Lue tietojenkäsittelyliite suomeksiLaki.ai Data Processing Addendum (DPA)
Version 3 – 1 September 2026
1.Scope and roles
- 1.1.
This Data Processing Addendum (DPA) is incorporated by reference into the Agreement when the applicable terms of use so provide. This includes, under the Laki.ai General Terms of Use, every authenticated User who uses the research functions of the Service through a supported channel, such as ChatGPT, Claude, or another MCP connection, including free accounts, as well as the Laki.ai PRO Terms of Use and Laki.ai Organization Customer Terms (the Terms). The DPA also applies when the parties have agreed to it in writing. Capitalised terms have the meanings given in the applicable Terms unless otherwise defined in this DPA.
- 1.2.
This DPA applies only to the extent that the Service Provider processes, on behalf of the Customer, personal data contained in inputs processed by the Service’s research functionality, including material supplied to the Service by a User and tool calls independently generated by an AI model, or in outputs produced from them by the Service (together, Research Material). In this respect, the Customer is the controller and the Service Provider is the processor within the meaning of Regulation (EU) 2016/679 (the GDPR). If the Customer processes personal data on behalf of another controller, the Customer acts as processor and the Service Provider as subprocessor within the meaning of Article 28(2) and (4) of the GDPR. References in this DPA to the Customer as controller then apply to the Customer as processor, and the Customer is responsible for having the controller’s prior authorisation under Article 28(2) of the GDPR to use the Service Provider as a subprocessor.
- 1.3.
The Service Provider is an independent controller for its account, billing, security, and service administration processing. That processing is described in the
Laki.ai Privacy Policy and is outside this DPA.
- 1.4.
In a conflict concerning personal data processing, this DPA prevails over the Agreement, the applicable Terms, and the Laki.ai General Terms of Use to the extent that they apply between the Customer and the Service Provider. For other matters, the order of precedence in the Agreement applies.
- 1.5.
An AI assistant, agent, or host service selected by the Customer processes data under its own terms and the terms agreed with the Customer. This includes Microsoft 365 Copilot, Microsoft Entra, and Microsoft’s Enterprise Token Store authentication path when selected and administered by the Customer. A customer-selected service is not a subprocessor of the Service Provider merely because it sends a tool request to Laki.ai or receives an output from Laki.ai. This DPA covers the Service Provider’s processing and the Service Provider’s subprocessors described in section 5. If the Service Provider later engages Microsoft Azure or another Microsoft service as its own subprocessor, the advance notice and objection procedure in section 5.2 applies.
2.Description of processing
- 2.1.
The subject matter and nature of processing are the receipt and temporary processing of Research Material, search, reading and evaluation operations, and generation of outputs in the Service. The purpose is to provide the Service under the Agreement. Processing lasts for the term of the Agreement.
- 2.2.
Data subjects may include the Customer’s clients, principals and employees, counterparties and witnesses in the matter being researched, representatives of public authorities, and other persons connected with that matter.
- 2.3.
Categories of personal data include ordinary personal data, special categories of personal data under Article 9 of the GDPR, and personal data relating to criminal convictions and offences under Article 10 of the GDPR to the extent supplied by the Customer for processing in accordance with the Terms.
- 2.4.
The Customer’s obligations and rights as controller are governed by applicable data protection law, the Agreement, and this DPA, including the rights to give instructions, receive information, object, and audit under this DPA. The Customer is responsible for ensuring an appropriate legal basis and, where applicable, an additional condition under Article 9 or Article 10 of the GDPR; minimising Research Material to what the research task requires; and ensuring that its documented instructions are lawful. Research Material must not contain PCI-regulated payment-card data, protected health information (PHI), government-issued personal identifiers, authentication credentials, or other secrets. Other regulated sensitive data, including special categories of personal data under Article 9 of the GDPR and personal data relating to criminal convictions and offences under Article 10 of the GDPR, may be processed only when strictly necessary for the legal task and after the Customer has ensured lawful control and legally adequate consent. Special categories of personal data and personal data relating to criminal convictions and offences may be provided only to the extent that they do not fall within the categories prohibited above; the Customer must remove personal identity codes, health information, and other prohibited data from the Research Material before providing it. The Service Provider does not undertake to detect or automatically classify prohibited material.
3.Instructions
- 3.1.
The Service Provider processes personal data in Research Material only on documented instructions from the Customer, including for transfers to a third country or international organisation, unless Union or Member State law applicable to the Service Provider requires otherwise. In that event, the Service Provider informs the Customer of the legal requirement before processing unless that law prohibits the information on important grounds of public interest. The Agreement, this DPA, and actions and selections made by Users in the Service are documented instructions, including the ordinary automated processing they initiate, such as receiving and processing tool calls independently generated by an AI model.
- 3.2.
The Service Provider immediately informs the Customer if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.
4.Confidentiality and security
- 4.1.
The Service Provider ensures that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory duty of confidentiality.
- 4.2.
Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and risks to the rights and freedoms of natural persons, the Service Provider implements appropriate technical and organisational measures required by Article 32 of the GDPR to ensure a level of security appropriate to the risk.
5.Subprocessors
- 5.1.
The Customer gives general written authorisation for the Service Provider to use the subprocessors named in the subprocessor list in this DPA, including potential subprocessors announced in advance in that list. The current list is published at
laki.ai/data-processing.
- 5.2.
The Service Provider gives the Customer reasonable advance notice by email or in the Service of any intended addition or replacement of subprocessors. Activating a potential subprocessor announced in advance is also such a change. The Customer may object before the change takes effect on reasonable data protection grounds, in which case the parties seek a reasonable solution. If no solution is found, the Customer may terminate the Agreement by written notice before the change takes effect.
- 5.3.
The Service Provider imposes in writing on its subprocessors the same data protection obligations set out in this DPA and remains liable to the Customer for their performance as for its own.
6.Assistance and personal data breaches
- 6.1.
Taking into account the nature of processing, the Service Provider assists the Customer, insofar as possible, by appropriate technical and organisational measures in responding to requests to exercise data subject rights.
- 6.2.
Taking into account the nature of processing and the information available to it, the Service Provider assists the Customer in ensuring compliance with Articles 32–36 of the GDPR, including data protection impact assessments and prior consultation.
- 6.3.
The Service Provider notifies the Customer of a personal data breach without undue delay after becoming aware of it.
7.International transfers
- 7.1.
Personal data may be processed outside the European Economic Area or transferred to an international organisation only under a lawful transfer mechanism. These mechanisms include a European Commission adequacy decision, the Commission’s standard contractual clauses with any required supplementary measures, or another transfer mechanism permitted by the GDPR.
8.Deletion and return
- 8.1.
After the end of the provision of the Service, the Service Provider, at the Customer’s choice, deletes or returns all personal data processed on the Customer’s behalf and deletes existing copies unless Union or Member State law requires storage of the personal data.
9.Information and audits
- 9.1.
The Service Provider makes available to the Customer all information necessary to demonstrate compliance with Article 28 of the GDPR and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Reasonable arrangements for timing, scope, duration, and confidentiality are agreed in advance; those arrangements do not limit the obligation in the first sentence to make the information available.
10.Version and changes
- 10.1.
This DPA is versioned, and the current version is published at
laki.ai/data-processing. Changes to the subprocessor list are governed by section 5. Other changes to this DPA are governed by the amendment provisions of the applicable Terms.
Subprocessor list
Updated 4 August 2026. This list is dated separately and is amended under section 5 of the DPA.
Subprocessors in use (may receive Research Material in production use of the Service):
Google – Google Cloud and Vertex AI: infrastructure, database, search, vector, and model processing. Model and embedding requests containing Research Material are processed in the Vertex AI EU region.
Potential subprocessors announced in advance (not in use; activation is a change under section 5.2 of the DPA and is notified in advance):
OpenAI
Anthropic
AWS, including Amazon Bedrock
Microsoft Azure, including Azure OpenAI (not the customer-selected Microsoft 365 Copilot, Entra, or Enterprise Token Store host path described in section 1.5)