LVAppSuite
Sign in Get started

LVAppSuite Data Processing Addendum

Peak Legal Ops, LLC

Version: 1.0Effective date: September 27, 2026

Contents

  1. 1. Definitions
  2. 2. Roles and Scope
  3. 3. Our Obligations
  4. 4. Subprocessors
  5. 5. Audits and Information
  6. 6. International Transfers
  7. 7. General
  8. Annex 1: Details of Processing
  9. Annex 2: Technical and Organizational Measures
  10. Annex 3: Subprocessors

This Data Processing Addendum (this “DPA”) forms part of the LVAppSuite Subscription Terms (the “Terms”) between Peak Legal Ops, LLC (“Peak Legal Ops,” “we,” “us,” or “our”) and the organization that has accepted the Terms (“Customer,” “you,” or “your”). It applies whenever we process Personal Data on your behalf in providing the Service, and it takes effect when you accept the Terms. Capitalized terms used but not defined in this DPA have the meanings given in the Terms.

1. Definitions

“Data Protection Laws” means all laws that apply to the processing of Personal Data under the Terms, including U.S. state privacy laws such as the California Consumer Privacy Act as amended (the “CCPA”) and, where applicable, the GDPR, the UK GDPR, and the Swiss Federal Act on Data Protection (the “Swiss FADP”).

“Data Subject” means the identified or identifiable individual to whom Personal Data relates.

“GDPR” means Regulation (EU) 2016/679 (the General Data Protection Regulation).

“Restricted Transfer” means a transfer of Personal Data that is subject to the GDPR, the UK GDPR, or the Swiss FADP to a country that those laws do not recognize as providing adequate protection, where a transfer mechanism is required.

“SCCs” means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914.

“UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under the UK Data Protection Act 2018.

“UK GDPR” means the GDPR as it forms part of the law of the United Kingdom.

“Controller,” “processor,” and “process” have the meanings given in the GDPR, and “business,” “service provider,” “sell,” and “share” have the meanings given in the CCPA. “Personal Data,” “Security Incident,” and “Subprocessor” have the meanings given in the Terms.

2. Roles and Scope

2.1 Roles. You are the controller (or business) of Personal Data, and we are your processor (or service provider). If you process Personal Data as a processor on behalf of another controller, we act as your subprocessor, and you are responsible for obtaining any authorizations that controller requires.

2.2 Details of Processing. The subject matter, nature, purpose, and duration of the processing, and the types of Personal Data and categories of Data Subjects, are described in Annex 1.

2.3 Compliance. Each Party will comply with the Data Protection Laws that apply to it. You are responsible for having a lawful basis for the processing and for giving any notices to, and obtaining any consents from, Data Subjects that Data Protection Laws require.

3. Our Obligations

3.1 Instructions. We will process Personal Data only on your documented instructions, which consist of the Terms, this DPA, and your configuration and use of the Service, unless the law requires otherwise. If the law requires other processing, we will tell you before processing unless the law prohibits it. We will tell you if we believe an instruction violates Data Protection Laws.

3.2 Confidentiality. We will ensure that everyone we authorize to process Personal Data is bound by an appropriate obligation of confidentiality.

3.3 Security. We will implement and maintain the safeguards described in Section 8 of the Terms and in Annex 2.

3.4 Data Subject Requests. If we receive a request from a Data Subject to exercise their rights about Personal Data we process for you, we will promptly forward it to you and will not respond to it ourselves except to direct the Data Subject to you. Taking into account the nature of the processing, we will give you reasonable assistance in responding to such requests.

3.5 Other Assistance. Taking into account the nature of the processing and the information available to us, we will give you reasonable assistance with data protection impact assessments and consultations with supervisory authorities that Data Protection Laws require of you in connection with the Service.

3.6 Security Incidents. We will notify you of a Security Incident as described in Section 8.3 of the Terms, and will provide the information about it that Data Protection Laws require you to have, to the extent it is available to us.

3.7 Deletion. We will delete Personal Data as described in Section 6.8 of the Terms, unless the law requires us to keep it. Any Personal Data we must keep remains protected under this DPA for as long as we hold it.

3.8 U.S. State Privacy Laws. Where the CCPA or a similar U.S. state privacy law applies, we will not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than providing the Service under the Terms, or outside our direct business relationship with you; or (c) combine Personal Data with personal information we receive from others, except as those laws permit. We will comply with the obligations those laws place on service providers and will tell you if we can no longer meet them. You may take reasonable and appropriate steps to stop and remedy any unauthorized use of Personal Data. We certify that we understand and will comply with the restrictions in this Section 3.8.

4. Subprocessors

4.1 Authorization. You give us general authorization to engage Subprocessors. Our current Subprocessors are listed in Annex 3 and at lvappsuite.com/subprocessors. We will give notice of new Subprocessors, and you may object to them, as described in Section 9.4 of the Terms.

4.2 Our Responsibility. We will engage each Subprocessor under a written agreement with data protection obligations at least as protective as those in this DPA, and we remain responsible for our Subprocessors’ performance of those obligations.

5. Audits and Information

5.1 Information. On your written request, no more than once in any twelve (12) month period (or more often after a Security Incident or where a supervisory authority requires it), we will provide information reasonably necessary to demonstrate our compliance with this DPA. This includes completing a reasonable security questionnaire and providing information about our Subprocessors’ security certifications and audit reports, which may include directing you to those Subprocessors’ published security resources.

5.2 Audits. If Data Protection Laws require more than the information described in Section 5.1, you may audit our compliance with this DPA, at your expense, through an independent auditor bound by confidentiality obligations, on at least thirty (30) days’ written notice, during normal business hours, and no more than once in any twelve (12) month period. The Parties will agree on the scope of any audit in advance, and any audit will not include access to other customers’ data or to our Subprocessors’ facilities.

6. International Transfers

6.1 Location. Customer Data is hosted in the United States, as stated in Section 6.6 of the Terms.

6.2 EU Transfers. To the extent your provision of Personal Data to us is a Restricted Transfer subject to the GDPR, the SCCs are incorporated into this DPA by reference, and: (a) Module Two (controller to processor) applies where you are a controller, and Module Three (processor to processor) applies where you are a processor; (b) the optional docking clause in Clause 7 does not apply; (c) in Clause 9, Option 2 (general written authorization) applies, with notice of new Subprocessors given as described in Section 4.1; (d) the optional language in Clause 11 does not apply; (e) in Clause 13, the competent supervisory authority is determined in accordance with that Clause; (f) in Clause 17, Option 1 applies and the governing law is the law of Ireland; (g) in Clause 18, disputes are resolved before the courts of Ireland; and (h) Annexes I and II of the SCCs are completed with the information in Annexes 1 and 2 of this DPA, and Annex III is completed with the information in Annex 3.

6.3 UK Transfers. To the extent your provision of Personal Data to us is a Restricted Transfer subject to the UK GDPR, the UK Addendum is incorporated into this DPA by reference. Tables 1 to 3 of the UK Addendum are completed with the information in Section 6.2 and the Annexes of this DPA, and in Table 4, neither Party may end the UK Addendum under its Section 19.

6.4 Swiss Transfers. To the extent your provision of Personal Data to us is a Restricted Transfer subject to the Swiss FADP, the SCCs apply as described in Section 6.2, with references to the GDPR read as references to the Swiss FADP, the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority, and the term “Member State” read to include Switzerland so that Data Subjects in Switzerland may enforce their rights there.

6.5 Conflicts. If the SCCs or the UK Addendum conflict with this DPA or the Terms, the SCCs or the UK Addendum control to the extent of the conflict.

7. General

7.1 Liability. Each Party’s liability under this DPA is subject to the limitations and exclusions in Section 12 of the Terms, except where Data Protection Laws or the SCCs do not permit those limitations, such as liability to Data Subjects under the SCCs.

7.2 Order of Precedence. For the processing of Personal Data, the SCCs and the UK Addendum (where they apply) control over this DPA, and this DPA controls over the rest of the Terms.

7.3 Duration. This DPA continues for as long as we process Personal Data on your behalf under the Terms.

7.4 Changes. We may update this DPA as described in Section 15 of the Terms, including to reflect changes in Data Protection Laws or in the transfer mechanisms they require.

7.5 Governing Law. This DPA is governed by the law that governs the Terms, except where the SCCs or Data Protection Laws require otherwise.

Annex 1: Details of Processing

Item Details
Data exporter Customer, the organization that has accepted the Terms, acting as controller (or as processor for another controller). Contact: the administrative contact on file for Customer’s Workspace.
Data importer Peak Legal Ops, LLC, Utah, United States, acting as processor. Contact: support@lvappsuite.com.
Categories of Data Subjects Customer’s Authorized Users; and individuals whose information appears in data that Customer configures the Service to process from its LawVu Organization, such as Customer’s employees, contacts at counterparties, outside counsel, and other parties to Customer’s matters and contracts.
Categories of Personal Data Authorized User identity and contact information (such as name, email address, and LawVu user identifier); sign-in and usage records; and names, contact details, roles, and other information about individuals contained in the matter, contract, and document records that Customer configures the Service to process.
Sensitive data None intended. The Service is not designed for special categories of personal data or other sensitive data, and Customer controls whether any such data is processed through its configuration of the Service.
Frequency of transfer Continuous during the Subscription Term.
Nature of processing Hosting and storage; retrieving data from and writing data to Customer’s LawVu Organization; running workflows and bulk updates; displaying tables and results; sending service emails; and providing support.
Purpose of processing To provide, secure, and support the Service under the Terms.
Retention The Subscription Term plus thirty (30) days, with backup copies removed within a further thirty (30) days, as described in Section 6.8 of the Terms.
Transfers to Subprocessors To the Subprocessors listed in Annex 3, for the same nature and purpose of processing, for the duration described above.
Competent supervisory authority As determined under Clause 13 of the SCCs, where they apply.

Annex 2: Technical and Organizational Measures

We maintain the following measures, as described further in Section 8 of the Terms:

  • (a) Encryption. Personal Data is encrypted in transit using industry-standard protocols and encrypted at rest. LawVu Credentials stored by the Service are additionally encrypted using AES-256-GCM.

  • (b) Access to the Service. Authorized Users sign in through LawVu. Access is limited to active LawVu organization administrators on the Workspace’s list of permitted users, and is revoked when a user no longer meets those requirements.

  • (c) Separation. Each customer’s Customer Data is logically separated from other customers’ data.

  • (d) Internal access. Access to production systems is limited to personnel who need it to provide, secure, and support the Service, and those personnel are bound by confidentiality obligations.

  • (e) Hosting. The Service is hosted with infrastructure providers that maintain independently audited SOC 2 Type 2 reports, and card payments are handled by a PCI DSS Level 1 certified service provider.

  • (f) Backups. The Service’s database is backed up regularly, and backup copies are removed on the schedule in Section 6.8 of the Terms.

  • (g) Incident response. We investigate, contain, and mitigate Security Incidents and notify customers as described in Section 8.3 of the Terms.

Annex 3: Subprocessors

As of the effective date of this version of this DPA, our Subprocessors are listed below. The current list is maintained at lvappsuite.com/subprocessors.

Subprocessor Purpose Location
Supabase, Inc. Database, backend services, and hosting of Customer Data (on Amazon Web Services) United States
Vercel Inc. Hosting and delivery of the Service’s web application United States, with global content delivery
Postmark (ActiveCampaign, LLC) Sending service emails, such as workspace set-up links and account notices (recipient name and email address, organization name, and email content) United States
Stripe, Inc. Card payment processing and the billing portal (billing contact and payment information only) United States
LVAppSuite

Built by Peak Legal Ops, LLC.

Pricing Terms DPA Privacy Policy Subprocessors Contact