Candor Data Processing Agreement
How Candor handles the personal data in a firm’s record: what is processed, how it is protected, and which companies help.
Effective October 7, 2026. Provider: Candor Software LLC, doing business as Candor. Part of the Candor Cloud Service Agreement.
Built on the Common Paper Data Processing Agreement Standard Terms, used under CC BY 4.0. Read the DPA Standard Terms.
#Cover Page
This Cover Page uses the Common Paper Data Processing Agreement Standard Terms (github.com/CommonPaper/DPA, commit 9f1c40d), incorporated by reference and unmodified. A copy is published with this page at candor.legal/dpa/standard. Common Paper agreements are free to use under CC BY 4.0. Capitalized terms not defined here have the meanings in the DPA Standard Terms.
This Cover Page and the DPA Standard Terms together form the DPA between Provider and Customer. It forms part of the Candor Cloud Service Agreement (the "Agreement", published at candor.legal/terms). If this Cover Page conflicts with the DPA Standard Terms, this Cover Page controls.
#Parties and agreement
- Provider
- Candor Software LLC, doing business as Candor
- Customer
- The Customer named in the Agreement
- Agreement
- The Candor Cloud Service Agreement between Provider and Customer
- Provider Security Contact
- jesse@candor.legal
- Security Policy
- candor.legal/security, together with Annex II below
- Governing Member State
- Ireland. This applies only if the EEA Standard Contractual Clauses apply to a transfer; Candor is offered to U.S. law firms.
#Annex I(B) — Details of processing
- Categories of Data Subjects
- Customer's personnel who use the service (attorneys and staff); Customer's billing contact; people named in matter references Customer enters (for example, a client name in a matter label); and, only if Customer turns on content retention, people mentioned in retained AI conversations.
- Categories of Personal Data
- Users' names, email addresses, roles and sign-in details; the record of AI use (who, when, which tool, which task, which matter reference, and related sign-offs, verifications, policy acknowledgments and consent records); billing contact email; the fact and topic of support requests; and, only if Customer turns on content retention, the text of retained AI prompts and answers.
- Special Category Data
- Not intended. It could appear only in matter references Customer writes or in retained conversations if Customer turns retention on.
- Special Category Data Restrictions or Safeguards
- Retention is off by default and turned on only by Customer's administrator; application-level encryption; per-firm isolation; access limited as in Annex II.
- Nature and Purpose of Processing
- Providing the Candor service to Customer: keeping Customer's record of AI use, running the checks Customer uses, sign-in, billing, support and service email.
- Duration of Processing
- The term of the Agreement, then the 30-day export period and deletion described below.
- Frequency of Transfer
- Continuous, while Customer uses the service.
#Annex II — Technical and organizational measures
- Encryption in transit: TLS on every connection.
- Encryption at rest: each stored record is encrypted by the application with AES-256-GCM before it reaches the database, on top of the hosting provider's storage encryption. Keys are held in the hosting provider's secret store, not in code.
- Integrity: the record is append-only and hash-chained; edits and deletions of individual entries are refused, and any change is detectable with the built-in integrity check.
- Tenant isolation: every request is scoped to the firm proven by the verified sign-in session. One firm cannot reach another firm's record.
- Access control: sign-in through Clerk; staff, attorney and administrator roles enforced on the server; browser extension devices use revocable per-device tokens with write-only access.
- Data minimization: text screened with the confidentiality pre-check is processed in the user's browser and never sent to Provider. The record keeps the fact of an action, not its content, unless Customer turns retention on.
- External lookups: citation checks send only the bare citation string to CourtListener, and statute checks only the title and section number to Cornell LII (and govinfo, if enabled); never case names, surrounding text or matter details. AI requests go to Customer's own AI provider with Customer's own key.
- Audit logging: reads of sensitive data are logged to Customer's audit log.
- Backups: automatic database backups, kept seven days.
- Incident response: a written incident plan with a 24-hour target for notifying Customer.
- Assurance: Provider does not yet hold a SOC 2 report or ISO 27001 certification.
#Annex III — Approved Subprocessors
| Subprocessor | What it does with Customer Personal Data | Location |
|---|---|---|
| Render | Hosts the Candor software and database | United States |
| Clerk | User sign-in, and invitation emails an administrator sends to add people | United States |
| Stripe | Subscription billing; card details go only to Stripe | United States |
| Resend | Delivers Candor's service email: the welcome email, setup, trial and billing reminders, and messages a user sends from Help in the app | United States |
| Google (Workspace) | Candor's own email inbox, where messages a user sends from Help in the app arrive: the sender's name, reply address, firm and message (screened for client details before sending, and not stored in the service) | United States |
Not subprocessors: Customer's own AI provider and practice management system, which Customer engages under its own agreements; and the public legal databases used for lookups (CourtListener, Cornell LII, govinfo), which receive only citation strings and statute numbers, not personal data.
#Additional terms
- 1.Client confidentiality. Provider understands Customer Personal Data may be information Customer must keep confidential for its clients, including under Rule 1.6 of the Rules of Professional Conduct, and treats all of it as Customer's Confidential Information. Provider personnel access it only to provide or secure the service. Provider's operating tools show counts and integrity status, not the content of a firm's record.
- 2.Security Incidents. For this DPA, "Security Incident" also includes any unauthorized access to or acquisition of Customer Personal Data, and any "breach of security" under Florida Statutes section 501.171, whether or not the GDPR applies. Provider will notify Customer as set out in the DPA Standard Terms (without undue delay and no later than 72 hours). Provider will not notify Customer's clients directly unless Customer asks it to or the law requires it.
- 3.U.S. privacy laws. Where the CCPA or a similar U.S. state law applies, Provider acts as Customer's service provider or processor, and does not sell or share Customer Personal Data or use it outside the direct business relationship with Customer.
- 4.New subprocessors. Provider will give Customer at least 30 days' notice, by email to the administrator, before adding or replacing a subprocessor. If Customer objects on reasonable data-protection grounds and the parties cannot resolve it, Customer may end the Agreement and receive a prorated refund of prepaid Fees for the unused period.
- 5.Export and deletion. Customer can export all of its data at any time, in a sealed format that restores exactly and a readable format that needs no Candor software. After the Agreement ends, Customer keeps read and export access for 30 days; Provider then deletes Customer's record and account within 30 days (or sooner on an administrator's written request) and confirms deletion in writing on request. Copies in automatic backups expire on their normal seven-day schedule. Because the record is append-only, deletion is done by Provider directly rather than through the software.
- 6.Security questions. Provider will answer Customer's reasonable written security questions and provide its security summary. On-site audits are not offered.
The DPA Standard Terms are the Common Paper Data Processing Agreement Standard Terms, by Common Paper, licensed under Creative Commons Attribution 4.0 International (CC BY 4.0). Candor uses them without changes to their wording; they are reformatted for this page. Common Paper is not a party to this agreement, and using its terms does not mean Common Paper endorses Candor.