.
| Subject matter | Provision of the AskPanda enquiry management platform to the Customer. |
|---|---|
| Duration | The term of the subscription plus the export and deletion periods in clause 8. |
| Nature and purpose | Receiving, storing and displaying enquiries; organising and summarising them, including with AI; routing them to the Customer's staff; sending and tracking communications on the Customer's instruction; and producing reports for the Customer about its own enquiries. |
| Categories of data subject | People who enquire with the Customer, including prospective and existing clients; people named in enquiries, such as opposing parties, family members or employers; and the Customer's Authorised Users to the extent they appear in enquiry records. |
| Categories of personal data | Names, email addresses, telephone numbers, postal addresses; the free-text description of the legal matter and any documents or correspondence provided; source and campaign information; IP address and approximate location of web submissions; email delivery, open and click events; notes and status added by the Customer's staff. |
| Automated decision-making | The Service classifies, prioritises and summarises enquiries automatically, and sends the communications the Customer has configured. It does not make decisions producing legal or similarly significant effects for a data subject within the meaning of Article 22: the Customer's staff review the output and decide whether to act on it. |
| Special category and criminal offence data | Enquirers write in their own words, so enquiries may contain information about health, family life, ethnicity, religion, sexual orientation, trade union membership or alleged criminal offences. We do not seek this data and process it only as part of the enquiry text on the Customer's instructions. |
We maintain measures appropriate to the risk in each of the following areas. Our current implementation of each is described on our Security page, which we update as the Service evolves. We will not make a change that materially reduces the overall level of protection.
We use the following sub-processors to deliver the service. Each is bound by a written data protection contract. None of them may use customer data for their own purposes, including training AI models. Last reviewed 18 September 2026.
| Sub-processor | Purpose | Location |
|---|---|---|
|
Amazon Web Services Amazon Web Services EMEA SARL | Hosting, database and backups | UK (London) |
|
Vercel Vercel Inc. | Website and app hosting | EU/US and global edge network |
|
Mailgun Sinch Email (Mailgun Technologies, Inc.) | Email delivery and routing | EU |
|
OpenAI OpenAI, L.L.C. | Data classification and summaries | US |
|
Sentry Functional Software, Inc. | Error monitoring | US |
|
Abstract API Abstract API, Inc. | IP geolocation for source reporting | US |
|
Crisp Crisp IM SAS | Support chat | EU |
Transfers to sub-processors in the US are covered by the UK-US Data Bridge where the provider is certified under the Data Privacy Framework, and otherwise by the ICO's Addendum to the EU Standard Contractual Clauses. We give customers at least 30 days' notice by email before adding or replacing a sub-processor. Services a customer connects itself, such as a telephone answering service, are the customer's own suppliers.
For questions about these documents or about how we handle data, email us or use the chat.