LEGAL DOCUMENT
Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the Ledesconverter Terms of Service or other written agreement between Asuka Yoshida, sole proprietor / Einzelunternehmerin, Thurgaustr. 10, 81475 Munich, Germany, operating Ledesconverter ("Ledesconverter," "Processor," "we," "us," or "our"), and the customer using the Service ("Customer," "Controller," "you," or "your"). Asuka Yoshida is not registered in the commercial register. VAT identification number: DE456448748. Tax number: not published.
| Field | Value |
|---|---|
| Last updated | 26 July 2026 |
| Processor / Provider / Operator | Asuka Yoshida, sole proprietor / Einzelunternehmerin, Thurgaustr. 10, 81475 Munich, Germany. Not registered in the commercial register. VAT identification number: DE456448748. Tax number: not published. |
| Website | ledesconverter.com |
| Customer / Controller | The business, professional, law-firm, company, organization, or other controller customer using the Service |
| Contact | contact@ledesconverter.com |
| Legal form / address | Thurgaustr. 10, 81475 Munich, Germany | Not registered in the commercial register | VAT identification number: DE456448748 | Tax number: not published |
1. Introduction and incorporation
This Data Processing Addendum ("DPA") forms part of the Ledesconverter Terms of Service or other written agreement between Asuka Yoshida, sole proprietor / Einzelunternehmerin, Thurgaustr. 10, 81475 Munich, Germany, operating Ledesconverter ("Ledesconverter," "Processor," "we," "us," or "our"), and the customer using the Service ("Customer," "Controller," "you," or "your"). Asuka Yoshida is not registered in the commercial register. VAT identification number: DE456448748. Tax number: not published.
This DPA applies only to the extent Ledesconverter processes Customer Personal Data on behalf of Customer as a processor in connection with the Service. It does not apply to personal data for which Ledesconverter acts as an independent controller, such as account administration, billing, subscription management, payment processing, analytics, security, product administration, legal compliance, and support communications, except to the extent expressly stated in this DPA.
This DPA is intended for business, professional, law-firm, company, organizational, or other controller customers where Ledesconverter processes Customer Personal Data as processor under the customer's instructions.
If Customer and Ledesconverter enter into a separately signed data processing agreement, that signed agreement controls over this DPA for the covered processing.
2. Definitions
| Term | Meaning |
|---|---|
| Applicable Data Protection Laws | All privacy, data protection, and data security laws applicable to the processing of Customer Personal Data, including where applicable Regulation (EU) 2016/679 (GDPR), the UK GDPR, the Swiss FADP, ePrivacy laws, and other applicable privacy laws. |
| Customer Content | Invoice PDFs, extracted invoice data, user-entered data, generated LEDES review data, edits, profile instructions, validation results, exports, support attachments voluntarily provided by Customer, and other content that Customer provides to or creates through the Service. |
| Customer Personal Data | Personal data contained in Customer Content that Ledesconverter processes on behalf of Customer to provide the Service. |
| GDPR | Regulation (EU) 2016/679. |
| Security Incident | A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Processor. |
| Service | The Ledesconverter website and related manual LEDES creation, AI-assisted autofill, validation, review, export, account, billing, usage-limit, and support features. |
| Subprocessor | A third party engaged by Processor to process Customer Personal Data on behalf of Customer in connection with the Service. |
The terms controller, processor, data subject, personal data, processing, supervisory authority, and personal data breach have the meanings given in Applicable Data Protection Laws.
3. Roles and scope
Customer is the controller of Customer Personal Data. Customer determines the purposes and means of processing Customer Personal Data, including whether invoice materials may be uploaded, entered, processed, reviewed, exported, or submitted through the Service.
Ledesconverter is the processor of Customer Personal Data when it processes invoice and generated LEDES-related data on Customer's documented instructions to provide the Service.
Ledesconverter may act as an independent controller for account, authentication, billing, subscription, payment, checkout acknowledgement, tax/accounting, analytics, security, abuse-prevention, product administration, legal compliance, and support data that Ledesconverter determines and processes for its own business purposes. That controller processing is governed by the Privacy Policy and is outside the processor obligations of this DPA.
In the current manual mode, Customer-entered invoice/LEDES data is intended to remain local in the browser and is not sent to Ledesconverter for AI extraction, OCR, or PDF text extraction. This DPA applies to manual-mode Customer Personal Data only to the extent it is actually transmitted to and processed by Ledesconverter as processor, for example through a support request or a future server-side feature.
4. Details of processing
The details of processing required under Article 28 GDPR and similar laws are set out below and in Annex I.
| Item | Description |
|---|---|
| Subject matter | Provision of PDF-to-LEDES and invoice-to-LEDES conversion, AI-assisted extraction, review, validation, export, custom-profile, account, customer support related to Customer Content and processor activities, security, and related SaaS functionality. |
| Duration | For the term of Customer's use of the Service and any post-termination period needed for deletion, return, legal compliance, backup expiry, dispute handling, security, or support. |
| Nature of processing | Collection, receipt, transmission, temporary hosting, extraction, parsing, structuring, classification, validation, transformation, display, export, support, troubleshooting, deletion, security monitoring, and limited operational logging. |
| Purpose | To provide, secure, troubleshoot, support, maintain, and improve the reliability, security, and functionality of the Service using Customer Personal Data only as necessary for the instructed Service, troubleshooting, security, and support, including AI-assisted extraction where Customer chooses AI-assisted mode, and not to train Ledesconverter's own AI models. |
| Frequency | Continuous or as initiated by Customer's use of the Service. |
5. Customer instructions
Processor will process Customer Personal Data only on Customer's documented instructions, including the Terms, this DPA, product settings, uploads, user actions, export choices, profile configurations, support requests, and any other written instructions accepted by Processor, unless required to do so by Union, Member State, or other applicable law.
If Processor is required by law to process Customer Personal Data other than on Customer's instructions, Processor will inform Customer of that legal requirement before processing unless the law prohibits such notice on important grounds of public interest.
Processor will inform Customer if, in Processor's opinion, an instruction infringes Applicable Data Protection Laws, unless prohibited by law. Processor is not responsible for independently verifying the legality of Customer's instructions, Customer Content, legal basis, professional secrecy obligations, client approvals, or e-billing requirements.
6. Customer obligations
Customer is responsible for ensuring that Customer has a lawful basis and authority to provide Customer Personal Data to Processor and instruct Processor to process it; providing all required notices and obtaining all required consents, approvals, instructions, or authorizations from clients, employers, law firms, data subjects, or other relevant parties; ensuring that uploaded invoices and related materials are appropriate for processing through the Service, including AI-assisted processing where selected; responding to data subject requests and supervisory-authority requests, except where Processor is legally required to respond directly; reviewing and validating all AI-assisted outputs, LEDES fields, billing codes, exports, and validation results before use or submission; and not uploading special-category data, health data, children's data, government identification numbers, criminal-offence data, or other highly sensitive data unless strictly necessary, lawful, permitted by Customer's policies, and covered by appropriate safeguards.
7. Confidentiality
Processor will ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations or are under an appropriate statutory obligation of confidentiality. Processor will limit access to Customer Personal Data to personnel, contractors, service providers, and advisers who need access for purposes of providing, securing, supporting, maintaining, or complying with legal obligations related to the Service.
8. Security measures
Taking into account the state of the art, implementation costs, nature, scope, context, and purposes of processing, and the risk to data subjects, Processor will implement appropriate technical and organizational measures designed to protect Customer Personal Data. Current measures are summarized in Annex II.
Processor may update its security measures from time to time, provided that the updated measures do not materially reduce the overall level of protection for Customer Personal Data during the term of the agreement.
9. Subprocessors
Customer gives Processor general written authorization to engage Subprocessors to provide, secure, maintain, support, and improve the Service.
Processor remains responsible for Subprocessors' processing of Customer Personal Data to the extent required by Applicable Data Protection Laws. Processor will impose data-protection obligations on Subprocessors that are substantially similar to those in this DPA, taking into account the nature of the services provided by the Subprocessor.
The current list of authorized Subprocessors and related service providers is set out in Annex III of this DPA. Some providers may act as independent controllers or processors for separate controller processing, such as payment processing, fraud prevention, tax, legal compliance, account administration, analytics, or security, depending on the activity and provider terms.
Processor will provide notice of material additions or replacements of Subprocessors by updating Annex III, notifying Customer by email, in-product notice, website notice, or another reasonable method. Customer may object to a new Subprocessor on reasonable data-protection grounds within the notice period stated in the notice or, if no period is stated, within 30 days after notice.
If Processor cannot reasonably accommodate the objection, either party may terminate the affected Service as the sole remedy for that objection, unless applicable law requires a different remedy.
10. International transfers
Processor will not transfer Customer Personal Data to a third country or international organization unless appropriate safeguards are in place where required by Applicable Data Protection Laws.
Appropriate safeguards may include adequacy decisions, standard contractual clauses, the UK International Data Transfer Addendum or IDTA, the EU-U.S. Data Privacy Framework where applicable, additional technical and organizational measures, or another lawful transfer mechanism.
If standard contractual clauses are required for transfers from the EEA, UK, Switzerland, or another protected jurisdiction, the parties agree that the relevant clauses are incorporated by reference to the extent necessary. For Customer-to-Processor transfers, Module Two will generally apply. For Processor-to-Subprocessor transfers, Module Three will generally apply. Annex I, Annex II, and Annex III of this DPA are intended to provide the processing, security, and subprocessor details needed for such transfer terms where applicable.
Unless separately agreed in writing, Processor does not promise that all Subprocessors process all data exclusively in one region. In particular, AI-assisted processing may involve OpenAI processing in locations determined by OpenAI if regional data residency, Zero Data Retention, or Modified Abuse Monitoring is not enabled for the relevant API project.
11. AI-assisted processing
Where Customer chooses AI-assisted mode, Customer instructs Processor to transmit the uploaded PDF invoice and related extracted or generated content to the AI provider identified in Annex III, currently OpenAI, for invoice extraction, review, consistency checking, and generation of editable structured output.
Processor does not use Customer Content to train its own AI models. Processor will not intentionally fine-tune or train proprietary models on Customer Content unless Customer separately instructs or agrees in writing.
AI provider data-use, retention, storage, logging, abuse-monitoring, and region controls are governed by the applicable AI provider terms and Processor's configuration described in the Privacy Policy. Using provider options such as store:false, where supported, is not the same as a formal zero-retention commitment unless expressly confirmed in writing.
Customer remains responsible for determining whether AI-assisted processing is appropriate for the invoice materials, client confidentiality requirements, professional secrecy obligations, jurisdiction, and customer policies that apply to Customer.
12. Assistance with data subject requests
Taking into account the nature of processing and the information available to Processor, Processor will provide reasonable assistance to Customer for responding to requests from data subjects exercising rights under Applicable Data Protection Laws, such as access, rectification, erasure, restriction, objection, and portability.
If Processor receives a request directly from a data subject relating to Customer Personal Data, Processor will, where legally permitted and where the request can be identified as relating to Customer, either direct the data subject to Customer or notify Customer. Processor will not respond to the request on Customer's behalf unless required by law or instructed by Customer.
13. Assistance with security, DPIAs, and consultations
Taking into account the nature of processing and the information available to Processor, Processor will provide reasonable assistance with Customer's obligations relating to security of processing, personal data breach notifications, data protection impact assessments, and prior consultations with supervisory authorities.
Processor may satisfy assistance obligations by providing the Privacy Policy, DPA, Annex III subprocessor list, security documentation, written responses, vendor documentation, standard questionnaires, or other reasonably available information. Assistance may be subject to reasonable limits, confidentiality, security controls, and separate fees for unusually burdensome requests unless prohibited by law or separately agreed.
14. Security Incident notification
Processor will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. The notice will include information reasonably available to Processor, such as the nature of the incident, affected data categories, likely consequences, mitigation steps, and contact point.
Processor may provide information in phases as it becomes available. Notification of a Security Incident is not an admission of fault or liability. Customer is responsible for determining whether and how to notify supervisory authorities, data subjects, clients, employers, law firms, or other parties, except where Applicable Data Protection Laws require Processor to notify directly.
15. Deletion or return of Customer Personal Data
Upon termination of the Service or upon Customer's written request, Processor will delete or return Customer Personal Data where technically feasible, unless retention is required by law or permitted under the agreement.
The Service is designed not to permanently store ordinary invoice-conversion PDFs, full extracted invoice contents, or original uploaded PDF filenames in the application database. Custom-profile request attachments and support attachments voluntarily provided by Customer may be stored for review, setup, and support. Deletion or return obligations for such content will typically relate to temporary processing data, voluntarily provided attachments, operational logs/metadata, backups, vendor-side retention, and any Customer Content that Customer has intentionally retained in browser sessions or exported files.
Custom profile configurations may be suspended after termination or cancellation and kept available for reactivation for up to 90 days, then archived or deleted unless retention is required or permitted by law, billing, support, security, or dispute-handling needs.
Customer is responsible for downloading, saving, backing up, and retaining its own source files, review data, exports, audit trails, and required business records. The Service is not intended to be Customer's archive, accounting system, billing system of record, document-management system, or legal file.
16. Audits and compliance information
Processor will make available information reasonably necessary to demonstrate compliance with this DPA. Customer may request an audit no more than once per year unless a Security Incident or legal requirement reasonably justifies an additional audit.
Audits must be reasonable, limited to relevant systems and records, conducted during normal business hours, subject to confidentiality, and designed not to compromise security, availability, trade secrets, or other customers' data. Where reasonable, Processor may satisfy audit requests through written responses, security documentation, vendor documentation, third-party reports, certifications, or remote review instead of on-site inspection.
Customer is responsible for its own audit costs and for Processor's reasonable costs if an audit is unusually burdensome, unless prohibited by law or otherwise agreed in writing.
17. Law enforcement and government requests
If Processor receives a legally binding request from a public authority for Customer Personal Data, Processor will, where legally permitted, notify Customer and provide reasonable information so Customer may seek a protective order or other remedy. Processor will only disclose Customer Personal Data to the extent legally required.
18. U.S. state privacy laws
This section applies only where U.S. state privacy laws apply.
Where U.S. state privacy laws apply and Customer is a business/controller, Processor will act as a service provider/processor for Customer Personal Data and will not:
- sell Customer Personal Data;
- share Customer Personal Data for cross-context behavioral advertising;
- retain, use, or disclose Customer Personal Data outside the business purposes of providing the Service, except as permitted by law;
- combine Customer Personal Data with personal data from other sources except as permitted by law.
Processor will process Customer Personal Data only for the limited and specified purposes described in this DPA, the Terms, Customer's instructions, and the Privacy Policy. This U.S. state privacy language applies only where such laws apply.
19. Liability, conflict, and order of precedence
The liability limitations and exclusions in the Terms or other applicable agreement apply to this DPA unless prohibited by Applicable Data Protection Laws or expressly agreed otherwise in writing.
If there is a conflict between this DPA and the Terms, this DPA controls only for Processor's processing of Customer Personal Data on behalf of Customer. The Privacy Policy controls for Ledesconverter's independent controller processing unless a signed agreement states otherwise.
Nothing in this DPA limits liability that cannot be limited under applicable law.
Annex I - Details of processing
| Category | Details |
|---|---|
| Processor | Asuka Yoshida, sole proprietor / Einzelunternehmerin, operating Ledesconverter, Thurgaustr. 10, 81475 Munich, Germany, contact@ledesconverter.com. Not registered in the commercial register. VAT identification number: DE456448748. Tax number: not published. |
| Controller | The business, professional, law-firm, company, organization, or other controller customer using the Service, as identified in the account, checkout, order form, or other agreement. |
| Subject matter | Provision of Ledesconverter's manual LEDES creation and optional AI-assisted PDF-to-LEDES conversion workflow. |
| Duration | For the term of Customer's use of the Service and any post-termination retention period needed for deletion, backups, legal compliance, billing, security, support, or dispute handling. |
| Nature of processing | Collection, receipt, transmission, temporary hosting, extraction, parsing, structuring, classification, validation, transformation, display, export, support, troubleshooting, deletion, security monitoring, and limited operational logging. |
| Purpose of processing | To provide and secure the Service, perform AI-assisted extraction where selected, generate editable review data and exports, enforce usage limits, troubleshoot issues, and comply with the agreement and law. |
| Processing frequency | Continuous during use of the Service and as initiated by Customer. |
| Location notes | The main AI extraction workflow uses our application servers and AI provider processing, while subprocessors and service metadata may be processed in different locations according to provider terms and transfer safeguards. |
Categories of data subjects
- Customer personnel and account users;
- law-firm personnel, attorneys, patent attorneys, paralegals, assistants, billing staff, finance staff, and timekeepers;
- clients, client contacts, inventors, applicants, assignees, agents, foreign associates, official representatives, vendors, and other invoice-related persons;
- individuals named in invoice narratives, billing descriptions, supporting documents, or exported LEDES data.
Categories of Customer Personal Data
- names, initials, roles, titles, business contact details, account identifiers, and organization references;
- invoice numbers, matter numbers, client references, billing periods, dates, amounts, currencies, rates, payment references, and tax/VAT information;
- patent, trademark, design, utility model, PCT, EPO, DPMA, EUIPO, WIPO, USPTO, or other IP/legal reference numbers and descriptions;
- timekeeper names, roles, classifications, activities, task descriptions, expense descriptions, disbursements, and professional-service details;
- text appearing in uploaded invoices and related files;
- generated LEDES fields, review-table data, warnings, assumptions, validation messages, and export data;
- usage metadata necessary to provide, secure, troubleshoot, meter, and support the Service.
Special categories and highly sensitive data
Customer should not upload special-category personal data, health data, children's data, government identification numbers, criminal-offence data, or other highly sensitive data unless strictly necessary for the invoice workflow, lawful, permitted by Customer's policies, and covered by appropriate safeguards. Legal invoices should be limited to information necessary for billing, review, LEDES creation, and related professional workflows.
Annex II - Technical and organizational measures
| Area | Measures |
|---|---|
| Encryption and transport | HTTPS/TLS encryption in transit; secure transport for browser-server and server-provider communications where supported. |
| Access control | Account authentication for signed-in and AI-assisted features; server-side protection of API keys and secrets; limited operational access; database access controls. |
| Upload controls | File type and size checks for uploads; PDF preflight checks before AI processing; signed-in user requirement for AI-assisted extraction. |
| Data minimization | No intentional permanent application-database storage of ordinary invoice-conversion PDFs or full extracted invoice contents; original uploaded PDF filenames are not stored in application usage events; custom-profile request attachments are stored only when voluntarily uploaded for setup review; support users are instructed not to send confidential materials unless necessary. |
| AI processing controls | No opt-in to OpenAI API data sharing for model training; supported Responses API calls configured with store:false where supported; no use of Customer Content to train Ledesconverter's own AI models. |
| Logging and monitoring | Production logging practices designed to avoid full invoice contents; operational metadata for security, debugging, usage, rate limiting, billing, credits, and abuse prevention. |
| Rate limiting and abuse prevention | IP-derived and/or user-based rate limiting; hashed rate-limit bucket identifiers; usage limits, quotas, file-size limits, credit checks, and abuse-prevention controls. |
| Retention and deletion | Operational cleanup for expired rate-limit buckets, old failed/pending AI usage events, old AI usage events/periods, processed Stripe webhook event IDs, and custom-profile request file contents according to the current product retention rules; billing/account/tax records retained as legally required. |
| Vendor management | Use of subprocessors and service providers subject to provider contracts, DPAs, privacy/security terms, and transfer safeguards where applicable. |
| Confidentiality | Confidentiality obligations for persons authorized to process Customer Personal Data; access limited to personnel, vendors, advisers, or authorities with a need to know. |
| Availability and resilience | Use of cloud hosting, database, and infrastructure providers; backups and resilience according to provider capabilities and production configuration. |
| Incident response | Procedures to investigate suspected security incidents and notify affected customers without undue delay where Customer Personal Data is affected. |
The following table lists the current authorized Subprocessors and related service providers used for Ledesconverter. Some providers may act as Subprocessors for Customer Personal Data, while others may act as independent controllers or processors for separate account, payment, tax, legal-compliance, analytics, security, or operational activities depending on the processing context and provider terms.
| Provider / category | Purpose | Data / notes | Location / transfer notes | Status |
|---|---|---|---|---|
| Vercel | Hosting, deployment, serverless infrastructure, CDN/edge, logs, application delivery, and Vercel Analytics if enabled. | May process request metadata and Customer Personal Data transmitted through server-side workflows. Analytics should not intentionally receive invoice content. | Server-side workflows, logs, CDN/edge delivery, analytics, failover, support, backups, and operational metadata may involve different provider locations. Provider DPA and transfer terms apply. | Required |
| OpenAI | AI-assisted invoice extraction, review, consistency checking, and structured output generation. | Receives uploaded PDFs and invoice content when AI-assisted mode is selected. Standard API retention and abuse-monitoring rules may apply unless separately configured. | We currently use the standard OpenAI API endpoint unless a different endpoint or retention configuration is enabled. OpenAI provider terms, data processing terms, and transfer safeguards apply. | Required for AI mode |
| Clerk | Authentication, account management, sessions, user metadata, and sign-in flows. | Account and authentication data. Not intended to receive invoice PDFs. | Provider privacy, security, DPA, retention, cookie/session, and transfer terms apply. | Required for signed-in features |
| Stripe | Checkout, subscriptions, billing, invoices, payment status, webhooks, tax/payment metadata, and fraud prevention. | Billing and transaction data. Not intended to receive invoice PDFs. Stripe may act as processor and/or independent controller depending on the activity. | Provider privacy, DPA, payment, retention, tax, fraud-prevention, and transfer terms apply. | Required for paid features |
| Neon / PostgreSQL database provider | Database for accounts, plans, billing metadata, usage events, AI invoice usage, rate limits, webhook metadata, and related operational data. | Not intended for permanent storage of ordinary invoice-conversion PDFs, full extracted invoice contents, or original uploaded PDF filenames. Custom-profile request attachments are handled separately when users deliberately upload them for setup review. | Provider hosting, backup, retention, security, DPA, subprocessor, and transfer terms apply. | Required |
| Resend | Email delivery for account, operational, notification, and support-related messages. | Email addresses, message metadata, message content needed to send emails, and related delivery/status information. Not intended to receive invoice PDFs. | Provider privacy, DPA, retention, security, and transfer terms apply. | Required for email notifications |
| Error monitoring or logging provider, if configured | Error tracking, reliability, debugging, security monitoring, and abuse prevention. | Should not intentionally receive invoice contents or confidential customer materials. Sensitive payloads should be scrubbed where possible. | Provider privacy, DPA, retention, security, and transfer terms apply if configured. | If used |
| Professional advisers and authorities | Legal, tax, accounting, audit, compliance, dispute handling, and lawful requests. | Relevant account, billing, support, security, or legal materials as necessary. | Subject to professional duties, confidentiality obligations, or legal authority. | As needed |
We do not sell Customer Personal Data or invoice content. We do not knowingly share Customer Personal Data or invoice content for behavioral advertising.
Processor may update this Annex III from time to time. For business/controller customers governed by this DPA, the authorization, notice, objection, and termination process in Section 9 applies to material additions or replacements of Subprocessors.
Annex IV - International transfer safeguards
Where Customer Personal Data is transferred outside the EEA, UK, Switzerland, or another protected jurisdiction, Ledesconverter and its providers rely on appropriate transfer mechanisms where required by applicable law.
These mechanisms may include adequacy decisions, EU Standard Contractual Clauses, the UK International Data Transfer Addendum or IDTA, Swiss transfer safeguards, the EU-U.S. Data Privacy Framework where applicable, supplementary measures, or another lawful transfer mechanism.
Provider processing locations, retention controls, regional data-residency options, and abuse-monitoring controls are governed by the applicable provider terms and by the configuration described in the Privacy Policy.
Questions about these documents? Contact contact@ledesconverter.com.