Last Updated: March 1, 2026
GDPR Compliant: This Data Processing Agreement complies with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer," "Controller," or "you") and Legacy ("Processor," "we," or "us").
This DPA governs the processing of Personal Data (as defined below) by Legacy on behalf of Customer in connection with the provision of our secure file transfer and beneficiary management Service.
By using the Service, you agree to the terms of this DPA. If you do not agree, you must not use the Service.
The following terms have the meanings set out below:
Controller:
The entity that determines the purposes and means of processing Personal Data. In this DPA, the Customer is the Controller.
Processor:
The entity that processes Personal Data on behalf of the Controller. In this DPA, Legacy is the Processor.
Personal Data:
Any information relating to an identified or identifiable natural person, as defined under applicable Data Protection Laws.
Data Subject:
An identified or identifiable natural person whose Personal Data is processed.
Data Protection Laws:
All applicable laws relating to data protection and privacy, including the GDPR, CCPA, and other similar legislation.
Processing:
Any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
Sub-processor:
A third-party processor engaged by Legacy to process Personal Data on behalf of Customer.
Applicability: This DPA applies to all processing of Personal Data by Legacy on behalf of Customer in connection with the Service.
Roles: Customer acts as Controller and determines the purposes and means of processing. Legacy acts as Processor and processes Personal Data only on behalf of and according to Customer's documented instructions.
Instructions: Customer's use of the Service, including uploading files and designating beneficiaries, constitutes documented instructions to Legacy to process Personal Data.
Compliance: Both parties agree to comply with all applicable Data Protection Laws.
Processing of Personal Data for the purpose of providing secure file storage, beneficiary management, and access control services.
Processing will occur for the duration of the Service agreement and during the data retention period specified in our Privacy Policy.
Legacy, as Processor, agrees to:
Authorization: Customer authorizes Legacy to engage the Sub-processors listed below. We will notify Customer of any changes to Sub-processors at least 30 days in advance.
Purpose: File storage and hosting infrastructure
Location: eu-north-1 (Stockholm, Sweden)
View AWS Privacy Policy →Purpose: Authentication and database services
Location: eu-central-2 (Zurich, Switzerland)
View Supabase Privacy Policy →Purpose: Email delivery service
Location: United States
Objection Right: Customer may object to the engagement of a new Sub-processor within 14 days of notification. If Customer objects, we will work with you to find a solution or allow you to terminate the Service.
Legacy implements the following technical and organizational security measures:
Legacy will assist Customer in fulfilling Data Subject requests to exercise their rights under Data Protection Laws, including:
Customer is responsible for responding to Data Subject requests. We will provide reasonable assistance, including providing access to relevant Personal Data within our systems, within 10 business days of Customer's request.
Notification: Legacy will notify Customer without undue delay and in any event within 72 hours of becoming aware of a Personal Data breach affecting Customer's data.
Information Provided: The notification will include:
Cooperation: We will cooperate with Customer and regulatory authorities in investigating and resolving the breach.
Customer has the right to audit Legacy's compliance with this DPA, subject to the following conditions:
Alternative: We may provide compliance certifications (e.g., SOC 2 reports) in lieu of an on-site audit.
Upon termination of the Service or upon Customer's request, Legacy will:
Exceptions: We may retain Personal Data to the extent required by applicable law or for legitimate business purposes (e.g., backups, legal holds).
Personal Data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States.
Transfer Mechanisms: For transfers from the EEA, we rely on:
We ensure that all international transfers comply with applicable Data Protection Laws and provide an adequate level of protection.
Liability: Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service.
Customer Indemnity: Customer will indemnify Legacy against claims arising from Customer's instructions that violate Data Protection Laws or this DPA.
Legacy Indemnity: Legacy will indemnify Customer against claims arising from Legacy's breach of this DPA or Data Protection Laws.
This DPA will remain in effect for as long as Legacy processes Personal Data on behalf of Customer.
Upon termination:
Sections that by their nature should survive termination will survive, including confidentiality, liability, and audit rights for claims arising before termination.
For questions about this DPA or data protection matters, please contact:
Legacy Data Protection Officer
Email: legal@legggacy.com
Address: Address available upon request. Contact: support@legggacy.com