Legal

Data Processing Addendum

Summary · July 21, 2026 · Request signed DPA: legal@citesafe.co

This page is a public summary of our standard processing terms for enterprise customers. A countersigned DPA controls if one is executed. Not legal advice.

1. Roles

For customer content submitted to CiteSafe in a firm account context, Customer is typically the Controller (or Processor for its clients) and CiteSafe is the Processor of that content. For website analytics-style metadata we control, we act as an independent controller.

2. Purpose limitation

We process Customer Content solely to provide CiteSafe (verification, related product features you enable, security, billing support). We do not sell Customer Content.

3. Training

Train public generative models on customer content: No. Train internal models on full documents by default: No.

4. Cite-only & minimization

Default product path extracts citation strings on-device and transmits public authority strings only. Full document mode is customer-initiated opt-in with confirmation. Verify API does not persist request bodies to a CiteSafe database ( body_stored=false).

5. Subprocessors

Listed at /subprocessors. Material changes posted there; enterprise customers may request notice by email.

6. Security & breach

Reasonable technical and organizational measures for SaaS beta. Confirmed personal-data breaches: target customer notice within 72 hours of confirmation where required. See Security.

7. Deletion & return

On written request after termination, we delete or return Customer Content in our control within 30 days, except copies retained as required by law or for security dispute resolution (limited, access-controlled). Device-local beta data is deleted by the user on-device.

8. International transfers

Primary processing in the United States. Signed DPAs may incorporate Standard Contractual Clauses or other transfer tools where required.

9. Request a signed DPA

Email legal@citesafe.co with firm name, contact, and jurisdictions of interest.