Data Processing Agreement

Hey, Lexxi LLC ("Service Provider")

Effective Date: July 19, 2026

 

This Data Processing Agreement (“DPA”) is entered into by and between Hey, Lexxi LLC (“Service Provider” or “Hey, Lexxi”) and the Subscriber identified in the applicable order form (“Business”), and forms part of the Terms of Service or other agreement between the parties governing the Hey, Lexxi Services (the “Agreement”). It governs Hey, Lexxi’s Processing of Personal Information on the Business’s behalf. Where terms differ between this DPA and the Agreement, this DPA controls with respect to the Processing of Personal Information.

1. Definitions

“Personal Information,” “Business,” “Service Provider,” “Sell,” “Share,” “Process/Processing,” “Consumer,” “Deidentified,” and “Sensitive Personal Information” have the meanings given in the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and its regulations (collectively, “CCPA/CPRA”). “Personal Information” as used here means Personal Information contained in Subscriber Data that Hey, Lexxi Processes on the Business’s behalf under the Agreement. “Applicable Privacy Law” means all data-protection and privacy laws applicable to the Processing, including the CCPA/CPRA and, where applicable, the California Confidentiality of Medical Information Act (“CMIA”).

2. Roles of the Parties

The Business is the “business” (and, where applicable, controller) that determines the purposes and means of Processing Personal Information. Hey, Lexxi is a “service provider” (and, where applicable, processor) that Processes Personal Information solely on behalf of, and under the documented instructions of, the Business. The Agreement and this DPA constitute the Business’s complete and final instructions.

3. Service Provider Obligations and Restrictions

Hey, Lexxi will Process Personal Information only as necessary to provide the Services and for the business purposes set out in Annex 1, and is prohibited from:

  • selling or Sharing Personal Information;

  • retaining, using, or disclosing Personal Information for any purpose other than the business purposes specified in this DPA, including outside the direct business relationship between the parties, except as permitted by Applicable Privacy Law;

  • retaining, using, or disclosing Personal Information outside the Agreement except where required by law; and

  • combining Personal Information received from the Business with personal information from other sources, except as permitted by the CCPA/CPRA to perform a business purpose.

Hey, Lexxi certifies that it understands and will comply with these restrictions. Hey, Lexxi will notify the Business promptly if it determines it can no longer meet its obligations under Applicable Privacy Law, and the Business may, upon notice, take reasonable steps to stop and remediate unauthorized Processing.

4. Confidentiality and Personnel

Hey, Lexxi will ensure that personnel authorized to Process Personal Information are bound by appropriate confidentiality obligations and are limited to those who need access to provide the Services, consistent with the principle of least privilege.

5. Security

Hey, Lexxi will implement and maintain reasonable administrative, technical, and physical safeguards appropriate to the nature of the Personal Information, as further described in Annex 2, designed to protect Personal Information against unauthorized or unlawful Processing, access, loss, destruction, or damage. Hey, Lexxi does not currently hold a SOC 2 or equivalent third-party attestation and makes no such representation in this DPA.

6. Subprocessors

The Business authorizes Hey, Lexxi to engage subprocessors to Process Personal Information. Hey, Lexxi will impose data-protection and security obligations on each subprocessor that are no less protective than those in this DPA, and remains responsible for its subprocessors’ performance to the extent required by Applicable Privacy Law. Hey, Lexxi will make its current list of subprocessors available on request and will provide notice of intended additions, allowing the Business a reasonable opportunity to object on reasonable data-protection grounds.

7. Assistance to the Business; Consumer Rights

Taking into account the nature of the Processing, Hey, Lexxi will provide reasonable assistance to enable the Business to respond to verifiable Consumer requests to know, access, delete, correct, or opt out, and to fulfill the Business’s obligations under Applicable Privacy Law. If Hey, Lexxi receives a Consumer request directly, it will, where lawful, direct the Consumer to the Business or promptly notify the Business.

8. Sensitive and Medical Information

Where Personal Information includes Sensitive Personal Information or medical information subject to the CMIA, Hey, Lexxi will Process it only as necessary to provide the Services and will not use it for the purpose of inferring characteristics about a Consumer or for any purpose other than those permitted under the CCPA/CPRA, the CMIA, and this DPA. The Business is responsible for ensuring it has a lawful basis and any required consents or authorizations to provide such information to Hey, Lexxi.

9. Security Incidents

Hey, Lexxi will notify the Business without undue delay after becoming aware of a confirmed breach of security leading to the unauthorized access to, or disclosure of, Personal Information Processed under this DPA, and will provide information reasonably available to assist the Business in meeting its notification obligations. The Business is responsible for any notifications to Consumers, regulators, or other parties that it is required to make.

10. Deletion and Return

Upon expiry or termination of the Agreement, or on the Business’s earlier written request, Hey, Lexxi will delete or return Personal Information Processed on the Business’s behalf, except copies retained in routine backups (deleted on their ordinary cycle) or as required by law, in which case Hey, Lexxi continues to protect the information under this DPA.

11. Audits

Hey, Lexxi will make available to the Business information reasonably necessary to demonstrate compliance with this DPA. The Business may, on reasonable prior notice, no more than once per year (absent a Security Incident or regulatory requirement), and subject to confidentiality, assess Hey, Lexxi’s compliance through Hey, Lexxi’s responses to a reasonable written security questionnaire or relevant documentation.

12. Business Responsibilities

The Business is responsible for: (a) determining, through its own due diligence, whether the Services and this DPA satisfy the Business’s own obligations under Applicable Privacy Law in every jurisdiction in which it operates, and for its own compliance with that law; (b) establishing and maintaining its own administrative, technical, and physical security measures for its systems and any data it exports from or stores outside the Services; (c) obtaining all consents, authorizations, and lawful bases required to provide Personal Information to Hey, Lexxi; and (d) notifying Hey, Lexxi in writing as soon as reasonably possible of any requirement, issue, or potential non-compliance of which it becomes aware and that Hey, Lexxi should reasonably know about. Hey, Lexxi is not a party to, and is not responsible for, any arrangement between the Business and its own clients or other third parties (including employers, insurance carriers, third-party administrators, insurance groups, or insurance administrators).

13. General

This DPA is governed by the law specified in the Agreement (California). If any provision is found invalid, the remainder stays in effect. Except as amended by this DPA, the Agreement remains in full force. To the extent of any conflict regarding the Processing of Personal Information, this DPA controls.


 

Annex 1 — Details of Processing

Element

Details

Subject matter

Provision of the Hey, Lexxi Services (generation and management of independent file reviews and related legal work product).

Duration

For the term of the Agreement, plus any retention period permitted under Section 10.

Nature and purpose

Hosting, storage, transmission, automated and AI-assisted processing, and display of Subscriber Data solely to provide, secure, and support the Services.

Categories of Consumers

The Business’s clients, claimants, patients, witnesses, and other individuals whose information appears in case materials submitted by the Business.

Categories of Personal Information

Identifiers, contact details, professional and case-related information, and, where submitted by the Business, medical information and other Sensitive Personal Information necessary for the requested review.

Business purposes

Performing the Services; security, debugging, and error correction; and producing de-identified and aggregated analytics to operate and improve the Services.

Annex 2 — Technical and Organizational Security Measures

Hey, Lexxi maintains the following measures, which it may update provided the overall level of protection is not materially diminished:

  • Encryption of Personal Information in transit and at rest using industry-standard protocols.

  • Role-based access controls, authentication requirements, and least-privilege access for personnel.

  • Logical separation of customer data and hardening of production environments.

  • Logging and monitoring designed to detect and respond to security events.

  • Vendor diligence and contractual security obligations for subprocessors.

  • Personnel confidentiality obligations and security awareness practices.

  • Backup and recovery processes designed to support the availability and integrity of data.