Legal

Data processing agreement.

Effective 8 August 2026snowLEX Oy · Helsinki, Finland

When your API requests contain personal data, you stay in control of it and we process it only to answer the request. This DPA sets that out in GDPR Art. 28 terms: transient, EU/EEA-based processing, no retention of content, no training on your data, and a published list of sub-processors.

§01Scope and roles

This Data Processing Agreement ("DPA") forms part of the Terms of Servicebetween you (the "Customer") and snowLEX Oy, Helsinki, Finland. It applies to personal data contained in the content you submit to the API and the output returned for it ("API Content"), for which you are the controller and snowLEX Oy the processor within the meaning of GDPR Art. 4.

For account, billing and request metadata, snowLEX Oy is an independent controller — that processing is described in the Privacy Policy and is outside this DPA.

§02Description of processing

  • Subject matter: API Content submitted to the snowLEX Developer Platform.
  • Nature and purpose: transient processing of message content to retrieve relevant legal sources and generate the requested answer.
  • Duration: the duration of each API request; API Content is not retained after the response is delivered (§08). The DPA applies for as long as the Terms do.
  • Data subjects and categories: whatever personal data the Customer chooses to include in prompts. The Customer should minimize personal data in prompts and must not submit special categories of data (GDPR Art. 9) unless it has a lawful basis to do so.

§03Instructions

snowLEX processes API Content only on the Customer's documented instructions (GDPR Art. 28(3)(a)). The Terms, this DPA and each API call — including its parameters — constitute those instructions. snowLEX does not use API Content to train models. snowLEX will inform the Customer if, in its opinion, an instruction infringes the GDPR or other EU or member-state data protection law.

§04Confidentiality

Persons authorized to process API Content are bound by contractual or statutory confidentiality obligations (Art. 28(3)(b)), and access is limited to what their role requires.

§05Security measures

snowLEX implements appropriate technical and organizational measures under GDPR Art. 32, including:

  • encryption in transit (TLS) for all API and console traffic;
  • encryption at rest for stored platform data;
  • API keys stored only as cryptographic hashes; secrets held in managed configuration, not in code;
  • role-based, least-privilege access controls and authenticated service-to-service calls;
  • no persistence of API Content by the gateway — processing is in-memory for the duration of the request;
  • logging limited to request metadata (ids, token counts, status) — never message content;
  • hosting on EU/EEA infrastructure (see the sub-processor list).

§06Sub-processors

The Customer grants a general written authorization to engage the sub-processors listed at /legal/subprocessors (Art. 28(2)). snowLEX imposes data-protection obligations on each sub-processor equivalent to those in this DPA and remains liable for their performance. Changes to the list are announced in advance via the console or email; the Customer may object on reasonable data-protection grounds, in which case the parties will seek a solution and, failing one, the Customer may terminate the affected service with a refund of its unused prepaid balance.

§07Assistance

Taking into account the nature of the processing, snowLEX assists the Customer with appropriate technical and organizational measures in fulfilling data-subject requests (Arts. 12–23) and in meeting the Customer's obligations under Arts. 32–36 (security, breach notification, impact assessments), insofar as the information is available to snowLEX. Because API Content is not retained, requests concerning it can typically be answered from the Customer's own records.

§08Deletion and return

API Content is processed transiently and is not stored by the platform, so deletion occurs by design at the end of each request. Upon termination of the Terms, snowLEX deletes remaining personal data it processes as controller in accordance with the Privacy Policy, except where EU or member-state law requires continued storage (Art. 28(3)(g)).

§09Personal data breach

snowLEX notifies the Customer without undue delay after becoming aware of a personal data breach affecting API Content, providing the information reasonably available to it to support the Customer's obligations under Arts. 33–34.

§10Audits

snowLEX makes available the information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits conducted by the Customer or an auditor it mandates (Art. 28(3)(h)): at most once per year, on at least 30 days' notice, during business hours, under confidentiality, at the Customer's expense, and without access to other customers' data.

§11International transfers

API Content is processed within the EU/EEA; the current processing locations are listed at /legal/subprocessors. snowLEX will not transfer API Content outside the EU/EEA unless a Chapter V transfer mechanism (such as an adequacy decision or Standard Contractual Clauses) is in place, and will inform the Customer in advance of any such change.

§12General

In case of conflict between this DPA and the Terms, this DPA prevails for data-protection matters. Liability under this DPA is subject to the limitations in the Terms to the extent permitted by law. Governing law and venue follow the Terms (Finnish law; Helsinki District Court).

LegalTerms of ServicePrivacy PolicyData Processing AgreementSub-processors