FirmShield
Data Processing Agreement
1. Roles
- Customer (Controller) — the law firm using FirmShield
- FirmShield (Processor) — the service provider operating this application
2. Processing activities
FirmShield processes the following categories of data on behalf of Customer:
- Identity data — user emails, names, and Entra subjects for authentication and audit
- Security configuration — Microsoft 365 control results and connection metadata
- Evidence artifacts — policies, attestations, uploads, and reports
- Workforce workflow data — onboarding/offboarding records and terminated-employee lists
3. Security measures
- Tenant isolation at the application and database layer
- Encryption in transit (TLS 1.2+) and at rest
- Secrets and tokens stored via Azure Key Vault in production
- Immutable audit logging of material platform actions
- Least-privilege Microsoft Graph application permissions
4. Subprocessors
- Microsoft Azure — hosting, database, and storage (United States)
- Microsoft Graph — M365 security verification in the Customer tenant
- Stripe — subscription billing (payment card data handled by Stripe)
- OpenAI / Azure OpenAI — optional AI drafting features when enabled
- Resend — transactional email when enabled
5. Retention
Active account data is retained for the subscription term. After termination, Customer data is deleted within 90 days unless longer retention is required by law or written agreement.
6. Customer instructions
FirmShield processes Customer data only to provide the Service, secure the platform, and comply with law. Customer is responsible for lawful collection of workforce and client questionnaire data entered into FirmShield.
7. Breach notification
FirmShield will notify Customer without undue delay, and within 72 hours where required, after becoming aware of a personal data breach affecting Customer data.
Privacy / DPA inquiries: privacy@lawfirmshield.com
