← Back to Maggie

Data Processing Agreement (DPA)

Summary of how Maggie processes personal data as a processor on behalf of law firms. Last updated: June 2026.

Note: This is a public summary for pilots and investor review. A signed DPA template for enterprise customers is available in documentacion/DPA_TEMPLATE.md in the repository. Have qualified counsel review before binding use.

Roles

  • Controller: The law firm or notary office using Maggie — decides why and how client/staff data is processed.
  • Processor: Maggie Legal CRM — processes data only on documented instructions from the Controller.
  • Subprocessors: Third parties listed on our Subprocessors page.

Subject matter & duration

Processing is limited to providing the Maggie platform: client and matter management, documents, calendar, billing, client portal, automations, and optional private AI features. Processing continues for the term of the subscription or pilot agreement and until data is deleted per the firm's instructions.

Categories of data & subjects

Data subjectsTypical data
Firm staffName, email, role, session logs
Clients & contactsIdentity, contact, address, case notes, documents
Portal usersEmail, messages, uploaded files, payment status
Special categoriesMay appear in legal files (immigration, health-related matters) — Controller determines lawful basis

Processor obligations

  • Process personal data only on documented instructions from the Controller.
  • Ensure personnel with access are bound by confidentiality.
  • Implement appropriate technical and organizational measures (see Security).
  • Maintain multi-tenant isolation — firm A cannot access firm B's data.
  • Assist the Controller with data subject requests where technically feasible.
  • Notify the Controller without undue delay after becoming aware of a personal data breach.
  • Delete or return personal data at end of service, subject to legal retention requirements.
  • Make available information necessary to demonstrate compliance and allow audits with reasonable notice.

AI & document processing

When enabled, uploaded documents may be text-extracted, chunked, and embedded for semantic search and chat. In the default deployment, embeddings and inference run on Ollama and vectors are stored in Qdrant on the same infrastructure — not sent to public LLM APIs. Document text snippets (up to ~2,000 characters per chunk) are stored in the vector index for retrieval.

International transfers

Production for maggie.law is hosted in the United States. Firms in the EU/UK should assess transfer mechanisms (SCCs, adequacy, or local deployment). Self-hosted or dedicated deployments may keep all processing in a jurisdiction chosen by the Controller.

Contact

Data protection inquiries: privacy@maggie.law · General: info@maggie.law

For investors: see also the live platform metrics page and subprocessor register.