1. Scope and role allocation
This Data Addendum is part of the Agreement between Talden and Customer. Definitions in the Platform Agreement apply. It protects Customer Content whether or not the content is Personal Data. Customer Personal Data means Personal Data included in Customer Content that Talden processes to provide the Service on Customer's instructions. Data Protection Law means privacy, security and data-protection law applicable to the relevant party and processing. Security Incident means an accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Content in systems controlled by Talden or its subprocessors. Awareness arises when Talden has a reasonable degree of certainty that such an incident has occurred; a final forensic finding is not required. Unsuccessful attempts that do not compromise Customer Content are not Security Incidents but remain subject to reasonable security management.
For Customer Personal Data, Customer acts as controller or business, or as a processor authorized by the relevant controller, and Talden acts as processor, subprocessor, service provider or contractor as applicable. These labels apply only where consistent with the actual activity and law. Talden separately determines limited purposes for its own account, payment, security and business records as explained in the Privacy Notice; that role does not convert substantive matter content into unrestricted controller data. No personal-use exception permits Talden to exploit client materials. Processing particulars are in Annex 1; minimum safeguards in Annex 2; retention in Annex 3; approved subprocessors in Document 07, incorporated as Annex 4. The International Processing and Transfer Rider applies only when effective for the relevant processing.
2. Confidentiality
Customer Content and nonpublic information about Customer's clients, matters, strategies and instructions are Customer's Confidential Information. Talden's nonpublic software, security evidence, technical documentation and business information disclosed as confidential or reasonably understood to be confidential are Talden's Confidential Information. A receiving party may use the other's Confidential Information only to perform or exercise rights under the Agreement, with reasonable care and no less protection than for its own information of similar sensitivity.
Access may be given only to personnel, approved service providers and professional advisers with a need to know for a permitted purpose and an enforceable duty of confidentiality. Each receiving party remains responsible for those persons' compliance within the Agreement's liability allocation. Talden may also disclose the material Customer specifically approves to the identified recipient of an enabled operation under the Agent Schedule; that approval authorizes only the specified disclosure, not unrelated use by Talden. No residuals clause permits use of remembered client information. Confidentiality does not prohibit Customer's lawful use and delivery of its own reviewed work product.
A receiving party may establish an exception with contemporaneous records showing that particular information was lawfully known without restriction before disclosure, became public without a confidentiality breach, was lawfully received without restriction from an independent source, or was independently developed without using the protected information. An exception affecting one source fact does not make a nonpublic compilation, client relationship or legal strategy public. Restrictions on processing Personal Data continue independently of these exceptions. Confidentiality duties last while the information remains nonpublic; trade secrets remain protected for as long as they qualify as trade secrets. Retention or termination does not authorize publicity or unrelated reuse.
3. Permitted processing; prohibited secondary use
Talden may process Customer Content only to perform Customer's documented instructions and supply the authorized Service; execute the automated inference, drafting, internal checking and source-verification passes needed for Customer's task; store, export and delete the resulting work; maintain user-approved personalization; meter attributable usage without transmitting substantive content to billing systems; provide specifically authorized support; investigate and address a genuine security, abuse or service-integrity event; and comply with a binding legal obligation under section 8.
Talden will not use Customer Content to train or fine-tune a shared or general-purpose model, develop a model for another customer, build a shared matter corpus, sell data, serve or target advertisements, or create marketing audiences. Talden will not authorize a subprocessor to do so. Automated quality checks within Customer's requested job are permitted Service processing, not authorization for a separate customer-content evaluation dataset. General product evaluation and prompt, retrieval or model development must use public or synthetic materials or appropriately non-content operational metrics unless Customer separately authorizes a specific dataset and use in writing with the necessary underlying rights. Consent to ordinary paid use is not that authorization.
Talden may use Operational Metrics, meaning technical counts, timings, model identifiers, resource consumption and reliability statistics that do not disclose substantive content, client identity, matter titles, confidential facts or an identifiable individual's sensitive information. Replacing a name in a recognizable document does not turn it into Operational Metrics. Where metrics are deidentified, Talden will use reasonable measures against reidentification, not attempt to reidentify them, and impose equivalent limitations on recipients. Data derived from restricted Google or Microsoft API material remains subject to applicable connected-data restrictions; this paragraph is not an exception to them.
Talden will not expose Customer Content to another Customer or use another Customer's content to answer Customer's request. User-approved practice-wide memory can intentionally affect matters within the same workspace; it must remain within the scope the User approved. Turning personalization off stops use of saved memories for new personalization but does not itself delete existing memories or source conversations. Deletion controls must distinguish those operations.
4. Personnel and support access
Routine human review of client content for model training or general product improvement is not permitted. Authorized personnel may access the minimum content necessary for a specific support request approved by Customer, a genuine security or abuse investigation, narrowly scoped incident remediation, or legal compliance. Access must be role-restricted, logged, time-bounded where practicable and subject to confidentiality. Debugging must use redacted material where feasible; unredacted examples require specific approval unless an immediate security need or law justifies the access. Talden will not ask Customer to place matter content in a public ticket or ordinary marketing chat.
If a connected-data policy requires approval to view specific messages or files, a general Terms acceptance is not that approval. The Support Access Authorization identifies the material and purpose. Personnel may not export content to personal AI accounts or unapproved tools. Talden must restrict access promptly when a role or engagement ends.
5. Instructions; statutory processor terms; assistance
Customer's documented instructions consist of the Agreement, accepted Order, approved feature settings, authorized prompts and task configurations, and subsequent lawful written instructions consistent with the Service. Talden will promptly notify Customer if it believes an instruction violates Data Protection Law, and may suspend that instruction while the concern is resolved. Talden is not required to perform a new service, support a prohibited category, or take an unlawful action. Customer is responsible for necessary controller instructions, lawful bases, special-category conditions, notices and permissions, including authority to appoint Talden as a subprocessor where Customer acts for a client.
Where United States state service-provider or processor rules apply, Talden will process Customer Personal Data only for the specified limited purposes, will not sell or share it for cross-context behavioral advertising, and will not retain, use or disclose it outside those purposes or the direct business relationship except as expressly permitted by applicable law. Talden will not combine it with personal information from another person's sources or its own interactions except as law permits for the specified service-provider purposes. Talden certifies that it understands and will comply with these restrictions, will provide the required level of protection, and will notify Customer if it can no longer comply. Customer may take reasonable and appropriate steps to stop and remediate unauthorized use, including through the evidence and audit procedure below.
Taking account of the nature of processing and information available to it, Talden will reasonably assist Customer with valid rights requests, security and breach obligations, legally required impact assessments and regulatory consultations. Talden will promptly refer a request concerning Customer-controlled matter data to Customer unless law requires a direct response. It will not disclose another person's confidential matter files merely because the requesting individual is mentioned in them. Talden may charge reasonable, previously disclosed fees for extraordinary assistance not caused by Talden's breach and not required to be provided without charge; it may not withhold mandatory assistance or breach cooperation pending agreement on fees.
6. Security; incidents; evidence
Talden will implement and maintain the safeguards in Annex 2 and reasonable measures appropriate to the nature of legal-matter content and risks of processing. It may update safeguards without materially reducing their overall protection. Customer controls its own endpoints, credentials, content selection and grants. Neither party promises that all security incidents can be prevented.
Talden will notify Customer without undue delay and in any event within 48 hours after becoming aware of a Security Incident affecting Customer Content. The initial notice may be preliminary and must not await completion of a forensic investigation. As information becomes available, Talden will provide the known nature and timing, affected data and persons or reasonable estimates, likely consequences, mitigation and containment steps, a contact, and information reasonably needed for Customer's legal obligations. It will preserve proportionate evidence, investigate, mitigate and reasonably cooperate, while protecting other customers and investigation integrity. A notice is not an admission of liability. A suspicion not yet meeting the awareness standard remains subject to prompt investigation and any earlier notice independently required by law; internal classification or escalation cannot postpone an awareness time already reached.
Customer controls notices to its clients and persons for whom it is responsible, unless law requires Talden to notify directly. Talden will, where lawful, consult Customer before identifying Customer publicly. Neither party may prevent the other from complying with law. Vendor notice and coordination requirements will be observed without delaying mandatory notice. Talden bears its own containment and remediation costs for its systems; allocation of other recoverable costs and liability follows the Platform Agreement.
Talden will make reasonably available information sufficient to demonstrate its compliance, using current security descriptions, relevant independent reports if available, and reasonable written answers first. It does not represent that a certification or independent report exists. Where those materials are insufficient to meet a legal requirement or substantiate a material concern, Customer may arrange a scoped audit by an independent, qualified, noncompetitor auditor bound by confidentiality. Except for a regulator request, Security Incident or reasonable evidence of material noncompliance, audits are limited to once a year on 30 days' notice, during business hours, with minimal disruption and at Customer's expense. No audit may expose another customer's information, require unsafe penetration testing or disclose unnecessary trade secrets. These procedural limits do not prevent a mandatory regulator inspection or an audit required by nonwaivable law. Talden pays reasonable verification costs where an audit establishes its material breach.
7. Subprocessors and supply-chain changes
Customer generally authorizes the subprocessors identified in Annex 4 for their listed purposes and routes. Talden will appoint them under written obligations appropriate to the processing and no less protective in substance than the relevant obligations here, including restricted use, confidentiality and security. Talden remains responsible for their performance of processing obligations it delegates, subject to the Agreement. Customer-selected independent services are not Talden subprocessors solely because Customer connects them; Talden's handling of imported copies remains covered.
Talden will give direct notice at least 15 days before a new or replacement subprocessor first receives Customer Content. Customer may object within 10 days on reasonable data-protection or confidentiality grounds. The parties will seek a practical solution, which may be an alternative route or disabled optional feature. If no solution is reasonably available, either may terminate only the materially affected service before the transfer, with the unused prepaid refund required for a Talden convenience termination. Customer has no absolute veto over Talden's entire supplier portfolio, and Talden need not build a bespoke platform. Silence after proper notice constitutes authorization, not consent to a new purpose.
An emergency necessary to address an imminent security issue may justify immediate replacement only where the alternative already satisfies the same protections and law permits it; Talden must notify Customer promptly, preserve the objection and exit rights, and not rely on that exception to bypass mandatory transfer-clause notice. Otherwise the affected function must pause. A model fallback or gateway change is a subprocessor change if it introduces a new content recipient, and cannot silently bypass the approved register.
8. Legal demands; privilege; restricted material
Talden may disclose protected information only to the extent legally required, after giving Customer prompt notice where permitted and a reasonable opportunity to seek protection. It will reasonably assess the demand's validity, seek clarification or narrowing where appropriate, cooperate with a lawful challenge, and disclose no more than required. It will not volunteer confidential matter content merely because a third party alleges a dispute. If notice is prohibited, Talden will seek permission to notify where reasonably available and notify when the restriction ends if lawful. Lawful preservation is distinct from public disclosure.
The parties intend Customer Content to be handled as confidential material through a limited service-provider relationship. Neither intends authorized processing to waive a protection otherwise available, but neither represents that the Agreement creates or guarantees attorney-client privilege, work product or compliance with a particular protective order. Customer must assess those matters, and Talden must supply accurate processing information and honor its commitments.
The standard Service is not approved for protected health information processed under HIPAA, payment-card authentication data, classified information, criminal-justice-system data requiring a special compliance regime, export-controlled technical information requiring unavailable controls, or other data requiring a contractual or technical regime Talden has not activated in writing. Consumer health data subject to a specialist health-data regime requires prior written route approval and the applicable processor or other documentation. A court-protected document is permitted only if the order and client instructions allow the approved data path. These restrictions do not prohibit ordinary confidential transactional or regulatory work merely because it is sensitive. Accidental submission must be reported promptly for restriction and lawful deletion; it does not authorize additional use or relieve Talden of directly applicable law.
9. Return, deletion and continuing duties
Talden will carry out return and deletion under Annex 3, including downstream instructions. It may retain only the specifically identified records for a permitted period or a binding legal hold. Retained content remains protected, access-restricted and unavailable for active inference or product development. Backups must not be used to restore deleted data into active service except for legitimate recovery followed by reapplication of the deletion record. At Customer's reasonable request, Talden will confirm completion and identify any remaining restricted category and its basis. Talden will not promise secure erasure merely because an item enters Trash or an original upload is removed.
Annex 1. Processing particulars
Parties and contact. Customer is the person identified in the accepted Order; its contact is the verified Order contact. Talden Inc. is the processor/service provider; its contact is Privacy and Data Requests in the Contact Directory. The Order and acceptance identify the parties and processing start. For international transfers, the separately completed Transfer Rider supplies exporter identity and authority.
Subject matter, nature and purpose. Provision of Customer-directed legal-work software: receipt and extraction of selected content; model inference; internal draft and citation checks; reduced-query public research; speech transcription and playback; approved matter, client and practice memory; storage; authorized read-only connected-account access; background research and draft preparation; scoped support, security, metering, export and deletion. No external-write function is included until activated. The Service performs collection, organization, retrieval, transmission to approved providers, generation, storage, restriction, return and deletion for those purposes.
People and information. Data subjects may include Customer and its personnel, clients and prospective clients, counterparties, witnesses, experts, public officials and other persons appearing in lawful matter materials. Data may include identifiers and contact information, professional and organizational details, client and party names, correspondence and attachments, contractual and financial facts, allegations and procedural information, instructions, images, audio, inferred analyses and content-bearing audit entries. The Service does not require a User to supply all these categories. Restricted categories in section 8 remain excluded unless specifically activated; merely listing foreseeable data does not authorize a prohibited upload.
Duration and frequency. Processing occurs on demand and, for a separately enabled ongoing responsibility, at the authorized 15-minute, hourly or daily interval. Active content is retained until the relevant deletion or closure trigger, subject to Annex 3. Transfers may be continuous while an authorized job runs or periodic for a scheduled job. Individual workspaces are not shared among customers. No foundation-model training, shared-client corpus or advertising use is authorized.
Instructions and destinations. Customer selects matters, files, sources, memories, connected resources and task permissions. Providers and locations must be those in the approved Annex 4 register. Perplexity receives only reduced issue-level queries and expressly named public targets; no files, matter records, memories or custom instructions are sent to that route. A reduced query can still identify a public matter and is not automatically anonymous. Anthropic inference may receive selected conversation context, attached text, matter context and approved memory through Vercel AI Gateway. OpenAI speech, OCR and permitted search routes receive only the input necessary for that function. No unlisted fallback is authorized.
Annex 2. Minimum security measures
A2.1 Identity and access. Unique accounts; password protection with emailed device verification in the standard production sign-in; privileged-access restrictions; timely removal of departed personnel; session revocation; protection and encryption of connector tokens; no routine collection of third-party passwords. Optional Microsoft Entra sign-in does not by itself create organization administration or a new content recipient.
A2.2 Data separation and encryption. Logical tenant isolation for storage, retrieval, memory and exports; matter-scope checks; encryption in transit over supported HTTPS connections and encryption of retained Customer Content and reusable authentication secrets at rest using appropriately managed keys, and protection of stored password verifiers through appropriately salted one-way hashing. Talden will test cross-workspace access and retrieval controls before enabling client-content processing and after material relevant changes. It does not promise end-to-end encryption under which its processing providers can never access content.
A2.3 Service protection. Rate limits, daily run limits, webhook-signature checks, HTTPS-only source fetching with server-side request-forgery protections, validation of tool inputs, restricted network destinations where appropriate, and separation of untrusted documents or web content from authorization instructions. External write functions remain technically disabled until approved. Scheduled jobs must respect revoked permissions, account suspension and billing limits.
A2.4 Development and vulnerability management. Controlled production changes; review proportionate to risk; dependency and vulnerability monitoring; documented triage, ownership, remediation or compensating controls; testing of material security and deletion changes; no known unresolved critical vulnerability permitting unauthorized Customer Content access at release. A vulnerability is not acceptable merely because a scanner label says low risk; the relevant exploit path must be considered.
A2.5 Logging and personnel. Content-minimized telemetry, redaction of error reports, access records sufficient for investigations, segregation of billing metrics from client information, confidentiality undertakings, staff training and an approved-tools policy. No advertising pixels or content-capturing session replay in authenticated workspaces. Support widgets load only on the User's request and must not automatically receive matter content or identity beyond the disclosed purpose.
A2.6 Incident and recovery. A documented incident response and escalation procedure, monitored security intake, vendor escalation, containment, evidence preservation and notification controls supporting section 6. Talden will maintain a proportionate documented recovery procedure and test the recovery and deletion treatment of backups it actually uses. It will not represent backup-based recovery as available before validating that capability. This baseline does not promise an uptime percentage, recovery-time objective, recovery-point objective, SOC 2 report, ISO certification or HIPAA qualification. Customer remains responsible for independent archival copies and required professional records.
Annex 3. Retention, export and deletion schedule
A3.1 Active matter data. Matters, transcripts, drafts, saved results, extracted text and approved memories remain until Customer permanently deletes the relevant material, closes the account, or an announced inactivity closure occurs. Trash has no automatic expiry and is not secure erasure. A permanent-delete instruction removes the selected item from normal access promptly; associated production copies and Customer Content derivatives selected for deletion will be deleted within 30 days, except specifically lawful holds and the non-content records permitted by A3.4. Removing personal identifiers alone does not authorize retention of confidential substance. Deleting an original file does not, without selecting the related material for deletion, delete a transcript, Output, extract or memory already created from it. A full matter purge or account closure covers associated derivatives and content-bearing logs.
A3.2 Originals and temporary attachments. Ordinary uploaded originals are removed after extraction by default; the extracted text and work product are retained under A3.1. Choosing Keep saves the original to the Library until deletion. Background-job attachments use the 24-hour temporary period unless Customer selects the expressly displayed 30-day longer-retention job setting; the period runs from upload, unless the disclosed job notice states a later expiry necessary for the authorized job. The precise stored expiry must be displayed and honored. Temporary expiry does not itself remove copied extracts or results. Talden may not silently move an ordinary upload to long-term original-file retention. Raw dictation audio, generated playback audio and temporary speech buffers have the following application-side retention and deletion trigger: To be confirmed. Transcripts and saved text remain governed by A3.1; provider-side audio retention is separately stated in the approved OpenAI route in Annex 4. No promise that raw audio is immediately discarded follows merely from deleting a transcript.
A3.3 Closure and export. Customer may export the practice archive, available documents, audit data and usage records in the supported ZIP, Word, PDF, CSV, email or calendar formats. A Customer-requested closure becomes effective when Support verifies the request; a Talden-initiated closure becomes effective on the notified termination date. On that date Talden stops new jobs, cancels renewal and auto-refill, and removes its connector tokens. This does not postpone an earlier billing cancellation. Unless Customer requests immediate deletion, Talden provides a 30-day export window from that date, after which production deletion is completed within 30 days. An immediate-deletion instruction waives the remaining export window and starts the 30-day production-deletion period on verification of that instruction. Talden will acknowledge the applicable dates. A financial cancellation alone is not account closure.
A3.4 Audit records and usage evidence. Client names, matter titles, substantive instructions and other content-bearing audit fields remain Customer Content, despite append-only or hash-chain architecture. They follow the applicable matter or account deletion trigger. Talden may preserve integrity proofs and non-content event metadata only if they no longer disclose or permit reconstruction of confidential substance, client identity or matter information. Content-bearing fields must be removed within the production-deletion period, using a documented method that does not misrepresent the resulting record as an unmodified original. Minimal evidence of contract acceptance, billing, purchased balances, refunds and cancellation may be retained for seven years after account closure, or longer only where a specific legal duty or hold requires it. That record must not retain full conversations or client identities merely for convenience. A legally required shorter period controls where applicable.
A3.5 Security, support and provider records. Content-minimized operational security logs are ordinarily retained no more than 90 days, with narrowly documented extensions for a genuine investigation or legal hold. Approved content-bearing support examples are deleted when the support purpose ends and no later than 30 days thereafter, unless Customer specifically requests continuing support or a lawful hold applies. Model-provider and gateway records may be retained only for their verified, disclosed operational or abuse-monitoring periods in Annex 4, with no training or unrelated use; the ordinary content-retention ceiling for such provider records is 30 days unless a shorter setting applies. A longer provider retention period may not be introduced through an undisclosed default and requires a lawful, specifically agreed exception before that route is used. This ceiling does not override a binding legal preservation duty, which remains narrowly restricted.
A3.6 Backups and holds. Deleted Customer Content remaining in backup systems must expire or be rendered inaccessible beyond recovery within 90 days after production deletion. Backups are isolated from ordinary processing and not used for training, analytics or routine retrieval. A legal hold preserves only required material with restricted access and a documented basis, reviewed periodically and released when the duty ends; production deletion must then be completed within 30 days after the hold ends, or sooner if law requires, without a new export window. Talden will identify material retained on that basis to Customer where lawful. Subprocessor dispatch, copying or a failed deletion job does not restart any deadline in this Annex. No claim of instantaneous deletion from every system is made.
A3.7 Connected data. Disconnecting a connection removes Talden's tokens and stops future access but does not itself revoke the provider-side grant or erase already imported copies. Customer can separately request deletion of imported material. Microsoft API data must also be corrected, restricted or deleted as required by source changes, abandonment, disconnection/deletion instructions, account closure and applicable API terms; those source-specific requirements prevail over a general retention permission. Talden will not use an independently saved copy or derived dataset to evade those requirements. Customer may retain its own lawfully exported work independently; Talden does not control copies already sent or exported outside its systems.
A3.8 Inactive accounts. Talden may close an unpaid account after at least 12 months without sign-in, an authorized run or other affirmative use, on 30 days' direct notice and an export opportunity. Mere existence of an expired or revoked automation does not establish active use. A connected source's earlier mandatory abandonment rule controls that source data. Minimal purchased-balance records and lawful redemption rights survive content deletion. Backup, provider and statutory-request rules may require a shorter or different treatment; Talden will apply the controlling requirement and inform Customer where appropriate.
Annex 4. Approved subprocessors
The version of the Subprocessor and Recipient Register presented with the accepted Data Addendum is incorporated as Annex 4. Later changes require section 7's notice and objection process. A provider or route with an unresolved identity, location, content-use or retention field is not approved for Customer Content merely because it appears in a draft register. Talden must complete and approve those facts before that route is activated; a Customer checkbox cannot substitute for Talden's supplier diligence.