01Roles
The customer is the controller (or, where the customer is itself a processor for its clients, the processor) in respect of personal data contained in documents uploaded to the service. Docket Build is the processor and acts only on the customer's documented instructions.
The agreement, this addendum and the customer's configuration of the service constitute the complete documented instructions. We will notify the customer if we believe an instruction infringes applicable data protection law.
02Subject matter and duration
| Element | Detail |
|---|---|
| Subject matter | Assembly of immigration petition packets from customer-supplied documents |
| Duration | The term of the agreement, plus the retention period configured by the customer |
| Nature and purpose | Classification, compliance checking, evidentiary mapping, pagination, Bates numbering, indexing, drafting, cross-checking and export |
| Categories of data subject | Beneficiaries, petitioners, dependants, declarants, witnesses and firm personnel |
| Categories of personal data | Identity, contact, immigration status, employment, education, financial and, in humanitarian matters, special category data |
03Confidentiality of personnel
Personnel authorised to process customer content are bound by written confidentiality obligations, receive annual data protection and security training, and are subject to background checks before production access is granted. Access is granted on a least-privilege basis and reviewed quarterly.
04Security measures
- AES-256 encryption at rest with envelope encryption and per-tenant data keys, rotated on a 90-day schedule.
- TLS 1.3 in transit with HSTS enforced.
- Isolated tenant storage; no shared buckets and no cross-tenant context at inference time.
- Matter-scoped role-based access control, with SSO/SAML and SCIM available on the Scale tier.
- Comprehensive audit logging of every document action, exportable by the customer.
- Annual third-party penetration testing and continuous vulnerability management.
- Documented business continuity and disaster recovery plan with tested failover.
05Subprocessors
The customer authorises the subprocessors listed on our subprocessors page. We impose data protection obligations on each subprocessor at least as protective as those in this addendum, and we remain liable for their performance.
We will give at least thirty days' notice before adding or replacing a subprocessor. The customer may object on reasonable data protection grounds within that period, in which case the parties will work in good faith to resolve it; if no resolution is possible, the customer may terminate the affected service without penalty.
06Model training exclusion
Docket Build will not use customer content — including client documents, firm work product, cover-letter templates, exhibit indexes and any derivative of them — to train, fine-tune, evaluate or benchmark any machine learning model, whether our own or a third party's.
This obligation applies to pre-training, fine-tuning, reinforcement learning, evaluation datasets and any human review programme. It is not subject to an opt-out, is not conditioned on tier, and survives termination of the agreement. Compliance with this control is tested as part of our SOC 2 Type II examination.
07Data subject requests
Taking into account the nature of the processing, we will assist the customer by appropriate technical and organisational measures in fulfilling its obligation to respond to data subject requests. Where we receive a request directly, we will not respond substantively and will forward it to the customer without undue delay.
08Personal data breach
We will notify the customer without undue delay and in any event within twenty-four hours of confirming a personal data breach affecting their content. Notification will describe the nature of the breach, categories and approximate volume of data affected, likely consequences and measures taken. A written incident report follows within five business days, and a post-incident review is available on request.
09Deletion and return
The customer configures retention. Source uploads default to deletion 180 days after packet export; matter-level retention is available on the Scale tier. On termination, we delete customer content in accordance with the configured retention period, and in any event within ninety days, except where retention is required by law.
We will issue a certificate of destruction on request for any specific document, matter or account.
10Audit
We will make available all information reasonably necessary to demonstrate compliance with this addendum, including our current SOC 2 Type II report, penetration test summary and hosting attestation under NDA. Where a customer's regulatory obligations require an on-site audit, we will accommodate one no more than annually, on reasonable notice and at the customer's cost.
11International transfers
Where processing involves transfer of personal data out of the EEA, the UK or Switzerland, the parties incorporate the applicable Standard Contractual Clauses, with Docket Build as data importer, together with a documented transfer impact assessment. Customers may select US or India data residency, and document processing remains within the selected region.
Contact
Docket Build, Inc., Plot No. 5, Road No. 5, Mahindra Hills East Marredpally, Nehrunagar, Hyderabad, Secunderabad, Telangana, 500026, India. Email privacy@docketbuild.com, telephone +91 (080) 4123-7700.