Terms of Service
Last updated: July 4, 2026
These Terms of Service (the "Terms") are a binding agreement between Brandon Brown, doing business as CourtDocs ("CourtDocs," "we," "us," or "our"), and the organization that accepts these Terms or uses the Service (the "Customer," "you," or "your"). These Terms govern your access to and use of the CourtDocs website at courtdocs.us and the CourtDocs application at app.courtdocs.us (together, the "Service").
These Terms include the Data Processing Addendum in Attachment 1 (the "DPA"), which is incorporated into and forms part of these Terms and applies automatically when you accept these Terms.
By creating an account, clicking to accept, or using the Service, you agree to these Terms. If you do not agree, do not use the Service.
1. Acceptance and eligibility
(a) Authority to bind. If you accept these Terms or use the Service on behalf of an organization (for example, a law firm, in-house legal team, public defender or legal-aid office, or law school clinic), you represent that you are authorized to bind that organization to these Terms, and "you" and "Customer" refer to that organization. If you do not have that authority, you may not accept these Terms or use the Service.
(b) Intended users. The Service is intended for legal professionals and the organizations they work for. It is not intended for use by consumers for personal, family, or household purposes, and it is not directed to children under 16.
(c) Capacity. You represent that you are at least 18 years old and able to enter into a binding contract.
2. Description of the Service
CourtDocs provides software that helps California legal professionals pre-populate, review, and export California Judicial Council forms. The Service lets you enter client, party, case, and matter data, renders editable forms in the browser, and exports filing-ready PDFs. CourtDocs may add, change, or remove features over time. The forms supported, the templates available, and the data fields may change as the Judicial Council revises its forms and as we expand coverage.
3. Accounts and security
(a) Registration. You must provide accurate and complete information when you create an account and keep it up to date.
(b) Credentials. You are responsible for safeguarding your account credentials and any access tokens issued to you, and for all activity that occurs under your account. Notify us promptly at hello@courtdocs.us if you suspect unauthorized access or use.
(c) Users within your organization. You are responsible for the acts and omissions of the individuals you authorize to use the Service under your account, and for ensuring they comply with these Terms.
4. Acceptable use
You agree not to, and not to permit anyone to:
- use the Service in violation of any applicable law or regulation, or to infringe or misappropriate any third party's rights;
- access or use the Service to build a competing product, or copy, scrape, or reverse engineer the Service except to the extent that restriction is prohibited by law;
- interfere with, disrupt, probe, or attempt to gain unauthorized access to the Service, other accounts, or the systems or networks connected to the Service;
- upload or transmit malicious code, or use the Service to store or transmit content that is unlawful;
- attempt to circumvent any usage limits, security controls, access controls, or authentication; or
- use the Service in a way that imposes an unreasonable or disproportionate load on our infrastructure.
We may suspend or limit access to protect the Service or other users, or to comply with law, and will use reasonable efforts to notify you when we do.
5. Customer Data and ownership
(a) Your data. "Customer Data" means the data you and your authorized users submit to the Service, including client, party, case, matter, and form-field information, and the documents you generate. As between you and CourtDocs, you own and retain all rights to your Customer Data. CourtDocs does not claim ownership of your Customer Data.
(b) License to operate the Service. You grant CourtDocs a limited, non-exclusive, worldwide, royalty-free license to host, store, copy, transmit, display, and process Customer Data solely as necessary to provide, maintain, secure, and support the Service for you, and as instructed by you through your use of the Service. This license exists only for as long as needed to provide the Service and to meet our obligations, and it is subject to the Privacy Policy and the DPA in Attachment 1.
(c) No AI training; no sale. CourtDocs does not sell your Customer Data, does not use your client, case, or matter data to train artificial-intelligence models, and does not send that data to third-party artificial-intelligence providers. (This commitment is restated, with its operational basis, in Section 3(d) of the DPA.)
(d) Your responsibility for Customer Data. You are responsible for the accuracy, quality, legality, and rights to use the Customer Data you submit, and for obtaining any consents required to provide it to us.
(e) Aggregated and de-identified data. CourtDocs may generate and use aggregated or de-identified information that does not identify you, your organization, or any individual, to operate, secure, analyze, and improve the Service, provided that such information is not used to identify you or your clients and is not Customer Data.
(f) Our materials. CourtDocs and its licensors own all right, title, and interest in and to the Service, including its software, design, and content, excluding Customer Data and the underlying public Judicial Council forms. No rights are granted to you except as expressly set out in these Terms.
6. No attorney-client relationship; not legal advice
(a) CourtDocs is not a law firm. CourtDocs is a software provider. It is not a law firm, does not practice law, and does not provide legal advice, legal opinions, or legal representation. Using the Service does not create an attorney-client relationship between you (or your clients) and CourtDocs, and no communication with CourtDocs or through the Service is protected by the attorney-client privilege as to CourtDocs.
(b) You are responsible for the legal work. The Service helps you prepare forms; it does not decide what is legally correct for your matter. You, as the legal professional or organization, are solely responsible for: reviewing every form and document for accuracy, completeness, and legal sufficiency before it is filed or relied upon; selecting the correct forms; meeting filing deadlines and court rules; and exercising independent professional judgment.
(c) Professional conduct. You are solely responsible for complying with the rules governing the unauthorized practice of law and the rules of professional conduct that apply to you, including your duties of competence, confidentiality, and supervision. The Service is a tool for legal professionals and does not authorize, and is not a substitute for, the practice of law by a qualified person.
(d) No guarantee of acceptance. CourtDocs does not guarantee that any form or document prepared with the Service will be accepted by a court or any other body. Acceptance depends on substantive law, local rules, and the specific facts of your matter, which are outside CourtDocs's control.
7. Fees and billing
(a) Plans and fees. Access to paid features is subject to the fees and plan terms for the plan you select. Current plans and prices are described at courtdocs.us/#pricing and may change as described in Section 14. Plans are offered with monthly or annual billing.
(b) Payment processing. Billing is handled through our payment processor, Stripe. By subscribing, you authorize us and Stripe to charge your designated payment method for the applicable fees. We do not store full payment-card numbers.
(c) Subscriptions and renewals. Subscriptions renew automatically for successive periods equal to your billing interval (monthly or annual) until cancelled. You may cancel at any time in the Service or by contacting us; cancellation takes effect at the end of the then-current billing period, and you keep access until then.
(d) Taxes. Fees are exclusive of taxes; you are responsible for any applicable taxes other than taxes on our net income.
(e) Refunds. Except where required by law or expressly stated in these Terms, fees are non-refundable and there are no credits for partial billing periods.
8. Confidentiality
Each party may have access to the other's non-public information ("Confidential Information"). The receiving party will use the disclosing party's Confidential Information only to perform under these Terms, will protect it with at least reasonable care, and will not disclose it except to its personnel and advisors who need to know and are bound by confidentiality obligations. Customer Data is the Customer's Confidential Information.
If the receiving party is compelled by law, regulation, or legal process to disclose the disclosing party's Confidential Information, it will (to the extent legally permitted) give the disclosing party prompt written notice before disclosure so the disclosing party may seek a protective order or other remedy, and will disclose only what it is legally required to disclose.
This Section does not apply to information that is or becomes public through no fault of the receiving party, is independently developed, or is rightfully received from a third party without restriction.
9. Privacy and data processing
(a) Privacy Policy. CourtDocs's handling of personal information for which CourtDocs is the business/controller (account, billing, and usage data) is described in the CourtDocs Privacy Policy, which is incorporated into these Terms.
(b) DPA. For personal information that CourtDocs processes on your behalf as a service provider (the client, party, case, and matter data you enter), the Data Processing Addendum in Attachment 1 governs that processing. The DPA is part of these Terms and takes effect automatically when these Terms do. In the event of a conflict between the body of these Terms and the DPA with respect to such processing, the DPA controls.
(c) Countersigned copy. On request, CourtDocs will provide a countersigned copy of the DPA for the Customer's records.
10. Warranties and disclaimers
(a) Limited mutual warranty. Each party represents that it has the authority to enter into these Terms.
(b) Disclaimer. EXCEPT AS EXPRESSLY STATED IN THESE TERMS, THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE," AND COURTDOCS DISCLAIMS ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT, AND ANY WARRANTY ARISING FROM COURSE OF DEALING OR USAGE OF TRADE. COURTDOCS DOES NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE, THAT IT WILL MEET YOUR REQUIREMENTS, OR THAT ANY FORM OR DOCUMENT PRODUCED WITH THE SERVICE WILL BE ACCURATE, COMPLETE, OR ACCEPTED BY ANY COURT OR OTHER BODY. COURTDOCS DOES NOT PROVIDE LEGAL ADVICE, AND THE SERVICE IS NOT A SUBSTITUTE FOR THE PROFESSIONAL JUDGMENT OF A QUALIFIED PERSON.
Some jurisdictions do not allow the exclusion of certain warranties, so some of the above exclusions may not apply to you.
11. Limitation of liability
(a) Exclusion of indirect damages. TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR EXEMPLARY DAMAGES, OR FOR LOST PROFITS, LOST REVENUE, LOST DATA, OR BUSINESS INTERRUPTION, ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
(b) Cap. TO THE MAXIMUM EXTENT PERMITTED BY LAW, EACH PARTY'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS (INCLUDING THE DPA) AND THE SERVICE WILL NOT EXCEED THE TOTAL FEES THE CUSTOMER PAID TO COURTDOCS IN THE TWELVE (12) MONTHS BEFORE THE EVENT GIVING RISE TO THE LIABILITY.
(c) Exceptions. The cap in subsection (b) does not apply to: (i) the Customer's payment obligations; (ii) a party's indemnification obligations under Section 12; or (iii) liability that cannot be limited under applicable law.
(d) Allocation of risk. The limitations in this Section reflect the allocation of risk between the parties and are an essential basis of the bargain.
12. Indemnification
(a) By the Customer. You will defend, indemnify, and hold harmless CourtDocs and its officers, employees, and agents from and against any third-party claims, and any resulting losses, damages, liabilities, costs, and reasonable attorneys' fees, arising out of or relating to: (i) your Customer Data; (ii) your use of the Service in violation of these Terms or applicable law; or (iii) your violation of any rule governing the practice of law or any duty you owe to a client or third party.
(b) By CourtDocs. CourtDocs will defend, indemnify, and hold you harmless from and against any third-party claim alleging that the Service, as provided by CourtDocs and used as permitted by these Terms, infringes that third party's United States copyright, trademark, or trade secret, and will pay any resulting damages finally awarded or agreed in settlement. CourtDocs may, at its option, procure the right for you to continue using the Service, modify the Service to be non-infringing, or terminate the affected Service and refund prepaid unused fees. This subsection does not apply to claims arising from Customer Data, from combination with items not provided by CourtDocs, or from the Judicial Council forms themselves.
(c) Procedure. The indemnified party must give prompt notice of the claim, allow the indemnifying party sole control of the defense and settlement (provided any settlement fully releases the indemnified party without admission of fault), and provide reasonable cooperation.
13. Term and termination
(a) Term. These Terms apply from when you first accept them or use the Service and continue until terminated as described here or in your plan.
(b) Termination by you. You may stop using the Service and terminate your account at any time, subject to your plan's cancellation terms in Section 7.
(c) Termination by us. We may suspend or terminate your access if you materially breach these Terms and do not cure the breach within thirty (30) days of notice (where the breach is curable), if required by law, or to protect the Service or other users. We may also discontinue the Service on reasonable prior notice, in which case we will refund any prepaid fees for the period after discontinuation.
(d) Effect of termination. On termination, your right to use the Service ends. Provisions that by their nature should survive (including Sections 5, 6, 8, 10, 11, 12, 15, and 16, and the DPA for as long as CourtDocs holds Customer Personal Information) survive termination.
(e) Data handling on termination. CourtDocs's handling of Customer Data and personal information after termination, including return, deletion, retention, and the audit-log and legal-hold carve-outs, is governed by Section 11 of the DPA and the Privacy Policy. You are responsible for exporting any Customer Data you wish to keep before the deletion window in the DPA elapses.
14. Modifications to these Terms
We may update these Terms (including the DPA and the pricing for renewal periods) from time to time. If we make a material change, we will notify your designated contact by email at least thirty (30) days before the change takes effect, and we will post the updated Terms with a new "Last updated" date. Your continued use of the Service after the effective date of a change means you accept the updated Terms. If you do not agree, you may cancel as described in Section 7 before the change takes effect and, for a material change that adversely affects you, receive a pro-rata refund of prepaid fees for the remainder of your billing period.
15. Governing law and dispute resolution
(a) Governing law. These Terms are governed by the laws of the State of California, without regard to its conflict-of-laws principles, and by applicable United States federal law.
(b) Venue. Subject to subsection (c), the parties consent to the exclusive jurisdiction and venue of the state and federal courts located in Alameda County, California for any dispute arising out of or relating to these Terms or the Service.
(c) Informal resolution first. Before filing a claim, each party agrees to give the other written notice of the dispute and thirty (30) days to resolve it informally.
16. General
(a) Entire agreement. These Terms, together with the Privacy Policy, the DPA (Attachment 1), and any order or plan terms, are the entire agreement between the parties regarding the Service and supersede prior agreements on that subject.
(b) Order of precedence. In the event of a conflict, the order of precedence is: (i) an executed order or master agreement, if any; (ii) the DPA, for the processing of Customer Personal Information; (iii) the body of these Terms; (iv) the Privacy Policy.
(c) Assignment. You may not assign these Terms without our prior written consent, except to a successor in connection with a merger or sale of substantially all assets, with notice to us. We may assign these Terms in connection with a reorganization, incorporation, merger, or sale.
(d) Severability and waiver. If any provision is held unenforceable, the rest remain in effect. A party's failure to enforce a provision is not a waiver.
(e) Force majeure. Neither party is liable for delay or failure to perform (other than payment obligations) due to events beyond its reasonable control.
(f) Notices. Notices to CourtDocs should be sent to hello@courtdocs.us. Notices to you may be sent to the email associated with your account.
(g) Independent contractors. The parties are independent contractors; these Terms do not create a partnership, agency, or joint venture.
17. Contact
Questions about these Terms? Email hello@courtdocs.us, or write to CourtDocs, Oakland, California, United States.
Attachment 1: Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of, and is incorporated into, the CourtDocs Terms of Service above (the "Agreement") between CourtDocs ("we," "us," or "Processor") and the customer that agreed to the Agreement (the "Customer," "you," or "Controller"). This DPA governs CourtDocs's processing of Personal Information on the Customer's behalf in connection with the CourtDocs service (the "Service"). It takes effect automatically when the Agreement does; no separate signature is required.
CourtDocs provides software that helps California legal professionals pre-populate, review, and export California Judicial Council forms. To do that, the Customer enters information about its clients, parties, cases, and matters into the Service. This DPA sets out how CourtDocs handles that information.
Effective date: the date the Agreement is accepted.
1. Definitions
Capitalized terms not defined here have the meaning given in the Agreement. Where a term below is defined by the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act and its implementing regulations (together, the "CCPA"), the CCPA meaning controls for that term.
- "Business" means the entity that determines the purposes and means of processing Personal Information. For the Customer Personal Information processed under this DPA, the Customer is the Business. "Business" and "Controller" are used interchangeably and refer to the Customer.
- "Service Provider" means a person that processes Personal Information on behalf of a Business pursuant to a written contract that meets the CCPA's requirements. CourtDocs is the Service Provider with respect to Customer Personal Information. "Service Provider" and "Processor" are used interchangeably and refer to CourtDocs.
- "Contractor" has the meaning given under the CCPA. To the extent any processing under the Agreement causes CourtDocs to be treated as a Contractor rather than a Service Provider, the Service Provider obligations in this DPA apply to CourtDocs as a Contractor with equal force.
- "Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household, that CourtDocs processes on the Customer's behalf under the Agreement. It includes the client, party, case, matter, and form-field data the Customer enters into the Service.
- "Sensitive Personal Information" has the meaning given under the CCPA, and includes the Social Security numbers, government identifiers, financial-account information, and precise geolocation that California Judicial Council forms can require the Customer to enter.
- "Customer Personal Information" means Personal Information that the Customer (or its authorized users) submits to the Service, or that CourtDocs processes on the Customer's behalf, in the course of providing the Service. It does not include CourtDocs's own account, billing, and usage records, for which CourtDocs is the Business (see Section 2).
- "Sub-Processor" means a third party engaged by CourtDocs to process Customer Personal Information in connection with the Service. The current Sub-Processors are listed in Schedule 3.
- "Process" / "Processing" means any operation performed on Personal Information, such as collection, storage, use, disclosure, retention, or deletion.
- "Consumer," "Sell," "Share," "Cross-Context Behavioral Advertising," and "Business Purpose" have the meanings given to them under the CCPA.
- "Data Subject Request" means a request from or on behalf of a Consumer to exercise a right under applicable privacy law, including the right to know, access, delete, correct, or opt out.
2. Roles of the parties
For the purposes of this DPA and applicable privacy law:
(a) Customer Personal Information. The Customer is the Business / Controller and CourtDocs is the Service Provider / Processor. CourtDocs processes Customer Personal Information only on the Customer's documented instructions and only to provide the Service, as further restricted in Section 3.
(b) CourtDocs account, billing, and usage data. CourtDocs is the Business / Controller for the account, organization, billing, and operational-usage data it collects to operate and secure the Service and to bill the Customer, including the account records of the Customer's own users, support correspondence, and in-app feedback submissions. CourtDocs's handling of that data is governed by the CourtDocs Privacy Policy, not by this DPA.
(c) Customer's own obligations. The Customer remains responsible for its own legal and professional obligations with respect to Customer Personal Information, including client confidentiality, the attorney-client privilege, and any duty owed to the individuals whose information the Customer enters into the Service. The Customer represents that it has the right and any necessary authority or consent to provide Customer Personal Information to CourtDocs and to instruct CourtDocs to process it as contemplated by the Agreement.
3. Purpose limitation and Service Provider restrictions
CourtDocs will process Customer Personal Information only for the limited and specified purpose of providing, maintaining, securing, and supporting the Service for the Customer (the "Business Purpose"), and on the Customer's documented instructions. The Agreement, this DPA, the configuration choices the Customer makes, and the Customer's use of the Service's features constitute the Customer's documented instructions. The nature, purpose, duration, and categories of Processing are described in Schedule 1.
As a Service Provider under the CCPA, and except as permitted by applicable law, CourtDocs will not:
(a) Sell or Share Customer Personal Information;
(b) Retain, use, or disclose Customer Personal Information for any purpose other than the Business Purpose specified in this DPA, including for any commercial purpose other than providing the Service, or outside the direct business relationship between the parties;
(c) Combine Customer Personal Information with Personal Information that CourtDocs receives from, or on behalf of, another person, or that CourtDocs collects from its own interaction with a Consumer, except as the CCPA permits a Service Provider (for example, to perform a Business Purpose on the Customer's behalf); or
(d) Use Customer Personal Information to train, develop, fine-tune, or improve any artificial-intelligence or machine-learning model, or transmit Customer Personal Information to any third-party artificial-intelligence provider. As an operational matter confirmed by the Service's architecture, CourtDocs does not transmit Customer client, case, or matter data to any third-party artificial-intelligence provider at runtime, and any artificial-intelligence tooling CourtDocs uses to build form templates operates only on blank, public Judicial Council forms, never on Customer Personal Information.
CCPA compliance and equivalent protection. CourtDocs will comply with all obligations applicable to it as a Service Provider under the CCPA, and will provide at least the same level of privacy protection for Customer Personal Information as the CCPA requires of a Business. CourtDocs certifies that it understands and will comply with the restrictions in this Section 3. If CourtDocs determines that it can no longer meet its obligations as a Service Provider under applicable law, it will notify the Customer without undue delay.
Customer's monitoring and remediation rights. The Customer may take reasonable and appropriate steps to ensure that CourtDocs uses Customer Personal Information in a manner consistent with the Customer's obligations under the CCPA, and, upon notice, to stop and remediate any unauthorized use of Customer Personal Information.
4. Confidentiality of personnel
CourtDocs will ensure that personnel authorized to process Customer Personal Information are bound by appropriate confidentiality obligations (whether contractual or statutory) and have been informed of the confidential nature of the data. CourtDocs will limit access to Customer Personal Information to personnel who need access to provide, support, or secure the Service, on a least-privilege basis.
5. Security measures
CourtDocs will implement and maintain the technical and organizational measures described in Schedule 2 to protect Customer Personal Information against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure, taking into account the nature of the data and the risks involved. Schedule 2 states the measures actually in place and separately identifies measures that are planned but not yet implemented, so that nothing in this DPA represents a control CourtDocs does not currently operate.
CourtDocs may update its security measures from time to time, provided it does not materially reduce the overall level of protection during the term. The Customer is responsible for configuring and using the Service securely, including safeguarding its account credentials and any access tokens.
6. Personal-data breach notification
CourtDocs will notify the Customer without undue delay, and in any event within seventy-two (72) hours after CourtDocs confirms a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Information processed by CourtDocs or its Sub-Processors (a "Personal-Data Breach").
The notification will, to the extent then known and as it becomes available, describe the nature of the Personal-Data Breach, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed to address it. CourtDocs will take reasonable steps to mitigate the effects of the Personal-Data Breach and will reasonably cooperate with the Customer in its investigation and in meeting the Customer's own legal notification obligations (including any obligation the Customer has, as the Business, to notify affected California residents or the Attorney General). CourtDocs's notification is not an acknowledgment of fault or liability.
7. Assistance with Data Subject Requests
(a) Hand-off to the Customer. Because the Customer is the Business / Controller of Customer Personal Information, the Customer is responsible for responding to Data Subject Requests relating to that information. If CourtDocs receives a Data Subject Request directed at Customer Personal Information, CourtDocs will not respond to it directly (except to confirm receipt and routing, or as required by law) and will, without undue delay, forward the request to the Customer.
(b) Assistance. Taking into account the nature of the Processing, CourtDocs will provide reasonable assistance to the Customer, through appropriate technical and organizational measures and insofar as feasible, to enable the Customer to respond to Data Subject Requests, including requests to access, delete, correct, or know about Personal Information.
(c) Current capability and its limits. As of the Effective Date, CourtDocs can effect deletion of Customer Personal Information at the organization, client, and case level, and can produce filled documents for download. CourtDocs does not yet offer a self-service bulk data-export feature, and certain assistance is currently performed by CourtDocs operations staff rather than through self-service tooling. Where assistance exceeds the standard functionality of the Service or the cooperation reasonably required by law, the parties may agree on reasonable fees for that assistance.
8. Sub-Processors
(a) Authorization. The Customer provides a general authorization for CourtDocs to engage Sub-Processors to process Customer Personal Information in connection with the Service, subject to this Section 8. The current Sub-Processors are listed in Schedule 3 and at courtdocs.us/subprocessors.
(b) Flow-down. CourtDocs will enter into a written contract with each Sub-Processor that imposes data-protection obligations substantially as protective as those in this DPA, to the extent applicable to the nature of the Sub-Processor's service, including the Service Provider or Contractor restrictions required by the CCPA. CourtDocs remains responsible for each Sub-Processor's performance to the same extent CourtDocs would be responsible if performing the service directly.
(c) Notice of changes. CourtDocs will provide the Customer with notice at least thirty (30) days before adding or replacing a Sub-Processor that processes Customer Personal Information, by updating the published Sub-Processor list and emailing the Customer's designated contact. If, within that notice period, the Customer reasonably objects to the new Sub-Processor on data-protection grounds, the parties will work together in good faith to find a resolution; if none can be reached within thirty (30) days of the objection, the Customer may terminate the Agreement and receive a pro-rata refund of prepaid fees for the period after termination, as its exclusive remedy.
9. Data Subject rights and Customer access
In addition to the assistance in Section 7, and for so long as the Agreement is in effect, the Customer may access, correct, and delete Customer Personal Information through the Service's available features and, where a feature is not yet self-service, through a request to CourtDocs. CourtDocs will give effect to the Customer's documented instructions to correct or delete Customer Personal Information, subject to the retention carve-outs in Section 11 and the residual-data limitations described in Schedule 1.
10. International transfers
CourtDocs processes and stores Customer Personal Information on infrastructure located in the United States, and its current Sub-Processors process Customer Personal Information in the United States. Application compute runs in Los Angeles, California, and the managed database runs in the AWS US West region. CourtDocs does not currently transfer Customer Personal Information outside the United States as part of providing the Service. If CourtDocs begins processing Customer Personal Information outside the United States, it will implement appropriate safeguards as required by applicable law and update Schedule 3 accordingly.
11. Term, termination, and deletion or return of Customer Personal Information
(a) Term. This DPA takes effect on the Effective Date and remains in effect for as long as CourtDocs processes Customer Personal Information under the Agreement.
(b) Deletion on termination. Upon termination or expiration of the Agreement, and on the Customer's written request made within thirty (30) days of termination, CourtDocs will delete Customer Personal Information in its possession or control, and delete existing copies, within thirty (30) days of the request, unless retention is required by applicable law. CourtDocs effects deletion through a hard delete of the Customer's organization data, which removes the Customer's case, client, party, form-instance, and generated-document records from the live database. Because CourtDocs does not yet offer a self-service bulk export, the Customer is responsible for downloading any documents it wishes to keep before deletion; "return" of Customer Personal Information today means per-document download of generated PDFs, not a bulk export file.
(c) Carve-outs from deletion. The following are carved out from the deletion obligation in (b):
- Audit and security logs. CourtDocs retains operational and audit logs for twelve (12) months, after which they are deleted. Where those logs reference a deleted organization, the organization reference is set to null, but the log entry itself may be retained for the remainder of that window for legal, security, and integrity purposes. Audit-log entries store a one-way hash of tool inputs rather than the underlying Customer Personal Information.
- Account login records. A Customer user's login-account record (name and email) is part of the user lifecycle rather than the organization record and is not removed by organization deletion today; CourtDocs will delete or de-identify it on request.
- Backup retention. Deleted records may persist in the managed database's point-in-time recovery history until that window ages out (currently a 7-day window).
- Legal hold. CourtDocs may retain Customer Personal Information to the extent, and for the period, required by applicable law or a valid legal hold, and will continue to protect any retained data under this DPA for as long as it is retained.
12. Audit and information rights
CourtDocs will make available to the Customer information reasonably necessary to demonstrate its compliance with this DPA, including the security-measures description in Schedule 2 and, on request, written responses to a reasonable security questionnaire, no more than once per twelve (12)-month period, on reasonable prior written notice, subject to confidentiality obligations. Audit rights under this Section are satisfied by such written information and questionnaire responses; on-site or hands-on-systems audits are excluded except where required of the Customer by a regulator or applicable law, or following a Personal-Data Breach, in which case the parties will agree on reasonable scope, timing, and cost allocation.
CourtDocs does not currently hold a third-party security certification (for example, SOC 2 or ISO 27001); the Customer should not rely on the existence of any such certification.
13. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in Section 11 of the Agreement, and any reference in the Agreement to a party's liability means the aggregate liability of that party under the Agreement and this DPA together. Nothing in this DPA limits liability to the extent it cannot be limited under applicable law.
14. Order of precedence
This DPA forms part of the Agreement. In the event of a conflict between this DPA and the body of the Agreement with respect to the Processing of Customer Personal Information, this DPA controls. In the event of a conflict between this DPA and the CourtDocs Privacy Policy with respect to Customer Personal Information, this DPA controls. Except as expressly modified by this DPA, the Agreement remains in full force and effect.
15. Governing law
This DPA is governed by the laws of the State of California, without regard to its conflict-of-laws principles, and by applicable United States federal law. The parties consent to the jurisdiction and venue set out in the Agreement.
16. Contact
Questions about this DPA or about CourtDocs's Processing of Customer Personal Information may be directed to hello@courtdocs.us, or to CourtDocs, Oakland, California, United States.
Schedule 1: Details of Processing
- Subject matter. CourtDocs's provision of the Service: pre-populating, rendering, and exporting California Judicial Council forms from data the Customer enters.
- Duration. For the term of the Agreement, plus the limited retention and backup windows described in Section 11 and Schedule 2.
- Nature and purpose. Storage, organization, retrieval, transformation (form fill and PDF generation), transmission, and deletion of Customer Personal Information, solely to provide and support the Service (the Business Purpose).
- Categories of data subjects. The Customer's clients; opposing parties and other parties named on a matter; household members of a client (as a form may require); and the Customer's own authorized users (attorneys and staff), noting that their account records are CourtDocs-as-Business data under Section 2(b).
- Categories of Personal Information. Names, postal addresses, email addresses, and telephone numbers; case and matter facts and party roles; and other fields a Judicial Council form requires.
- Categories of Sensitive Personal Information. Depending on the form, this can include Social Security numbers, dates of birth, financial-account numbers, and protective-order victim addresses.
- Residual-data limitation. Deleting an individual client record does not by itself remove that person's data from form records already generated on a matter; full erasure of an individual requires deletion of each matter on which they appear, or of the organization.
Schedule 2: Technical and Organizational Security Measures
These are the measures in place as of the Last updated date, stated factually. Section F lists measures that are planned but not yet implemented, so this schedule does not represent a control CourtDocs does not operate.
A. Access control and tenant isolation
- Each Customer organization's data is isolated by a type-enforced organization scope, so a query that omits the organization scope fails to compile rather than risking a cross-tenant read; this is regression-tested with cross-tenant scenarios.
- Role-based access within an organization (owner, admin, member), with administrative actions restricted to owner/admin.
- Mutating operations require an active subscription; production-data operator access is controlled at the infrastructure level on a least-privilege basis.
B. Encryption in transit
- HTTPS is forced at the edge; plaintext HTTP is redirected.
- Baseline security response headers are set (X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy: strict-origin-when-cross-origin).
- HTTP Strict Transport Security is enabled at the standard one-year max-age for the application domain; it does not set includeSubDomains or preload.
- Session cookies are HttpOnly and SameSite=Lax, and Secure in production.
C. Encryption at rest
- The managed database platform (Neon, AWS US West) encrypts data at rest at the platform level (AES-256).
- Application-level field encryption of individual sensitive fields is not implemented today (see section F).
D. Authentication and credential storage
- Passwords are stored using scrypt; plaintext passwords are never stored.
- Personal access tokens are stored only as a keyed (HMAC-SHA-256) hash using a server-side secret held separately from the database; the raw token is never stored.
- Sessions have a fixed expiry. Optional multi-factor authentication (authenticator-app one-time codes, with single-use backup codes) is available to users; it is not enforced organization-wide today (section F).
E. Logging, monitoring, and resilience
- Operational logs are designed to carry identifiers rather than the underlying Personal Information; email addresses are redacted as standard practice, and the audit trail stores a one-way hash of tool inputs rather than the raw inputs.
- Operational and audit logs are retained for twelve (12) months and then deleted.
- Secrets are managed through a dedicated secrets store and injected at deploy time; no secrets are committed to source control; the server fails to start if a critical secret is missing.
- Generated documents are delivered through HMAC-signed, short-lived (15-minute) download URLs, and the download route additionally requires an authenticated in-organization caller; on-disk generated files are removed after a 7-day window.
- Backups and recovery rely on the managed database's continuous point-in-time recovery, with a 7-day history window.
- Defense-in-depth controls include request rate limiting on the authentication surface, request-body size caps, schema validation of all tool inputs, idempotency keys for mutating operations, and verified, deduplicated payment-webhook handling.
F. Planned but NOT yet implemented (stated so this schedule does not overclaim)
- Application-level, field-level encryption of the most sensitive identifiers (Social Security numbers, dates of birth, financial-account numbers, protective-order victim addresses).
- Organization-wide enforcement of multi-factor authentication (MFA is available today as an optional per-user setting).
- A self-service bulk data-export feature and self-service organization/client deletion in the application UI; these are currently operator- or API-assisted.
Schedule 3: Approved Sub-Processors
Current as of July 4, 2026. This schedule is mirrored at courtdocs.us/subprocessors; changes are announced as described in Section 8(c).
- Fly.io — application hosting and compute. Customer Personal Information in process while in use; ephemeral generated PDFs. United States (Los Angeles).
- Neon — managed Postgres database, the durable store for account, organization, case, client, party, and form data. All persisted Customer Personal Information. United States (AWS US West).
- Cloudflare — DNS, reverse proxy in front of the application (Customer Personal Information transits the edge in TLS), and static hosting for the marketing site. United States edge.
- Stripe — payment processing and subscription billing. Card data is handled by Stripe; CourtDocs stores only billing and customer identifiers. United States.
- Resend — transactional and notification email, and early-access/lead email. Email addresses of the Customer's users; no client or matter data. United States.
- Axiom — operational logging and monitoring. Identifiers and hashed values; redacted emails. United States.
Scope notes.
- Support and feedback channels. Support email sent to hello@courtdocs.us and submissions through the in-app feedback widget are CourtDocs-as-Business communications from the Customer's users, governed by the Privacy Policy (Section 2(b)), not Sub-Processing of Customer Personal Information. Do not include client or matter details in support or feedback messages.
- Artificial-intelligence tooling. CourtDocs uses AI tooling only offline, to build form templates from blank, public Judicial Council forms. No AI provider receives Customer Personal Information, and none is a Sub-Processor. This is the operational basis for Section 3(d).