Contract framework
Parties, scope and object
These Terms of Service (Terms) govern the supply and professional use of the app.legiscope.com software-as-a-service platform and related services. Legiscope means the app.legiscope.com platform operated by Legiscope UAB, company code 304581221, registered at Laisvės pr. 60-1107, LT-05120 Vilnius, Lithuania. Legiscope UAB is the provider and contracting party; a reference in these Terms to Legiscope performing, owing or enforcing an obligation means Legiscope UAB acting as operator of the platform. Customer means the business, public body or other organisation identified in the Order Form. Legiscope UAB and the Customer are each a Party and together the Parties.
The object of the Agreement is to provide the Customer a hosted, customer-controlled workspace for maintaining privacy and data-protection governance records, coordinating supported workflows, reviewing evidence, using enabled AI-assisted operations and exporting Customer records within the purchased Plan and Limits.
The Service is designed to support the Customer’s work; it does not assume the Customer’s legal responsibilities. The Agreement is exclusively for professional business use. It is not offered to consumers, and each signatory represents that they are authorised to bind the identified Party.
Agreement, formation and precedence
The Agreement consists only of: (a) the Order Form that defines the details of the Services purchased; (b) these current Terms, including the Plan Catalogue reproduced in them; and (c) the Data Processing Agreement (DPA) as published at www.legiscope.com/dpa.html.
The Parties first negotiate the commercial scope of the subscription — the Plan and options, quantities, term and price; these exchanges do not bind either Party. During the negotiation, Legiscope may provide a product demonstration in one of two forms. A standard demonstration is a presentation of the Service on screen by Legiscope personnel that displays the product features (the prospect submits no data and no account is created). An assisted demonstration is a hands-on session in a dedicated demonstration account, provided under the Assisted Demonstration Agreement published at www.legiscope.com/demo-agreement.html, accepted by the prospect — by email or through the demonstration booking flow — before the demonstration begins. Neither form of demonstration forms the Agreement described in these Terms; an assisted demonstration is governed exclusively by the Assisted Demonstration Agreement.
Once the commercial scope is agreed, Legiscope issues the final Order Form, which constitutes its offer. The Order Form may be issued as a standalone document or as an electronic quote issued through Legiscope’s billing provider. It states the selected Plan and options, the applicable prices and discounts, the quantities, allowances and term, and any separately priced service offered by Legiscope.
The Agreement is formed when the Customer accepts the Order Form through one of the following methods: (i) an agreed electronic signature; (ii) acceptance of an electronic quote through the billing provider’s hosted acceptance flow; (iii) payment of the initial payment stated in the Order Form; or (iv) clear written confirmation sent by email by an authorised representative of the Customer — in each case preserving the accepted terms.
The Agreement takes effect on the acceptance date (Effective Date) unless the Order Form states a different date. Legiscope activates access to the Service only after receipt of the initial payment stated in the Order Form.
Service, plans and licence
Service licence and delivery
Subject to payment and compliance with the Agreement, Legiscope grants the Customer a limited, non-exclusive, non-transferable right during the Subscription Term to permit its Authorised Users to access and use the Service for the Customer’s internal professional purposes within the selected Plan and Limits.
Legiscope supplies the Service online and remotely.
A preview, prototype, beta, evaluation feature or marketing reference is not a contractual commitment unless the Order Form expressly includes it. Legiscope may withdraw a non-contracted preview at any time.
Compliance workflows
The Service provides compliance-management workflows. Its current core covers privacy and data-protection governance — including records of processing activities, application inventories, processor relationships, personal-data-breach management, data-subject-rights handling, impact assessments, audits and evidence, and remediation planning. Legiscope may extend the Service to further compliance domains and workflows; a new capability is provided under the Agreement as stated in “Documented instructions and new services”.
The Service operates on the information and documents the Customer supplies, and helps the Customer structure, draft and review its compliance records. It does not verify the authenticity, completeness or sufficiency of Customer records, certify compliance, decide whether a legal obligation applies, or send notifications or responses to authorities or third parties in the Customer’s name. Conclusions, approvals and communications remain the Customer’s.
Plans and entitlements
The Customer subscribes to one Plan, identified in the Order Form. The entitlements, limits and standard list prices of each Plan are set out in the Legiscope Plan Catalogue, version 2026-09-01, reproduced in the table below. The version reproduced in these Terms is binding; the public pricing page displays the same catalogue for convenience and has no contractual effect.
The price, total commitment, Token allocation and any negotiated variation stated in the accepted Order Form prevail over the Plan Catalogue. The Order Form also identifies any non-standard connected ingestion, integration, SSO or API connection or bespoke capability.
| Plan term or entitlement | Mini | Organisation | Group | Assurance | Enterprise |
|---|---|---|---|---|---|
| Standard list pricing (price per year) | |||||
| 1 y. contract | €3,335 | €5,520 | €11,040 | €16,560 | From €27,600 |
| 3 y. contract | €3,045 | €5,040 | €10,080 | €15,120 | From €25,200 |
| 5 y. contract | €2,900 | €4,800 | €9,600 | €14,400 | From €24,000 |
| Scope | |||||
| Managed organisations? | 1 | 10 | 20 | 50 | Order Form |
| Authorised Users? | 20 | 50 | 100 | 200 | Order Form |
| AI tokens? | 150,000 | 500,000 | 1,000,000 | 1,500,000 | 2,500,000 |
| Services | |||||
| Core services? | |||||
| Automated DPIA? | |||||
| Ingestion service? | |||||
| Ingestion connectors? | |||||
| Support? | 2 h / year | 5 h / year | 10 h / year | ||
| Included onboarding? | 1 h | 2 h | 2 h | 4 h | |
| Enterprise options | |||||
| SSO? | Option | Option | |||
| MCP access? | Option | Option | |||
Customer responsibilities, acceptable use and suspension
Account creation and administration
The Customer tenant is created after receipt of the initial payment. Within five Business Days after the later of the Agreement taking effect, receipt of the initial payment and receipt of the complete provisioning information reasonably required, Legiscope creates the Customer tenant and the initial Customer Administrator account identified in the Order Form and provides a secure activation method.
The Customer administers its own accounts. Authorised User accounts are created and managed by the Customer through the Service’s administration functions; Legiscope does not intervene in the Customer’s account administration. Customer Administrators manage user access, roles, organisation scope and integrations on the Customer’s behalf. The Customer must keep its administrator contact current and must promptly remove or restrict access that is no longer authorised.
Each account is for one named individual. Credentials and authentication factors must not be shared. The Customer must maintain appropriate endpoint security and promptly notify Legiscope of suspected compromise. The Customer is responsible for activity through its accounts except to the extent caused by Legiscope’s breach of the Agreement.
Customer responsibilities and acceptable use
The Customer determines the purposes of its privacy programme and remains responsible for the lawfulness, accuracy, completeness and quality of Customer Content, its users’ instructions and its configuration. It must provide required notices and obtain the rights, authorisations and lawful bases needed for Customer Content, integrations and selected workflows. This allocation does not reduce Legiscope’s processor obligations under the DPA.
The Customer and its Authorised Users must not:
- use the Service unlawfully, infringe another person’s rights or submit content the Customer is not authorised to process;
- share accounts, bypass access or usage controls, or use the Service outside the purchased programme scope;
- upload malware or attempt unauthorised access, disruption, probing, extraction or circumvention, except for an audit or security test expressly permitted by the DPA or a specific written agreement with Legiscope;
- resell, sublicense, provide service-bureau access, reverse engineer or extract non-public software, models, system prompts, reusable prompt templates, security controls or platform components except where mandatory law permits;
- unlawfully scrape personal data or infringe database, confidentiality or intellectual-property rights;
- submit special-category or criminal-conviction data without an applicable Article 9(2) or Article 10 condition and any required sector-specific authorisation, or outside a workflow and provider route permitted by the Order Form or documented configuration — the sensitive-data conditions in the DPA’s Annex II are conditions of use of the Service.
Suspension
Legiscope may suspend access to all or part of the Service, or to a specific account or function, where reasonably necessary: (i) to address a serious security threat; (ii) to stop unlawful use, or use in breach of the Agreement that causes harm to Legiscope, its customers or third parties; (iii) to comply with applicable law; or (iv) after notice, for persistent non-payment of an undisputed amount. A suspension is limited in scope and duration to what is proportionate to its cause.
Except where the urgency of the cause or a legal prohibition prevents it, Legiscope gives the Customer notice and an opportunity to remedy the cause before suspending. Legiscope restores the affected access promptly once the cause is resolved. Fees remain due during a suspension caused by the Customer.
Fees, term and renewal
Fees, invoicing and taxes
The Order Form states the fees, the total commitment for the fixed term, the currency, the billing contact, the Service Start Date and any one-off fees. Subscription fees are invoiced in advance, either annually at the start of each Contract Year or as a single upfront payment for the Subscription Term, as agreed in the Order Form; if the Order Form is silent, fees are invoiced annually. Fees exclude VAT and other applicable taxes unless expressly stated otherwise. Legiscope administers quotes, orders, invoices and payments through an electronic billing provider; a billing-provider record is billing evidence only and does not modify the term, price or scope stated in the accepted Order Form. Subscription invoices are payable by wire transfer only. A purchase of additional Tokens is payable through the billing provider’s payment flow or by wire transfer.
The initial payment is the first annual subscription fee unless the Order Form states another amount or payment schedule. Unless the Order Form states otherwise, each later annual subscription fee is invoiced in advance at the start of the relevant Contract Year and payable under paragraph (c).
Invoices are payable within 14 calendar days of issue, unless the Order Form states a different due date. Payment is made without set-off or deduction, except where mandatory law provides otherwise.
On an overdue undisputed amount, Legiscope may charge statutory late-payment interest. The Customer additionally bears all documented recovery costs, including debt-collection charges, court costs and attorney fees. If an undisputed amount remains unpaid more than 90 days after its due date, the Customer owes a contractual penalty of 10% of the overdue amount, with a minimum of EUR 500, in addition to interest and recovery costs. Persistent non-payment may lead to suspension and, after the applicable cure period, termination.
Fees are non-cancellable and non-refundable except where the Agreement provides an express pro-rata remedy. A Plan upgrade during a Subscription Term requires an accepted Order Form amendment; the Customer may purchase additional Tokens at any time. A downgrade is not available during a running Subscription Term; it takes effect only at the end of the current term, for the renewal term, and only if agreed before the applicable non-renewal deadline.
Tokens and usage
Tokens are contractual units used to access AI-assisted operations in the Service. When such an operation is performed, Tokens are deducted from the Customer’s Token balance.
Legiscope credits the annual Token amount included in the Plan when it activates the Customer’s account after receipt of the initial payment. At the beginning of each later Contract Year, Legiscope credits the applicable annual Token amount after receiving all subscription fees then due. Additional Tokens purchased by the Customer are credited after Legiscope receives payment for them.
The Service shows the Customer’s current Token balance and aggregate summaries of Tokens credited and consumed. These summaries do not identify individual operations or disclose operation-level Token consumption, Legiscope’s internal allocation methods, processing costs or other internal commercial information. Legiscope maintains the authoritative Token ledger and will review and correct any verified error notified by the Customer.
Unused Tokens roll over between Contract Years while the subscription continues. When the balance reaches zero, operations that consume Tokens pause until Tokens are credited; other Service features remain available. Tokens are non-transferable and have no cash, refund or redemption value. Any Token balance unused when the Agreement ends lapses and is not carried into a later subscription.
Fixed term, renewal and price protection
The initial Subscription Term begins on the Service Start Date and runs for the fixed duration selected in the Order Form: 12, 36 or 60 months.
After the initial term, the Subscription Term renews automatically for successive 12-month periods unless either Party gives written notice of non-renewal before the current term ends. A notice of non-renewal does not terminate the current committed term.
Legiscope may change its list prices for new subscriptions at any time. The annual subscription price applicable to a Subscription Term is fixed until that term ends. A renewal takes place at the same annual price unless: (i) Legiscope publishes a different applicable price and its effective date on its website at least 90 days before that date, in which case the different price applies to renewals beginning on or after that date; or (ii) where no applicable public price exists, Legiscope communicates a different renewal price to the Customer in writing at least 120 days before the current term ends.
Customer Content, AI Output and intellectual property
Legiscope intellectual property
Legiscope owns the proprietary elements of the Service and retains all intellectual-property rights in them. These elements include all Legiscope-developed code, architecture, interfaces, workflows, functionality, UX/UI and visual design, documentation, methodologies, database structures, system and developer prompts, reusable prompt templates, model-routing and orchestration logic, evaluation methods and underlying technology.
Third-party libraries and components remain subject to the rights of their respective owners. Except for the rights expressly granted by the Agreement, no rights in the Service are transferred to the Customer.
Customer Content and AI Output
Customer Content belongs to the Customer. Customer Content includes all data, records, documents, files, instructions, configurations and other materials that the Customer or an Authorised User uploads, imports, enters, creates, transmits or stores in the Service, including through an integration. It includes records maintained through supported workflows, such as RoPAs, DPIAs, processor relationships, incidents and breaches, data-subject requests, audits and supporting evidence. Legiscope acquires no ownership, intellectual-property right or other proprietary interest in Customer Content.
To provide the Service, the Customer grants Legiscope and its authorised subprocessors a limited, non-exclusive licence, for the duration of the Agreement, to host, copy, transmit, analyse, transform and otherwise process Customer Content only to perform the Agreement and follow the Customer’s documented instructions.
AI Output documents generated for the Customer in the ordinary course of using the Service through automated or AI processing, belongs to the Customer
Ownership of AI Output does not give the Customer any rights in the Legiscope technology used to generate it.
Confidentiality, security and data protection
Confidentiality
All Customer Content is confidential. This includes all data, records, documents, files and other information uploaded, imported, entered, created or stored in the Service by or for the Customer.
Legiscope will protect this information with reasonable care. It may process the information itself and through the authorised subprocessors listed at https://www.legiscope.com/subprocessors.html only to provide, secure and support the Service, comply with law, or follow the Customer’s documented instructions. This includes AI processing when the Customer uses or enables an AI-assisted feature.
Only personnel and authorised providers that need the information to perform their functions may access it, and they must be bound by confidentiality obligations. Legiscope remains responsible for the performance of the obligations it delegates to them. These duties continue for as long as Legiscope retains the information.
Data protection and processing roles
Each Party will comply with the data-protection law applicable to its role. Where Legiscope processes Customer Personal Data on the Customer’s documented instructions, the complete DPA as published at acceptance automatically forms part of the Agreement and controls that processing. No separate DPA signature is required.
The DPA remains the controlling and complete instrument for the subject matter, duration, nature, purpose, personal-data categories, data subjects, processor and subprocessor activities, security, subprocessors, international transfers, assistance, audit, personal data breach, return and deletion obligations applicable to Customer Personal Data.
Where support, troubleshooting, tenant security, incident response, restoration or Customer-directed transactional email requires processing Customer Personal Data to operate the Customer’s tenant or respond to its instruction, Legiscope acts as processor and the DPA applies. Legiscope acts as an independent controller only for the separately defined activities in the independent-controller register for which it determines its own purposes and essential means. The same technical event may produce distinct data elements processed in different roles. The Customer must make the controller information in these Terms available to its representatives and Authorised Users where required.
Customer instructions and new features
The Customer instructs Legiscope to process Customer Personal Data as necessary to provide the purchased Service and the features that the Customer or its Authorised Users enable, configure or use. The Agreement, Order Form, account configuration, authenticated user actions and documented support requests are the Customer’s documented instructions under the DPA.
A new feature enabled, configured or used by the Customer is covered by the same instructions and DPA. A separate Order Form is required only if the feature is separately priced. If the feature requires a new subprocessor, the DPA’s subprocessor-change process applies.
Legiscope decides the technical implementation of the Service, including its architecture, operations and routing among authorised subprocessors, provided it acts within the Customer’s documented instructions and the DPA.
Security and customer-controlled connectors
Legiscope protects Customer Personal Data in accordance with Article 32 GDPR and implements the technical and organisational measures stated in the DPA. The Customer is responsible for determining whether its selected Service and configuration are suitable for the data it submits and for securing its endpoints, user permissions, downloaded exports and systems outside Legiscope’s control.
In case of a personal data breach affecting Customer Personal Data processed by Legiscope or its authorised subprocessors, Legiscope will notify the Customer and provide assistance in accordance with the DPA and applicable data-protection law.
The Service may include connectors that allow the Customer to import data from third-party services. The Customer controls each connector and decides which sources and data to import. By enabling or configuring a connector, the Customer instructs Legiscope to retrieve, import and automatically process the selected data within the functionality and Limits of the purchased Service.
Service availability
Legiscope will use reasonable efforts to make the Core Service available at least 99.9% of each calendar month. The Core Service means the production web application functionality that allows Authorised Users to authenticate and access Customer records. It excludes AI processing, Customer-selected connectors, email delivery, preview or beta features and professional services.
Monthly Availability Percentage is the percentage of applicable minutes during the calendar month in which the Core Service is available. An Unavailable Minute occurs when the Customer’s Authorised Users cannot authenticate or access Customer records because of a failure within the Legiscope-managed Service. The calculation excludes: scheduled maintenance notified at least 48 hours in advance, up to four hours per month; emergency maintenance reasonably necessary to protect the Service; Customer systems, actions, configuration or credentials; Customer-selected services and connections; internet failures outside the Service boundary; force majeure events; and suspension permitted by the Agreement.
If Monthly Availability Percentage is below 99.9%, Legiscope will refund the pro rata portion of the applicable monthly subscription fee corresponding to the Unavailable Minutes. The monthly subscription fee is one-twelfth of the annual subscription fee and excludes Tokens, add-ons, professional services and taxes. The Customer must request the refund within 15 days after the affected month and identify the relevant dates and times. Legiscope will pay an approved refund or add a credit to the account of the same amount within 30 days. The refund cannot exceed the applicable monthly subscription fee.
Legiscope as independent controller
Legiscope UAB acts as an independent controller when it processes personal data for its own contracting, billing, customer-relationship, platform-security, service-operation and legal-compliance purposes. Its privacy contact is contact@legiscope.com. These activities, their legal bases, retention periods, recipients and individual rights are described in the register below.
This processing is separate from Customer Personal Data processed on the Customer’s behalf under the DPA. It does not permit Legiscope to use Customer Content for its own purposes.
Contracting, orders and customer-relationship administration
- Purpose
- Identify the contracting organisation and authorised representatives, verify contracting authority and relevant business-domain information, negotiate and form the Agreement, administer the professional relationship and preserve acceptance evidence.
- Categories of data subjects
- Customer and prospect representatives, authorised signatories, procurement, legal, privacy, security and operational contacts, and participating advisers.
- Personal data and source
- Names, work contact details, organisation, role, authority, correspondence, Order Form details, signatures or acceptance evidence and relationship notes, supplied by the individual, a colleague, the organisation, advisers or the accepted ordering process.
- Legal basis
- Article 6(1)(f) GDPR: legitimate interests in professional contracting, relationship administration and evidencing authority and agreement. Article 6(1)(b) applies where an individual is personally the contracting party and requests or enters the contract.
- Recipients and transfers
- Authorised Legiscope personnel, professional advisers, Google Workspace for correspondence and Stripe where used for ordering evidence. Restricted provider transfers use the applicable provider terms and 2021 EU Standard Contractual Clauses.
- Retention
- Prospect records are ordinarily retained for up to three years after the last meaningful contact. Contract and acceptance records are retained for the Agreement and the applicable statutory or legal-claim period.
- Requirement and consequences
- Identity, work contact and authority information are contractually necessary to negotiate, accept and administer an Order Form. Without them Legiscope may be unable to form or operate the Agreement.
- Individual rights
- Access, rectification, restriction and objection may apply. Erasure is limited where contract evidence, a legal obligation or legal claims require retention. Portability applies only where Article 6(1)(b) and its other conditions are met.
- Automated decisions
- No solely automated decision produces legal or similarly significant effects for the individual in this activity.
AI funding, billing, payments, tax and accounting
- Purpose
- Maintain the authoritative EUR-denominated AI funding wallet and commercial ledger, administer funding and usage amounts, reconcile charges, resolve metering disputes, prevent commercial abuse, issue and administer invoices, collect payments, manage tax information and maintain accounting records.
- Categories of data subjects
- Customer billing contacts, payers, authorised representatives, Authorised Users linked to a metered operation, and sole traders or other individuals identified in transaction records.
- Personal data and source
- Name, work contact details, billing address, organisation, account and user identifiers, tax or VAT identifiers, Order and invoice data, EUR funding and usage amounts, operation identifier and time, wallet balance, correction and dispute history, payment token and transaction status, obtained from the Customer, the individual, Service metering events, Stripe and financial or tax records. This activity does not include Customer Content, prompts, source material or generated Output.
- Legal basis
- Article 6(1)(b) where necessary for a contract with the individual; Article 6(1)(c) for accounting, tax and payment-record duties; and Article 6(1)(f) for business-to-business entitlement administration, metering reconciliation, commercial-abuse prevention, dispute handling and debt recovery.
- Recipients and transfers
- Authorised finance personnel, Stripe, banks, accountants, auditors, tax authorities, advisers and courts where necessary. Stripe’s applicable services agreement, DPA and transfer safeguards govern its processing.
- Retention
- The commercial metering ledger is retained for the configured period necessary to administer the Subscription Term, reconcile statements and resolve a timely dispute. Billing, payment, tax and accounting records are retained for the mandatory statutory period and longer only where necessary for an active audit, dispute or legal claim.
- Requirement and consequences
- Accurate entitlement, charge, billing identity, address and applicable tax information are contractually or legally required. Missing information may prevent metered operations, invoicing, payment processing or continued paid service.
- Individual rights
- Access, rectification and restriction may apply. A verified error will be corrected, but these rights do not require alteration of an accurate commercial or statutory record. Erasure, objection and portability are limited by contract administration, statutory accounting, tax and legal-claim requirements.
- Automated decisions
- Automated invoice, payment-status and fraud signals may support administration, but no solely automated decision produces legal or similarly significant effects for the individual.
Platform-wide security, vulnerability management, fraud and abuse prevention
- Purpose
- Determine and operate proportionate platform-wide measures to protect Legiscope infrastructure, software, accounts, customers and rights; verify privileged-access requests; detect and investigate threats, fraud, abuse and malicious activity; and remediate security weaknesses.
- Categories of data subjects
- Authorised Users, administrators, support contacts, suspected actors and persons connected with a security or abuse event.
- Personal data and source
- Account, tenant and organisation identifiers; identity, authority and domain-verification information; roles; authentication and access events; IP address; device, browser and request details; vulnerability and threat signals; reports; and investigation records generated by use of the Service or supplied by customers, reporters and providers. Customer Content is not collected into this activity as a general source; access strictly necessary for a Customer-specific support or tenant-security case remains processor activity under APP-P11 or APP-P12.
- Legal basis
- Article 6(1)(f) GDPR: legitimate interests in securing the platform, verifying privileged access, preventing fraud and abuse, protecting customers and establishing or defending legal rights. A specifically applicable binding security or reporting obligation is handled under APP-C04.
- Recipients and transfers
- Restricted Legiscope security personnel, AWS security and logging services, relevant advisers, incident responders and competent authorities where necessary. Provider transfer safeguards apply to restricted access.
- Retention
- Routine security events are kept for the configured period proportionate to event type, detection window and investigation need. Records attached to a confirmed incident, abuse case or claim are retained until the matter and applicable claim period close.
- Requirement and consequences
- Security event processing is inherent in use of the Service and cannot be disabled where necessary to protect the platform. Refusal to provide verification information may prevent privileged access or restoration.
- Individual rights
- Access, rectification, restriction and objection may apply, subject to exemptions necessary to preserve security, another person’s rights, legal duties and legal claims. Erasure is limited while the record remains necessary for those purposes.
- Automated decisions
- Automated signals may temporarily restrict suspicious access, but material account or contractual action receives proportionate human review unless immediate containment is necessary.
Legal compliance, regulatory responses and legal claims
- Purpose
- Comply with binding law and authority requests, maintain required corporate records, establish or defend legal claims and document compliance decisions.
- Categories of data subjects
- Customer representatives, Authorised Users, complainants, claimants, counterparties, witnesses, advisers and other persons relevant to the legal matter.
- Personal data and source
- Identity, work contact, contract, billing, security, correspondence, complaint, authority-request, evidence and claim information obtained from the individual, Customer, providers, advisers, authorities, courts and relevant records.
- Legal basis
- Article 6(1)(c) GDPR for binding legal obligations and Article 6(1)(f) for legitimate interests in legal governance and establishing, exercising or defending claims. Article 9(2)(f) applies where special-category data is necessary for legal claims.
- Recipients and transfers
- Restricted Legiscope personnel, lawyers, auditors, insurers, authorities, courts and counterparties where disclosure is necessary and lawful. Transfer safeguards or a lawful Article 49 condition apply where a restricted transfer is unavoidable.
- Retention
- For the mandatory retention period or, for disputes and claims, until final closure and expiry of the applicable limitation and enforcement periods.
- Requirement and consequences
- Information may be legally required or necessary to preserve rights. Failure to provide it may prevent Legiscope from addressing the request or may lead to action based on the available evidence.
- Individual rights
- Access, rectification and restriction may apply. Other rights are limited where processing is legally required, necessary for claims or subject to a lawful privilege or exemption.
- Automated decisions
- No solely automated decision produces legal or similarly significant effects for the individual in this activity.
Essential service and business communications
- Purpose
- Send and retain notices for Legiscope’s own contract, account-administration, security, legal and relationship purposes and respond to professional business contacts. Customer-directed workflow notices are excluded and processed under APP-P15.
- Categories of data subjects
- Customer representatives, administrators, Authorised Users, procurement and operational contacts and other professional recipients designated by the Customer.
- Personal data and source
- Name, work email, organisation, role, communication preferences, message and delivery metadata, supplied by the person, Customer, a colleague, the account record or ordinary correspondence.
- Legal basis
- Article 6(1)(f) GDPR: legitimate interests in operating and communicating about the professional service and customer relationship. Article 6(1)(b) applies where an individual contracting party needs the communication to perform the contract.
- Recipients and transfers
- Authorised Legiscope personnel, Google Workspace and applicable email infrastructure used for Legiscope’s own notices. Restricted transfers use the applicable provider DPA and 2021 EU Standard Contractual Clauses.
- Retention
- Operational correspondence is retained while relevant to the relationship and ordinarily for up to three years after the last meaningful contact, unless contract, security, legal or claim records require a longer period.
- Requirement and consequences
- A current operational contact is necessary to administer the Service. Non-essential business communication may be declined; essential contractual and security notices cannot be suppressed while the relationship continues.
- Individual rights
- Access, rectification, erasure, restriction and objection may apply. A recipient may object to non-essential legitimate-interest communication; required service, security and legal notices remain permitted.
- Automated decisions
- No solely automated decision produces legal or similarly significant effects for the individual in this activity.
Platform engineering, maintenance and service reliability
- Purpose
- Build, edit, test, deploy, operate, maintain and improve the Legiscope platform; monitor availability, performance and capacity; diagnose platform-wide faults; manage changes; and verify backup-system health, restoration procedures and business continuity.
- Categories of data subjects
- Authorised Users, administrators, support contacts and other persons represented by proportionate account, request or diagnostic metadata used for platform operations.
- Personal data and source
- Pseudonymous account and tenant identifiers, feature and request metadata, error and diagnostic events, performance and availability measurements, deployment and change records, support-derived defect signals, and backup-job, recovery-validation and continuity metadata generated by operation of the Service or supplied in a defined support case. Customer Content is excluded from product-development and general maintenance datasets; access to it for a Customer-specific case remains processor activity under APP-P11, APP-P12 or APP-P13.
- Legal basis
- Article 6(1)(f) GDPR: legitimate interests in developing, maintaining and improving a reliable professional service, preventing and correcting faults, managing capacity and changes, and assuring recoverability. The necessity and balancing assessment requires data minimisation, short-lived identifiable diagnostics where practicable and aggregation or anonymisation for longer-term product analysis.
- Recipients and transfers
- Restricted Legiscope engineering, operations and reliability personnel; AWS infrastructure, monitoring and recovery services; and specialist providers or advisers where necessary for a defined fault or continuity matter. Provider transfer safeguards apply to restricted access.
- Retention
- Identifiable operational diagnostics are kept for the configured period needed to detect trends, reproduce faults and assure reliability, then deleted or aggregated. Change, recovery-test and confirmed-fault records are retained for the applicable assurance, contract or legal-claim period without retaining Customer Content as a controller dataset.
- Requirement and consequences
- Proportionate operational metadata processing is inherent in providing and maintaining the hosted Service. A user cannot disable processing strictly necessary for reliability, deployment safety, capacity management or recovery assurance, but optional product research must be separately identified.
- Individual rights
- Access, rectification, restriction and objection may apply. Erasure and objection may be limited while a record remains necessary to maintain service integrity, diagnose a live fault, demonstrate a recovery control or establish or defend legal rights.
- Automated decisions
- Automated health, deployment and capacity signals may trigger rollback, failover or temporary technical restrictions, but no solely automated decision produces legal or similarly significant effects for the individual.
AI-assisted features and professional judgment
AI-assisted features and material risks
AI-assisted processing occurs when an Authorised User starts an AI operation or the Customer enables or configures an identified AI workflow. It forms part of the Customer-instructed Service purpose. Legiscope sends only the Customer Content, instructions and context needed for the operation to an authorised AI subprocessor listed on the Subprocessors page and may select or change the provider and model used.
Customer Content is not used by Legiscope to train, fine-tune models or pooled into a cross-customer training dataset.
Customer is warned that AI Output is probabilistic and may be inaccurate, incomplete, inconsistent, fabricated, biased, outdated or non-unique. It may omit legal significant issues or misstate facts, citations, relationships, deadlines or conclusions. Legiscope does not warrant that AI Output is protectable, exclusive or free from third-party rights.
AI Output is draft decision-support material. It is not legal advice, an official finding, a certification or a guarantee of compliance. Before using it for a legally significant purpose, the Customer must verify it against the original evidence, current authoritative sources and applicable law, correct material errors and obtain competent human approval. AI Output must not be the sole or determinative basis for a decision producing legal or similarly significant effects on a person.
Professional review and template limitations
The Service provides software tools and information for professional review, not legal advice, legal representation or a legal-document drafting service. Any document generated through the Service is a draft produced under the Customer’s control. Use of the Service does not create a lawyer-client relationship or, by itself, confer legal professional privilege; it does not affect any privilege or professional-secrecy protection that otherwise applies to Customer Content.
Templates, checklists, action lists and workflows may be simplified or limited to a specific purpose. They are not a complete statement of applicable law, a compliance determination or a substitute for assessing the Customer’s particular circumstances. Legiscope does not warrant that they are exhaustive or suitable for the Customer’s intended use, or that they address every applicable requirement, exception, fact, deadline or jurisdiction. The Customer must select, review, adapt, complete and approve them before relying on them for a legally significant purpose and remains responsible for obtaining professional advice where appropriate and for every decision, filing, notification and communication made in its name.
Warranties and liability
Warranties and disclaimers
Each Party warrants that it has authority to enter into the Agreement. Legiscope warrants that it will provide the Service with reasonable skill and care and materially in accordance with these Terms and the Order Form.
If the Customer notifies Legiscope of a material non-conformity in sufficient detail, Legiscope will use reasonable efforts to correct it or re-perform the Affected Service. If Legiscope cannot do so within a reasonable period, the Customer may terminate the Affected Service and receive a pro-rata refund of prepaid subscription fees for the period after termination. Except for rights that cannot lawfully be limited, these are the Customer’s exclusive remedies for breach of the warranty in paragraph (a).
Legiscope uses reasonable efforts to provide a reliable Service. However, Legiscope does not warrant that every error, risk, deadline, legal issue or compliance gap will be detected, that every source is accurate or current, or that use of the Service makes the Customer compliant with law.
Liability
To the maximum extent permitted by law, Legiscope is not liable for indirect or consequential loss or for loss of profit, revenue, anticipated savings or goodwill.
Except where liability cannot lawfully be limited, Legiscope’s total liability for all claims arising in a Contract Year under or in connection with the Agreement, will not exceed the subscription fees payable under the affected Order Form for that Contract Year.
The Customer remains responsible for its legal and regulatory obligations and for decisions made using the Service. To the maximum extent permitted by law, the Customer bears any regulatory fine or penalty imposed on it and may not recover that amount from Legiscope. Nothing transfers a statutory responsibility or limits a public authority’s powers.
Nothing in this provision excludes or limits Legiscope’s liability for fraud, wilful misconduct, gross negligence, death or personal injury caused by negligence, or any liability that cannot lawfully be excluded or limited. Nothing limits the rights of a data subject under applicable law.
Termination, switching, export and deletion
Termination
The Customer may give notice of non-renewal at any time. The Agreement, Service access and payment obligations continue until the end of the current Subscription Term and the Agreement then ends without renewal.
Legiscope may terminate the Agreement if the Customer fails to pay an undisputed amount when due, materially breaches the Agreement, uses the Service unlawfully, creates a material security risk, or if continued performance would be unlawful. Where the cause can reasonably be remedied, Legiscope will first give the Customer a reasonable opportunity to do so.
Fees paid for the current Subscription Term are non-refundable, and any remaining instalments remain payable according to the agreed payment schedule. Unused Tokens are not refundable when the Agreement ends.
Termination ends access to and the licence for the Service. Outstanding payment obligations and the ownership, confidentiality, liability and dispute provisions continue to apply.
The Customer is responsible for exporting any exportable data it wishes to retain before the Agreement ends or during the applicable retrieval period. Retention and deletion are governed by “Retention, deletion and backups” and the DPA.
Data Act export and switching
The Customer may use the Service’s automated export tools at any time to download all exportable data and digital assets in a structured, commonly used and machine-readable format. The exhaustive exportable categories are all Customer Content, AI Output and customer-visible account, configuration, user, permission, usage and metadata records. Current formats, structures, interfaces and known limitations are listed at https://www.legiscope.com/portability-deletion.html.
The exhaustive exclusions are Legiscope or third-party intellectual property and trade secrets, including source code, platform components, reusable templates, system prompts, model weights, algorithms and routing logic; credentials, security logic, internal risk signals and provider-wide telemetry; irreversibly anonymised analytics; other customers’ data; and third-party material the Customer is not entitled to receive. These exclusions will not impede or delay switching.
The Customer initiates switching to another provider, porting to its own infrastructure or erasure through the Service’s automated exit tools. Starting the selected process constitutes notice, and no separate contact or manual coordination is required. Legiscope provides the required information and reasonable assistance through those tools and the published documentation. The Customer is responsible for operating the tools and importing the exported data at its destination. Switching and associated data egress are free.
Any switch that would not be completed immediately through the automated tools provided by Legiscope is governed by the mandatory timing, security, retrieval and termination rules in Article 25 of the Data Act.
Retention, deletion and backups
The Customer may delete its account through the Service at any time, including during the Subscription Term. The Customer is responsible for exporting its data first.
If the Agreement ends before the Customer deletes its account, the DPA’s courtesy-retention and deletion periods apply to the account and all its contents.
When the Customer deletes its account, the account, Customer Content and AI Output are deleted from active systems without undue delay. Residual copies remain for 90 days in access-restricted, immutable disaster-recovery backups and are then automatically deleted. The DPA governs the deletion of Customer Personal Data.
General provisions and definitions
Service development and pricing
Legiscope determines how the Service is designed, developed and operated and may add, modify, replace, rebuild or discontinue features, workflows, interfaces, models, providers and technical components. This includes changes made because functionality does not perform as expected or to improve, secure, maintain or operate the Service for its customers as a whole. Legiscope will exercise this right reasonably, taking into account the functionality and continuity of the Customer’s purchased Plan and the interests of its customers as a whole.
Legiscope determines the pricing of the Service and may set or change prices for new subscriptions, renewal terms and new or optional features, modules and services. New or modified functionality may be included in an existing Plan or offered separately at Legiscope’s discretion. The price and financial commitment for the current Subscription Term remain fixed, and renewal pricing is governed by “Fixed term, renewal and price protection.”
Updates to the Terms and DPA
Legiscope may update these Terms or the DPA to reflect changes to the Service, applicable law, security requirements or provider arrangements, or to clarify the Agreement. Corrections of typographical or formatting errors, clarifications and other changes that do not materially affect the Parties’ rights or obligations may take effect upon publication without prior notice. Material updates are governed by paragraphs (b) and (c).
For a material update, Legiscope will notify the Customer’s contract contact by email and publish the revised document at least 30 days before the effective date. An update will not amend the Commission Clauses, reduce the protection of Customer Personal Data required by the DPA or applicable law, or change the amount payable or total financial commitment for the current Subscription Term. A change to the Service permitted under “Service development and pricing” does not by itself change that price or financial commitment. Legiscope may apply an update immediately when required by law or reasonably necessary to address an urgent material security risk and will notify the Customer as soon as reasonably practicable.
The Customer may object in writing to a material update before its effective date. The Parties will seek a reasonable solution in good faith. If no solution is agreed before that date, either Party may terminate the affected Service or the Agreement when the update takes effect, and Legiscope will refund prepaid fees for the period after termination. If the Customer does not object and continues using the Service after the effective date, the update is accepted.
General provisions
Neither Party may transfer the Agreement without the other Party’s prior consent, except to an affiliate or in connection with a merger, reorganisation or sale of the relevant business or assets, provided that the new party assumes the Agreement. Legiscope may use subcontractors while remaining responsible for its obligations under the Agreement and DPA.
Neither Party is liable for delay or failure to perform caused by an event beyond its reasonable control that it could not reasonably prevent or overcome. This does not excuse the Customer’s payment obligations.
The Customer grants Legiscope a non-exclusive, royalty-free licence during the Agreement to use its name and unmodified logo solely to identify it as a Legiscope customer on Legiscope’s website, in newsletters, on social media and in other marketing and communications materials. The Customer may withdraw this permission prospectively by written notice. Legiscope will not imply endorsement or publish a testimonial or case study without the Customer’s prior written approval.
Notices under the Agreement must be sent by email to contact@legiscope.com for Legiscope and to the notice email in the Order Form for the Customer. Either Party may change its notice email by written notice. Mandatory rules governing court or authority documents continue to apply.
Contract interpretation and governing law
The Agreement constitutes the entire agreement between the Parties concerning its subject matter and supersedes all prior proposals, discussions and understandings. No person other than a Party may enforce the Agreement, except as expressly provided by the DPA or mandatory law. A failure or delay in exercising a right does not waive that right. If any provision is unenforceable, it will be limited to the minimum extent necessary and the remainder of the Agreement will continue in effect.
The Order Form controls the Customer-specific commercial terms and any non-standard scope expressly permitted by these Terms. It does not otherwise amend these Terms. The DPA governs the processing of Customer Personal Data, and its Commission Clauses prevail over any conflicting provision. These Terms govern all other matters. A purchase order or other Customer document is administrative only and does not form part of or amend the Agreement.
The Agreement and any non-contractual obligations arising from or connected with it are governed by Lithuanian law, excluding its conflict-of-law rules. Subject to mandatory law, the courts of Vilnius, Lithuania have exclusive jurisdiction over any dispute arising from or connected with the Agreement. The English version prevails unless the signed Order Form expressly designates another controlling language.
Definitions
- Affected Service means the purchased workflow, feature or professional service directly affected by an event. Any refund or credit uses the fee allocated in the Order Form, the applicable standalone price or, if neither exists, a reasonable proportion of the annual subscription fee based on the relative scope and value of the Affected Service.
- Agreement means the Order Form, these Terms and the DPA, as described in “Agreement, formation and precedence”.
- AI Output means a document or other result generated for the Customer through the Service’s artificial-intelligence functionality.
- Authorised User means a named individual whom the Customer authorises to use the Service for its internal professional purposes.
- Business Day means a day other than a Saturday, Sunday or public holiday in Lithuania.
- Contract Year means each consecutive 12-month period beginning on the Service Start Date or its anniversary.
- Customer Administrator means an Authorised User permitted to manage the Customer’s accounts, access, roles, organisation scope and integrations.
- Customer Content means data, records, documents, files, prompts, instructions, configurations and other material submitted to or stored in the Service for the Customer, including Customer Personal Data.
- Customer Personal Data means personal data that Legiscope processes on the Customer’s behalf under the DPA. It excludes personal data that Legiscope processes as an independent controller for the activities described in “Legiscope as independent controller”; this exclusion does not permit Legiscope to repurpose Customer Content.
- Limits means the programme, Token amount, features, integrations, services and other entitlements applicable under these Terms and the Order Form.
- Order Form means the sales record accepted by the Parties that identifies the Customer, selected Plan and Limits, permitted non-standard scope, price, total fixed-term commitment, Subscription Term, Service Start Date and controlling Terms version.
- Plan means a subscription plan set out in the Plan Catalogue reproduced in these Terms and selected in the Order Form.
- Service means the hosted Legiscope platform, documentation and support, together with any implementation or professional service expressly included in the Order Form.
- Service Start Date means the date stated in the Order Form on which the initial Subscription Term begins.
- Subscription Term means the initial fixed term and each renewal term described in “Fixed term, renewal and price protection”.
- Tokens means contractual units used for AI-assisted operations. They are service-use entitlements, not deposits, payment accounts, electronic money or redeemable stored value.