Data Processing
Last updated July 21, 2026
This summary describes how Pcnaid Inc. (“Pcnaid”) processes personal data on behalf of the firms that use Pcnaid Legal Hub (the “Service”). When a firm places client data in the Service, the firm is the data controller and Pcnaid is the processor, acting on the firm’s documented instructions. Customers with a regulatory requirement can request our full Data Processing Addendum (DPA) to sign.
1. Roles
The firm determines the purposes and means of processing its client data and is responsible for the lawfulness of that data. Pcnaid processes it only to provide, secure, and support the Service, and only as instructed by the firm through the product and these terms.
2. Scope of processing
- Subject matter: provision of the legal-operations Service.
- Duration: for the term of the firm’s subscription, plus limited retention for backups and legal obligations.
- Nature and purpose: hosting, storing, transmitting, and processing customer content to deliver the Service’s features.
- Data types: matter and client records, documents, communications, billing and trust-accounting data, and user account data.
- Data subjects: the firm’s clients, contacts, and personnel.
3. Confidentiality
Personnel authorized to process customer data are bound by confidentiality obligations and access data only as needed to operate and support the Service.
4. Security measures
Pcnaid maintains technical and organizational measures appropriate to the risk, including per-tenant isolation with row-level scoping, encrypted transport, access controls, checksum-verified document storage, an offsite audit-log mirror, rate limiting, and audit logging. These are described further in our security overview.
5. Subprocessors
Pcnaid engages vetted subprocessors to provide parts of the Service — including edge and hosting infrastructure, database and object storage, payments, email and SMS, scheduling, identity, error monitoring, and analytics. We remain responsible for their performance and require them to meet obligations no less protective than those in our DPA. A current list is available on request, and we will give notice of material changes.
6. AI subprocessing
Where a firm uses the AI assistant, relevant workspace content is sent to our AI provider to generate the requested output, scoped to the matter. This content is not used to train third-party models.
7. Assistance to the controller
Taking into account the nature of the processing, Pcnaid provides reasonable assistance to the firm in responding to data-subject requests and in meeting the firm’s security, breach notification, and impact-assessment obligations. Pcnaid will notify the firm without undue delay on becoming aware of a personal-data breach affecting the firm’s data.
8. Data-subject requests
If Pcnaid receives a request from a data subject relating to a firm’s data, we will, where lawful, refer the request to that firm rather than responding directly.
9. Return and deletion
On termination, the firm may export its data, after which Pcnaid deletes or de-identifies it within a reasonable period, subject to backup cycles and legal-retention requirements.
10. International transfers
The Service runs on a global edge network. Where personal data is transferred across borders, Pcnaid applies appropriate safeguards as required by applicable law.
11. Contact
To request our signable DPA or subprocessor list, contact support@pcnaid.com.