Legal
Data Processing Agreement
Last updated: 20 March 2026
This Data Processing Agreement ("DPA") is incorporated into the Navionra Terms of Service and applies whenever Navionra processes personal data on behalf of a law firm customer ("Controller"). For Enterprise customers requiring a countersigned DPA, contact legal@navionra.com.
1. Definitions
- "Controller" — the law firm or organisation that subscribes to Navionra and determines the purposes and means of processing personal data.
- "Processor" — Navionra Ltd, processing personal data on behalf of the Controller.
- "Personal Data" — any information relating to an identified or identifiable natural person, as defined by UK GDPR.
- "Sub-processor" — a third party engaged by Navionra to process Personal Data in connection with the Service.
- "Data Subject" — the individual whose Personal Data is processed.
2. Scope and nature of processing
| Subject matter | Legal practice management — document storage, AI analysis, compliance, HR, billing |
| Duration | For the term of the subscription, plus 90 days post-cancellation for data export |
| Nature | Storage, retrieval, AI processing, search indexing, audit logging |
| Purpose | Provision of the Navionra service as instructed by the Controller |
| Data subjects | Lawyers, support staff, clients, counterparties, witnesses, and other individuals whose data appears in uploaded documents |
| Data categories | Names, contact details, identification documents, financial records, legal correspondence, medical/sensitive data (where uploaded by the Controller) |
3. Navionra obligations as Processor
Navionra shall:
- Process Personal Data only on documented instructions from the Controller (including these Terms).
- Ensure that persons authorised to process Personal Data are bound by appropriate confidentiality obligations.
- Implement appropriate technical and organisational security measures (see §6).
- Not engage new Sub-processors without prior notice to the Controller (see §5).
- Assist the Controller in responding to Data Subject rights requests and supervisory authority enquiries.
- Delete or return all Personal Data upon termination of the service, as directed by the Controller.
- Provide all information necessary to demonstrate compliance with this DPA and cooperate with audits.
4. Controller obligations
- The Controller is responsible for having a lawful basis for processing Personal Data before uploading it to Navionra.
- The Controller must ensure that Data Subjects have been informed of the processing as required by UK GDPR Articles 13/14.
- The Controller is responsible for the accuracy and lawfulness of the Personal Data it uploads.
5. Sub-processors
Navionra uses the following Sub-processors. The Controller provides general authorisation for Navionra to engage Sub-processors, subject to notification of any changes.
| Sub-processor | Purpose | Location |
|---|---|---|
| Anthropic, PBC | AI language model processing (zero-retention policy) | USA (adequacy safeguards: SCCs) |
| Microsoft Azure | Document storage, infrastructure | EU / UK South |
| Stripe, Inc. | Payment processing | USA (adequacy safeguards: SCCs) |
| Onfido Ltd | Identity verification (KYC add-on only) | UK |
| ComplyAdvantage | Sanctions / PEP screening (KYC add-on only) | UK / USA |
We will provide 14 days' notice of any new Sub-processor via email. If you object, you may terminate the subscription without penalty within that notice period.
6. Security measures
- Encryption in transit: TLS 1.2+ for all data in transit.
- Encryption at rest: AES-256 for all stored documents and database backups.
- Access control: Role-based access control (RBAC) with principle of least privilege; MFA available for all accounts.
- Audit logging: All access and modification events are logged with user ID, timestamp, and IP.
- Penetration testing: Annual third-party pen tests; results available to Enterprise customers on request.
- Vulnerability management: Automated dependency scanning (Dependabot) and regular security reviews.
- Incident response: We will notify the Controller within 72 hours of becoming aware of a personal data breach.
7. International transfers
Where Personal Data is transferred outside the UK/EEA (e.g. to Anthropic or Stripe in the USA), Navionra ensures appropriate safeguards are in place — currently UK International Data Transfer Agreements (IDTAs) or Standard Contractual Clauses (SCCs) as applicable.
8. Data Subject rights assistance
Navionra will assist the Controller in fulfilling Data Subject rights requests (access, erasure, portability, restriction). Submit requests via the in-app data export tool or email privacy@navionra.com. We will respond within 5 business days.
9. Termination and data deletion
On termination of the service, the Controller may export all data via the in-app export tool within 90 days. After 90 days, all Customer Content and associated Personal Data is permanently deleted from our systems and Sub-processors, excluding billing records retained for legal compliance (7 years).
10. Governing law
This DPA is governed by English law and subject to the exclusive jurisdiction of the courts of England and Wales.
Enterprise DPA
Enterprise customers may request a countersigned, customised DPA — including bespoke data residency, audit rights, and additional sub-processor restrictions. Contact legal@navionra.com.