Legal
Data Processing Addendum
Summary · July 21, 2026 · Request signed DPA: legal@citesafe.co
This page is a public summary of our standard processing terms for enterprise customers. A countersigned DPA controls if one is executed. Not legal advice.
1. Roles
For customer content submitted to CiteSafe in a firm account context, Customer is typically the Controller (or Processor for its clients) and CiteSafe is the Processor of that content. For website analytics-style metadata we control, we act as an independent controller.
2. Purpose limitation
We process Customer Content solely to provide CiteSafe (verification, related product features you enable, security, billing support). We do not sell Customer Content.
3. Training
Train public generative models on customer content: No. Train internal models on full documents by default: No.
4. Cite-only & minimization
Default product path extracts citation strings on-device and transmits public authority strings only. Full document mode is customer-initiated opt-in with confirmation. Verify API does not persist request bodies to a CiteSafe database ( body_stored=false).
5. Subprocessors
Listed at /subprocessors. Material changes posted there; enterprise customers may request notice by email.
6. Security & breach
Reasonable technical and organizational measures for SaaS beta. Confirmed personal-data breaches: target customer notice within 72 hours of confirmation where required. See Security.
7. Deletion & return
On written request after termination, we delete or return Customer Content in our control within 30 days, except copies retained as required by law or for security dispute resolution (limited, access-controlled). Device-local beta data is deleted by the user on-device.
8. International transfers
Primary processing in the United States. Signed DPAs may incorporate Standard Contractual Clauses or other transfer tools where required.
9. Request a signed DPA
Email legal@citesafe.co with firm name, contact, and jurisdictions of interest.