This Data Processing Agreement (DPA) is referenced in Immediator's Terms of Service and governs the processing of personal data by Immediator on behalf of its clients. It is intended to satisfy obligations under applicable data protection laws including GDPR and CCPA.
Controller: The client entity that determines the purposes and means of processing personal data
Processor: Immediator, which processes personal data on behalf of the Controller
Data Subject: An individual whose personal data is processed
Personal Data: Any information relating to an identified or identifiable natural person
Processing: Any operation performed on personal data (collection, storage, use, disclosure, deletion, etc.)
Sub-processor: A third party engaged by Immediator to process personal data on the Controller's behalf
Immediator processes personal data submitted by the Controller through the Immediator platform for the purpose of providing legal analytics and settlement intelligence services.
Immediator processes personal data for the duration of the agreement between the parties, and for such period thereafter as required to fulfill legal obligations or as agreed in writing.
Analyzing case data to generate settlement predictions and legal analytics
Running sensitivity analysis on the Immediator algorithm using anonymized data
Improving platform accuracy and performance using anonymized, de-identified data (see TOS Section X)
May include: names, contact information, case details, medical records (where submitted), financial information, and other data relevant to personal injury litigation
Plaintiffs, defendants, attorneys, and other individuals whose information appears in submitted case data
Immediator agrees to:
Process personal data only on documented instructions from the Controller, including for transfers to third countries
Ensure that personnel authorized to process personal data are bound by confidentiality obligations
Implement appropriate technical and organizational security measures to adequately protect personal data during transmission, storage, and processing.
Respect the conditions for engaging sub-processors (see Section 5)
Assist the Controller in responding to Data Subject rights requests
Assist the Controller in fulfilling obligations related to security, breach notification, impact assessments, and prior consultation
Delete or return all personal data upon termination of services, at the Controller's election
Provide all information necessary to demonstrate compliance with this DPA and cooperate with audits
The Controller agrees to:
Ensure it has a lawful basis for processing and sharing personal data with Immediator
Provide accurate and complete instructions for processing
Ensure Data Subjects have been provided appropriate notice of processing activities
Comply with applicable data protection laws in its own processing activities
The Controller provides general authorization for Immediator to engage sub-processors, subject to the conditions in this section.
| Sub-processor | Purpose | Location |
|---|---|---|
| AWS (Amazon Web Services) | Infrastructure and hosting | USA (US regions only) |
Immediator will notify the Controller of any intended changes to sub-processors at least 30 days in advance. The Controller may object to such changes within 14 days of notification.
Immediator will impose data protection obligations on sub-processors equivalent to those in this DPA.
Immediator will promptly notify the Controller of any Data Subject rights requests received and will assist the Controller in fulfilling such requests, including:
Right of access
Right to rectification
Right to erasure
Right to restriction of processing
Right to data portability
Right to object
Immediator will maintain appropriate technical and organizational security measures as described in the Security Policy
In the event of a personal data breach, Immediator will notify the Controller without undue delay and within 72 hours of becoming aware
Breach notifications will include: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed
Immediator will not transfer personal data outside the country or region of origin without appropriate safeguards
For transfers from the EU/EEA, Immediator will rely on Standard Contractual Clauses (SCCs) or equivalent mechanisms
[Confirm applicability based on client base and infrastructure location]
The Controller may, upon reasonable notice and at its own expense, audit Immediator's data processing activities or commission a qualified third party to do so. Immediator may require reasonable confidentiality undertakings from the auditor.
This DPA is effective for the duration of the services agreement between the parties
Upon termination, Immediator will delete or return all personal data within [30] days unless retention is required by law
Obligations regarding confidentiality and security survive termination