Legal assurance
Data Processing Agreement
The commercial terms that sit under the technical controls: what we may process, for how long, who else touches it, and what happens if something goes wrong.
Our standard DPA is available for execution before any pilot begins. We accept redlines and can sign your paper where it is compatible with the controls described here.
Roles and instructions
- You are the controller; TokenGrill is the processor and acts only on your documented instructions.
- Processing is limited to delivering the service — no secondary use, no training, no profiling, no resale.
- Sub-processors are bound to equivalent terms, and you are notified before a new one that can touch content is added.
Retention and deletion
- TokenGrill retains no client content at any time — all matter data lives on the appliance you own.
- Matter indices, execution metadata and audit logs persist on the box for the retention period you set; audit records are append-only during that period by design.
- On termination you keep or wipe the appliance's storage yourself; there is no vendor-side copy to request deletion of.
Security and incidents
- Technical and organisational measures are the controls described in the security whitepaper, incorporated by reference.
- Incident notification without undue delay, with the facts you need for your own regulatory and client notifications.
- Audit and information rights, satisfied in the first instance by documentation and questionnaire responses.
Transfers
There are no international transfers of client data: processing happens at the physical location of the appliance. Standard contractual clauses are available for the limited account and billing data we hold.
Need this in writing for your review?
We share the underlying documentation with security and risk teams under NDA, and will walk your counsel through anything on this page.
Request documentation