Data Processing Addendum

Last updated: August 2, 2026

1. IMPORTANT TERMS.

This Harvey AI Data Processing Addendum (the “DPA”) governs Harvey’s processing of Personal Data that is required to provide the Service under the Platform Agreement or other agreement between You and Harvey pertaining to the use of Harvey’s software-as-a-service offering (the “Agreement”), support Your use of the Service and, support our business operations. This DPA is part of Your Terms with Harvey. In the event of any conflicting language between the Agreement, the other Terms, or any operative Order Form, the terms of this DPA control.

You and Harvey each agree to comply with their respective obligations under Data Protection Law.

Data Processing Roles

To the extent Harvey Processes Personal Data, You and Harvey will Process such Personal Data according to the following roles:

  • Customer Personal Data: As between You and Harvey, You are the Data Controller, and Harvey is the Data Processor, Processing Customer Personal Data on Your behalf.
  • Account Information and Usage Personal Data: Harvey acts as independent Data Controller.

The purposes, categories, and duration of Processing below applies when Harvey acts as a Data Processor:

Data Processing Purposes

Harvey will Process Customer Personal Data as Your Data Processor for the purpose of providing or maintaining the Service and in accordance with the Instructions. Harvey acknowledges that You are disclosing Customer Personal Data for these limited and specific purposes.

Categories of Personal Data

Categories of Personal Data contained within Customer Personal Data. Examples include name, and demographic information.

Categories of Data Subjects

Individuals identified in Customer Personal Data. Examples include authorized users of Harvey’s applications, users’ clients.Duration of Processing

Subject to the other Terms and Section 14 of this DPA, Customer Personal Data will be Processed for the term of the Agreement.

2. DEFINITIONS. The definitions in Section 16 (Defined Terms) apply to this DPA. All terms in quotation marks in the body of this DPA are also defined terms. Any capitalized terms used but not defined in this DPA have the meaning set forth in the Agreement and the other Terms.

3. PROCESSING REQUIREMENTS. As a Data Processor, Harvey will:

3.1 Process Customer Personal Data on Your behalf, according to the Instructions, and only in a manner necessary for the performance of the Service;

3.2 promptly notify You in writing if it cannot comply with the requirements of this DPA;

3.3 promptly inform You if, in Harvey’s opinion, an Instruction from You infringes applicable Data Protection Law; and

3.4 ensure that all persons authorized by Harvey to Process Customer Personal Data are subject to a duty of confidentiality.

4. SUBPROCESSORS. As a Data Processor, Harvey will:

4.1 engage the organizations or persons listed at harvey.ai/legal/subprocessors (the “Subprocessor List”) as necessary to perform the Service. You consent to Harvey’s use of its existing Subprocessors and You grant Harvey a general written authorization to engage Subprocessors to perform all or part of the Processing activities required to provide the Service. If You subscribe to receive email notifications at the Subprocessor List, then Harvey will notify You if Harvey intends to add one or more Subprocessors to the Subprocessor List at least 30 days before the change takes effect. You may, within 15 days of receiving the notice of the change, reasonably object to Harvey’s use of a Subprocessor on reasonable grounds relating to the protection of Customer Personal Data (the “Objection”) by following the instructions set forth in the Subprocessor List or by contacting privacy@harvey.ai (the “Objection Notice”). In such case, Harvey shall have the right to cure the Objection through one of the following options: (i) Harvey will offer an alternative to provide its Service without such Subprocessor, (ii) Harvey will take the corrective steps requested by You in the Objection Notice and proceed to use the Subprocessor, (iii) Harvey may cease to provide, or You may agree not to use, whether temporarily or permanently, the particular aspect or feature of the Service that would involve the use of such Subprocessor, or (iv) You may cease providing Customer Personal Data to Harvey for Processing. If none of the above options are commercially feasible, in Harvey’s reasonable judgment, and the Objection has not been resolved to the satisfaction of the parties within 30 days of Harvey’s receipt of the Objection Notice, then either party may terminate any subscriptions, order forms or usage regarding the Service for cause and in such case, You will be refunded any pre­paid but unused fees for the applicable subscriptions, order forms or usage to the extent they cover periods or terms following the date of such termination. Other than accepting such cure as may be offered by Harvey, such termination right is Your sole and exclusive remedy if You object to any new Subprocessor;

4.2 enter into contractual arrangements with each Subprocessor binding them to data protection obligations that are materially equivalent to, and no less protective than, those imposed on Harvey under this DPA, and to provide the same level of security provided for in this DPA. Harvey will remain fully liable to You for the performance of each Subprocessor to the extent the Subprocessor fails to fulfill its data protection obligations under the applicable data processing agreement with Harvey with regard to Customer Personal Data.

5. NOTICE TO CUSTOMER. Harvey will inform You, to the extent legally permitted, if Harvey receives:

5.1 any legally binding request for disclosure of Customer Personal Data by a law enforcement authority. If Harvey is legally prohibited from notifying You, Harvey will use its best efforts to request a waiver of the prohibition and will document that request. Harvey will notify You once the prohibition expires or has been lifted with the aim of providing as much relevant information to You as reasonably possible;

5.2 any notice, inquiry, or investigation by a Supervisory Authority with respect to Customer Personal Data; or

5.3 any complaint or request from a Data Subject (including “verifiable consumer requests” as defined by CCPA) exercising their right under Data Protection Law to (i) access their Customer Personal Data, (ii) have their Customer Personal Data corrected or erased, (iii) restrict or object to the Processing of their Customer Personal Data, or (iv) data portability of Customer Personal Data (collectively “Data Subject Request”). Other than to request further information or identify the Data Subject, Harvey will not respond to any Data Subject Request, relating to the Processing of Customer Personal Data, without prior written authorization from You.

6. PERSONAL DATA BREACH. If Harvey experiences a breach of security leading to any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data (“Personal Data Breach”), Harvey will notify You in accordance with the timeframe set out under the heading “Incident Detection and Response” in the Security Addendum which is incorporated into this DPA. Harvey will provide You with all information about the Personal Data Breach as required by Data Protection Law including the information outlined under the heading “Incident Detection and Response” in the Security Addendum.

7. ASSISTANCE TO CUSTOMER AND AUDITS. Upon Your written request, Harvey will provide reasonable assistance to You regarding:

7.1 Your obligations to respond to Data Subject Requests relating to Harvey’s Processing of Customer Personal Data;

7.2 Your preparation of data protection impact assessments with respect to the Processing of Customer Personal Data by Harvey and, where necessary, carrying out consultations with any Supervisory Authority with jurisdiction over such Processing; and

7.3 information, assessments, or audits, to the extent required by Data Protection Law, and as necessary to confirm that Harvey is Processing Customer Personal Data in a manner consistent with this DPA. All audits and assessments will be performed in the manner set out under the heading “Customer Audit Rights” in the Security Addendum. All reports and documentation provided to You are Harvey’s Confidential Information.

8. REQUIRED PROCESSING. If Harvey is required by applicable law to Process Customer Personal Data outside of Your Instructions, Harvey will inform You of this requirement in advance of any Processing, unless Harvey reasonably believes it is legally prohibited from informing You of such Processing.

9. SECURITY. Harvey will:

9.1 implement and maintain a written information security program with the data security measures set out in the Security Addendum to protect against unauthorized or accidental access, loss, alteration, disclosure or destruction of Customer Personal Data and to protect the rights of the Data Subject; and

9.2 take appropriate steps to confirm that all Harvey personnel and persons or entities authorized to Process Customer Personal Data on Harvey’s behalf are protecting the security, privacy, and confidentiality of Customer Personal Data consistent with the requirements of this DPA.

10. US SPECIFIC DATA PROTECTION OBLIGATIONS. To the extent applicable under US State Privacy Law, Harvey certifies that it understands and will comply with its obligations under US State Privacy Law to:

10.1 only Process Customer Personal Data for the purposes set out in this DPA, the Agreement, or the other Terms, unless otherwise permitted by law;

10.2 not “sell” or “share” (as defined by CCPA) Customer Personal Data;

10.3 not retain, use or disclose Customer Personal Data outside of the direct business relationship between Harvey and Customer unless otherwise required or permitted by law;

10.4 Process Customer Personal Data in a manner that provides no less than the level of privacy protection required by US State Privacy Law;

10.5 not combine any Customer Personal Data with Personal Data that Harvey receives from or on behalf of a third party other than You or collects from Harvey’s own interactions with individuals, provided that Harvey may combine Personal Data as permitted under US State Privacy Laws or if directed to do so by Customer;

10.6 not attempt to reidentify any deidentified data that You provide to Harvey, except for the sole purpose of determining whether the deidentification processes are compliant with applicable Data Protection Law; and

10.7 grant You the right to take reasonable and appropriate steps to (i) ensure that Harvey uses Customer Personal Data in a manner consistent with Data Protection Law and (ii) stop and remediate unauthorized use of Customer Personal Data.

11. OBLIGATIONS OF CUSTOMER.

11.1 You represent, warrant and covenant that You have and shall maintain throughout the Term all necessary rights, consents and authorizations to provide the Customer Personal Data to Harvey and to authorize Harvey to Process Customer Personal Data as contemplated by this DPA, the Agreement, the other Terms and/or other Instructions provided to Harvey. By using the Service, You are instructing Harvey to Process Customer Personal Data as reflected in the Documentation.

11.2 You shall reasonably cooperate with Harvey to assist Harvey in performing any of its obligations under Data Protection Law in relation to Customer Personal Data.

11.3 You acknowledge and agree that You, rather than Harvey, are responsible for certain configurations and design decisions for the Service (including whether and how You use optional Service features or third-party integrations, and selecting the technology You use to access the Service), and that You are responsible for implementing those configurations and design decisions in a secure manner that complies with applicable Data Protection Law.

11.4 You shall not provide Customer Personal Data to Harvey except through agreed mechanisms for transmitting data to the Service. For example, You shall not include Customer Personal Data, in technical support tickets or transmit Customer Personal Data to Harvey by email.

12. CROSS-BORDER DATA TRANSFERS.

12.1 You acknowledge that, unless You and Harvey have agreed, in Your currently operative order form or otherwise in writing, to Process and store Customer Personal Data exclusively in a different geographic location, You may transfer Personal Data to Harvey in the United States, in order for Harvey to provide the Service and for the purposes set out in this DPA. If the transfer comprises Personal Data that requires a Data Transfer Mechanism, the Data Transfers Addendum, which is incorporated into this DPA, will apply.

13. FUTURE REGULATIONS.

13.1 In the event that new legislation and regulations are implemented that specifically govern the use of artificial intelligence solutions, both parties agree to review this DPA to ensure compliance with such legislation and regulations.

13.2 If substantial modifications are required to the terms and conditions of this DPA to render it or the parties’ performance under it compliant with any legislation or regulations implemented following its Effective Date, both parties shall negotiate in good faith to make necessary amendments.

13.3 Should new legislation or regulations render the continued Processing of Customer Personal Data under this DPA infeasible or unlawful, either party may initiate termination of this DPA by providing written notice to the other party. Termination shall be effective after a reasonable notice period, as agreed upon by both parties.

13.4 The termination of this DPA due to the aforementioned regulations shall not relieve either party from any outstanding obligations or liabilities incurred prior to the termination.

13.5 If any provision of this DPA is found to be inconsistent with future regulations, such provision shall be interpreted in a manner consistent with the applicable laws, or if necessary, deemed null and void without affecting the validity of the remaining provisions.

14. RETENTION PERIOD. This DPA shall remain in effect until (i) the Service is terminated and (ii) Harvey no longer Processes Customer Personal Data on Your behalf, except that Section 15 shall survive as long as Harvey processes Account Information and Usage Personal Data. Within 30 days of either (i) termination of the Service; or (ii) upon Your reasonable request; Harvey shall, and shall direct each Subprocessor to, return to You or delete the Customer Personal Data, unless Harvey is required by law to retain such Customer Personal Data.

15. HARVEY AS A DATA CONTROLLER. When Harvey processes Personal Data contained in Account Information and Usage Personal Data, Harvey is acting as a Data Controller, and Harvey will:

15.1 Process such Personal Data, in compliance with applicable Data Protection Law, and strictly to:

15.1.1 manage Your account, and Harvey’s relationship with You, including identity verification, and providing support, required to access or use the Service;

15.1.2 to carry out Harvey’s core business operations, such as accounting, and auditing;

15.1.3 to prevent, detect, or investigate security incidents and manage the security of Harvey's platform and Service;

15.1.4 for business analytics and product strategy; and

15.1.5 to develop and improve new products and services and improve the performance, functionality, safety, and security of the services.

15.2 Harvey will implement technical and organizational measures designed to mitigate the risk of unlawful or unauthorized access, destruction, alteration, disclosure or use of Account Information and Usage Personal Data. These technical and organization measures will be designed to provide a level of security appropriate to the risk of processing.

16. DEFINED TERMS

16.1 “Account Information” means Personal Data that relates to Harvey's relationship with You, including the names or contact information of individuals, login credentials of individuals authorized to use the Service, and information used to handle administrative matters including billing and technical or product support. For the sake of clarity, Account Information does not include Customer Data or Content.

16.2 “Customer Personal Data” means Customer Data or Your Content that is provided through the Service and that is Personal Data.

16.3 “Data Controller” means the person or entity that determines the purposes and means of Processing Personal Data, which may include, as applicable, equivalent concepts under Data Protection Law (for example, “Business” as defined by CCPA).

16.4 “Data Processor” means the person or entity that Processes Personal Data on behalf of the Data Controller, which may include, as applicable, equivalent concepts under Data Protection Law (for example, “Service Provider” as defined by CCPA).

16.5 “Data Protection Law” means privacy and data protection law applicable in connection with Your use of the Service. Data Protection Law may include, depending on the circumstances, Cal. Civ. Code §§ 1798.100 et seq., as amended and its implementing regulations (“CCPA”) and the European Union General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”).

16.6 “Data Subject” means an identified or identifiable natural person to which Customer Personal Data relates, to the extent their Personal Data is protected by Data Protection Law.

16.7 “Data Transfer Addendum” means the data transfer addendum located at https://www.harvey.ai/legal/data-transfers-addendum.

16.8 “Data Transfer Mechanism” means a transfer mechanism that enables the lawful cross-border transfer of Customer Personal Data under Data Protection Law. This includes transfer mechanisms that are required under Data Protection Law in the EEA, UK, and Switzerland such as the Data Privacy Framework, the EEA SCCs, the UK International Data Transfer Addendum and any data transfer mechanism available under Data Protection Law that is incorporated into this DPA.

16.9 “EEA” means the European Economic Area.

16.10 “EEA SCCs” means Module 1 (Controller to Controller) and Module 2 (Controller to Processor) of the standard contractual clauses set out in the European Commission Implementing Decision (EU) 2021/914 on standard contractual clauses for the transfer of personal data to third countries according to the GDPR.

16.11 “Instructions” means any (i) documented communication from You which includes actions taken or input provided through the Service; or (ii) agreement between You and Harvey that requires Harvey to provide the Service; or (iii) the Documentation.

16.12 “Personal Data” means any information relating to an identifiable natural person which is protected under Data Protection Law and Processed in connection with Your use of the Service or to support our business operations. This includes equivalent concepts as defined by Data Protection Law (for example, “personal information” as defined under the CCPA).

16.13 “Platform Agreement” means the Platform Agreement located at harvey.ai/legal.

16.14 “Processing” means any operation or set of operations which is performed on Your behalf on Personal Data, whether or not by automated means, such as collecting, recording, organization, structuring, storage, adaptation, or alteration, retrieval, consultation, use, disclosure by transmission, or dissemination. “Process”, “Processes” and “Processed” will be interpreted accordingly.

16.15 “Security Addendum” means the Security Addendum located at https://www.harvey.ai/legal/security-addendum.

16.16 “Subprocessor” means an entity Harvey engages to Process Customer Personal Data on Harvey’s behalf, to carry out specific Processing activities on Your behalf.

16.17 “Supervisory Authority” means an independent public authority which is (i) established by a member state pursuant to Article 51 of the GDPR; (ii) the public authority governing data protection that has supervisory jurisdiction over You.

16.18 “UK International Data Transfer Addendum” means the international data transfer addendum to the EEA SCCs issued by the United Kingdom’s Information Commissioner’s Office which came into force in accordance with s119A of the UK Data Protection Act on 21 March 2022.

16.19 “You” or “Your” means the organization contracting for the use of the Service.

16.20 “Usage Personal Data” means Personal Data included in Usage Data (as defined in the Agreement).

16.21 “US State Privacy Law” means all state laws relating to the protection and processing of Personal Data in effect in the United States of America, which may include, without limitation, the CCPA, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, and the Utah Consumer Privacy Act.

Previous Versions

2025