OULUTION LEGAL
OULUTION DATA PROCESSING ADDENDUM
ON THIS PAGE
- 1. Parties, scope, incorporation
- 2. Definitions
- 3. Roles
- 4. Oulution’s obligations as Processor
- 5. Subprocessing
- 6. International transfers
- 7. Audit
- 8. Data Subject rights and complaints
- 9. Government access requests
- 10. Liability, precedence
- 11. General
- ANNEX I — DETAILS OF PROCESSING
- ANNEX II — TECHNICAL AND ORGANISATIONAL MEASURES
- ANNEX III — LIST OF SUBPROCESSORS
1. Parties, scope, incorporation
1.1 This Data Processing Addendum (“DPA”) is between Oulution Holdings Limited (“Oulution”, “Processor”) and the customer identified in the underlying agreement (“Customer”, “Controller”).
1.2 This DPA is incorporated into, and forms part of, the Master Subscription Agreement, the Enterprise Terms of Service, or any other agreement between the parties for the Services (the “Agreement”). In the event of conflict on processing of Personal Data, this DPA prevails over the Agreement.
1.3 This DPA implements:
(a) Article 28 GDPR (Regulation (EU) 2016/679);
(b) Article 28 UK GDPR read with the Data Protection Act 2018;
(c) the Hong Kong PDPO;
(d) PIPL entrusted-processing requirements;
(e) CCPA/CPRA service-provider terms;
(f) LGPD; and
(g) other applicable Data Protection Laws.
2. Definitions
Terms in bold in the GDPR (Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing, Special Category Data, Supervisory Authority) bear their GDPR meaning or the closest equivalent under applicable Data Protection Laws.
“Data Protection Laws” — all laws applicable to processing under this DPA (including those in clause 1.3).
“Restricted Transfer” — a transfer of Personal Data to a country without an adequacy decision under the applicable regime.
“SCCs” — EU Commission Implementing Decision (EU) 2021/914 of 4 June 2021 as amended.
“UK IDTA” — the UK International Data Transfer Agreement and/or the UK Addendum to the EU SCCs, issued under s.119A DPA 2018.
“PIPL Standard Contract” — the Standard Contract for Outbound Cross-Border Transfer of Personal Information (CAC, Feb 2023).
“Subprocessor” — a third party engaged by Oulution to process Personal Data on the Customer’s behalf.
3. Roles
3.1 For Customer Personal Data: Customer is Controller (or Processor for a third-party controller); Oulution is Processor (or Sub-processor).
3.2 Oulution acts as independent Controller for: (a) billing, (b) Authorised User account administration, (c) security and fraud prevention, (d) product analytics on de-identified data. The Privacy Policy governs those operations.
3.3 Details of processing are in Annex I.
4. Oulution’s obligations as Processor
4.1 Processing on instructions. Oulution processes Personal Data only (a) on the Customer’s documented instructions (Agreement, Order Form, this DPA) and (b) as required by law applicable to Oulution, in which case Oulution informs the Customer before processing unless the law prohibits notice on important public-interest grounds.
4.2 Purpose limitation (CCPA service-provider certification). Oulution will not sell, share, retain, use, or disclose Personal Data outside the direct business relationship or for any purpose other than the specific business purposes set out in the Agreement and Annex I. Oulution certifies it understands and will comply with these restrictions (Cal. Civ. Code §§ 1798.140(ag)(1), 1798.140(ah)).
4.3 Confidentiality. Personnel authorised to process Personal Data are bound by confidentiality.
4.4 Security. Oulution implements the technical and organisational measures in Annex II, appropriate to the risk.
4.5 Assistance to Controller. Taking into account the nature of processing and information available, Oulution assists the Customer with: (a) Data Subject rights requests (access, rectification, erasure, restriction, portability, objection, and equivalents); (b) GDPR Arts. 32–36 compliance (security, breach notification, DPIA, prior consultation); (c) equivalent obligations under UK GDPR, PDPO, PIPL, CCPA (including verifiable consumer requests), and LGPD.
4.6 Personal Data Breach. Oulution notifies the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, providing the information required by GDPR Art. 33(3) as available, with updates as facts develop.
4.7 Records. Oulution maintains records of processing under GDPR Art. 30(2).
4.8 End of processing. On termination/expiry, at Customer’s option Oulution deletes or returns all Personal Data and deletes copies, unless retention is required by law (in which case continued protection under this DPA applies).
5. Subprocessing
5.1 Customer authorises Oulution to engage Subprocessors. Current list: oulution.ai/subprocessors (the “Subprocessor List”), reproduced in Annex III.
5.2 Oulution: (a) imposes on each Subprocessor written data-protection obligations substantially equivalent to this DPA; (b) remains liable for Subprocessor acts and omissions as its own; (c) gives at least 30 days’ prior notice of addition/replacement, via the Subprocessor List with email notification for subscribers.
5.3 If the Customer has a reasonable documented data-protection objection within 15 days of notice, the parties discuss in good faith. If unresolved, the Customer may terminate the affected Services with a refund of pre-paid unused Fees for those Services.
6. International transfers
6.1 Personal Data may be transferred outside the Customer’s or Data Subjects’ jurisdictions.
6.2 EEA transfers. For Restricted Transfers from the EEA, the EU SCCs are incorporated as follows:
(a) Module Two (Controller→Processor) where Customer is Controller and Oulution is Processor;
(b) Module Three (Processor→Processor) where Customer is Processor and Oulution is Sub-processor;
(c) Clause 7 (docking) applies;
(d) Clause 9(a) Option 2 (general written authorisation) with 30 days’ notice;
(e) Clause 11(a) optional independent-DR language does not apply;
(f) Clause 17 — SCCs governed by the law of Ireland;
(g) Clause 18(b) — courts of Ireland;
(h) Annexes I, II, III to the SCCs are populated by Annexes I, II and III of this DPA respectively.
6.3 UK transfers. The UK Addendum to the EU SCCs (Version B1.0, in force 21 March 2022) is incorporated. Parties may alternatively use the stand-alone UK IDTA populated by this DPA’s Annexes.
6.4 Swiss transfers. EU SCCs apply with FDPIC-required amendments (GDPR references read as FADP; supervisory authority = FDPIC; Swiss law for Swiss-only transfers).
6.5 PRC transfers. Parties comply with PIPL cross-border requirements. Where the PIPL Standard Contract is required, parties enter into it and file it with the provincial cyberspace administration as required. Where a CAC Security Assessment is required (by volume or sensitivity), Customer is responsible as data handler / Controller; Oulution provides reasonable cooperation.
6.6 Other jurisdictions. For transfers from Brazil (LGPD), Singapore (PDPA), Japan (APPI), Korea (PIPA), Australia, and equivalent regimes, parties comply with applicable transfer requirements using SCCs, consent, or other lawful mechanisms.
7. Audit
7.1 Oulution makes available information reasonably necessary to demonstrate compliance, through:
(a) up-to-date third-party audit reports (SOC 2 Type II, ISO 27001, or equivalent) on request under confidentiality;
(b) written information requests within 30 days;
(c) on-site audit up to once every 12 months (or more frequently where required by a Supervisory Authority or where Oulution has notified a Personal Data Breach affecting Customer Personal Data in the preceding 12 months), on 30 days’ prior written notice, during business hours, subject to (i) auditor confidentiality, (ii) auditor not being a competitor of Oulution, and (iii) Customer bearing its own costs.
7.2 Findings are Oulution’s Confidential Information, used only for Customer’s compliance purposes.
7.3 Where the SCCs apply, SCC Clause 8.9 governs to the extent of inconsistency.
8. Data Subject rights and complaints
8.1 Oulution forwards direct Data Subject requests to the Customer without undue delay and does not respond except on Customer’s documented instructions or as required by law.
8.2 Oulution assists the Customer, insofar as possible, in responding to Data Subject rights requests.
8.3 Where Oulution must respond directly to a Data Subject by law (e.g. CCPA service-provider scenarios), it does so consistently with Customer’s instructions to the extent lawful.
9. Government access requests
9.1 If Oulution receives a legally binding request from a public authority for Customer Personal Data, Oulution will, unless legally prohibited:
(a) promptly notify the Customer;
(b) inform the authority of its contractual obligations under this DPA and any objections;
(c) use reasonable efforts to challenge requests that are manifestly unlawful, disproportionate, or excessive under applicable Data Protection Laws;
(d) provide only the minimum data reasonably necessary.
9.2 Where legally prohibited from notifying, Oulution uses best efforts to obtain a waiver and documents its efforts. Oulution publishes at least annual transparency reports summarising, to the extent lawful, government access requests received.
9.3 This clause supplements the SCCs and is intended to satisfy the Schrems II (C-311/18) and EDPB Recommendations 01/2020 supplementary-measures analysis.
10. Liability, precedence
10.1 The Agreement’s liability provisions (including caps and super-caps) apply to liability under this DPA, save that no provision limits either party’s liability to a Data Subject under GDPR Art. 82 or equivalent to the extent such limitation is impermissible.
10.2 Where the SCCs apply, nothing here limits liability owed to Data Subjects or Supervisory Authorities under the SCCs.
11. General
11.1 Term. Effective on the Agreement’s effective date; continues until Oulution has ceased processing all Customer Personal Data.
11.2 Amendments. Oulution may update this DPA on notice to reflect changes in Data Protection Laws or transfer mechanisms, provided updates do not materially reduce Customer protections.
11.3 Order of precedence. (i) mandatory Data Protection Laws, (ii) SCCs / UK IDTA / PIPL Standard Contract (as applicable), (iii) this DPA, (iv) the Agreement.
11.4 Signatures. By entering into the Agreement, both parties are deemed to have signed this DPA. Where a standalone signature is required for a Supervisory Authority filing, either party may request execution and the other will not unreasonably refuse.
ANNEX I — DETAILS OF PROCESSING
A. List of Parties
Data Exporter / Controller: the Customer (details in the Agreement / Order Form). Role: Controller (or Processor where the underlying data belongs to a third-party controller).
Data Importer / Processor: Oulution Holdings Limited, Business Registration Number 72443593, registered office: Room D07, 8/F, Kai Tak Fty Building, No. 99 King Fuk Street, Sanpokong, Kowloon, Hong Kong. Contact: info@oulution.ai. Role: Processor (or Sub-processor).
B. Description of Processing
Categories of Data Subjects:
- Authorised Users of the Customer (employees, contractors, professional personnel);
- Individuals whose Personal Data is contained in Inputs submitted by the Customer (Customer’s clients, counterparties, employees, and third parties referenced in matters).
Categories of Personal Data:
- Identification and contact data (name, business email, phone, employer);
- Professional data (role, qualifications, sector);
- Account and authentication data;
- Usage and log data (timestamps, IP address, session identifiers);
- Personal Data contained in Inputs (names, contact details, financial data, transactional data, and free-text content referring to identifiable individuals).
Special Category / Sensitive Personal Data:
Not knowingly processed by design. Customer undertakes not to submit Special Category Data (GDPR Art. 9) or CCPA-sensitive personal information unless (i) it has a valid legal basis and any Art. 9 condition (or equivalent), and (ii) it has notified Oulution in writing to enable additional safeguards.
Nature and Purpose of Processing:
Provision of the Oulution AI legal-information platform — hosting, processing prompts, generating AI Outputs, storing matters and documents, collaboration features, security, support, billing, and (where Customer opts in) model training and improvement.
Duration of Processing:
For the Term of the Agreement, plus any period reasonably required for return / deletion under clause 4.8 or as required by law.
Frequency of Transfer:
Continuous, as part of ordinary Services operation.
C. Competent Supervisory Authority (for SCCs)
The supervisory authority of the Member State in which the Data Exporter is established; or, where the Data Exporter is not established in an EU Member State but has designated an Art. 27 representative, the supervisory authority of the Member State of the representative.
ANNEX II — TECHNICAL AND ORGANISATIONAL MEASURES
Oulution implements, at minimum, the following measures. Where a measure is provided by a Subprocessor (e.g. hosted cloud infrastructure), Oulution ensures contractually equivalent protection.
- Governance — Documented information security policy; designated security officer; annual policy review; documented risk assessments.
- Access control — Role-based access control; least-privilege; multi-factor authentication for all administrative access; unique credentials; quarterly access reviews; joiner-mover-leaver process.
- Encryption — TLS 1.2+ in transit; AES-256 at rest for stored data; encrypted backups; encrypted key management using an industry-standard KMS.
- Environment segregation — Logical separation of Customer environments; separation of production and non-production; no use of production Personal Data in non-production except where masked or synthetic.
- Logging and monitoring — Centralised logging; anomaly detection; alerting on privileged actions; security log retention of at least 12 months.
- Personnel security — Background checks where lawful; confidentiality undertakings; annual security and privacy training; onboarding/offboarding with credential revocation.
- Secure development — Secure SDLC; peer code review; SAST and DAST; dependency and secrets scanning; change management.
- Vulnerability and patch management — Regular vulnerability scanning; severity-based patching SLAs; annual third-party penetration test.
- Business continuity and disaster recovery — Documented BCP/DRP; regular backup and restore testing; defined RTO/RPO published to Customer on request.
- Incident response — Documented plan; 24/7 on-call; forensic capability; post-incident review; breach-notification procedures aligned to clause 4.6.
- Physical security — Hosted in Tier III+ data centres operated by certified providers (AWS / GCP / Azure or equivalent) with SOC 2 Type II / ISO 27001 attestations.
- Vendor risk management — Vendor risk assessment; contractual data-protection obligations flowing down this DPA; ongoing monitoring.
- Data lifecycle — Documented retention schedules; secure deletion; data-minimisation practices; pseudonymisation where appropriate.
- AI-specific safeguards — Input filtering for sensitive data; exclusion of flagged content (privileged, special category, children’s data, Customer-flagged confidential) from training datasets; model output evaluation; prompt-injection defences; opt-in only training on Customer Data.
- Certifications (target) — SOC 2 Type II and ISO/IEC 27001 within 18 months of launch; ISO/IEC 27701 and ISO/IEC 42001 (AI management system) on the medium-term roadmap.
ANNEX III — LIST OF SUBPROCESSORS
The Subprocessor List is maintained at oulution.ai/subprocessors and updated in accordance with clause 5.2(c). The categories below reflect the operational scope; the specific entity, legal name, jurisdiction, and processing purpose for each Subprocessor is populated in the live List prior to go-live and updated on change.
# | Category | Purpose of processing | Location(s) | Personal Data categories accessed |
|---|---|---|---|---|
1 | Cloud infrastructure (IaaS/PaaS) | Hosting Services; storage; compute for model inference | [primary region] with [DR region] | All categories in Annex I.B |
2 | AI foundation-model provider(s) | Model inference for Output generation, under contractual no-training terms | [region] | Inputs and Outputs (transient) |
3 | Analytics and product telemetry | Aggregated usage and feature analytics | [region] | Usage, device, session IDs |
4 | Error monitoring and diagnostics | Crash reporting, performance monitoring | [region] | Device, diagnostics, limited log data |
5 | Payment processing | Subscription and pay-per-matter billing | [region] | Account, billing (financial data handled directly by processor) |
6 | Customer support tooling | Ticket handling, in-app chat, knowledge base | [region] | Account, communications |
7 | Email and transactional communications | Service emails, notifications | [region] | Account, email address |
8 | Security operations | SIEM, DDoS protection, WAF | [region] | Log data, IP, session |
9 | Identity and authentication | SSO, MFA, session management | [region] | Account, authentication data |
10 | Cross-border transfer counsel-of-record (Art. 27 / UK Rep / PIPL local representative) | Statutory representative function | EU, UK, PRC | Contact data for representative filings |
Each Subprocessor is bound by written contract to data-protection obligations substantially equivalent to this DPA. Oulution assesses each Subprocessor before engagement and monitors on an ongoing basis.