AEGYS Data Processing Addendum
Operator: A & S INFORMATION SOLUTIONS OPC Product: AEGYS Effective: 19 August 2026 Version: dpa-2026-08-19-v1 This Data Processing Addendum (“DPA”) forms part of the AEGYS Terms of Service between A & S INFORMATION SOLUTIONS OPC (“A & S”, “PIP”) and the subscribing law firm (“Customer”, “PIC”) for processing of Customer Personal Data in the AEGYS tenant workspace.
AEGYS is the full commercial production system. This DPA does not describe a pilot, controlled-launch, or reduced product.
Consent is not the universal legal basis for sensitive personal information or for cross-border processing. Cross-border cloud processing is not automatically or universally based on individual consent.
1. Roles and scope
1.1 For Customer Personal Data (tenant workspace data processed for the Customer’s law practice), the Customer is the Personal Information Controller and A & S is the Personal Information Processor.
1.2 This DPA does not apply to A & S’s own platform/business records (subscription administration, licensing/payment records, legal-acceptance records when enabled, A & S operator audit, security/compliance records, DPO/DSAR records, incident records, legal-hold and deletion/offboarding evidence, support records, and similar), for which A & S is PIC. Those records are described in the Privacy Notice and Retention Schedule.
1.3 Customer Personal Data includes information relating to identified or identifiable natural persons that the Customer or its Authorized Users enter, generate, or cause to be collected in AEGYS, including through client-facing portal, token, upload, payment, consultation, and similar functions.
1.4 Authorized Users are law-firm personnel authorized for authenticated workspace access. Clients and Portal/Link Recipients are not Authorized Users.
2. Subject matter, duration, nature, and purpose
2.1 Subject matter: hosting and processing Customer Personal Data to provide AEGYS as described in the Terms, including clients, matters, filings, billing, documents, correspondence, reports, notarial and walk-in workflows, Client Portal, and other existing product functions.
2.2 Duration: the subscription/authorized-use period plus the applicable 90-day retained-workspace period (or earlier verified deletion, or longer if a legal hold applies), and any remaining provider recovery window.
2.3 Nature: storage, retrieval, transmission, display, generation of documents, transactional email where the Customer causes mail to be sent, client-facing limited functions, backup/recovery copies as they actually exist, logging, and security/abuse-prevention measures.
2.4 Purpose: to provide AEGYS to the Customer on documented instructions. A & S does not determine the purposes of the Customer’s law practice.
3. Categories of data and data subjects
3.1 Data subjects: the Customer’s clients and related persons; opposing/collaborating counsel and other professional contacts as stored by the Customer; firm personnel whose information is stored in the workspace; Portal/Link Recipients to the extent the Customer causes their information to be processed.
3.2 Categories: identity and contact data; matter/case and court data; documents and files; billing and payment-related workspace records; correspondence; professional identifiers; and other law-practice data the Customer stores.
3.3 SPI / privileged information. AEGYS does not require unnecessary sensitive personal information or privileged information for ordinary platform operation. The Customer may process such information where necessary and lawful. The Customer determines necessity, lawful basis, purpose, and proportionality. A & S will not scan, classify, or block content to “prevent” SPI, and will not disable existing functionality because SPI or privileged information may be processed. A & S remains bound by confidentiality, security, tenant isolation, and this DPA.
4. Documented instructions
4.1 The Customer instructs A & S to process Customer Personal Data solely to provide, maintain, secure, and support AEGYS, and as otherwise required by applicable law.
4.2 The Customer’s use of product functions (including client-facing functions the Customer enables) constitutes documented instruction to process the data those functions require.
4.3 A & S shall inform the Customer if, in A & S’s reasonable judgment, an instruction infringes applicable Philippine data-protection law, unless law prohibits that notice.
5. Confidentiality
5.1 A & S shall ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations.
5.2 A & S treats Customer Personal Data as confidential. Legal privilege is not created by use of AEGYS and is not determined by A & S. See the Terms and Privacy Notice.
6. Security measures
6.1 A & S shall implement appropriate organizational, physical, and technical measures given the nature of the processing, including:
- tenant isolation by firm identifier and database row-level security for AEGYS tenant queries;
- restricted A & S operator access and session controls;
- authentication of Authorized Users (Google OAuth);
- scoped, time-limited tokens for client-facing functions;
- encryption in transit (HTTPS);
- private object storage with authenticated, scoped file delivery;
- least-privilege operator access;
- logging of material A & S operator actions.
6.2 These measures are not a representation of SOC 2, ISO, NPC certification, perfect security, or tested disaster recovery.
6.3 Production file objects are stored in a private object store. Direct object URLs are not a public download path. Authorized users receive files through AEGYS’s authenticated or scoped delivery routes.
7. Subprocessing
7.1 The Customer authorizes A & S to use the Material Subprocessors disclosed in the Privacy Notice and the then-current Material Subprocessor list A & S maintains, and to use additional or replacement Material Subprocessors subject to Section 7.3.
7.2 Current Material Subprocessors (as of 19 August 2026, based on production/account evidence):
| Provider | Function | Tenant PD? | Geography |
|---|---|---|---|
| Vercel | Hosting / logs | Yes | Cloud processing across Vercel’s infrastructure; a single exclusive country is not verified |
| Neon | Database | Yes | AWS ap-southeast-1 (Singapore) — verified |
| Vercel Blob | File/blob storage | Yes | Singapore (sin1) — verified for the production store |
| Resend | Transactional email | Yes when mail is sent | Cloud email infrastructure; a single exclusive country is not verified from A & S account evidence |
| Vercel KV | Rate limiting (IP) | Limited | Cloud key-value infrastructure used through Vercel; a single exclusive country is not verified |
Google OAuth is used for Authorized User sign-in. Google is treated as independent PIC of the Google Account; A & S is PIC of identity data it retains. PayMongo, if used by the Customer with the Customer’s own keys, is the Customer’s processor, not an A & S licence-fee processor.
7.3 Notice of material change. Where reasonably practicable, A & S will give at least fifteen (15) calendar days’ advance notice before a new or replacement Material Subprocessor begins processing the Customer’s Personal Data, identifying provider, function, general nature of processing, geography where verified and appropriate, and effective date. Notice may be by email to the registered administrative address, AEGYS administrative notice, a maintained list plus direct notice of material changes, or another reasonable written electronic method.
7.4 Objection. The Customer may object during the notice period on reasonable documented data-protection or information-security grounds. Preference for another vendor, branding, pricing unrelated to privacy/security, a demand for Customer-selected infrastructure, or a demand for Philippine-only hosting is not an unrestricted veto. A & S will review in good faith. If a reasonable objection cannot be resolved and A & S cannot avoid using the proposed Material Subprocessor for that Customer, the Customer may terminate the affected service before the change takes effect without that termination being treated as Customer breach, with unused prepaid subscription (not an already-earned setup fee) refunded under the Terms.
7.5 Urgent security, legal, provider-failure, or service-continuity changes may occur on shorter notice, with notice as soon as reasonably practicable.
7.6 A & S shall engage Material Subprocessors only under contractual or other legally sufficient safeguards appropriate to the processing and sufficient for A & S to meet its applicable PIP obligations. Where an available provider arrangement cannot provide the legally required protections for the affected processing, A & S will not represent that provider as acceptable merely because stronger terms are unavailable. Any such deficiency is for owner/provider resolution and is not cured by publication of this DPA.
8. Cross-border processing
8.1 The Customer authorizes processing of Customer Personal Data outside the Philippines where A & S uses cloud/infrastructure providers whose processing locations may be outside the Philippines.
8.2 Verified: Neon production on AWS ap-southeast-1 (Singapore); production Vercel Blob store in sin1 (Singapore). Other listed providers process on cloud or global infrastructure rather than a single verified country.
8.3 A & S does not promise Philippine-only storage, a single fixed jurisdiction, or Customer-selectable data residency.
8.4 Safeguards: contractual or other legally sufficient provider arrangements where in place and sufficient for A & S’s PIP obligations; organizational and technical measures in this DPA; continued application of Philippine privacy and accountability obligations. Cross-border processing is not a waiver of the Data Privacy Act.
8.5 Cross-border cloud processing is not automatically or universally based on individual consent. The Customer as PIC remains responsible for having the applicable lawful basis or authority, and for providing required transparency, for its processing. A & S remains responsible for its PIP obligations and for appropriate subprocessor safeguards.
9. Assistance with data-subject requests
9.1 The Customer, as PIC, is responsible for responding to data-subject requests concerning Customer Personal Data.
9.2 A & S shall assist the Customer without undue delay. A & S targets assistance or a substantive status update within five (5) business days of a verified PIC request. That target is a contractual operating standard, not a universal statutory DSAR completion deadline.
9.3 A & S will not automatically disclose or delete tenant data on an unverified third-party request. A & S will ordinarily refer such requests to the relevant PIC.
10. Personal data breach and security incidents
10.1 Definitions and the 24-hour / 72-hour framework are as in the Terms and A & S’s personal-data-breach procedure.
10.2 A & S shall notify the Customer without undue delay, and where reasonably practicable within 24 hours of becoming aware of a Personal Data Breach affecting that Customer’s Personal Data. The 24-hour period is an AEGYS operational/contractual target, not a universal NPC statutory deadline.
10.3 The Customer, as PIC, remains responsible for applicable NPC and data-subject notifications. A & S shall assist, including with information reasonably available to it.
10.4 Supplemental notices will be provided as information develops. Current operational recording is by DPO/mailbox/manual process.
11. Audit and compliance assurance
11.1 A & S shall provide the Customer with information reasonably necessary to assess A & S’s compliance with its applicable PIP obligations, and will permit and reasonably cooperate with appropriate compliance reviews and audits as provided in this Section. Audit rights do not include unrestricted access to A & S systems, production databases, source code, credentials, other tenants, or cloud-provider consoles.
11.2 Documentary assurance first. The ordinary method of satisfying a Customer compliance request is documentary or written assurance. Subject to confidentiality, security and availability, A & S may provide relevant materials such as: a description of applicable technical and organizational safeguards; a tenant-isolation/security architecture summary; applicable privacy/security policies; DPO/contact information; the then-current Material Subprocessor list; relevant retention/offboarding information; breach-response procedures; appropriate contractual/security information concerning material providers that A & S is permitted to share; independent certification or audit reports if A & S later obtains them and may lawfully share them; and other reasonably relevant compliance documentation. A & S does not promise documents or certifications that do not exist, including SOC 2, ISO, penetration-test, or NPC certification of AEGYS unless actually obtained and verified.
11.3 Follow-up information. If documentary information does not reasonably address a legitimate compliance question, A & S shall provide reasonable follow-up, which may include written responses, a remote compliance meeting, clarification from the DPO or an A & S operator, or additional appropriately scoped evidence. The Customer must identify the particular compliance issue it is seeking to assess. A & S is not required to produce every internal document merely because the Customer submits a broad request for all security records.
11.4 Formal audit. If documentary and follow-up information is insufficient for a legitimate compliance need, the Customer may require a formal audit. A legally required or otherwise legitimate formal audit is not dependent on A & S arbitrarily agreeing that an audit may occur. Ordinary Customer-requested formal audits:
- are limited to once in any twelve (12)-month period, absent a justified exception;
- require at least ten (10) business days’ written notice where reasonably practicable;
- must have a defined scope, identified compliance purpose, reasonable duration, and reasonable timing;
- must be conducted by a qualified independent auditor where a third party is used, bound by confidentiality;
- must not expose other tenants’ data, credentials, source code, or unnecessary security secrets;
- are ordinarily conducted remotely first; on-site inspection of A & S-controlled premises is not the default and is not a right to inspect third-party cloud data centers.
Shorter notice or more frequent audit may apply where required by applicable law, NPC/regulatory authority, a material personal data breach or material security incident, substantiated material non-compliance, a material change affecting the Customer’s personal data, or an urgent, objectively substantiated privacy/security concern. Those exceptions, and lawful NPC/regulatory inspection rights, remain unaffected by the ordinary frequency and notice standards.
11.5 A & S may reasonably object to a proposed third-party auditor who is a direct competitor of A & S, demonstrably conflicted, unwilling to sign reasonable confidentiality obligations, or proposing unsafe or disproportionate methods. If A & S reasonably objects, the Customer may propose another qualified auditor. A & S does not have an arbitrary right to reject every outside auditor.
11.6 Costs. The Customer normally bears its external auditor costs and other expenses it voluntarily incurs for a Customer-requested audit. A & S will ordinarily provide reasonable standard compliance assistance without charging a separate audit fee. Where a Customer requests an unusually burdensome, repetitive or customized audit beyond ordinary reasonable assistance, A & S may require reimbursement of reasonable incremental costs if disclosed and agreed in advance. A & S will not use audit charges to obstruct a legitimate compliance request. If an audit establishes material non-compliance by A & S, A & S will not charge the Customer extraordinary A & S audit-assistance costs attributable to investigating that established material non-compliance.
11.7 Customer audit rights do not authorize unscoped penetration testing, vulnerability scanning of production, credential attacks, scraping, denial-of-service testing, or other active technical security testing of AEGYS. Any active technical security testing requires A & S’s prior written authorization, including agreed scope, timing, methods, systems, and safety controls. Accidental good-faith vulnerability reports remain welcome.
11.8 Lawful NPC and other regulatory inspection rights remain unaffected.
12. Return, deletion, and offboarding
12.1 During an active subscription, the Customer may export data using in-product export functions that exist, and may request A & S operator assistance with a documented administrative export.
12.2 After trial expiry or after the effective date of cancellation/termination/lapse, Customer Personal Data is retained up to 90 days and then deletion-eligible, subject to legal hold and verified early deletion.
12.3 Application deletion removes active tenant data and associated files. Provider recovery copies may remain until those windows expire (Neon Instant Restore currently approximately 6 hours — verified; restore not tested. Independent Vercel Blob undelete is not a verified AEGYS backup service). This is not a daily backup or guaranteed disaster-recovery service.
12.4 A & S PIC records (including a minimal account-deletion tombstone) are retained under the Retention Schedule and are not a 10-year archive of the deleted workspace.
12.5 Reactivation. If the same workspace still exists before actual deletion, the Customer may request reactivation of the same firm identifier and retained tenant workspace, subject to verified authority, A & S confirmation, applicable payment and subscription requirements, and absence of a legal or security bar. Valid reactivation restores the same workspace rather than creating a duplicate tenant, clears the cancellation-based deletion path while the restored subscription remains active, and begins a new paid term at the then-current applicable recurring price unless otherwise agreed. Payment alone does not automatically revive a cancelled tenant. After actual deletion, the old workspace is not restored.
13. Legal hold
13.1 A & S may suspend deletion of affected Customer Personal Data when a legal hold is recorded. Removing a hold does not automatically create a fresh 90-day retention period if the original deadline has passed.
13.2 Legal hold is an operational safeguard, not a product reduction.
14. Liability and indemnity
14.1 Liability under this DPA is subject to the limitation of liability in the Terms.
14.2 Indemnity is as in the Terms. This DPA does not create a separate unlimited indemnity.
15. Term and termination
15.1 This DPA remains in effect for as long as A & S processes Customer Personal Data under the Terms, including the retained-workspace period and any remaining provider recovery window.
15.2 Provisions that by nature should survive (confidentiality, liability, deletion/return evidence, legal hold, audit of closed incidents as applicable) survive termination.
16. Order of precedence
If this DPA conflicts with the Terms on a processing-specific matter, this DPA controls for that matter.