Kefilex Data Processing Agreement
Status: company-drafted, pending solicitor review. Version 1.1-draft, 28 Jul 2026. Items in [square brackets] to be completed before first external signature.
This Data Processing Agreement ("DPA") forms part of the Kefilex Terms of Business between Kefilab of 301 Bath Road, Hounslow, London TW3 3DB, ICO registration ZC207164 ("Kefilab", the processor) and the subscribing law firm ("the Firm", the controller), and applies whenever Kefilab processes personal data on the Firm's behalf in providing the Kefilex service.
1. Roles and scope
1.1 The Firm is the controller of personal data processed in the Kefilex service (including data synchronised from the Firm's Clio account, captured from the Firm's website forms, phone systems, email integrations and referrer portal). Kefilab is the Firm's processor.
1.2 Kefilab is an independent controller only of: (a) the Firm's own account and billing records; and (b) product-usage analytics collected under the consent and policy described in the Kefilex Privacy Policy.
1.3 "Data Protection Law" means the UK GDPR and the Data Protection Act 2018, and where applicable the EU GDPR.
2. Details of processing (Annex I summary)
- Subject matter / purpose: provision of the Kefilex legal-intake platform — lead capture, intake pipeline, matter and billing analytics, referrer portal, and related support.
- Duration: the subscription term plus the 90-day post-termination export window (clause 9).
- Nature: hosting, storage, display, synchronisation with the Firm's Clio account and connected channels, automated classification and routing, reporting, and transactional email on the Firm's behalf.
- Categories of data subjects: the Firm's prospective, current and former clients; callers and enquirers; referrers/introducers; the Firm's own personnel.
- Categories of personal data: names, contact details, enquiry content and call summaries, matter references and status, billing and payment-status figures, marketing attribution identifiers (e.g. click IDs), and communication metadata.
- Special-category and criminal-offence data: the platform is sold to law firms, so enquiry and matter content will contain special-category data within the meaning of Article 9 (health in personal-injury and family work; sex life, religious or philosophical beliefs in family work) and criminal-offence data within the meaning of Article 10 UK GDPR and Schedule 1 DPA 2018. Kefilab treats such content as present by default rather than exceptional: it is stored in the Firm's own isolated schema, is never used to train models and is never included in product analytics (see the Privacy Policy), and Kefilab personnel reach it only under clause 6. The Firm remains responsible for the lawful basis and, where required, the Article 9(2) condition or Schedule 1 condition for the content it processes.
3. Kefilab's obligations as processor
Kefilab shall:
(a) process the personal data only on the Firm's documented instructions (this DPA, the Terms of Business, and the Firm's configuration of the service being those instructions), unless required otherwise by law — in which case Kefilab will inform the Firm unless prohibited;
(b) ensure persons authorised to process the data are bound by confidentiality obligations;
(c) implement the technical and organisational measures described in the Kefilex Security Overview (Annex II), maintaining a level of security appropriate to the risk;
(d) assist the Firm with data-subject requests (access, erasure, rectification, portability) and with the Firm's obligations under Articles 32–36 UK GDPR, taking into account the nature of processing. This assistance is provided at no charge. Where a request is manifestly unfounded or excessive, in particular because it is repetitive, Kefilab may charge a reasonable fee reflecting its administrative cost, having first told the Firm and agreed it;
(e) notify the Firm without undue delay and in any event within 24 hours of confirming a personal-data breach affecting the Firm's data, with the information reasonably required for the Firm's own regulatory assessment, and keep the Firm updated as the position develops. Kefilab sets this deadline deliberately short: the Firm's own 72-hour clock to the ICO runs from the point Kefilab becomes aware, so time Kefilab takes is time the Firm loses. Reasonable costs of investigating and responding to a breach (including forensics, legal advice and regulatory correspondence) are borne by the party responsible for the breach, subject to clause 10;
(f) at the Firm's choice, delete or return all personal data at the end of the subscription (clause 9), unless law requires retention;
(g) make available information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits (satisfied in the first instance by Kefilab's written security documentation and completed questionnaires; on-site audits by agreement, at the Firm's cost, no more than annually);
(h) immediately inform the Firm if, in Kefilab's opinion, an instruction from the Firm infringes Data Protection Law, and pause the affected processing until the Firm confirms or withdraws it; and
(i) maintain the records of processing required of a processor by Article 30(2) UK GDPR.
Nothing in this DPA relieves Kefilab of its own responsibilities and liabilities as a processor under Data Protection Law.
3A. The Firm's obligations as controller
Article 28(3) requires this contract to set out the controller's obligations and rights as well as the processor's. The Firm shall:
(a) ensure it has a lawful basis for the personal data it processes in the service, and where that data falls within Article 9 or Article 10 UK GDPR, an applicable condition for it;
(b) give lawful and accurate instructions — including through its own configuration of the service, the integrations it enables and the data it chooses to import — and ensure those instructions comply with Data Protection Law;
(c) be responsible for the accuracy, quality and legality of the personal data it provides, and for its own transparency obligations to data subjects, including telling them that Kefilab acts as its processor;
(d) manage its own users' access, including designating super users, setting roles and capabilities, and removing access promptly when a person leaves; and
(e) respond to data-subject requests forwarded under clause 7, which remain the Firm's to answer.
The Firm has the right to the assistance, information, audit co-operation, notification and deletion provisions set out in clauses 3, 4 and 9.
4. Sub-processors (Annex III)
4.1 The Firm gives general written authorisation to the sub-processors listed below. Kefilab will give 30 days' notice of any intended addition or replacement (via the service or email), during which the Firm may object on reasonable data-protection grounds.
4.2 Where Kefilab engages a sub-processor, it will put in place a written contract imposing the same data-protection obligations as those set out in this DPA, in particular the obligation to provide sufficient guarantees of appropriate technical and organisational measures. Kefilab remains fully liable to the Firm for the performance of each sub-processor's obligations, subject to clause 10.
4.3 If the Firm objects under clause 4.1 and Kefilab cannot within 30 days offer a reasonable alternative that meets the objection, the Firm may terminate the affected part of the service without penalty, and Kefilab will refund any fees already paid for that part for the period after termination. Neither party is otherwise liable for the termination.
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase (AWS) | Database, authentication, storage | eu-west-2 (London) |
| Netlify | Application hosting and serverless functions | Functions in eu-west-2 (London); static assets cached on a global CDN |
| Resend | Transactional email delivery | [confirm: EU region pinned, or amend clause 5 — see the note below] |
| Stripe | Subscription billing (Kefilab's own controller purpose) | EU/UK entity |
| PostHog | Product analytics (EU cloud; content-blind for paid firms per the Privacy Policy) | EU (Frankfurt) |
| Sentry (Functional Software, Inc.) | Application error and performance monitoring (diagnostics only; configured with no default PII and payload scrubbing so client personal data is excluded from error reports) | EU (Germany; host ingest.de.sentry.io) |
4.4 Customer-directed integrations (the Firm's own Clio account, phone/reception providers, Google/Meta advertising APIs, the Firm's website) are engaged on the Firm's instruction under the Firm's own agreements with those providers and are not Kefilab sub-processors. Where the Firm enables an advertising conversion integration, Kefilab transmits only the identifiers the Firm configures (e.g. hashed email, click ID) to that platform on the Firm's behalf.
5. International transfers
Production data is stored and processed in the United Kingdom / EEA — the database, application functions and product analytics are in the London and EU regions listed above, and the Firm's matter, client and enquiry data is not stored outside the UK/EEA.
Two points of detail, stated rather than glossed:
- Static assets only on the CDN. Content cached on Netlify's global network is static application assets — scripts, styles, images. Pages containing the Firm's data are generated on demand by functions in eu-west-2 and are not cached at the edge. Requests are routed through Netlify's edge network in transit.
- Transactional email. Email Kefilab sends on the Firm's behalf (notifications, invitations, alerts) passes through Resend. [Where Resend's EU region is enabled, this remains within the EEA; if it is not, this is a transfer and is covered by the mechanism below. Confirm before first external signature.]
If a sub-processor requires a transfer outside the UK/EEA, Kefilab will put in place a valid transfer mechanism (UK IDTA / Addendum or EU SCCs) and complete a transfer risk assessment before any transfer, and notify the Firm under clause 4.
6. Confidentiality and legal professional privilege
Kefilab acknowledges the Firm's data may be subject to legal professional privilege and solicitor–client confidentiality. Kefilab personnel access Firm data only for support, incident response, or as otherwise instructed, on a need-to-know basis, and access is logged. Kefilab will refer any third-party demand for Firm data to the Firm unless legally prohibited, and will not voluntarily disclose it.
7. Data-subject requests
Kefilab will forward to the Firm, without undue delay, any data-subject request it receives that relates to the Firm's data, and will not respond directly except to redirect the requester to the Firm.
8. Security
The measures in the Kefilex Security Overview (Annex II — published at kefilex.com and provided with this DPA) apply, including tenant isolation by dedicated database schema and role, encryption in transit and at rest, role-and-capability-based access control, audited administrative access, and UK/EU data residency.
9. Return and deletion
On termination or expiry of the subscription, the Firm may export its data for 90 days, free of charge and in machine-readable form. After that window Kefilab deletes the Firm's personal data from production systems, with backup copies expiring on backup rotation [state rotation period, e.g. 30 days], unless retention is required by law. Kefilab's own controller records (billing, accounting) are retained per statutory requirements. Kefilab will provide written confirmation of deletion on the Firm's request.
10. Liability and order of precedence
Liability under this DPA is subject to the limitations and exclusions in the Terms of Business. If this DPA conflicts with the Terms of Business on data-protection matters, this DPA prevails.
Signed by incorporation into the Kefilex Terms of Business, or on request as a countersigned standalone document.