Skip to main content

Headlight is in a closed beta. Access is by invitation only. Request early access

FeaturesPricingSecurityFAQ
Sign in

Data Processing Addendum

Last updated: July 22, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between Headlight Tech LLC ("Headlight") and the customer ("Customer") governing Customer's use of Headlight's services (the "Agreement"), whether that is our Terms of Service or a separately signed agreement. It applies whenever Headlight processes Customer Personal Data on Customer's behalf.

1. Definitions

  • "Customer Personal Data" means personal information contained in Customer Content (as defined in the Agreement) that Headlight processes on Customer's behalf — for example, the names, contact details, dates of birth, family relationships, government identifiers, financial account details, and tax information of Customer's clients and related parties.
  • "Data Protection Laws" means the privacy and data protection laws applicable to the processing of Customer Personal Data under the Agreement, which may include U.S. state privacy laws (such as the California Consumer Privacy Act, "CCPA"), the Gramm-Leach-Bliley Act ("GLBA") and SEC Regulation S-P as applicable to Customer, and, where applicable, the EU and UK General Data Protection Regulation ("GDPR").
  • "Subprocessor" means a third party engaged by Headlight to process Customer Personal Data in providing the services.
  • Terms such as "controller," "processor," "business," "service provider," "data subject," "processing," and "sell or share" have the meanings given in applicable Data Protection Laws.

2. Roles and Scope

  • Customer is the controller (or business) of Customer Personal Data, or processes it on behalf of its own clients. Headlight is Customer's processor (or service provider).
  • This DPA applies only to Customer Personal Data. Personal information that Headlight controls directly (such as Customer's account, billing, and website data) is governed by Headlight's Privacy Policy.
  • Details of the processing — subject matter, duration, nature and purpose, categories of data and data subjects — are set out in Annex A.

3. Processing Instructions

Headlight will:

  • Process Customer Personal Data only to provide, secure, and support the services, as instructed through Customer's configuration and use of the services, and as otherwise documented in the Agreement;
  • Not sell Customer Personal Data, share it for cross-context behavioral advertising, or process it for any commercial purpose other than providing the services;
  • Not combine Customer Personal Data with personal information from other sources except as needed to provide the services;
  • Not use Customer Personal Data to train, fine-tune, or improve artificial intelligence models, whether Headlight's or a third party's; and
  • Notify Customer if it determines it can no longer meet its obligations under applicable Data Protection Laws, in which case Customer may take reasonable steps to stop or remediate the unauthorized processing.

For Customers that are financial institutions subject to GLBA or SEC Regulation S-P, Headlight acts as a service provider with respect to nonpublic personal information in Customer Personal Data and processes it only as permitted under the exceptions for service providers, consistent with this DPA.

4. Confidentiality

Headlight ensures that personnel authorized to process Customer Personal Data are bound by written confidentiality obligations, are granted access on a least-privilege basis, and access Customer Personal Data only when necessary to provide support, investigate security incidents, or as required by law. Such access is logged.

5. Security

Headlight implements and maintains the technical and organizational measures described in Annex B, including encryption in transit and at rest, application-layer field encryption for the most sensitive values, database-enforced tenant isolation, role-based access control, and audit logging. Headlight may update these measures over time, provided the overall level of protection is not materially reduced.

6. Subprocessors

  • Customer provides general authorization for Headlight to engage the Subprocessors listed in Annex C and in our Trust Center, which is the canonical list of subprocessors and may be updated between DPA revisions.
  • Headlight will impose data protection obligations on each Subprocessor that are no less protective than those in this DPA, and remains responsible for each Subprocessor's performance.
  • Headlight will give Customer at least 30 days' notice (by email or through the services) before adding or replacing a Subprocessor that processes Customer Personal Data. Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection in good faith, Customer may terminate the affected services and receive a prorated refund of prepaid fees.

7. Data Subject Requests

Taking into account the nature of the processing, Headlight will assist Customer in responding to requests from data subjects exercising rights under Data Protection Laws (such as access, correction, and deletion), including through the retrieval, correction, and deletion capabilities of the services. If a data subject contacts Headlight directly about Customer Personal Data, Headlight will refer the request to Customer without responding substantively, except as required by law.

8. Security Incidents

Headlight will notify Customer without undue delay, and in any event within 72 hours, after confirming a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data. The notice will describe, to the extent known, the nature of the incident, the data and data subjects affected, the measures taken, and a contact point. Headlight will cooperate reasonably with Customer's own notification obligations. Headlight's notification is not an admission of fault.

9. Audits and Documentation

On written request, no more than once per year (except after a security incident affecting Customer Personal Data), Headlight will make available information reasonably necessary to demonstrate compliance with this DPA, such as security documentation, audit reports (for example, SOC 2 reports when available), and responses to reasonable security questionnaires. Where Data Protection Laws grant Customer an audit right that cannot be satisfied by documentation, the parties will agree on the scope, timing, and conditions of an audit conducted at Customer's expense with minimal disruption to Headlight's operations.

10. Return and Deletion

During the term, Customer can retrieve its documents and records through the services and their API, and Headlight will provide reasonable assistance with exporting Customer Content on request. After termination of the Agreement, Customer Content remains available for retrieval or reactivation for 30 days, unless we are required by law to retain it longer or a separate agreement with Customer provides a different period, then Headlight deletes Customer Personal Data from production systems — including database records, stored documents, and derived data such as extracted text, document chunks, and vector embeddings. Residual copies in encrypted, access-controlled backups are deleted in the ordinary course as backups expire (currently seven days for production database clusters) and are not used to restore individually deleted records.

11. International Transfers

Headlight processes Customer Personal Data in the United States. We offer the Service to organizations established in the United States unless the parties have agreed otherwise in writing.

Customer Personal Data may relate to individuals located outside the United States, including in the EEA, UK, or Switzerland, because Customer's clients and related parties may reside or be present there. GDPR and similar laws may protect individuals based on where they are located, not only their citizenship. Customer, as controller (or processor on behalf of its clients), is solely responsible for determining that its collection of such data and transfer to Headlight in the United States has an appropriate legal basis.

This DPA does not incorporate EU Standard Contractual Clauses, the UK Addendum, or other GDPR-specific transfer or processor annexes unless the parties execute a separate written addendum. Customer must request such terms in writing before processing Customer Personal Data that triggers those requirements. Relying on Headlight's U.S.-only customer eligibility alone does not replace Customer's obligations when Customer systematically processes data about individuals in the EEA, UK, or Switzerland.

12. Liability and Precedence

This DPA is subject to the limitations of liability in the Agreement, including the carve-outs in Section 16 of the Terms of Service (such as for breach of confidentiality, fraud, willful misconduct, gross negligence, and violations of law). If this DPA conflicts with the Agreement regarding the processing of Customer Personal Data, this DPA controls. Headlight may update this DPA as practices or laws change; material changes will be notified in accordance with the Agreement.

Annex A — Details of Processing

  • Subject matter and duration: Processing of Customer Personal Data to provide the services for the term of the Agreement, plus the post-termination retention period in Section 10.
  • Nature and purpose: Hosting and storage of documents and records; AI-assisted extraction of structured data from documents; retrieval-augmented question answering; task, deadline, and workflow management; client and trustee portals; and related support and security operations.
  • Categories of data subjects: Customer's clients and prospective clients and their family members and related parties (including beneficiaries, grantors, and trustees, who may include minors); Customer's personnel; recipients of portals and shared links.
  • Categories of personal data: Names, contact details, dates of birth and death, family relationships, addresses; financial and estate information including account details, transactions, ownership stakes, and tax-form data; government identifiers; and other personal information contained in documents Customer submits.

Annex B — Technical and Organizational Measures

  • Encryption in transit (TLS) and at rest (AWS KMS) for all customer data
  • Application-layer field encryption (AES-256-GCM with KMS-backed keys) for the most sensitive values, including contact details, extracted document text, and sensitive financial fields
  • Multi-tenant isolation enforced at the database layer with PostgreSQL row-level security
  • Role-based access control, with audit logging of sensitive actions
  • AI inference performed within Headlight's AWS environment (Amazon Bedrock); Customer Personal Data is not used to train or improve models under this DPA
  • Public reference search sends only scrubbed, approved query text to Brave Search; documents and client records are not sent
  • API keys stored hashed; secrets and encryption keys managed in AWS Secrets Manager and KMS with least-privilege access
  • Soft-delete plus controlled hard-purge workflows for deletion, with deletion extending to derived data (extracted text, chunks, embeddings)
  • Personnel confidentiality obligations, least-privilege access, and logged support access
  • A SOC 2-aligned control environment, including vendor management, risk management, incident response, and vulnerability management programs

Annex C — Subprocessors

The authoritative list of subprocessors, including each provider's function and the data it handles, is maintained in our Trust Center. The table below summarizes the subprocessors in effect as of the Last updated date above and may be superseded by the Trust Center list.

SubprocessorFunctionCustomer Personal Data processedLocation
Amazon Web ServicesCloud hosting, storage, key management, transactional email (SES), AI inference (Amazon Bedrock)All Customer ContentUnited States
WorkOSAuthentication and identityUser identities of Customer's authorized usersUnited States
InngestBackground job orchestrationBounded job metadata (record identifiers, counts); no document contentUnited States
SentryError and performance monitoringTechnical diagnostics that may incidentally reference recordsUnited States
AblyRealtime in-app status updatesEphemeral event signals that may include file names and record display names; no document content; messages are not persistedGlobal edge network
LangfuseSelf-hosted AI observability and tracing in Headlight's AWS environment (when enabled)Trace metadata and bounded excerpts; not full document content for unrelated purposes; stored in our infrastructure, not Langfuse CloudUnited States
Brave SearchPublic web search for assistant queriesScrubbed search query text only after identifying-information checks; no documents or client recordsUnited States

Stripe (billing) processes Customer's payment and billing information as described in the Privacy Policy; it does not process Customer Personal Data contained in Customer Content. Third-party services Customer chooses to connect, including but not limited to Box, Dropbox, Google Drive, or Google Calendar, are engaged at Customer's direction and are not Headlight Subprocessors. Data synced from Google Calendar into the Service is stored as Customer Content in Headlight's systems; Google remains a service Customer engages directly through OAuth, not a Headlight Subprocessor.

Contact

Privacy questions and requests: privacy@withheadlight.com

Security: security@withheadlight.com

  • Security
  • FAQ
  • Privacy
  • Terms of Service
  • Trust Center
© 2026 Headlight