Privacy Notice
What we process, on whose instructions, where it is stored, and what you can ask us to do with it.
Last updated: 29 जून 2026
BOOK III. DATA PROTECTION, PRIVACY, HOSTING & DATA PROCESSING AGREEMENT
A. General Principles
HAQQ recognizes the importance of privacy, confidentiality, cybersecurity, professional secrecy, and data protection in the provision of legal technology services. HAQQ will process Customer Personal Data in accordance with this Book III, applicable law, and the Customer’s documented instructions where HAQQ acts as Processor.
This Book III forms part of the Agreement and operates as a data processing agreement to the extent HAQQ processes Customer Personal Data on behalf of a Customer as Processor, service provider, or equivalent role.
B. Roles of the Parties
For Business Subscriptions, the Customer generally determines the purposes and means of processing Customer Data submitted into the Ecosystem and acts as Controller. HAQQ processes such Customer Data on behalf of the Customer and acts as Processor, except where HAQQ determines the purposes and means of processing for its own legitimate business operations or legal obligations.
For Personal Subscriptions, HAQQ may act as Controller for account information, billing data, usage data, fraud prevention, customer support, and compliance processing. If a Personal Subscriber uploads third-party personal data, the Personal Subscriber may act as Controller for such third-party data and HAQQ may act as Processor for that data.
HAQQ acts as an independent Controller for processing necessary for its own billing, accounting, tax, fraud prevention, sanctions compliance, security monitoring, legal claims, product administration, internal compliance, and corporate governance obligations. HAQQ’s internal product development does not involve training, fine-tuning, or improving AI models on Customer Data, Matter Data, prompts, outputs, or User content, except where expressly agreed in a separately signed written agreement and permitted by law.
C. Cross-Jurisdictional Application
Data residency determines the default hosting location and may affect transfer mechanisms, local hosting commitments, and technical safeguards applicable to Customer Data. However, the privacy and data protection laws applicable to a particular processing activity may also depend on additional factors, including the location of the data subject, the establishment or place of business of the Controller or Processor, the jurisdiction in which services are offered or targeted, mandatory consumer or privacy laws, the nature of the data processed, and any separately executed agreement or Official Proposal.
HAQQ will process Customer Personal Data in accordance with the Applicable Data Protection Laws that apply to HAQQ in its role as Controller, Processor, service provider, or equivalent role. The Customer remains responsible for determining and complying with the laws applicable to its own collection, use, submission, and processing of Customer Data.
Examples of potentially relevant privacy laws include the GDPR, UK GDPR, UAE PDPL, KSA PDPL, Oman PDPL, Kuwait CITRA Data Privacy Protection Regulation, Bahrain PDPL, and Lebanon Law No. 81 of 2018. These examples are illustrative and do not exclude the application of other mandatory privacy, consumer, cybersecurity, telecommunications, professional secrecy, or sector-specific laws.
D. Processing Principles
HAQQ processes personal data in accordance with the following principles:
- Lawfulness, Fairness and Transparency. Data is processed on a lawful basis and described through these Terms and applicable notices.
- Purpose Limitation. Data is processed for specified, explicit, and legitimate purposes connected to the Services.
- Data Minimization. Data processed is limited to what is adequate, relevant, and necessary for the applicable purposes.
- Accuracy. Reasonable measures are taken to keep data accurate and up to date where HAQQ controls the data.
- Storage Limitation. Data is retained only for as long as necessary, subject to legal, regulatory, backup, audit, security, billing, and dispute requirements.
- Integrity and Confidentiality. Data is protected through technical and organizational measures appropriate to the risk.
- Accountability. HAQQ maintains policies, logs, and records designed to demonstrate compliance with its obligations.
E. Categories of Data Processed
HAQQ may process the following categories of data:
- Identity Data: names, titles, identifiers, professional identifiers, government-issued identifiers where required, and account identifiers.
- Contact Data: email addresses, telephone numbers, addresses, organization details, and contact preferences.
- Professional Data: job title, firm or organization, bar membership, professional licenses, practice areas, credentials, and role information.
- Case and Matter Files: legal documents, contracts, pleadings, memoranda, evidence, correspondence, discovery materials, exhibits, court documents, matter notes, tasks, hearings, milestones, and related records.
- CRM Data: client records, contact records, relationship history, billing data, timekeeping records, notes, communications, and interaction logs.
- Authentication Data: usernames, hashed passwords, tokens, MFA factors, security challenge responses, access credentials, and session identifiers.
- System Metadata: IP addresses, device identifiers, browser types, operating system data, logs, timestamps, location derived from IP or device settings, diagnostics, performance data, and activity trails.
- Billing and Payment-Interface Data: invoice data, subscription data, transaction references, payment status, tax data, billing profile data, and limited payment metadata. Full payment card data is processed by the Payment Partner or PCI-DSS compliant processor, not by HAQQ except where expressly stated.
- Support Data: support tickets, chat content, screenshots, diagnostic files, reproduction steps, logs, and communications with HAQQ.
- Derived Data: anonymized and aggregated telemetry, usage metrics, performance analytics, reliability data, and security diagnostics that do not identify Customers, Users, Clients, or data subjects.
F. Sensitive and Special Categories of Data
HAQQ does not require Customers to submit special categories of personal data, criminal-offence data, health data, biometric data, children’s data, financial account data, litigation evidence, privileged information, or other sensitive or regulated information unless such data is necessary for the Customer’s authorized use of the Products.
Because the Products may be used for legal practice management, case management, client intake, Legal AI assistance, document storage, billing, and e-Client communication, Customers may choose to upload or process sensitive information within Case and Matter Files. Where a Customer submits sensitive or special-category data, the Customer represents and warrants that it has a lawful basis, valid consent where required, appropriate notices, professional authorization, confidentiality authority, and any required regulatory basis to process such data through the Products.
HAQQ will apply the technical and organizational measures described in this Agreement, but the Customer remains responsible for determining whether the Products are appropriate for the sensitivity, jurisdiction, and regulatory status of the data it submits. HAQQ may reject, suspend, restrict, delete, quarantine, or require additional safeguards for categories of data that HAQQ reasonably determines create unacceptable legal, security, regulatory, operational, or safety risk, subject to applicable law and any separately executed agreement.
G. Purposes of Processing
HAQQ processes data for the following purposes:
- account registration, identity verification, authentication, and access management;
- delivery and administration of Products and Services;
- e-Firm case and matter management;
- Legal AI retrieval, indexing, summarization, drafting assistance, extraction, classification, workflow assistance, and tenant-specific contextualization;
- e-Client communication, document exchange, invoice visibility, and client portal functionality;
- Legal Directory profile listing, search, inquiry, and matching functionality;
- eBar institutional workflows;
- eWallet technology-layer functionality and payment-interface support;
- billing, invoicing, subscription management, accounting, tax, and collection;
- support, troubleshooting, maintenance, incident response, and service improvement;
- security monitoring, fraud prevention, misuse detection, sanctions screening, AML/CTF support where applicable, and compliance;
- audit, risk management, legal claims, regulatory response, and enforcement of this Agreement;
- anonymized and aggregated telemetry for service performance, reliability, capacity planning, diagnostics, security, and operational analytics;
- any other purpose authorized by the Customer or required by law.
H. Lawful Basis
Where HAQQ acts as Controller, HAQQ may rely on one or more lawful bases, including performance of a contract, compliance with legal obligations, legitimate interests, consent, establishment or defense of legal claims, or other lawful bases recognized under applicable law.
Where HAQQ acts as Processor, the Customer is responsible for identifying and documenting the lawful basis for Customer Personal Data submitted to the Products. HAQQ processes such data on the Customer’s documented instructions, including this Agreement, applicable Order Forms, Official Proposals, platform configurations, and authorized User actions.
I. Processor Obligations
Where HAQQ acts as Processor, HAQQ shall:
- process Customer Personal Data only on documented instructions from the Customer, unless required by law;
- ensure persons authorized to process Customer Personal Data are bound by confidentiality obligations;
- implement appropriate technical and organizational measures as described in this Agreement;
- assist the Customer, taking into account the nature of processing, in responding to data subject requests where required by law;
- notify the Customer of confirmed Personal Data Breaches in accordance with Section P;
- assist with data protection impact assessments and regulator consultations where required by law and reasonably necessary;
- make available reasonable information necessary to demonstrate compliance, subject to confidentiality, security, and proportionality;
- return, delete, anonymize, or render inaccessible Customer Personal Data in accordance with Section Q; and
- impose appropriate data protection obligations on subprocessors.
J. Customer Obligations
The Customer shall:
- collect, use, submit, and process Customer Data lawfully;
- provide all notices and obtain all consents, permissions, client authorizations, professional approvals, and legal bases required for use of the Products;
- ensure that Customer Data does not infringe rights or violate law;
- configure permissions, access rights, retention settings, and product features appropriately;
- respond to data subject requests where the Customer is Controller;
- maintain appropriate security for its own systems, devices, credentials, and users;
- notify HAQQ promptly of suspected incidents affecting the Products or Customer Data;
- comply with applicable professional secrecy, confidentiality, privilege, court, bar, and client-consent obligations; and
- indemnify HAQQ for claims arising from the Customer’s unlawful processing, Customer Data, or breach of this Agreement, subject to Book XIV.
K. Data Subject Rights
HAQQ will facilitate rights requests as required by Applicable Data Protection Laws. Data subject rights may include access, correction, deletion, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority.
Requests should be submitted to info@haqq.ai or another address designated by HAQQ. Where HAQQ acts as Processor, HAQQ may refer the request to the Customer and act on the Customer’s documented instructions unless required by law to respond directly. HAQQ may require reasonable identity verification and may reject or charge for repetitive, manifestly unfounded, excessive, or unlawful requests where permitted by law.
L. Subprocessors
The Customer authorizes HAQQ to engage subprocessors in connection with the Services. Subprocessors may include cloud hosting providers, infrastructure providers, data storage providers, analytics providers, payment-interface providers, communications providers, support systems, AI infrastructure providers, identity services, security tools, and other service providers reasonably necessary for the Ecosystem.
HAQQ shall select subprocessors using reasonable diligence and shall enter into written agreements imposing data protection obligations no less protective than those required by Applicable Data Protection Laws. HAQQ shall remain responsible for subprocessor acts and omissions to the extent required by law and this Agreement.
HAQQ shall maintain a subprocessor list or equivalent notice mechanism identifying material subprocessors, their function, and their processing location or region where commercially practicable. HAQQ may provide the list through the Platform, a Trust Center, email notice, contractual schedule, or upon written request.
A Customer may object in good faith to a new subprocessor by notifying HAQQ in writing within fifteen (15) days of notice. The objection must identify a reasonable legal, security, confidentiality, professional-responsibility, or regulatory basis. If the objection cannot reasonably be resolved, HAQQ may make commercially reasonable alternative arrangements or the Customer may terminate only the affected Product or processing activity, without penalty, subject to payment of undisputed fees accrued before termination.
M. Security Measures
HAQQ shall implement and maintain technical and organizational measures appropriate to the risk. Measures may include:
- encryption in transit and at rest;
- role-based access controls;
- tenant isolation;
- logging and monitoring;
- vulnerability management;
- access reviews;
- least-privilege access;
- incident response procedures;
- backup and disaster recovery measures;
- personnel confidentiality obligations;
- security training;
- secure development practices;
- physical and environmental security through hosting providers;
- penetration testing, assessments, audits, or certification reviews where applicable; and
- customer-managed encryption keys where available for applicable subscription tiers.
Any reference to SOC 2, ISO/IEC 27001, ISO/IEC 42001, GDPR, or other frameworks means HAQQ’s security, privacy, and AI-governance program is designed to align with relevant controls or obligations. It is not a representation that every Product, feature, hosting location, partner-hosted deployment, customer-managed environment, beta feature, integration, or third-party service is covered by the same certification or audit scope.
N. International Transfers
HAQQ offers regional data residency where available and hosts data in-region by default where expressly committed in an Order Form, Official Proposal, or platform configuration. Cross-border transfers may occur where necessary for support, security, billing, subprocessor services, redundancy, legal compliance, or operation of the Services.
Where required by Applicable Data Protection Laws, transfers may rely on adequacy decisions, Standard Contractual Clauses, UK addenda, equivalent contractual safeguards, supplementary measures, explicit consent, necessity for contract performance, establishment or defense of legal claims, or other lawful transfer mechanisms.
Where required by Applicable Data Protection Laws, HAQQ will perform or rely on transfer impact assessments, supplementary safeguards, encryption, pseudonymization, access controls, contractual commitments, and legal-environment assessments designed to provide a level of protection appropriate to the transfer.
O. Audit Rights and Compliance Evidence
Business Subscribers may request reasonable compliance evidence relating to HAQQ’s security, confidentiality, and processing obligations. Enterprise Subscribers, regulated Customers, and Customers with a specific legal or regulatory audit obligation may request additional audit materials or audit procedures, subject to confidentiality, security, proportionality, availability, scope, and applicable fees.
HAQQ may provide compliance evidence through executive summaries, certifications, audit summaries, security white papers, trust-center materials, policy summaries, or questionnaires. Full audit reports, penetration-test details, or sensitive security materials may require a mutual nondisclosure agreement and may be redacted to protect security, confidentiality, privilege, or third-party rights.
On-site or remote audits are permitted only in exceptional circumstances where written materials are insufficient to satisfy a mandatory legal or regulatory obligation. Such audits must be limited in scope, conducted no more than once annually unless legally required, subject to at least sixty (60) days’ notice, performed during normal business hours, not disrupt HAQQ operations, and be conducted by independent auditors bound by confidentiality.
P. Breach Notification
A Personal Data Breach means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by HAQQ.
Upon becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data for which the Customer is Controller, HAQQ will notify the Customer without undue delay and, where feasible, within seventy-two (72) hours. “Becoming aware” means the point at which HAQQ has a reasonable degree of certainty that a breach has occurred and affected Customer Personal Data.
HAQQ’s notice will include, to the extent known: the nature of the breach, categories and approximate number of affected data subjects and records, likely consequences, measures taken or proposed, contact point, and recommendations to mitigate adverse effects. Information may be provided in phases as it becomes available.
Security alerts, unsuccessful attacks, blocked intrusion attempts, routine vulnerability reports, or incidents that do not compromise Customer Personal Data will be handled under HAQQ’s incident response program but will not necessarily constitute Personal Data Breach notice.
The Customer is responsible for determining whether notice to regulators, courts, professional bodies, Clients, or data subjects is required, unless HAQQ has a direct legal obligation to notify. HAQQ will provide reasonable assistance where required.
Each party bears its own costs associated with breach management unless the breach is primarily caused by the other party’s breach of this Agreement or applicable law, in which case the responsible party shall bear reasonable and demonstrable costs, subject to Book XIV.
Q. Retention, Export and Deletion
Unless otherwise required by Applicable Data Protection Laws, legal hold, tax law, audit requirements, sanctions screening obligations, anti-money-laundering obligations, court order, professional obligation, or a separately executed agreement, HAQQ will provide a ninety (90) day export window following termination or expiration of the applicable Subscription for the Customer to retrieve Customer Data.
Following expiry of the ninety (90) day export window, HAQQ will delete, anonymize, or render inaccessible Customer Data from active production systems within a commercially reasonable period, subject to legal, regulatory, security, backup, disaster recovery, billing, audit, dispute, and compliance retention obligations.
Data may persist in encrypted backup or disaster recovery archives for a period not exceeding one (1) year from termination, unless a longer period is required by law, litigation hold, security investigation, disaster recovery integrity, or immutable-backup architecture. Backup data will not be restored to production except for disaster recovery, security, continuity, legal compliance, or investigation purposes. If backup data is restored, HAQQ will re-apply deletion or anonymization procedures in accordance with this Section.
HAQQ may retain Derived Data indefinitely, provided it is irreversibly anonymized or aggregated and does not constitute personal data under Applicable Data Protection Laws.
Upon written request, HAQQ may provide reasonable confirmation of deletion, subject to confidentiality, security, legal, and technical limitations.
R. Data Processing Schedule
- Subject Matter of Processing. HAQQ processes Customer Personal Data to provide, secure, support, maintain, improve, and administer the Products and related Services under this Agreement, applicable Order Forms, Official Proposals, and Statements of Work.
- Duration of Processing. Processing continues for the term of the applicable Subscription or Service and any post-termination retention, export, backup, legal, regulatory, audit, dispute, or compliance period described in this Agreement.
- Nature and Purpose of Processing. Processing may include hosting, storage, retrieval, transmission, indexing, access control, authentication, encryption, support, troubleshooting, billing, analytics using anonymized and aggregated telemetry, AI-assisted retrieval and generation, document processing, matter management, client communication, payment-interface support, migration, integration, and security monitoring.
- Categories of Data Subjects. Data subjects may include Customers, Authorized Users, Account Owners, administrators, employees, contractors, lawyers, legal-service clients, counterparties, witnesses, court personnel, suppliers, contacts, prospective clients, listed professionals, bar association members, End Customers, Partner personnel, and individuals whose data appears in Customer Data.
- Categories of Personal Data. Personal data may include identity data, contact data, authentication data, professional data, account data, CRM data, billing data, matter data, case files, legal documents, communications, metadata, logs, usage data, payment-interface data, KYC or intake data, and other data submitted by the Customer.
- Sensitive Data. Sensitive data may be processed if submitted by the Customer in connection with legal matters, client intake, professional workflows, evidence, litigation, family matters, criminal matters, health-related matters, financial matters, employment matters, or other use cases. The Customer is responsible for ensuring an appropriate legal basis and safeguards for such data.
- Subprocessors. HAQQ may engage subprocessors as described in Section L. The current subprocessor list or equivalent information will be made available through the Platform, Trust Center, written request, or contractual schedule.
- Technical and Organizational Measures. Measures may include encryption in transit and at rest, tenant isolation, access controls, role-based permissions, logging, monitoring, vulnerability management, incident response, backup and disaster recovery controls, personnel confidentiality, training, physical security, and audit procedures.
- Transfers. International transfers are governed by Section N and may rely on adequacy decisions, SCCs, UK addenda, equivalent contractual safeguards, supplementary measures, or other lawful transfer mechanisms.
- Deletion or Return. Return, export, deletion, anonymization, backup retention, and certification of deletion are governed by Section Q and Book XIV.