Data processing agreement
The processor terms between a law firm and OrdoMetric: roles, residency, encryption, backups, staff access, sub-processors, AI, bring-your-own storage and keys, and deletion.
Version 0.1 · Effective September 7, 2026Draft for counsel review
Draft for counsel review
A Nepali practitioner has not yet reviewed this document. The highlighted markers show the statements awaiting confirmation; until they are cleared, this text is not a binding version.
This agreement forms part of the service agreement between the law firm named in that agreement (the Firm) and OrdoMetric [verify legal entity name] (OrdoMetric). It governs the processing of personal information that OrdoMetric performs for the Firm. Where it differs from the service agreement, this agreement prevails for that processing [verify with a Nepali practitioner].
1. Roles
1.1 The Firm is the controller of the personal information it records in OrdoMetric: it decides what is recorded, why and for how long, and it is responsible to its clients and to the people named in its files. OrdoMetric is the Firm's processor and processes that information only as this agreement and the Firm's configuration of the service instruct.
1.2 Nepali law does not yet define these roles. The parties adopt them contractually, following the structure of Article 28 of the EU General Data Protection Regulation, so that the Firm's obligations under the Individual Privacy Act, 2075 and the Individual Privacy Regulation, 2077 flow down to OrdoMetric in writing [verify applicability of the Act's personal-information chapter to private bodies with a Nepali practitioner].
1.3 This agreement is governed by the law of Nepal [verify with a Nepali practitioner]. It refers to the Individual Privacy Act, 2075 and the Individual Privacy Regulation, 2077 [verify sections], to the Electronic Transactions Act, 2063 for the legal recognition of electronic records and the offence of unauthorized access [verify], and to the confidentiality duty of legal practitioners under the Nepal Bar Council Act, 2050 and the Legal Practitioners' Code of Conduct, 2051 [verify rule].
2. Subject matter, duration, nature and purpose
2.1 Subject matter: the case files, client records, documents, notes, hearings, messages and user accounts the Firm keeps in OrdoMetric (Annex A).
2.2 Duration: the term of the service agreement plus the export and deletion period in clause 12.
2.3 Nature and purpose: hosting, storage, encryption, search, notification and backup and, where the Firm enables them, AI processing and connector access, so that the Firm can manage its cases and communicate with its clients.
2.4 Data subjects: the Firm's users; the Firm's clients and their contacts; opposing parties, counsel, witnesses, judges and court staff named on a case; recipients of the Firm's client updates.
3. OrdoMetric's obligations
OrdoMetric will:
- (a) process personal information only on the Firm's documented instructions, which are this agreement, the service agreement and the settings the Firm's Owners and Admins configure, and tell the Firm if it believes an instruction breaches the law [verify with a Nepali practitioner];
- (b) ensure that the people it authorizes to operate the service are bound by confidentiality and have no standing access to the Firm's content (clause 7);
- (c) implement the security measures in Annex B and keep them under review;
- (d) engage sub-processors only under clause 8;
- (e) assist the Firm, within 30 days of a request, in answering requests from data subjects for access, correction or deletion. The Firm answers such requests through its own channels; OrdoMetric provides the export, correction and deletion functions in the service and, where the Firm instructs it in writing, performs the export or erasure of the records concerned;
- (f) notify the Firm's Owners of a personal-data breach affecting the Firm within 72 hours of becoming aware of it, with the scope known at that time, the actions taken and the actions recommended, and support the Firm's own notices to its clients; no Nepali statute currently sets a deadline [verify], and 72 hours is OrdoMetric's contractual commitment;
- (g) at the end of the service, return the Firm's data by export and then delete it as clause 12 describes;
- (h) make available the information the Firm needs to demonstrate compliance: the Security page, the Sub-processor register, the current mapping of controls to ISO 27001:2022 Annex A and SOC 2, the summary of each external penetration test once it has been performed, and the record of each restore drill once it has been run. A formal audit by the Firm or its appointed auditor may be requested with 30 days' notice, no more than once a year unless required by an authority or following a breach, at the Firm's cost and under confidentiality [verify with a Nepali practitioner].
4. Hosting and residency
4.1 Pilot profile. OrdoMetric hosts the Firm's database, documents and backups with Railway in Singapore (asia-southeast1) [verify Railway region list]. Cloudflare provides DNS, TLS termination, a web application firewall and rate limiting at its global edge; TLS terminates at Cloudflare, so request content is visible to it in transit, and Cloudflare stores no request bodies or dynamic responses. The off-site copy of the nightly encrypted database backup (clause 6.1) is stored in Cloudflare R2 object storage, whose location Cloudflare assigns automatically [verify R2 region auto placement].
4.2 India option. On request, and once the profile has been activated for the Firm, OrdoMetric places a Firm that requires India residency, hardware-backed per-firm keys, approver-gated staff access or regional high availability on its Google Cloud profile in Mumbai (asia-south1), with backups and the second copy of documents in Delhi (asia-south2). The properties that differ between the two profiles are stated in clauses 5, 6 and 7.
4.3 No region in Nepal is available from any provider. The parties record that the Act contains no express restriction on processing personal information abroad [verify] and that the Firm obtains its clients' informed consent to electronic storage abroad in its engagement letter [verify with a Nepali practitioner].
4.4 OrdoMetric will not move the Firm's data to another country without at least 30 days' written notice to the Firm's Owners [verify DPA notice period], except to restore the service after a disaster, in which case it notifies the Firm without undue delay.
5. Encryption
5.1 Per-firm keys. Every firm has its own data-encryption key. Documents and their extracted text are encrypted under that key before they reach storage, and so are the sensitive database fields: citizenship numbers on party records, the Firm's storage tokens and its AI credentials. Other database contents (case facts, notes, client and party contact details, search indexes) rely on the hosting platform's encryption at rest [verify Railway volume encryption] and on the access controls in Annex B. TLS protects everything in transit.
5.2 Pilot and self-hosted profiles (envelope model). The Firm's key is wrapped by a versioned key-encryption key that lives only in the platform's sealed secret store, never in code, images or logs. Objects are encrypted by the application before they are written to the object store, so the storage provider holds only ciphertext. Deleting the Firm nulls the wrapped key, which makes every live copy of the Firm's documents and encrypted fields unreadable at once. Caveat: the wrapped key remains inside database backups until those backups age out, so a backup could in principle be decrypted by someone holding both that backup and the platform's key-encryption key until that date; the deletion certificate (clause 12) states the date [verify Railway backup retention].
5.3 Google Cloud profile. Each firm has its own Cloud KMS key, applied as customer-managed encryption to every object and wrapping the same data key. Destroying that key version renders every copy of the Firm's data unreadable, including copies inside backups and the Delhi replica. This is the stronger property and one reason the profile exists.
6. Backups, recovery and continuity
6.1 Pilot profile. A nightly encrypted dump of the database is kept for 35 days [verify BACKUP_RETENTION_DAYS on the pilot], with an off-site copy in Cloudflare R2 under separate credentials (clause 4.1), in addition to the platform's own scheduled volume backups [verify Railway backup schedules and retention]. The recovery point objective is 24 hours: up to one day of changes can be lost in a disaster, and there is no point-in-time recovery. Documents are stored in a single region; their durability is the object store's own. The recovery time objective is about 4 hours. OrdoMetric restores the latest backup into a fresh database at least quarterly and runs its tenant-isolation suite against it; the record of each drill is available under clause 3(h).
6.2 Google Cloud profile. Point-in-time recovery with a recovery point of 5 minutes or better, daily snapshots kept 35 days in Delhi, and documents replicated across Mumbai and Delhi. The recovery time objective is 4 hours.
6.3 The Firm acknowledges the pilot posture in clause 6.1 and may at any time ask to be placed on the Google Cloud profile once it is activated. OrdoMetric proposes the move itself before the Firm's data grows beyond what a 24-hour recovery point can reasonably cover.
7. Staff access and break-glass
7.1 OrdoMetric's staff have no standing access to the Firm's content on any profile. Access to the hosting accounts is limited to two named people, each with multi-factor authentication as a condition of holding it; database credentials exist only in the platform's sealed secret store.
7.2 Pilot profile (procedural break-glass). When an incident or a support request requires
OrdoMetric to open the Firm's data, the person doing so runs the break-glass tool, which (i) records
a written justification, the requester, the start time and the planned duration in the Firm's audit
log as a break_glass.access entry, (ii) emails the Firm's Owners at once, (iii) creates a database
role that expires automatically after at most 4 hours and logs every statement it runs, and (iv)
on closing, removes the role, rotates the credential used and writes a closing audit entry
summarizing what was run. Any document read during that window is written to the Firm's audit log as
a break-glass download. Disclosed limitation: on this profile there is no independent approver
between the request and the access; the controls are the audit trail, the Owner notification and
the time box.
7.3 Google Cloud profile. Break-glass runs through Google Cloud's Privileged Access Manager: a
justification is required, a second person approves, the grant lasts at most 4 hours, and the
database and storage access logs feed the same break_glass.access audit entry and Owner email.
7.4 A firm that requires approver-gated access is placed on the Google Cloud profile once it is activated.
8. Sub-processors
8.1 The Firm gives OrdoMetric general authorization to engage the sub-processors listed in the Sub-processor register, which is incorporated into this agreement by reference. Each is bound by a written agreement imposing data-protection obligations no less protective than this one, and OrdoMetric remains responsible to the Firm for their performance [verify with a Nepali practitioner].
8.2 OrdoMetric notifies the Firm's Owners by email at least 30 days before a new sub-processor processes the Firm's data [verify DPA notice period]. If the Firm objects on reasonable data-protection grounds and the parties cannot resolve the objection, the Firm may terminate the affected service and export its data under clause 12 without penalty.
8.3 Controller-selected processors. Where the Firm itself selects a processor, that is an alternative AI provider (clause 10) or its own Dropbox or Google Drive account (clause 11), that provider is engaged by the Firm, is listed in the register's controller-selected section for transparency, and must be named in the Firm's own notice to its clients. OrdoMetric is not responsible for such a provider's compliance.
9. AI processing
9.1 AI processing is off by default and starts only when one of the Firm's Owners enables it in Settings after reading the sub-processor notice. Until then no case text leaves the hosting region for AI purposes.
9.2 With AI enabled, OrdoMetric sends the platform AI provider, Anthropic, in the United States, the following, and only where the requesting user is authorized to read it: for the assistant, summaries, drafts and key-date extraction, the text the user may read (passages of documents and notes returned by permission-checked tools, and the case facts the user can see); for OCR of scanned documents, the document file itself, uploaded once to Anthropic's Files API and referenced by an identifier that OrdoMetric records so that it can delete the file when the document is excluded or purged [verify Files API retention]. Anthropic's commercial terms exclude training on the Firm's inputs. OrdoMetric has requested zero data retention in writing; until it is confirmed, the provider's standard API retention applies and is stated on the consent screen [verify zero-data-retention availability for the selected models]. Document embeddings for search are computed by Google Cloud (Vertex AI) in Mumbai (asia-south1) by default; an alternative embedding provider selected by the Firm falls under clause 10.
9.3 There is no automated removal of personal information from text before it is sent. The controls are: the Owner-only switch in clause 9.1; the Firm's exclusion of any case, note or client (a client's recorded refusal excludes all of that client's cases, and exclusion purges the derived text, vectors and uploaded files already produced); tool results limited to what the requesting user may read, with citizenship numbers stored encrypted and returned only when that user holds write access to the section concerned; a usage record that keeps only a short excerpt of each prompt, redacted after 90 days by default and configurable by the Firm; and an entry in the Firm's audit log for every AI call.
9.4 Anything the assistant proposes that is client-facing or changes the state of a case is a draft that a person approves; the assistant reads only what the requesting user may read.
9.5 The Firm is responsible for informing its clients about AI-assisted processing in its engagement letter; OrdoMetric provides a suggested clause on request [verify with a Nepali practitioner].
10. Alternative AI providers and bring-your-own keys
10.1 The Firm may select OpenAI, Azure OpenAI, AWS Bedrock or Google Vertex AI as its AI provider for the assistant, OCR and, where offered, embeddings, instead of the platform default. That provider processes the Firm's text and, for OCR, rendered page images in the region the Firm configures, under the provider's terms; the Firm's own notice must name it (clause 8.3).
10.2 With a bring-your-own key, the Firm's own agreement with the vendor governs that processing. OrdoMetric records only the provider, the region and the last characters of the key, stores the key encrypted under the Firm's data key, never shows it again after entry, and stops using it the moment the Firm revokes it or the vendor rejects it. OrdoMetric never moves the Firm to a different vendor silently: if the Firm's key stops working, calls fail with a clear error until an Owner acts.
11. Bring-your-own storage (Dropbox or Google Drive)
11.1 An Owner may connect the Firm's own Dropbox or Google Drive account so that new uploads are stored there. The Firm is the account holder and controller of that account; OrdoMetric holds a refresh token, encrypted under the Firm's data key and never sent to a browser, and uses the narrowest scopes the provider offers (a Dropbox app folder [verify Dropbox app-folder registration]; Google Drive access limited to files the app created).
11.2 Guarantees that differ for documents held in the Firm's own account:
-
originals are protected by the provider's encryption rather than by the Firm's OrdoMetric key; crypto-shredding under clause 5 and the backup age-out under clause 12 cover only the derived copies OrdoMetric keeps (extracted text, search vectors, thumbnails);
-
legal hold is a platform flag whose violations OrdoMetric can only detect: files renamed, moved or deleted outside OrdoMetric are marked as drifted or missing by the daily reconciliation and shown to the Firm's Admins, not prevented;
-
a deletion or purge performed by OrdoMetric leaves a recoverable copy in the Firm's own account (Google Drive's trash; Dropbox's version history), which the Firm controls;
-
if the Firm revokes the token, new uploads are refused and the documents already stored in the Firm's account cannot be opened through OrdoMetric until an Owner reconnects the same account; platform-held documents, notes, search and everything else keep working.
11.3 Viewing and downloading such documents streams through OrdoMetric, so the same authorization checks and audit entries apply.
12. Retention, export and deletion
12.1 During the term, retention follows the policies the Firm configures (default 7 years from the closing of a case [verify against Nepali tax and Bar record-keeping expectations]); deleted items are restorable for 30 days and then purged; cases under legal hold are never purged.
12.2 On termination, the Firm has a 30-day export window during which an Owner can produce a complete archive (documents plus structured data, including the audit log); OrdoMetric reminds the Owners weekly. The archive is encrypted under the Firm's key and downloaded only after authentication and step-up verification.
12.3 After the window, OrdoMetric destroys the Firm's data key as clause 5 describes, deletes the Firm's rows and platform-held objects, and anonymizes its user records. OrdoMetric issues a deletion certificate stating what was deleted, when, and the date on which the last backup containing the Firm's data ages out: on the pilot profile, when the last platform volume backup and the last nightly dump (and its off-site copy in Cloudflare R2) containing the Firm expire [verify Railway backup retention]; on the Google Cloud profile, 35 days after key destruction. Documents in the Firm's own Dropbox or Google Drive account are not touched by OrdoMetric's deletion; they remain the Firm's to keep or remove.
13. Client messages and the Claude connector
13.1 Messages OrdoMetric sends to the Firm's clients on a user's instruction contain the case stage, the next steps and the Firm's contact details only. SMS is off during the pilot; if the Firm later enables it, the SMS providers join the register under clause 8 before any message is sent.
13.2 The Claude connector lets a user reach the Firm's cases from the user's own Anthropic account (claude.ai or Claude Code). Data exchanged through it flows under that account's terms and outside this agreement. The connector is off by default, is enabled by an Owner, respects every exclusion, watermarks its responses with the case reference and logs every call.
14. Liability and precedence
Liability, indemnity and the order of precedence between this agreement and the service agreement are to be settled by counsel before signature [verify with a Nepali practitioner].
Annex A: description of the processing
| Item | Description |
|---|---|
| Data subjects | The Firm's users; clients and their contacts; opposing parties, counsel, witnesses, judges and court staff named on a case; recipients of client updates |
| Categories of data | Identity and contact details; case facts, pleadings and evidence, including the sensitive categories of section 2 of the Individual Privacy Act, 2075 as they occur in case files [verify s. 2 definition]; hearing and deadline dates; notes and comments; documents and their extracted text; consent and lawful-basis records; audit and security logs |
| Frequency | Continuous, for the term |
| Location | Singapore (asia-southeast1) on the pilot profile [verify Railway region list], with the off-site backup copy in Cloudflare R2 at a location Cloudflare assigns [verify R2 region auto placement]; Mumbai (asia-south1) and Delhi (asia-south2) on the Google Cloud profile once activated; AI providers as clauses 9 and 10 state |
Annex B: security measures
The measures are described on the Security page and summarized here: one data-encryption key per firm (clause 5); row-level security on every tenant table with a runtime role that cannot bypass it, checked by a cross-tenant test suite on every build; organization roles and per-case role templates deciding access down to each section of a case; multi-factor authentication mandatory for Owners and Admins and enforceable for everyone; an audit log with actor, action, target, address and time, exportable by the Firm; content security policies, HSTS, rate limits and antivirus scanning of every upload; secret and dependency scanning, static analysis and image scanning in the build pipeline; an external penetration test before the first paying firm; and the incident-response commitment in clause 3(f). The controls are aligned with OWASP ASVS Level 2 and mapped to ISO 27001:2022 Annex A and SOC 2; OrdoMetric does not claim certification.
Annex C: sub-processors
The Sub-processor register, as amended under clause 8.