Skip to content

Data Processing Agreement

Last updated: January 15, 2026

1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service or other written agreement between ROJI Inc. ("ROJI," "Processor," "we," "us," or "our") and the customer agreeing to these terms ("Customer," "Controller," "you," or "your") for the use of the roji.ai platform and related services (the "Services").

This DPA sets forth the terms and conditions under which ROJI processes Personal Data on behalf of Customer in connection with the Services. This DPA is intended to ensure compliance with applicable Data Protection Laws, including the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation ("UK GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other applicable data protection and privacy laws.

In the event of a conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to the processing of Personal Data.

2. Definitions

  • "Authorized Sub-processor" means a third party authorized by ROJI to process Personal Data in connection with the Services, as listed on our Subprocessors page.
  • "Data Protection Laws" means all applicable laws and regulations relating to the processing of Personal Data, including the GDPR, UK GDPR, CCPA/CPRA, and any other applicable data protection legislation.
  • "Data Subject" means an identified or identifiable natural person whose Personal Data is processed under this DPA.
  • "Personal Data" means any information relating to a Data Subject that is processed by ROJI on behalf of Customer through the Services, as further described in Annex 1.
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
  • "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.
  • "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission.
  • "Technical and Organizational Measures" means the security measures described in Annex 2 of this DPA.

3. Scope and Roles

3.1 Roles of the Parties

For the purposes of this DPA, Customer is the Controller (or, where applicable under the CCPA, the "Business") and ROJI is the Processor (or, where applicable under the CCPA, the "Service Provider") with respect to Personal Data processed through the Services.

3.2 Scope of Processing

ROJI shall process Personal Data only on behalf of and in accordance with Customer's documented instructions. The details of the processing are described in Annex 1 to this DPA.

3.3 Customer's Responsibilities

Customer is responsible for:

  • Ensuring that it has a lawful basis for processing Personal Data and for providing Personal Data to ROJI
  • Providing any required notices to and obtaining any required consents from Data Subjects
  • Ensuring that its instructions to ROJI comply with applicable Data Protection Laws
  • Assessing the suitability of the Services for its data processing activities

4. Processing Instructions

4.1 Customer Instructions

ROJI shall process Personal Data only in accordance with Customer's documented instructions, unless required to do so by applicable law. The parties agree that this DPA and the Terms of Service constitute Customer's complete and final instructions at the time of execution. Any additional or alternative instructions must be agreed upon separately in writing.

4.2 Notification of Conflicting Instructions

If ROJI becomes aware that Customer's instructions may violate applicable Data Protection Laws, ROJI shall promptly notify Customer. ROJI is not obligated to assess the legality of Customer's instructions but will inform Customer of any conflicts it becomes aware of.

4.3 Processing by Applicable Law

If ROJI is required by applicable law to process Personal Data other than in accordance with Customer's instructions, ROJI shall inform Customer of that legal requirement before processing, unless prohibited from doing so by law.

5. Confidentiality

5.1 Personnel Obligations

ROJI shall ensure that personnel authorized to process Personal Data have committed to confidentiality obligations or are under an appropriate statutory obligation of confidentiality.

5.2 Access Limitations

ROJI shall limit access to Personal Data to those personnel who require access for the performance of the Services.

6. Security

6.1 Technical and Organizational Measures

ROJI shall implement and maintain appropriate Technical and Organizational Measures to protect Personal Data, as described in Annex 2. These measures are designed to ensure a level of security appropriate to the risk, taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing.

6.2 Security Assessments

ROJI shall regularly assess and evaluate the effectiveness of its Technical and Organizational Measures. ROJI undergoes an annual SOC 2 Type II audit and will make a summary of the audit report available to Customer upon request.

7. Sub-processing

7.1 Authorization

Customer provides general written authorization for ROJI to engage Authorized Sub-processors to process Personal Data in connection with the Services. The current list of Authorized Sub-processors is available at our Subprocessors page.

7.2 Sub-processor Obligations

ROJI shall:

  • Enter into a written agreement with each Authorized Sub-processor imposing data protection obligations no less protective than those set out in this DPA
  • Remain fully liable to Customer for the performance of each Authorized Sub-processor's obligations

7.3 Changes to Sub-processors

ROJI shall notify Customer at least 30 days before engaging a new Sub-processor or replacing an existing Sub-processor. Notifications will be sent to the email address associated with Customer's account.

7.4 Objection to Sub-processors

If Customer has a reasonable objection to a new Sub-processor based on data protection grounds, Customer shall notify ROJI in writing within 15 days of receiving notice. The parties shall discuss Customer's concerns in good faith. If the parties cannot resolve the objection within 30 days, Customer may terminate the affected Services without penalty by providing written notice.

8. Data Subject Rights

8.1 Assistance with Requests

ROJI shall, taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures in fulfilling Customer's obligation to respond to requests from Data Subjects exercising their rights under Data Protection Laws.

8.2 Notification

If ROJI receives a request from a Data Subject regarding Personal Data processed on behalf of Customer, ROJI shall promptly redirect the Data Subject to Customer and notify Customer of the request. ROJI shall not respond to such requests directly unless authorized by Customer.

9. Personal Data Breach

9.1 Notification

ROJI shall notify Customer of a Personal Data Breach without undue delay, and in any event within 72 hours of becoming aware of the breach. The notification shall include:

  • A description of the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and Personal Data records affected
  • The name and contact details of ROJI's point of contact for the breach
  • A description of the likely consequences of the Personal Data Breach
  • A description of the measures taken or proposed to address the Personal Data Breach, including measures to mitigate its possible adverse effects

9.2 Cooperation

ROJI shall cooperate with Customer and take reasonable steps to assist Customer in investigating, mitigating, and remediating the Personal Data Breach.

9.3 No Acknowledgment of Fault

Notification of a Personal Data Breach shall not be construed as an acknowledgment of fault or liability by ROJI.

10. Data Protection Impact Assessments

Where required by Data Protection Laws, ROJI shall provide reasonable assistance to Customer in conducting data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of processing and the information available to ROJI.

11. International Data Transfers

11.1 Transfer Mechanisms

Where Personal Data is transferred from the EEA, United Kingdom, or Switzerland to a country that does not provide an adequate level of data protection, ROJI shall ensure that appropriate safeguards are in place, including:

  • Standard Contractual Clauses (Module Two: Controller to Processor) approved by the European Commission Decision 2021/914
  • The UK International Data Transfer Agreement or Addendum, where applicable
  • Any other valid transfer mechanism under applicable Data Protection Laws

11.2 Additional Safeguards

ROJI shall implement supplementary measures where necessary to ensure that the level of protection of Personal Data is not undermined by the transfer, including encryption of data in transit and at rest, and access controls limiting who can access transferred data.

12. Audit Rights

12.1 Information and Audit

ROJI shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA. Customer may, at its own expense and with at least 30 days' prior written notice, conduct an audit (or appoint a qualified third-party auditor) to verify ROJI's compliance with this DPA. Audits shall:

  • Be conducted during normal business hours
  • Not unreasonably interfere with ROJI's operations
  • Be subject to reasonable confidentiality obligations
  • Be limited to once per 12-month period, unless a Personal Data Breach has occurred

12.2 SOC 2 Reports

ROJI shall provide Customer with a copy of its most recent SOC 2 Type II audit report upon request. Customer agrees that the SOC 2 report may satisfy audit requirements under this Section 12, unless Customer has specific and reasonable grounds for requesting an additional audit.

13. Return and Deletion of Data

13.1 Upon Termination

Upon termination of the Services, ROJI shall, at Customer's election:

  • Return all Personal Data to Customer in a standard, machine-readable format; or
  • Delete all Personal Data from its systems

Customer must make this election within 30 days of termination. If no election is made, ROJI shall delete the Personal Data.

13.2 Retention Exceptions

ROJI may retain Personal Data to the extent required by applicable law, provided that ROJI shall (a) limit such retention to the minimum extent and duration required, (b) maintain the confidentiality of such data, and (c) process such data only for the purpose for which retention is required.

13.3 Certification

Upon request, ROJI shall provide written certification that it has complied with the deletion requirements of this section.

14. CCPA-Specific Provisions

To the extent that the CCPA applies to the processing of Personal Data under this DPA:

  • ROJI is a "Service Provider" as defined under the CCPA
  • ROJI shall not sell or share (as defined by the CCPA) Personal Data
  • ROJI shall not retain, use, or disclose Personal Data for any purpose other than providing the Services as specified in the Terms of Service and this DPA, or as otherwise permitted by the CCPA
  • ROJI shall not combine Personal Data received from Customer with personal information received from other sources, except as permitted by the CCPA
  • ROJI certifies that it understands and will comply with the restrictions set forth in this section

15. Term and Termination

This DPA shall remain in effect for the duration of the Terms of Service. Sections of this DPA that by their nature should survive termination shall continue to apply after termination, including obligations related to confidentiality, data deletion, and cooperation with audits.

16. Liability

The liability of each party under this DPA is subject to the limitations of liability set forth in the Terms of Service.

17. Contact

For questions about this DPA, please contact:

ROJI Inc. Email: privacy@roji.ai Website: https://roji.ai


Annex 1: Details of Processing

Categories of Data Subjects

  • Customer's employees, contractors, and staff
  • Customer's clients and their representatives
  • Opposing parties and their counsel
  • Court personnel, witnesses, and other individuals related to legal matters
  • Vendors and third-party contacts

Categories of Personal Data

  • Contact information (name, email, phone number, address)
  • Professional information (job title, bar number, firm affiliation)
  • Matter and case information (case details, parties, deadlines, notes)
  • Financial information (billing records, payment information, trust account data)
  • Documents and correspondence (uploaded files, emails, notes)
  • Usage data (login records, feature usage, IP addresses)

Sensitive Data

Customer may upload sensitive data (such as information related to legal proceedings, health information in personal injury matters, or financial data) to the Services. Customer is responsible for ensuring it has a lawful basis for processing such data.

Purpose of Processing

  • Providing the practice management platform and related Services
  • Processing and storing Customer Data as directed by Customer
  • Providing AI-powered features (document analysis, summarization, drafting assistance)
  • Billing, invoicing, and payment processing
  • Customer support and service improvement
  • Security monitoring and incident response

Duration of Processing

Processing continues for the duration of the Terms of Service and for such additional period as required for data deletion in accordance with Section 13.


Annex 2: Technical and Organizational Measures

Encryption

  • Data in transit: TLS 1.2 or higher
  • Data at rest: AES-256 encryption
  • Database encryption with customer-managed or platform-managed keys

Access Controls

  • Role-based access control (RBAC) for all systems
  • Multi-factor authentication required for administrative access
  • Principle of least privilege for employee access
  • Regular access reviews and recertification

Network Security

  • Network segmentation and firewalls
  • Intrusion detection and prevention systems
  • DDoS protection
  • VPN access for administrative operations

Application Security

  • Secure software development lifecycle (SSDLC)
  • Regular penetration testing by third-party firms
  • Automated vulnerability scanning
  • Code review and static analysis

Physical Security

  • SOC 2 Type II certified data centers
  • Biometric and multi-factor physical access controls
  • 24/7 security monitoring and surveillance
  • Environmental controls (fire suppression, climate control, power redundancy)

Organizational Measures

  • Information security policies and procedures
  • Employee background checks
  • Mandatory security awareness training
  • Incident response plan and procedures
  • Business continuity and disaster recovery plans
  • Data Protection Officer (or equivalent) appointed

Data Segregation

  • Logical separation of Customer Data between tenants
  • Isolated AI processing per customer
  • Separate encryption keys per customer

Monitoring and Logging

  • Centralized logging of access and changes to Personal Data
  • Real-time security monitoring and alerting
  • Audit trail retention for a minimum of 12 months
  • Regular review of security logs