Last updated: September 20, 2026
This Data Processing Addendum (“DPA”) is part of the agreement between Sidebar AI LLC (“Sidebar”) and the customer that accepted it (“Customer”), including Sidebar’s Terms of Service (the “Agreement”). It applies automatically when Customer accepts the Agreement, with no signature required. Capitalized terms are defined in Section 6 or in the Agreement.
1.1 Roles. Customer decides what Customer Data to submit. Sidebar processes it on Customer’s behalf as Customer’s “service provider” and “processor” under Data Protection Laws.
1.2 Details of processing. Customer discloses Customer Data to Sidebar only for the limited and specified business purpose of providing, securing, and supporting the Service, an AI workspace for legal research, drafting, and document work, as Customer and its Authorized Users direct through their use of it. Processing lasts for the term of the Agreement plus the deletion period in Section 2.10. Customer Data may include any information Customer chooses to submit, such as names, contact details, matter information, correspondence, and other contents of legal files, about Customer’s clients, opposing parties, witnesses, Authorized Users, and other individuals.
1.3 Account Data. Sidebar handles Account Data for its own business purposes under its Privacy Policy, not as Customer’s service provider, and the rest of this DPA does not apply to it.
2.1 Instructions. Sidebar will process Customer Data only as described in Section 1.2, the Agreement, and this DPA, unless the law requires otherwise, in which case Sidebar will first notify Customer if the law allows.
2.2 Restrictions. Sidebar will not (a) sell Customer Data or share it for cross-context behavioral advertising; (b) retain, use, or disclose Customer Data for any purpose other than the business purpose in Section 1.2, or outside its direct business relationship with Customer, except as Data Protection Laws permit; (c) combine Customer Data with personal data from other sources, except as Data Protection Laws permit; or (d) use Customer Data to train or fine-tune any artificial intelligence model. Sidebar will use AI model providers only under terms that prohibit them from training on Customer Data and that limit their retention of it as described in the list of Subprocessors at https://www.sidebar-ai.com/legal/subprocessors (the “Subprocessor List”).
2.3 Compliance. Sidebar will comply with the Data Protection Laws that apply to it as a service provider, including by giving Personal Data the same level of privacy protection those laws require of Customer, and will notify Customer promptly if it can no longer do so. On reasonable notice, Customer may take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Data, and to confirm Sidebar’s compliance as described in Section 2.9.
2.4 Confidentiality. Sidebar will keep Customer Data confidential and limit access to personnel who need it to operate, secure, or support the Service and who are bound by confidentiality obligations. Personnel will access the content of Customer Data only for those purposes, at Customer’s request, or as the law requires.
2.5 Security. Sidebar will maintain reasonable administrative, technical, and organizational measures designed to protect Customer Data, including encryption in transit and at rest, logical separation of each customer’s data, and access controls.
2.6 Security Incidents. Sidebar will notify Customer’s account administrator without undue delay after becoming aware of a Security Incident and will provide the relevant information reasonably available to it about what happened, what Customer Data was affected, and what it is doing in response. Sidebar need not disclose its own privileged material, security-sensitive details, or other customers’ information. Sidebar will take reasonable steps to contain and investigate the Security Incident and give Customer the information it reasonably needs to meet its own notification duties, which remain Customer’s responsibility. Notice of a Security Incident is not an admission of fault or liability.
2.7 Subprocessors. Customer authorizes Sidebar to use the Subprocessors on the Subprocessor List. Sidebar will engage each under written terms, which may be the Subprocessor’s standard terms, with data protection obligations appropriate to its processing, and remains responsible for its processing of Customer Data, subject to Section 5.1. Sidebar will notify Customer by email or in the Service when it adds a Subprocessor to the Subprocessor List. If Customer objects on reasonable data protection grounds within 10 days after the notice and the parties cannot resolve the objection, Customer’s sole remedy is to terminate the affected subscription.
2.8 Legal demands. If Sidebar receives a subpoena, court order, or other legal demand for Customer Data, it will direct the requester to Customer where it reasonably can; notify Customer before disclosing anything, or as soon as practicable afterward if advance notice is not reasonably practicable, unless the law prohibits notice; cooperate reasonably at Customer’s expense with Customer’s efforts to contest the demand; and disclose only what the demand legally requires.
2.9 Assistance and information. Sidebar will give Customer reasonable help, on request, in responding to individuals exercising rights under Data Protection Laws, and will refer to Customer any individual who contacts Sidebar about Customer Data. No more than once in any 12 months, Sidebar will on written request describe its security measures and respond to a reasonable security questionnaire. Customer will exercise any audit or assessment right through this Section. Sidebar does not provide on-site audits or access to its systems, and what it provides is its confidential information.
2.10 Deletion. Customer can delete Customer Data in the Service at any time and is responsible for exporting what it wants to keep before the Agreement ends. Sidebar will delete Customer Data from its production systems, including Customer Data it stores with Subprocessors, within 30 days after Customer closes its account or asks in writing or through the Service, and otherwise within 90 days after the Agreement ends. Backup copies expire in the ordinary course and will not be restored except to recover the Service. Sidebar may keep Account Data, records that do not contain the content of Customer Data, and anything the law requires it to keep.
3.1 Rights and consents. Customer is responsible for having the rights and consents needed to submit Customer Data to the Service, including any client consent or notice that rules of professional conduct require, and for its Authorized Users and their credentials.
3.2 Optional features. Customer decides whether to use optional features and whether the Service suits the Customer Data it submits. When an Authorized User runs legal or web research, Sidebar sends search text to research providers identified on the Subprocessor List. Sidebar does not add Customer or user identifiers, but search text is composed from the conversation and may reflect names or matter details. If an Authorized User connects a third-party account, such as a Google account, Sidebar will access it through the integration Subprocessor identified on the Subprocessor List, only at that user’s direction, and will not send email from the account, or change or delete its content, unless the user approves the specific action. The account’s provider processes data in that account under Customer’s own agreement with that provider, not on Sidebar’s behalf, and is not a Subprocessor. Sidebar will revoke its access to a connected account when the user disconnects it or Customer closes its account.
3.3 Restricted data. Sidebar is not a business associate under the Health Insurance Portability and Accountability Act (“HIPAA”) and does not sign business associate agreements. Customer will not submit (a) protected health information that it holds as a HIPAA covered entity or business associate; (b) classified information or technical data controlled under U.S. export control laws, such as ITAR; or (c) Personal Data subject to the data protection laws of the European Economic Area, the United Kingdom, or Switzerland. Customer will send Customer Data only through the Service, not by email, unless Sidebar asks.
4.1 Acknowledgment and no warranty. Customer Data may include material protected by the attorney-client privilege, the work product doctrine, or a duty of confidentiality. Sidebar receives and processes it only as Customer’s service provider, under the confidentiality and use restrictions in this DPA, and the parties do not intend Customer’s use of the Service to waive any privilege or protection. Sidebar does not warrant that any privilege or protection applies or will be upheld. Customer is responsible for deciding whether its use of the Service is consistent with its professional obligations.
5.1 Liability. Each party’s liability arising out of or relating to this DPA, under any theory and including Sidebar’s liability for its Subprocessors, is subject to the exclusions and limitations of liability in the Agreement, which apply to the Agreement and this DPA together and not separately. Only Customer and Sidebar may enforce this DPA. It gives no rights to Authorized Users, Customer’s clients, or anyone else.
5.2 Precedence, term, law, and notices. If this DPA conflicts with the rest of the Agreement on the processing or protection of Customer Data, this DPA controls, except that the Agreement’s exclusions and limitations of liability always apply. This DPA applies for as long as Sidebar holds Customer Data. It is governed by the law, and disputes will be resolved in the forum, that the Agreement specifies. Notices to Sidebar go to legal@sidebar-ai.com. Notices to Customer go to its account administrator’s email address, which Customer must keep current.
5.3 Changes. Sidebar may update this DPA by posting the new version and notifying Customer by email or in the Service at least 30 days before it takes effect. No update will materially reduce the protection of Customer Data. A Customer that does not agree may terminate the affected subscription before the update takes effect and receive a refund of prepaid fees for the unused term.
“Account Data” means information Sidebar needs to run accounts and manage its relationship with Customer, such as Authorized Users’ names and email addresses, login records, billing details, support correspondence, and technical data about use of the Service. It excludes the content of Customer Data.
“Authorized User” means an individual Customer permits to use the Service under its account.
“Customer Data” means the content that Customer or its Authorized Users submit to or generate with the Service, including prompts, outputs, conversations, documents, matter information, and content retrieved from an account an Authorized User connects. It does not include Account Data.
“Data Protection Laws” means the privacy and data security laws of the United States and its states that apply to Sidebar’s processing of Personal Data for Customer, including the California Consumer Privacy Act and its regulations.
“Personal Data” means Customer Data that relates to an identified or identifiable individual and is protected by Data Protection Laws.
“Security Incident” means a breach of the security of Sidebar or a Subprocessor that results in unauthorized access to, or unauthorized acquisition, disclosure, loss, or alteration of, Customer Data in Sidebar’s or the Subprocessor’s possession. Unsuccessful attempts that do not compromise Customer Data are not Security Incidents.
“Service” means the Sidebar products and services provided to Customer under the Agreement.
“Subprocessor” means a third party Sidebar engages to process Customer Data on its behalf to provide the Service.