Legal
Security, Privacy & Legal Policies
Comprehensive Policy Whitepaper
Iqidis, Inc. · 3 Columbus Circle, Floor 15, New York, NY 10019
Last Updated: September 1, 2026
Owner: Legal & Security, Iqidis, Inc. · Contact: info@iqidis.ai
This whitepaper consolidates Iqidis's six core policy documents into a single reference for customers, enterprise prospects, security reviewers, and legal teams. In the event of any conflict between this compiled document and the original individual policies as published on the Iqidis platform or website, the original individual policies shall control.
Security & Privacy Overview
Last Updated: August 14, 2026. Owner: Legal & Security, Iqidis, Inc. · Contact: info@iqidis.ai
Irys is designed for professional legal work and incorporates security, privacy, and data-governance controls throughout the platform.
This overview is provided for informational purposes only. The applicable Terms of Service, Privacy & Data Policy, Data Processing Addendum (where applicable), and other individual policies govern and control.
Security
Irys maintains technical and organizational safeguards designed to protect customer information, including:
- Encryption of customer content in transit and at rest.
- Logical segregation of customer content by organization and applicable user/workspace controls.
- Least-privilege and role-based access controls.
- Support for enterprise authentication controls such as SSO and MFA.
- Monitoring and logging of relevant production and administrative activity.
- Vulnerability-management, security-testing, and incident-response processes.
- Security and confidentiality obligations for personnel with authorized access.
Iqidis maintains SOC 2 Type II attestation and ISO/IEC 27001:2022 certification, and its data-protection program complies with HIPAA, GDPR, and CPRA. A Business Associate Agreement (BAA) is available for customers subject to HIPAA. Current reports and certificates are available to customers and prospects under NDA on request.
Customer Data & AI
Customer Content is not used to train Irys or third-party foundation models unless expressly agreed otherwise in writing.
Irys uses a combination of Iqidis-controlled systems and approved third-party service providers to deliver the Services.
Where third-party AI providers are used, they are subject to applicable contractual, privacy, security, and data-use controls. Iqidis maintains a current Service Providers & Subprocessors list identifying relevant providers and their purposes.
Data Isolation
Customer Content is logically segregated from unrelated customers.
Irys is designed so that one customer’s documents, matters, and other content are not intentionally pooled with or made available to another customer.
Access to Customer Content by authorized Iqidis personnel is limited to legitimate purposes such as support, security, service operation, incident response, or legal compliance and is subject to appropriate access controls.
Privacy
Iqidis processes personal data in accordance with its Privacy & Data Policy and, where applicable, an executed or incorporated Data Processing Addendum.
Depending on the customer’s configuration and applicable law:
- Iqidis may act as a processor or service provider for Customer Personal Data.
- Appropriate safeguards may be used for international data transfers.
- Customers retain responsibility for determining the lawful and appropriate use of personal, confidential, privileged, or regulated information within their matters.
Data Location & Subprocessors
Processing may occur in the United States and other supported regions depending on the Services, customer configuration, and applicable service providers.
Regional requirements can be evaluated with Iqidis for applicable enterprise deployments.
Iqidis maintains a current list of service providers and subprocessors and provides applicable notice of material subprocessor changes.
Telemetry
Irys may collect limited operational and security telemetry to support reliability, performance, fraud and abuse prevention, and security.
Ordinary operational telemetry is designed not to include the substantive contents of customer prompts, model outputs, or uploaded documents, except where processing is reasonably necessary for an authorized support, security, incident-response, or legal-compliance purpose.
Incident Response
Iqidis maintains processes for identifying, investigating, containing, and remediating security incidents.
Where required by applicable law or contract, affected customers will be notified of qualifying incidents and provided reasonable information and cooperation necessary to address applicable obligations.
Security concerns may be reported to:
info@iqidis.ai
Professional Use of Irys
Irys is an assistive legal AI platform.
AI-generated output may contain errors or inaccuracies and should be independently reviewed before professional reliance. Irys does not replace professional judgment, legal research, supervision, or the obligations of licensed legal professionals.
For additional information, please review:
- Privacy & Data Policy
- Terms of Service
- Acceptable Use Policy
- Disclaimer
- Cookie Policy
- Service Providers & Subprocessors
- Data Processing Addendum - available where applicable
Questions regarding security, privacy, enterprise requirements, or data processing may be directed to info@iqidis.ai.
Disclaimer
Your use of the Site and Services is subject to the Iqidis Terms of Service and this Disclaimer.
Last Updated: May 18, 2026. Owner: Legal & Security, Iqidis, Inc. · Contact: info@iqidis.ai
Irys can make mistakes. Please review outputs.
Irys is an assistive legal AI platform. AI-generated Output may contain errors or inaccuracies and should be independently reviewed before professional reliance. Irys is not a substitute for independent legal judgment and does not provide legal advice.
1. AI Technology and Output
Irys uses artificial intelligence and related technologies to assist with drafting, analysis, research, document review, and other legal workflows. Because AI systems are probabilistic, Output may be inaccurate, incomplete, outdated, or otherwise erroneous.
Users are responsible for reviewing material Output before relying on it in legal practice. This includes checking, as appropriate, legal authorities, quotations, factual assertions, dates, amounts, calculations, jurisdiction, procedural posture, and source materials.
Confident or polished language should not be assumed to be correct solely because it appears complete or professionally formatted.
2. Professional Use and No Legal Advice
The Services and Output do not constitute legal advice and do not create an attorney-client relationship with Iqidis. Irys is designed to assist legal professionals, not replace them.
Legal professionals remain responsible for their professional judgment, work product, filings, advice, supervision, client obligations, court obligations, and compliance with applicable professional and ethical rules.
Before Output is filed, submitted to a court or regulator, delivered to a client, executed, or otherwise relied upon in a professional context, the responsible professional should perform the review appropriate to the task and applicable obligations.
3. Citation and Verification Features
Irys may include tools that assist users in checking citations, authorities, source links, or available treatment information. These tools are intended to support review and reduce risk; they are not guarantees or certifications.
Users should review the underlying authority before professional reliance.
4. Source Materials and Third-Party Services
The Services may retrieve, reference, link to, or interact with third-party databases, websites, applications, models, or other services. Third-party sources may contain errors, omissions, delays, coverage limitations, or availability issues.
Iqidis does not control and cannot guarantee the accuracy, completeness, availability, or currentness of third-party information. A source link does not constitute Iqidis approval of the legal proposition or professional use of the resulting Output.
Users should verify material factual assertions against the underlying record and appropriate authoritative sources. Irys should not be treated as a system of record.
5. Website, Testimonials, and General Information
Information on Iqidis websites is provided for general informational purposes. Iqidis provides such information in good faith but does not warrant its accuracy, adequacy, validity, reliability, availability, or completeness.
Testimonials and endorsements reflect individual user experiences and may not be representative of all users or outcomes. Testimonials may be edited for clarity or length without changing their substance.
6. Data Handling and Subprocessors
Iqidis may use trusted service providers and subprocessors to deliver, maintain, secure, or support the Services as described in the Terms of Service, Privacy Policy, Data Processing Addendum, and Subprocessor Policy.
Iqidis does not use Customer Content to train its own or third-party foundation models unless expressly agreed otherwise in writing. Third-party model calls are configured with vendor caching or retention disabled where supported and applicable and are used for inference in accordance with Iqidis policies and agreements.
Users remain responsible for determining whether information may lawfully and ethically be submitted to the Services and for complying with applicable confidentiality and privilege obligations.
7. “As Is,” Warranties, and Liability
To the fullest extent permitted by law, the Site, Services, Output, and related features are provided “as is” and “as available,” without warranties of any kind, express or implied, including warranties of merchantability, fitness for a particular purpose, title, and non-infringement.
Iqidis does not warrant that Output will be accurate, complete, current, reliable, or error-free, or that every issue will be detected by a verification feature. Iqidis does not warrant that the Services will be uninterrupted, timely, secure, or error-free.
Limitations of liability applicable to the Services are set forth in the Iqidis Terms of Service and any applicable negotiated agreement.
8. Reporting a Material Issue
If you identify a potentially material issue involving Irys that has resulted in or could reasonably result in a court or regulatory filing issue, sanctions or professional-responsibility inquiry, client claim, material security or privacy concern, or media inquiry concerning the technical operation of the Services, please contact info@iqidis.ai promptly where legally permitted.
Prompt notice helps Iqidis investigate technical facts, support the Customer, preserve relevant information where appropriate, and improve applicable safeguards. Nothing in this Disclaimer limits a lawyer’s or Customer’s legal, ethical, professional, court-ordered, regulatory, insurer, or client disclosure obligations.
9. Changes to This Disclaimer
Iqidis may update this Disclaimer as the Services, technology, and applicable requirements evolve. Material changes will be handled in accordance with the Terms of Service. The current version will identify its effective date.
10. Contact Us
IQIDIS, INC. | 3 Columbus Circle, Floor 15, New York, NY 10019 | info@iqidis.ai
Privacy & Data Policy
Last Updated: May 15, 2026. Owner: Legal & Security, Iqidis, Inc. · Contact: info@iqidis.ai
1. Introduction
Iqidis, Inc. (“Iqidis,” “we,” “us,” or “our”) is committed to protecting privacy and safeguarding information.
This Privacy & Data Policy explains how we collect, use, disclose, secure, and retain information when you use the Irys legal AI platform, our websites, and related applications and services (collectively, the “Services”).
“Irys” is a product name and brand of Iqidis, Inc. and is not a separate legal entity.
This Policy should be read together with our Terms of Service, Acceptable Use Policy, Cookie Policy, Disclaimer, and Service Providers & Subprocessors Policy.
2. Scope and Roles
This Policy applies to:
- customers and authorized users of the Services;
- visitors to our websites;
- prospective customers who interact with us through demos, events, forms, or other communications; and
- other individuals whose information we process in connection with operating the Services.
Organization Customers
Where an organization uses Irys and determines the purposes and means of processing Customer Content, the organization acts as the controller and Iqidis generally acts as its processor or service provider.
Authorized Users act on behalf of the applicable organization.
Customer Content and Output remain subject to the ownership provisions in the Terms of Service and applicable customer agreements.
Iqidis as Controller
Iqidis may act as a controller for information it processes for its own legitimate business purposes, including account administration, billing, website operations, security, fraud prevention, legal compliance, and marketing communications.
3. Information We Collect
Information You Provide
We may collect:
- Account and Profile Information: such as name, email address, organization, role, and authentication information.
- Billing Information: payment and billing information processed through approved payment providers.
- Customer Content: documents, prompts, files, text, and other information submitted to or generated through the Services.
- Support and Feedback: information provided through support requests, product feedback, or other communications.
Information Collected Automatically
We may collect limited operational information such as:
- IP address;
- browser and device information;
- timestamps;
- authentication and security events;
- general location information derived from IP; and
- interaction and performance metadata used to operate, secure, and improve the Services.
Ordinary operational telemetry is designed not to include the substantive contents of customer prompts, model outputs, or uploaded documents except where processing is reasonably necessary for an authorized support, security, incident-response, or legal-compliance purpose.
Information from Third Parties
We may receive limited information from service providers, security and fraud-prevention partners, event or marketing platforms, and other sources consistent with this Policy.
Publicly Available Information
Iqidis may use publicly available legal and other information to develop, operate, and improve the Services in accordance with applicable law.
4. How We Use Information
We may use information to:
- provide and operate the Services;
- process customer requests and generate Output;
- provide customer support;
- maintain account and billing functions;
- improve reliability, performance, and product functionality;
- detect and prevent fraud, misuse, and security threats;
- comply with legal obligations;
- enforce our agreements and policies;
- communicate service, administrative, and product updates; and
- analyze general usage patterns and performance.
Where Iqidis acts as a processor, Customer Personal Data is processed on the applicable customer’s documented instructions and in accordance with the applicable agreement and Data Processing Addendum, where applicable.
5. AI Processing and Customer Content
Irys uses a combination of Iqidis-controlled systems and approved third-party service providers to deliver the Services.
No Training on Customer Content
Iqidis does not use Customer Content to train Iqidis or third-party foundation models unless expressly agreed otherwise in writing.
Where third-party AI providers process Customer Content as part of the Services, they are subject to applicable contractual, privacy, security, and data-use controls.
Iqidis configures third-party AI services to restrict training and vendor-side retention or caching where supported and applicable to the Services.
Current providers are identified in our Service Providers & Subprocessors Policy.
Data Minimization
Iqidis seeks to limit data sent to third-party providers to information reasonably necessary to perform the applicable function.
Data Isolation
Customer Content is logically segregated by organization and applicable user or workspace controls.
Customer Content is not intentionally pooled with unrelated customers’ Customer Content for model training.
6. Access, Storage, and Retention
Authorized Access
Access to Customer Content by Iqidis personnel is limited to authorized purposes such as:
- providing customer support;
- troubleshooting technical issues;
- maintaining and securing the Services;
- investigating incidents;
- complying with legal obligations; and
- enforcing applicable agreements.
Access is subject to appropriate access controls and confidentiality obligations.
Customer Content Retention
Customer Content may be retained during an active subscription as necessary to provide the Services and according to applicable customer settings and agreements.
Upon termination or expiration, Customer Content is handled in accordance with the Terms of Service and, where applicable, the Data Processing Addendum.
Residual copies may remain temporarily in secure backup systems until overwritten in the ordinary course.
Operational Data
Operational logs and telemetry may be retained for periods reasonably necessary for security, reliability, fraud prevention, compliance, and service operation.
7. Sharing and Disclosure
Iqidis does not sell Customer Personal Data.
We may disclose information to:
- Service Providers and Subprocessors necessary to provide and secure the Services;
- professional advisors such as attorneys, auditors, and insurers;
- government authorities or regulators where legally required;
- business transaction participants in connection with a merger, acquisition, financing, or similar transaction, subject to appropriate protections;
- other Authorized Users where directed through the Services and applicable organization permissions; and
- other parties with your consent or at your direction.
Current service providers and subprocessors are listed in our Service Providers & Subprocessors Policy.
8. Organization Accounts
Where Customer Content is created within an Organization Account, that content is processed within the applicable organization context.
Organization administrators may manage users, roles, and organization-level controls.
Access to individual user workspaces is governed by the product’s applicable permissions and administrative features.
When an Authorized User is removed from an Organization, that user’s access to the applicable Organization Account is terminated. Customer Content associated with the Organization remains subject to the Organization’s rights and applicable agreement.
9. Security
Iqidis maintains technical and organizational measures designed to protect Customer Personal Data against unauthorized access, disclosure, alteration, loss, and misuse.
These measures may include:
- encryption in transit and at rest;
- role-based and least-privilege access controls;
- authentication and identity-management controls;
- security logging and monitoring;
- vulnerability-management and security-testing processes;
- network and infrastructure protections;
- secure software-development practices; and
- incident-response procedures.
Iqidis maintains SOC 2 Type II attestation and ISO/IEC 27001:2022 certification, and its data-protection program complies with HIPAA, GDPR, and CPRA. A Business Associate Agreement (BAA) is available for customers subject to HIPAA. Current reports and certificates are available under NDA on request.
No security system can eliminate all risk, and these measures do not constitute a guarantee that a security incident can never occur.
10. Personal Data Breaches
If Iqidis becomes aware of a Personal Data Breach affecting Customer Personal Data for which Iqidis acts as a processor, Iqidis will notify the applicable Customer without undue delay in accordance with Applicable Data Protection Laws and any applicable Data Processing Addendum.
Where reasonably practicable, the notice will include information then available regarding:
- the nature of the incident;
- affected information or individuals, where known;
- likely consequences;
- mitigation or remediation measures; and
- other information reasonably necessary for the Customer to meet applicable legal obligations.
Information may be provided in phases as the investigation develops.
Notification does not constitute an admission of fault or liability.
Iqidis does not publicly identify customers in connection with security incidents unless authorized by the customer or required by law.
11. Customer Security Responsibilities
Customers are responsible for:
- managing Authorized Users;
- protecting credentials;
- removing access when authorization ends;
- configuring available security controls appropriate to their environment;
- maintaining security of customer-controlled devices and systems; and
- promptly reporting suspected unauthorized access or account compromise.
12. Data Processing Addendum
Where Iqidis acts as a processor and applicable law or the parties’ agreement requires additional processor terms, the Iqidis Data Processing Addendum (“DPA”) may be incorporated into the applicable Order Form, enterprise agreement, or other customer agreement.
The DPA addresses matters including:
- controller and processor obligations;
- subprocessors;
- security;
- Data Subject rights;
- audits;
- deletion and return;
- international data-transfer mechanisms; and
- related privacy obligations.
If there is a conflict between this Policy and an applicable DPA, the DPA controls for the matters it governs.
The DPA is available where applicable by contacting info@iqidis.ai.
13. International Data Transfers
Customer Personal Data may be processed in the United States and other supported locations depending on the Services, customer configuration, and applicable service providers.
Where applicable law requires a transfer mechanism for Personal Data transferred internationally, Iqidis uses appropriate safeguards, which may include:
- European Commission Standard Contractual Clauses;
- the UK International Data Transfer Addendum;
- recognized Swiss transfer safeguards;
- adequacy decisions; or
- other lawful mechanisms available under Applicable Data Protection Laws.
Additional details are contained in the applicable DPA and Service Providers & Subprocessors Policy.
14. Privacy Rights
Depending on applicable law and Iqidis’s role in the Processing, individuals may have rights to:
- request access to Personal Data;
- correct inaccurate Personal Data;
- request deletion;
- restrict or object to certain Processing;
- obtain eligible Personal Data in a portable format;
- withdraw consent where Processing is based on consent; and
- lodge a complaint with a relevant supervisory authority.
Where Customer Personal Data is processed by Iqidis on behalf of an organization, requests relating to that Customer Personal Data should generally be directed to the applicable organization.
Requests relating to Personal Data for which Iqidis acts as controller may be submitted to:
info@iqidis.ai
Iqidis may take reasonable steps to verify identity before fulfilling a request.
15. Automated Decision-Making
Iqidis does not use Personal Data for solely automated decision-making that produces legal or similarly significant effects on individuals unless expressly disclosed and permitted by applicable law.
16. Children’s Privacy
The Services are not intended for individuals under 18 acting as users of the Services.
Iqidis does not knowingly create accounts for children under 18.
Customer Content may contain information about minors where lawfully submitted by customers in connection with legal matters or other professional use.
17. Cookies and Tracking Technologies
Our use of cookies and similar technologies is described in the Cookie Policy.
Where required by applicable law, users may manage non-essential cookies and related preferences through available consent controls.
18. Changes to This Policy
Iqidis may update this Policy to reflect changes in law, technology, the Services, or our business practices.
Material changes will be communicated with reasonable advance notice where appropriate.
The current version will identify its effective date.
19. Contact Us
Iqidis, Inc.
3 Columbus Circle, Floor 15
New York, NY 10019
Email: info@iqidis.ai
Service Providers & Subprocessors Policy
Last Updated: May 15, 2026. Owner: Legal & Security, Iqidis, Inc. · Contact: info@iqidis.ai
1. Purpose & Scope
This Policy explains who processes Customer Data and Customer Content for Iqidis customers, how we control those processors, and what security and privacy safeguards apply. It covers Iqidis's first-party (in-house) processing, including our Knowledge Graph (KG), Retrieval-Augmented Generation (RAG), and orchestration/multi-agent layers, as well as third-party Service Providers and Subprocessors.
2. Definitions
- Customer Data: Personal data related to account/profile administration and service operation.
- Customer Content: Documents, prompts, files, and other content a customer inputs for processing, plus any model Output returned by the Services.
- Service Providers: Third parties supporting Iqidis's infrastructure/operations that may process Customer Data and limited telemetry.
- Subprocessors: Third parties that may process Customer Content (or its derivatives) to deliver a specific feature or inference step.
- Internal Processing Services: Iqidis-operated, first-party systems (KG/RAG/orchestration) running inside Iqidis-controlled environments. These are not “subprocessors.”
3. Processing Architecture
How Iqidis differs from “ChatGPT” or out-of-the-box LLMs: Iqidis is not a simple wrapper around a single model. We operate a hybrid architecture that maximizes confidentiality and control.
In-House Backbone (Default)
Most requests are handled inside Iqidis by our KG/RAG and orchestration services within Iqidis-controlled infrastructure. Customer Content is containerized per tenant and per user profile; we do not pool or commingle Customer Content across firms or matters.
Selective, Discrete Subprocessor Calls (Only When Needed)
For certain discrete aspects of a query, our orchestrator may invoke a subprocessor for inference only. These calls are ephemeral (vendor caching/retention disabled), region-aware where available, and contractually restricted from training on Customer Content. Payloads are minimized and limited strictly to the narrow task.
Zero Training on Customer Content
Iqidis does not use Customer Content to train Iqidis or third-party models. Third-party models are used only for stateless inference with no vendor-side retention enabled.
4. Key Differentiators
- Local-first, hybrid architecture. Processing runs in-house via KG, RAG, and orchestration layers. Third-party LLMs are invoked for inference steps only, with caching/retention disabled and contractual no-training obligations.
- Your data stays in your tenant, never conglomerated. Customer Content is stored and processed within your organization's dedicated Iqidis tenant and per-user profile containers.
- Scoped subprocessor use. When a subprocessor is invoked, we transmit the minimum payload needed. Vendors do not retain your prompts/outputs and do not train on your data.
- You own your data and output. You remain the data controller/owner of your User Content and Output. Iqidis acts solely as a data processor/service provider.
- Minimal, content-free telemetry. We collect only behavioral/interaction metadata. We do not log prompts, model outputs, or uploaded documents/files.
5. Security Measures
Iqidis maintains SOC 2 Type II attestation and ISO/IEC 27001:2022 certification, and its security program complies with HIPAA, GDPR, and CPRA. Controls include encryption in transit and at rest; access controls; network security; vulnerability management; monitoring & audit; and secure SDLC. Current reports and certificates are available to customers and prospects under NDA on request.
Breach Notification. If we become aware of a breach affecting Customer Data/Content, we will notify impacted customers without undue delay and no later than 72 hours of becoming aware, unless prohibited by law.
6. Data Location & Transfers
Data is processed primarily in the U.S. and E.U. Regional routing can be adjusted based on customer requirements and technical feasibility. Cross-border transfers use appropriate safeguards as described in the Privacy & Data Policy.
7. Subprocessor Selection, Contracts & Monitoring
Before engaging or materially changing a subprocessor, Iqidis performs due diligence, establishes contractual controls (confidentiality, purpose limitation, no training, security, breach notice, deletion/return on termination), enforces configuration requirements, and conducts ongoing oversight.
8. Change Management & Customer Right to Object
Iqidis will provide ≥30 days' prior notice of any new subprocessor or material change. Customers may reasonably object (on privacy/security grounds) within the notice period, and we will work in good faith to mitigate concerns.
9. Current Service Providers
These providers support the platform and may process Customer Data. They are not used to train models.
| Provider | Purpose | Location(s) |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, file storage, and compute | U.S. |
| Vercel | Web hosting / edge delivery | U.S. |
| Neon | Managed PostgreSQL database | U.S. |
| Okta | Enterprise single sign-on (SSO) | U.S. |
| Stripe | Payment processing & billing | U.S. |
| Resend | Transactional email delivery | U.S. |
| Mailchimp | Lifecycle & marketing email | U.S. |
| HubSpot | Customer relationship management (CRM) | U.S. |
| Slack | Internal notifications & support workflows | U.S. |
| Sentry | Error monitoring & diagnostics | U.S. |
| Mixpanel | Product usage analytics | U.S. |
| Segment | Analytics event routing | U.S. |
| Chameleon | In-app onboarding & guidance | U.S. |
10. Current Subprocessors — No Training
These vendors may process Customer Content to deliver a specific feature or inference step. Iqidis enforces no-training obligations and disables vendor-side caching/retention where supported. Rows marked “Customer-directed” are user-authorized connectors that access content in the customer's own third-party account only when the customer connects it.
| Subprocessor | Purpose | Location(s) | Retention |
|---|---|---|---|
| OpenAI, L.L.C. | LLM inference & document embeddings | U.S. & E.U. | None |
| Anthropic (Claude) | LLM inference | U.S. & E.U. | None |
| Google (Gemini / Vertex AI) | LLM inference & compute | U.S. & E.U. | None |
| Mistral AI | Document OCR & text extraction | U.S. & E.U. | None |
| Perplexity AI | Legal research lookups | U.S. | None |
| ConvertAPI | Document format conversion | U.S. / E.U. | None |
| CloudConvert | Document format conversion | E.U. | None |
| Unstructured | Document parsing & extraction | U.S. | None |
| CourtListener (Free Law Project) | Case-law & citation lookup | U.S. | Query only |
| Linkup | AI web research | U.S. | None |
| Google Workspace (Drive, Gmail, Docs) | User-authorized file & email import/export | U.S. | Customer-directed |
| Microsoft (OneDrive, Outlook) | User-authorized file & email import/export | U.S. | Customer-directed |
| Dropbox | User-authorized file import | U.S. | Customer-directed |
Many requests may be satisfied entirely in-house (KG/RAG/orchestration) without calling an external LLM, further reducing third-party exposure.
11. Internal Processing Services (Operated by Iqidis)
- Knowledge Graph (KG) & RAG: Proprietary services that index/link a customer's authorized sources, perform targeted retrieval, and compose grounded prompts.
- Orchestration/Multi-Agent Layer: Directs tool use, applies legal workflows, manages internal reasoning, and decides if/when to call an external LLM.
- Isolation: All internal services run with per-tenant logical isolation and encryption. They are not subprocessors because Iqidis operates them directly.
12. Transparency, Assurance & Changes
Upon reasonable request, Iqidis can provide summaries of third-party audit reports or recent pen-test executive summaries. Direct audit is available as required by law or agreed in a separate enterprise agreement. Material updates will be communicated with ≥30 days' advance notice.
Data Processing Addendum (DPA)
Last Updated: April 7, 2026 · Owner: Legal & Security, Iqidis, Inc. · Contact: info@iqidis.ai
This Data Processing Addendum (“DPA”) forms part of the Terms of Service (the “Agreement”) between IQIDIS, INC. (“Iqidis,” “Processor”) and you as the Customer and controller (“Controller”) concerning the processing of Customer Personal Data in connection with the Irys legal AI services, including the website currently available at https://iqidis.ai (and any successor domains, including https://irys.ai), and any related applications or services (collectively, the “Services”). “Irys” is a product name and brand of Iqidis, Inc., and not a separate legal entity. Capitalized terms used but not defined in this DPA have the meaning given to them in the Terms of Service.
1. Scope, Roles, and Definitions
1.1 Scope. This DPA governs Iqidis's Processing of Customer Personal Data on behalf of Customer in providing the Services.
1.2 Roles. For such Processing, Customer is the Controller (or “Business” under US state privacy laws) and Iqidis is the Processor (or “Service Provider”).
1.3 Definitions.
- “Applicable Data Protection Laws” means GDPR/UK GDPR/Swiss FADP, applicable US state privacy laws (e.g., CPRA/Colorado/Virginia), and Canadian privacy laws (including PIPEDA, Québec Law 25, and applicable provincial PIPAs), in each case as amended.
- “Content” means Input and Output collectively, as those terms are defined in the Terms of Service.
- “Customer Personal Data” means Personal Data contained in Customer Content that Iqidis Processes on Customer's behalf under the Agreement.
- “Customer Content” means all Content submitted to or generated through the Services by or for a Customer or its Authorized Users.
- “Data Security Incident” means a confirmed unauthorized access to or disclosure of Customer Personal Data processed by the Services, to the extent such breach results from Iqidis's breach of this DPA; unsuccessful attacks, attempted attacks, or events affecting only one or more of the following: anonymized data, aggregated data, or telemetry are excluded.
- “Personal Data” means any information relating to an identified or identifiable natural person, as defined under Applicable Data Protection Laws.
- “Security Measures” means the technical and organizational measures in Annex II.
- “Subprocessor” means a third party engaged by Iqidis to Process Customer Personal Data in delivering the Services.
- “Standard Contractual Clauses” / “SCCs” means EU Commission Decision 2021/914 (Module 2, and Module 3 if applicable).
2. Documented Instructions; How the Service Works
2.1 Instructions. Iqidis will Process Customer Personal Data only on Customer's documented instructions: the Agreement, this DPA, in-product settings, and written instructions (including via the Services). If Iqidis cannot comply, it will notify Customer.
2.2 Local-first; No Training by Design and Contract. Iqidis Processes requests primarily on Iqidis-controlled infrastructure using Iqidis's knowledge graph (KG), retrieval-augmented generation (RAG), and orchestration layers. Where Iqidis uses a third-party model for a discrete inference step, it does so only for stateless inference with vendor caching/retention disabled and under no-training commitments. Iqidis does not use Customer Content to train Iqidis or third-party models.
2.3 Isolation & Location. Customer Content is logically segregated per tenant and per user profile and not commingled across customers. Processing primarily occurs in the U.S. (and the EU where configured). Details appear in Annex I.
2.4 Minimal Telemetry. Iqidis may collect limited operational telemetry (e.g., UI events/clicks, navigation flows, request timing, status/error codes, coarse device/browser metadata) for reliability, security, and abuse detection; telemetry does not include prompts, model outputs, or uploaded files.
3. Confidentiality and Personnel
Iqidis ensures personnel authorized by or on behalf of Iqidis to Process Customer Personal Data are bound by confidentiality obligations and receive appropriate and consistent privacy/security training.
4. Security; Audits & Assurance
4.1 Security Measures. Iqidis will implement and maintain the Security Measures in Annex II and not materially reduce them during the Subscription Term.
4.2 Customer Security Responsibilities. Customer is responsible for configuring and using available security features (e.g., MFA, SSO, role-based access), managing user access, and the legality and accuracy of Customer Personal Data. Iqidis is not responsible for incidents arising from Customer's configurations, credentials, systems, or third-party services not controlled by Iqidis.
4.3 Independent Assurance. Upon reasonable request (no more than annually), Iqidis will provide summaries of relevant third-party audit reports (e.g., SOC-aligned controls) or a recent penetration test executive summary. Direct audits occur only if required by law or under a separately negotiated and agreed agreement.
5. Data Security Incidents
5.1 Notice. If Iqidis becomes aware of a Data Security Incident, it will notify Customer without undue delay after confirming such Data Security Incident and, in any event, no later than 72 hours from such confirmation, unless prohibited by law.
5.2 Contents & Cooperation. In connection with any Data Security Incident, Iqidis will provide the Customer with then-available information regarding the nature of the incident, affected data categories/volumes (if known), likely consequences, and measures taken or proposed. Iqidis will promptly investigate, mitigate, take reasonable steps to prevent recurrence, and cooperate with Customer's reasonable requests for additional information needed to meet its legal or regulatory duties.
5.3 Subprocessor Incidents. Iqidis requires Subprocessors to provide equivalent notice and cooperation and will coordinate the response.
5.4 No Public Statements. Iqidis will not name Customer in public statements regarding a Data Security Incident without Customer's prior approval, unless required by law/regulator.
6. Subprocessors
6.1 Authorization. Customer authorizes Iqidis to engage Subprocessors to deliver the Services. Current Subprocessors are listed in Iqidis's Service Providers & Subprocessors Policy (as updated).
6.2 Change Notice & Objection. Iqidis will give ≥30 days' prior notice of new Subprocessors or material changes. Customer may object on reasonable privacy/security grounds within that period. Iqidis will work in good faith to mitigate; if unresolved, Customer may disable the affected feature or terminate the impacted component without penalty.
6.3 Flow-down & Responsibility. Iqidis will impose written terms on Subprocessors that are no less protective than this DPA (including no training on Customer data, security, and incident notice) and remains responsible for Subprocessors' performance.
6.4 Where confidentiality restrictions prohibit sharing a Subprocessor agreement, Iqidis will provide, on a confidential basis, all information it reasonably can about such agreement.
7. Assistance; Data Subject Requests; DPIAs
7.1 Data Subject Requests. Taking into account the nature of Processing, Iqidis will reasonably assist Customer in responding to data subject requests under Applicable Data Protection Laws. If Iqidis receives a request directly, it will, where legally permitted, redirect the requester to Customer or respond per Customer's instructions.
7.2 DPIAs & Consultations. Iqidis will provide reasonable assistance with data protection impact assessments and consultations with regulators to the extent required for the Services and to the extent Customer cannot reasonably obtain the information otherwise.
8. International Transfers; SCCs / UK / Swiss / Australia
8.1 Transfers. Where Customer Personal Data is transferred to a country without an adequacy decision, the Parties will rely on appropriate safeguards.
8.2 SCCs. The EU SCCs are incorporated by reference and completed as specified in Annex IV of this DPA.
8.3 UK & Switzerland. Where applicable, the UK ICO Addendum and Swiss Addendum are incorporated by reference; Annex I/II/III supply the required details.
8.4 Australia. Where applicable, the Australia Addendum set forth in Annex IV applies.
8.5 Alternative Transfer Mechanism. If a new or alternative lawful transfer mechanism (including any updated SCCs, adequacy decision, or recognized framework) becomes available and applicable, the Parties agree it will automatically apply in lieu of, or in addition to, the above to the extent it ensures a level of protection required by applicable law.
9. US State Privacy (Service Provider)
For Customer Personal Data regulated by US state privacy laws, Iqidis will act as a Service Provider: Iqidis will not sell or share Customer Personal Data; will not retain, use, or disclose it except to provide the Services and as permitted by law; and will not combine it with other data except as allowed to provide and secure the Services for Customer (e.g., security, debugging, availability). Iqidis will notify Customer if it can no longer comply.
10. Retrieval and Deletion
Upon termination/expiration of the Services (or earlier upon written request), Iqidis will delete Customer Personal Data and delete existing copies within 30 days, unless retention is required by law or the Parties otherwise agree in writing. Prior to termination, Customer is responsible for exporting its Customer Personal Data using the export features then-available in the Services. Residual backup copies will be overwritten in the ordinary course under standard retention cycles.
11. Government Access Requests
If a governmental body seeks access to Customer Personal Data, Iqidis will (to the extent legally permitted) promptly notify Customer, challenge unlawful or overbroad demands, and disclose only the minimum necessary to comply with a lawful demand.
12. Liability; Privacy/Security Indemnity (Optional)
12.1 General. Each party's liability under this DPA is subject to the Agreement's limitations and exclusions, except as modified below.
12.2 Privacy/Security Indemnity (Processor → Controller). Subject to the terms below, Iqidis will defend and indemnify Customer against any unaffiliated Third-Party Claim to the extent directly caused by a Data Security Incident within Iqidis-controlled production systems that results from Iqidis's material breach of this DPA or failure to implement the Security Measures, and will pay damages and court-awarded costs (or settlement amounts approved by Iqidis) to the extent permitted by law.
- “Third-Party Claim” means a claim brought by a data subject or supervisory authority seeking monetary relief. For clarity, administrative fines/penalties are not included unless indemnification for such fines is expressly permitted by applicable law and insurable, and then only to the extent insurable.
Conditions. Iqidis's obligations apply only if Customer: (a) promptly provides written notice of the claim (and in any event within a commercially reasonable time); (b) grants Iqidis sole control of the defense and settlement; and (c) provides reasonable cooperation at Iqidis's expense. Failure to give prompt notice limits Iqidis's obligations only to the extent Iqidis is materially prejudiced.
Exclusions. No indemnity to the extent the claim arises from or is increased by: (a) Customer instructions/configurations (including continuing a practice after Iqidis advises it is non-compliant); (b) Customer's failure to implement available security features (e.g., SSO, MFA, role-based access) after written notice; (c) Customer systems/devices or third-party services not controlled by Iqidis; (d) Combinations, modifications, or processing not contemplated by the Documentation or in violation of the Agreement/AUP; (e) Voluntary or precautionary measures (e.g., credit monitoring, broad notifications, PR costs) not required by a final order specifically attributing responsibility to Iqidis; (f) Customer's use of any beta, pre-release, or evaluation-stage feature or service made available by Iqidis.
Remedies. Iqidis may, at its option: (1) remediate and mitigate the incident; (2) provide reasonable cooperation with Customer's legally required notifications; or (3) if the claim cannot reasonably be defended or mitigated, resolve the matter by settlement approved by Iqidis.
Cap (Security Cap; sits within the general cap). Notwithstanding the limitation of liability set forth in Section 10.2 of the Agreement, Iqidis's total aggregate liability for all claims arising from or related to any and all Data Security Incidents shall not exceed an amount equal to two times (2x) the Fees paid or payable by Customer for the Services in the twelve (12) months preceding the event giving rise to liability (the “Security Cap”).
13. Term; Order of Precedence; Governing Law
This DPA remains in effect while Iqidis Processes Customer Personal Data on Customer's behalf. In case of conflict between this DPA and the Agreement, this DPA controls as to data protection/security/transfers; otherwise the Agreement controls (including governing law/venue).
Annex I - Description of Processing
A. Parties.
- Data Exporter (Controller): Customer
- Data Importer (Processor): IQIDIS, INC., 3 Columbus Circle, Floor 15, New York, NY 10019, USA.
B. Nature and Purpose. Provision of AI-enabled legal productivity Services (drafting, research, analysis, summarization), including local-first in-house processing (KG, RAG, orchestration) and selective third-party inference with no training and no vendor retention.
C. Categories of Data Subjects. Customer's employees/contractors; Customer's clients and counterparties; other individuals whose data Customer includes in Customer Content.
D. Categories of Personal Data. Identifiers (name, email), professional data (role, firm), matter-related personal data included in Customer Content, and limited telemetry (behavioral metadata; no prompts/outputs/uploads).
E. Special Categories. Not intended. Any special category data is supplied at Customer's discretion; Iqidis applies Security Measures to any such data.
F. Frequency & Duration. Continuous Processing during the Subscription Term; retention per the Agreement/this DPA (default deletion/return within 30 days post-termination; vendor calls are ephemeral with caching/retention disabled).
G. Processing Operations. Ingestion, storage, retrieval (RAG), generation, transformation, display, export of Output; purpose-limited support access; deletion/return upon termination.
Annex II - Technical and Organizational Security Measures (TOMs)
1) Data Security
- Encryption for data in transit (TLS) and at rest using industry-standard algorithms.
- Monitoring & logging of production systems (availability, auth events, anomalies) with alerting and access to audit trails.
- Vulnerability management with regular scanning and timely remediation; security updates applied on a commercially reasonable basis.
- Resilient cloud infrastructure with backup and recovery procedures designed to minimize data loss and downtime.
2) Access Control
- Least-privilege, role-based access control (RBAC) for systems and data; access reviewed at least annually and on role change.
- Support for SSO/MFA; customers are encouraged to enable available controls for their tenant.
- Strong credential and session management; administrative actions are logged.
3) Data Segregation, Minimization & Deletion
- Logical isolation by tenant and user profile; Customer Content is not pooled or commingled across customers.
- No training on Customer Content. When third-party models are used for a discrete inference step, vendor caching/retention is disabled and calls are stateless.
- Minimal telemetry (interaction metadata only, e.g., clicks/timing/status codes; not prompts, outputs, or uploaded files) for reliability and abuse detection.
- Deletion/return: Upon written request, Customer Personal Data is deleted or returned, with residual backup copies overwritten in the ordinary course per standard retention cycles.
4) Workforce Security
- Security awareness for employees with onboarding and periodic refreshers appropriate to role.
- Confidentiality obligations for personnel with access to Customer Personal Data.
5) Incident Response
- Documented incident response process for detection, containment, investigation, and remediation.
- Customer notification for qualifying incidents without undue delay and no later than 72 hours, consistent with the DPA; reasonable cooperation with legally required notifications.
- Clear channels for reporting suspected security incidents to info@iqidis.ai.
6) Subprocessor Controls
- Subprocessors are engaged under written terms that include confidentiality, security, and incident-notice obligations; for any Subprocessor used for AI inference, such terms further include a contractual prohibition on using Customer Personal Data to train, retrain, or improve its models.
- Iqidis maintains a list of its Subprocessors in its Subprocessor Policy, and endeavors to update the list in a timely manner following the engagement of a new Subprocessor.
7) Governance
- Governance controls maintained under SOC 2 Type II attestation and ISO/IEC 27001:2022 certification, addressing HIPAA, GDPR, and CPRA requirements.
- Periodic risk and control reviews; reasonable updates may be made over time without materially decreasing overall security.
Annex III - List of Data Subprocessors
Iqidis's current Subprocessors are listed in the Service Providers & Subprocessors Policy (as updated from time to time). Typical categories include cloud infrastructure/hosting and LLM inference vendors used only for discrete, stateless inference with no retention and no training on Customer data.
Annex IV - SCC / UK / Swiss / Australia Details
1. EU Standard Contractual Clauses (SCCs). The Parties agree that, where Customer Personal Data is transferred from the EEA to a third country that is not subject to an adequacy decision by the European Commission, the following will apply:
- The EU Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (“SCCs”) are incorporated by reference.
- Module 2 (Controller → Processor) applies where Customer is the Controller and Iqidis is the Processor.
- Module 3 (Processor → Processor) applies where Customer is itself acting as a Processor and Iqidis is engaged as a Sub-processor.
- Clause 7 (Docking Clause): not applicable.
- Clause 9(a) (Sub-processor changes): general written authorization; notice period: 30 days.
- Clause 9(c) (Sub-processor agreements): where confidentiality restrictions prevent providing a copy of the Sub-processor agreement, Iqidis will provide, on a confidential basis, all information it reasonably can.
- Clause 11(a) (Redress Mechanism): not applicable.
- Clause 13 (Supervisory Authority): the competent supervisory authority will be determined in accordance with Annex I.C of the SCCs.
- Clause 17 (Governing Law): the law of Ireland governs the SCCs.
- Clause 18 (Dispute Resolution): any dispute arising under the SCCs shall be resolved by binding arbitration conducted under the rules of the International Chamber of Commerce (ICC). The arbitration shall be conducted remotely by videoconference unless both parties agree otherwise; the tribunal shall consist of a single arbitrator experienced in data protection law; the language of arbitration shall be English; the seat of arbitration shall be Dublin, Ireland for purposes of the SCCs, but hearings will be remote; judgment on the award may be entered in any court of competent jurisdiction.
- Annex I.A (Parties), Annex I.B (Transfers), Annex I.C (Authority), Annex II (TOMs), and Annex III (Sub-processors): are completed by Annexes I, II, and III of this DPA.
2. UK Addendum. Where Customer Personal Data is transferred from the UK to a third country not deemed adequate under UK GDPR:
- The International Data Transfer Addendum to the EU Commission SCCs, issued by the UK Information Commissioner's Office (ICO) (version in force as of the effective date of this DPA) (“UK Addendum”), is incorporated by reference.
- The SCCs apply as set out above, but as modified by the UK Addendum.
- Tables 1-3 of the UK Addendum are completed with the information contained in Annexes I, II, and III of this DPA.
- Disputes under the SCCs as modified by the UK Addendum will be resolved as above, with the seat deemed London, UK, but hearings remote.
- Table 4 of the UK Addendum is deemed completed by selecting “Importer may make reasonable changes to format that do not alter the Approved Addendum terms.”
- In the event of conflict between the SCCs and the UK Addendum, the UK Addendum will control for transfers of UK Personal Data.
3. Swiss Addendum (nFADP). Where Customer Personal Data is transferred from Switzerland to a third country not deemed adequate under the revised Swiss Federal Act on Data Protection (nFADP), the SCCs as incorporated above will also apply with the following modifications:
- References to “GDPR” are interpreted to include the Swiss FADP.
- References to “supervisory authority” are interpreted to mean the Swiss Federal Data Protection and Information Commissioner (FDPIC).
- Clause 17 governing law: Switzerland.
- Clause 18 disputes: resolved by binding arbitration as above, with the seat deemed Zurich, Switzerland, but hearings remote.
4. Australia Addendum. For the purposes of this Addendum, “Personal Information” shall have the meaning assigned to it in the Australian Privacy Act 1988 (Cth). Any such Personal Information contained in Customer Content shall be deemed to be “Customer Personal Data” under the DPA. To the extent Customer transfers such Personal Information to Iqidis, Customer acknowledges and agrees that the security measures and processing obligations set forth in this DPA protect the information in a way that is substantially similar to the Australian Privacy Principles (except APP 1).
Terms of Service
Last Updated: September 1, 2026. Owner: Legal & Security, Iqidis, Inc. · Contact: info@iqidis.ai
PLEASE READ THESE TERMS OF SERVICE CAREFULLY. BY REGISTERING FOR, ACCESSING, OR USING THE SERVICES, YOU AGREE TO BE BOUND BY THESE TERMS. IF YOU DO NOT AGREE TO ALL OF THESE TERMS, DO NOT ACCESS OR USE THE SERVICES.
Irys is an assistive legal AI platform, not a substitute for professional legal judgment. AI-generated Output may contain errors or inaccuracies and must be independently reviewed and verified before professional reliance.
This Terms of Service agreement (this “Agreement”) constitutes a legally binding agreement between you, whether personally or on behalf of an entity (“you” or “Customer”), and IQIDIS, INC. (“Iqidis,” “Company,” “we,” “us,” or “our”), concerning your access to and use of the Irys legal AI services, including the websites currently available at https://iqidis.ai and https://irys.ai, and any related applications or services (collectively, the “Services”). “Irys” is a product name and brand of Iqidis, Inc., and not a separate legal entity.
By registering for, accessing, or using the Services, you acknowledge that you have read, understood, and agree to be bound by this Agreement and the documents and policies incorporated by reference, including our Data Processing Addendum, Privacy Policy, Acceptable Use Policy, applicable product-specific addenda, Subprocessor Policy, Cookie Policy, and Disclaimer. If you create, access, or use the Services on behalf of an Organization, you represent and warrant that you have authority to bind that Organization to this Agreement. In that case, the Organization is the Customer for purposes of this Agreement.
1. Definitions
1.1 Acceptable Use Policy or AUP. Means the Iqidis Acceptable Use Policy, available on our website, within the Irys platform, or by request, as may be updated from time to time.
1.2 Account. Means the account created by or for a User to access and use the Services.
1.3 Authorized User. Means an individual user who has been invited to, accepted access to, or otherwise uses the Services under an Organization Account.
1.4 Confidential Information. Means information disclosed by one party (“Discloser”) to the other (“Recipient”) that is designated confidential or that reasonably should be understood to be confidential given the nature of the information and circumstances of disclosure. Iqidis Confidential Information includes, without limitation, non-public aspects of the Services, technology, pricing, security information, and Non-Public Materials. Customer Confidential Information includes Customer Content that is not publicly available. Confidential Information does not include information that: (i) becomes publicly available through no fault of the Recipient; (ii) was lawfully known to the Recipient without restriction before disclosure; (iii) is lawfully received from a third party without breach of an obligation; or (iv) is independently developed without use of or reference to the Discloser’s Confidential Information.
1.5 Content. Means Input and Output collectively.
1.5.1 Customer Content. Means all Content submitted to or generated through the Services by or for a Customer or its Authorized Users. Customer Content excludes Feedback, Usage Data, telemetry, and Account registration information.
1.5.2 Personal Content. Means Customer Content created by an Authorized User within that Authorized User’s personal workspace and not explicitly shared with other users.
1.5.3 Shared Content. Means Customer Content that an Authorized User affirmatively shares with one or more other Authorized Users or with an Organization pursuant to the sharing features of the Services.
1.6 Cookie Policy. Means the Iqidis Cookie Policy, available on our website, within the Irys platform, or by request, as may be updated from time to time.
1.7 Customer. Means (a) an individual person, where the Services are purchased or used under an individual subscription, or (b) an entity, such as a law firm, company, or other organization, where the Services are purchased or used under an organization or enterprise subscription.
1.8 Data Processing Addendum or DPA. Means the Iqidis data processing addendum, available on our website or by request, that governs Processing of Customer Personal Data on Customer’s behalf and sets forth applicable obligations concerning data protection, security, subprocessors, and international data transfers.
1.9 Data Retention Policy. Means the Iqidis policy, available by request, describing available data retention features, settings, and default periods applicable to Customer Content.
1.10 Disclaimer. Means the Iqidis Disclaimer, available on our website, within the Irys platform, or by request, as may be updated from time to time.
1.11 Feedback. Means suggestions, ideas, enhancement requests, recommendations, or other information provided to Iqidis relating to the Services, including during a Free Trial or use of Beta Services.
1.12 Input. Means text, queries, prompts, documents, data, matters, voice or audio recordings, or other information provided or uploaded by a User to the Services for processing.
1.13 Intellectual Property Rights. Means patents, copyrights, trademarks, service marks, trade names, design rights, database rights, rights in software, trade secrets, know-how, and all other intellectual property or proprietary rights recognized in any jurisdiction.
1.14 Irys. Means the artificial-intelligence-powered legal software platform branded as “Irys,” which is owned, operated, and provided by Iqidis, Inc. References to the Irys platform or Irys Services refer to the Services.
1.15 Non-Public Materials. Means any part of the Services or related information that requires authentication or is otherwise not intentionally made public by Iqidis, including the user interface, screens, workflows, dashboards, administrative consoles, in-product messages, non-public performance results, pre-release or beta features, and documentation or APIs marked confidential. Access through a trial or demo does not make Non-Public Materials public.
1.16 Organization or Organization Account. Means a Customer account established by or on behalf of an entity, under which one or more users may be provisioned access to the Services through seats, roles, or workspaces and for which billing is managed at the organization level.
1.17 Output. Means data, text, responses, summaries, analyses, drafts, citations, or other information generated and returned by the Services based on User Input.
1.18 Public-Facing Materials. Means content Iqidis intentionally makes available without authentication, such as marketing webpages, public documentation, and blog posts.
1.19 Privacy Policy. Means the Iqidis Privacy & Data Policy, available on our website, within the Irys platform, or by request, as may be updated from time to time.
1.20 Retention Period. Means the period following the Expiration Date of a subscription cancelled by the Customer through an available self-service cancellation feature, as designated in or selected by the Customer through the cancellation flow, or, if no period is designated, a default period of ninety (90) days, during which the Agreement remains in effect but access to the Services is restricted to Customer Content export or account reactivation.
1.21 Subscription Term. Means the period during which Customer has subscribed to access and use the Services, as specified in the applicable order or registration process.
1.22 Subprocessor Policy. Means the Iqidis Subprocessor Policy, available on our website, within the Irys platform, or by request, as may be updated from time to time.
1.23 User. Means an individual human who accesses or uses the Services, whether on that individual’s own behalf or as an Authorized User of a Customer Organization.
1.24 User Content. Means that portion of Customer Content provided, submitted, or generated directly by an individual User.
1.25 Workspace. Means a logical environment within the Services in which content is created, stored, and managed.
2. The Services
2.1 Purpose. The Services provide an AI-powered platform designed to assist legal professionals with tasks such as research, drafting, analysis, document review, summarization, and related workflows. The Services are intended as assistive tools and are not a substitute for professional legal judgment, advice, supervision, or independent verification.
2.2 AI Limitations. Customer acknowledges that the Services use artificial intelligence and machine learning technologies that are probabilistic and may produce Output that is inaccurate, incomplete, outdated, or otherwise erroneous. Errors may involve legal authorities, quotations, factual assertions, dates, amounts, legal analysis, or source materials. Iqidis does not warrant the accuracy, reliability, completeness, or suitability of Output. Customer and each User are responsible for reviewing and verifying material Output before relying on or using it.
2.3 Professional Review Before External Use. Output should not be treated as professionally approved, filing-ready, client-ready, or otherwise verified merely because it is presented in completed legal format, contains citations or source links, or has been processed by a verification feature. Before Output is filed, submitted, distributed, executed, or otherwise relied upon in a professional context, the responsible legal professional must perform the review appropriate to the task and applicable professional obligations.
2.4 Verification Features. The Services may include features that assist users in checking citations, authorities, source links, or related information. These features are intended to reduce risk and support professional review; they are not warranties or certifications. Unless expressly stated otherwise for a specific feature, a successful match, pass, source link, or treatment indicator does not by itself establish that an authority supports a particular proposition, that a quotation is exact and complete, that all subsequent treatment has been identified, or that the resulting work product is appropriate for a particular filing, jurisdiction, client, or matter. Users should review the underlying sources before professional reliance.
2.5 Architecture; Local-First Processing; Scoped Subprocessor Inference. By default, requests are processed within Iqidis-controlled infrastructure using Iqidis proprietary systems and orchestration layers. User Content is logically segregated per tenant and per user profile and is not pooled or commingled with the content of other Customers. For certain aspects of a request, the Services may invoke a subprocessor, such as OpenAI, Anthropic, or Google, for inference. Vendor-side caching or retention is disabled where supported and contractually applicable, payloads are minimized where practicable, and contractual no-training restrictions apply. Additional detail appears in the Privacy Policy and Subprocessor Policy.
2.6 Authorized Users. Authorized Users may access and use the Services solely for the benefit of the applicable Customer and subject to this Agreement. Customer is responsible for managing Authorized User access and for ensuring that Authorized Users are notified of applicable terms, policies, training, and organization-level requirements. Notwithstanding the Customer’s primary liability, each Authorized User remains individually bound by this Agreement upon accessing the Services. Customer assumes primary and direct responsibility for acts and omissions of its Authorized Users as if performed by Customer itself.
2.7 Free Trial. If Customer registers for a free trial, Iqidis will make the Services available on a trial basis until the earlier of the end of the trial period or the start date of a paid subscription. Customer Content provided during a free trial may be permanently deleted after the trial unless Customer purchases a subscription or otherwise agrees with Iqidis in writing.
2.8 Beta Services. From time to time, Iqidis may invite Users to test pre-release, experimental, or beta features or models (“Beta Services”). Beta Services are provided for evaluation and testing and may be modified, suspended, or discontinued without notice. AI models powering Beta Services may be actively calibrated and may produce less predictable Output.
NOTWITHSTANDING ANYTHING TO THE CONTRARY IN THIS AGREEMENT, DURING A FREE TRIAL OR USE OF BETA SERVICES, THE SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE,” WITHOUT ANY WARRANTY, SERVICE LEVEL, SUPPORT, OR INDEMNITY OBLIGATION OF ANY KIND FROM IQIDIS, EXCEPT THAT IQIDIS’S COMMITMENT NOT TO USE CUSTOMER CONTENT FOR AI MODEL TRAINING, AS SET FORTH IN SECTION 5.5, REMAINS IN EFFECT.
3. Accounts and Registration
3.1 Registration. Users may be required to register for an Account. User agrees to provide accurate, current, and complete information during registration and to keep that information current.
Accounts created using false or misleading information, disposable emails, impersonated credentials, or other deceptive means are subject to immediate suspension or termination.
3.2 Account Security. User is responsible for safeguarding Account credentials and for activities occurring under the Account. User agrees to notify Iqidis promptly of unauthorized access or use.
3.3 Eligibility. The Services are intended for Users who are at least 18 years old and possess legal capacity to enter into this Agreement.
3.4 Roles. Organization Accounts may include multiple role types, such as Owner, Administrator, and Member. Role-based permissions determine administrative capabilities, including User management, billing, and settings.
3.5 Administrative Controls. Organization Owners and Administrators may invite or remove Authorized Users, assign or modify user roles, manage subscription and billing settings, configure organization-level preferences, and exercise visibility and control over Shared Workspaces as made available by the Services.
Organization Administrators do not automatically have access to the contents of another Authorized User’s personal workspace unless content has been explicitly shared or access is required for support, security, legal compliance, preservation, or transfer of content from a deactivated account as permitted by this Agreement.
3.6 Safeguards and Account Practices. Users may not knowingly bypass, disable, remove, or circumvent in-product warnings, verification steps, administrative restrictions, or organization-mandated controls. Where individual Accounts are provided, credentials should not be shared among multiple individuals unless Iqidis expressly permits a shared-access configuration.
4. License Grant and Restrictions
4.1 License. Subject to all terms and conditions of this Agreement, payment of applicable fees, and compliance by Customer and its Authorized Users, Iqidis grants Customer and its Authorized Users a limited, non-exclusive, non-transferable, non-sublicensable, revocable license during the Subscription Term to access and use the Services, including the right to use, modify, reproduce, and distribute Output for Customer’s internal business purposes or for providing legal services to Customer’s clients, provided such use complies with this Agreement and applicable professional and ethical obligations.
During any applicable Retention Period, Iqidis grants Customer a limited license to access the Services solely for exporting Customer Content or reactivating a subscription.
4.2 General Use Restrictions. Customer and Users shall not, and shall not permit others to:
- Use the Services in violation of the Acceptable Use Policy or applicable law;
- License, sublicense, sell, resell, rent, lease, transfer, assign, time-share, or otherwise commercially exploit the Services except as expressly permitted for Customer’s legal services;
- Modify, copy, or create derivative works based on the Services except as expressly permitted with respect to Output;
- Use the Services to store or transmit unlawful, infringing, libelous, or tortious material or material that violates third-party privacy or intellectual property rights;
- Transmit viruses, worms, malicious code, or other harmful material;
- Interfere with or disrupt the integrity or performance of the Services;
- Attempt to gain unauthorized access to the Services or related systems or networks;
- Remove or obscure proprietary notices or labels;
- Knowingly make materially false statements of fact concerning Iqidis, Irys, or the technical operation, security, or capabilities of the Services;
- Capture, copy, distribute, or publicly disclose screenshots, screen recordings, or other visual depictions of Non-Public Materials without Iqidis’s prior written consent, except as necessary for Customer’s internal business purposes, client deliverables, or disclosures required by law or professional obligation; or
- Treat trial or demo access as permission to publish or disclose Non-Public Materials.
Nothing in this Section prohibits a truthful review, opinion, or legally required disclosure concerning the Services.
4.3 Prohibitions on Reverse Engineering and Unfair Competition. User acknowledges that the Services, including their underlying technology, algorithms, architecture, and design, constitute valuable trade secrets and proprietary intellectual property of Iqidis. Accordingly, User shall not, and shall not permit or authorize any third party to:
- (a) reverse engineer, decompile, disassemble, translate, or otherwise attempt to discover, derive, or reconstruct source code, object code, underlying structure, proprietary prompts, datasets, trade secrets, know-how, algorithms, or architecture of the Services except to the extent such restriction is prohibited by law;
- (b) access, use, monitor, copy, or benchmark the Services or Output for the purpose of developing, building, training, improving, or offering a product or service competitive with the Services, including by extracting data or Output for competitive analysis or model training, replicating core functionality or workflows, or publicly disseminating non-public performance information or benchmarks without prior written consent; or
- (c) use false or deceptive means to access the Services for unauthorized testing, benchmarking, probing, analyzing, or evaluating the Services.
4.4 Monitoring and Access Control. To protect the integrity of the Services and enforce this Agreement, Iqidis may monitor and analyze usage patterns, registration behavior, IP address logs, device information, and other technical metadata for fraud detection, abuse prevention, compliance verification, security auditing, and enforcement of this Agreement. Iqidis may restrict, suspend, or terminate access in accordance with this Agreement if a violation or abuse is reasonably suspected.
5. Content and Data
5.1 Content Ownership. Subject to the terms of this Agreement, as between Customer and Iqidis, Customer retains all right, title, and interest in and to Customer Content, including applicable Intellectual Property Rights. Customer grants Iqidis and its necessary service providers a worldwide, non-exclusive, royalty-free license to host, store, transfer, process, analyze, modify, and use Customer Content solely to the extent necessary to provide, maintain, secure, support, and operate the Services in accordance with this Agreement.
5.2 Responsibility for Content. Customer is responsible for the accuracy, quality, integrity, legality, reliability, and appropriateness of Input. Customer represents and warrants that it has necessary rights, consents, and permissions to provide Input to Iqidis and that Input and its use within the Services will not violate applicable law or third-party rights.
5.3 Data Processing and Privacy. For information on Iqidis data practices, please see the Privacy Policy and Data Processing Addendum.
5.4 Data Retention and Deletion. During an active Subscription Term, Iqidis retains Customer Content as necessary to provide the Services and in accordance with Customer settings and applicable policies. Customer is responsible for managing its Content to meet its own business, professional, ethical, or regulatory record-keeping obligations.
Notwithstanding ordinary retention settings, Iqidis may preserve relevant information where required by applicable law, valid legal process, litigation hold, security obligations, or another binding legal requirement, in each case consistent with the DPA and Privacy Policy.
5.5 AI Processing and Data Retention. Iqidis utilizes AI technologies that process Customer Content in real time. Iqidis does not use Customer Content to train its own or third-party foundation models unless expressly agreed otherwise in writing. Third-party model calls are configured with vendor caching or retention disabled where supported and applicable and are used for stateless inference.
Iqidis may access Customer Content only for limited purposes permitted by this Agreement, including providing customer support, troubleshooting technical issues, ensuring service operation, investigating a reported product or security incident, complying with applicable law or valid legal process, and enforcing this Agreement, subject to the Privacy Policy, DPA, and applicable safeguards.
5.6 Usage Data and Telemetry. Iqidis may collect, analyze, and use aggregated or anonymized data derived from use of the Services (“Usage Data”) and limited operational telemetry, such as UI events, navigation flows, request timing, status or error codes, and coarse device or browser metadata, for performance monitoring, service improvement, security, and abuse detection. Usage Data and telemetry will not identify User or contain Customer Confidential Information and do not include prompts, model outputs, or uploaded documents or files unless expressly described in an applicable policy or agreement.
5.7 Roles; Ownership; Data Location and Segregation. As between Customer and Iqidis, Customer is the controller or owner of Customer Content. Where Customer is an Organization, Authorized Users act on behalf of Customer in their use of the Services. Iqidis acts as Customer’s processor or service provider as applicable. Customer Content is stored and processed within Customer’s Iqidis tenant and user-profile containers and is not pooled or commingled with content of other Customers. Regional routing may be available and automatically applied.
5.8 Organization Shared Content; Offboarding. By sharing Shared Content within an Organization Account, each Authorized User grants the Organization a non-exclusive, worldwide, royalty-free license to access, use, reproduce, modify, export, and retain such Shared Content and resulting Output for the Organization’s internal business or legal-services purposes. Upon removal of an Authorized User from an Organization Account, the Organization may retain access to Customer Content created by that Authorized User in the context of the Organization, subject to applicable law and Customer policies.
Customer is responsible for promptly removing Authorized Users when authorization ends. Upon removal, the User’s access is revoked, applicable Customer Content may be preserved for the Organization, and Organization Administrators may request transfer of archived content to another active Authorized User as supported by Iqidis.
6. Intellectual Property
6.1 Iqidis IP. Iqidis and its licensors own and retain all right, title, and interest, including Intellectual Property Rights, in and to the Services, underlying technology, Usage Data, Iqidis Confidential Information, and modifications or enhancements thereto. No rights are granted other than those expressly set forth in this Agreement.
6.2 Output. Subject to Section 6.1, Section 5.1, and Customer’s compliance with this Agreement, as between the parties and to the extent permitted by law, Customer owns Output generated through the Services by Customer or its Authorized Users. Due to the nature of AI, Output may not be unique and other users may receive similar or identical Output. Rights in Output do not extend to Iqidis technology or third-party data incorporated into Output.
6.3 Feedback. User and Customer grant Iqidis a worldwide, perpetual, irrevocable, transferable, sublicensable, royalty-free license to use, reproduce, modify, create derivative works from, incorporate, and otherwise exploit Feedback for service improvement, development, and promotional purposes, subject to applicable confidentiality obligations.
7. Fees and Payment
7.1 Fees. Customer shall pay all fees specified in the applicable order form or registration process (“Fees”). Fees are based on the subscription plan purchased and not actual usage. Payment obligations are non-cancelable and Fees paid are non-refundable except as expressly provided in this Agreement or an applicable order form.
7.2 Payment Terms. Fees will be invoiced or charged in advance on a monthly, annual, or other agreed billing cycle. Unless otherwise expressly stated in an applicable Order Form, all invoiced amounts are due immediately upon receipt of the invoice.
Customer agrees to provide and maintain valid and current payment information. If paying by credit card or other automatic payment method, Customer authorizes Iqidis and its payment processor to charge all Fees when due.
If any amount is not paid when due, including because a payment method is declined or fails, Iqidis may, in its sole discretion and without prior notice or opportunity to cure, immediately suspend, restrict, or terminate Customer’s access to any or all Services, Accounts, Organization Accounts, and Authorized User accounts until all outstanding amounts are paid in full. Iqidis may also terminate this Agreement immediately for non-payment.
Suspension, restriction, or termination for non-payment does not relieve Customer of any payment obligations, and all outstanding Fees remain immediately due and payable. Iqidis’s exercise of these rights is without prejudice to any other rights or remedies available under this Agreement or applicable law.
7.3 Taxes. Fees are exclusive of applicable taxes, levies, duties, or similar governmental assessments. Customer is responsible for taxes associated with its purchases, excluding taxes based on Iqidis net income.
7.4 Fee Changes. Iqidis may change Fees or institute new charges upon at least thirty (30) days’ notice. Fee changes take effect at the start of the next Subscription Term unless otherwise agreed.
7.5 Mid-Term Subscriptions. Customer may add Authorized User subscriptions during a Subscription Term by Order Form, amendment, or supported self-service functionality. Fees, billing cycle, and term for additional subscriptions will be as specified in the applicable transaction.
8. Confidentiality
8.1 Obligations. The Recipient will use the Discloser’s Confidential Information only for purposes of this Agreement, protect it using at least reasonable care, and disclose it only to personnel, contractors, and agents with a need to know who are bound by appropriate confidentiality obligations.
8.2 Compelled Disclosure. If the Recipient is required by law or valid governmental order to disclose Confidential Information, it will, where legally permitted, provide prompt notice and reasonable assistance in seeking confidential treatment or a protective order. Disclosure will be limited to what is required.
8.3 Non-Public UI and Screens. Non-Public Materials are Iqidis Confidential Information. Trial or demo access does not waive confidentiality. Users may not publicly distribute screenshots or recordings of Non-Public Materials except as permitted by this Agreement or required by law or professional obligation.
9. Disclaimers
9.1 General. THE SERVICES, SITE, AND RELATED CONTENT ARE PROVIDED “AS IS” AND “AS AVAILABLE,” WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS OR IMPLIED, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT.
9.2 AI Output. Iqidis does not warrant that Output will be accurate, complete, reliable, current, or suitable for any particular purpose. Output may contain errors, omissions, or biases and may not be unique. Material Output must be independently reviewed and verified with professional judgment before reliance.
9.3 Verification Features. Verification features are provided to support review and reduce risk. They do not guarantee that every issue will be detected or that a matched authority supports a particular proposition, quotation, filing, or legal conclusion.
9.4 No Legal Advice. The Services and Output do not constitute legal advice or the practice of law. Use of the Services does not create an attorney-client relationship. Irys is an assistive tool for legal professionals and is not a substitute for licensed legal counsel.
9.5 Availability. Iqidis does not warrant that the Services will be uninterrupted, timely, secure, or error-free. Remedies for availability shortfalls are limited to those expressly provided in an applicable service-level agreement.
9.6 Reference. Additional disclaimers are described in the Iqidis Disclaimer, which is incorporated by reference into this Agreement.
10. Limitation of Liability
10.1 Exclusion of Indirect Damages. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL EITHER PARTY BE LIABLE FOR ANY INDIRECT, PUNITIVE, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR EXEMPLARY DAMAGES, INCLUDING LOSS OF PROFITS, GOODWILL, USE, DATA, OR OTHER INTANGIBLE LOSSES, ARISING OUT OF OR RELATING TO THIS AGREEMENT OR THE USE OF, OR INABILITY TO USE, THE SERVICES, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
10.2 Cap on Direct Damages. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT SHALL NOT EXCEED THE TOTAL AMOUNT PAID OR PAYABLE BY CUSTOMER TO IQIDIS FOR THE SERVICES DURING THE TWELVE (12) MONTH PERIOD IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM, OR ONE HUNDRED U.S. DOLLARS ($100.00), WHICHEVER IS GREATER.
10.3 Exceptions. The limitations in Sections 10.1 and 10.2 shall not apply to: (i) indemnification obligations under Section 11.2; (ii) a party’s breach of confidentiality obligations under Section 8, except that liability arising from a Data Security Incident is subject to any limitation stated in the DPA; (iii) User’s breach of Section 4.2 or 4.3; or (iv) a party’s gross negligence or willful misconduct.
10.4 Basis of Bargain. The parties acknowledge that the disclaimers and limitations of liability in this Agreement reflect a reasonable allocation of risk and form an essential basis of the bargain between the parties, and that Iqidis pricing reflects this allocation.
11. Indemnification
11.1 Indemnification by Iqidis. Iqidis will defend or settle any unaffiliated third-party claim alleging that the Services, including Output generated by the Services when used as delivered and in accordance with this Agreement, directly infringe or misappropriate such third party’s U.S. patents, copyrights, or trademarks (“Infringement Claim”), and will indemnify Customer against damages and reasonable costs finally awarded or agreed in settlement. Iqidis has no obligation to the extent an Infringement Claim arises from Customer Content, modification or republication of Output, non-Iqidis applications or services, combinations not supplied by Iqidis, or use in violation of this Agreement. If the Services are or are likely to become subject to an Infringement Claim, Iqidis may secure continued use rights, replace or modify the affected Services, or terminate the affected Services and refund prepaid unused Fees for the remainder of the Subscription Term. This Section states Iqidis entire liability and Customer’s exclusive remedy for third-party IP claims concerning the Services.
11.2 Indemnification by Customer. Customer shall defend, indemnify, and hold harmless Iqidis and its affiliates, directors, officers, employees, and agents from and against any unaffiliated third-party claim arising from or related to: (a) Customer Content, including allegations that Customer Content violates third-party rights or law; (b) Output that Customer or an Authorized User modifies, republishes, distributes, or uses beyond the form delivered by the Services; (c) Customer’s or an Authorized User’s use of the Services in violation of this Agreement, the AUP, or applicable law; or (d) Customer’s or an Authorized User’s violation of professional or ethical obligations in connection with use of the Services. Customer will indemnify Iqidis for damages, attorney fees, and costs finally awarded against Iqidis or paid by Iqidis under a court-approved settlement, provided that Iqidis promptly notifies Customer, grants Customer control of the defense and settlement subject to an unconditional release of Iqidis, and provides reasonable cooperation at Customer’s expense.
12. Term and Termination
12.1 Term. This Agreement commences on the date it is first accepted by or on behalf of Customer and continues until all Subscription Terms and any applicable Retention Periods have expired, unless terminated earlier under this Section.
12.2 Subscription Renewal. Unless otherwise specified in an applicable order form, subscriptions automatically renew for additional periods equal to the expiring Subscription Term or one year, whichever is shorter, unless either party provides written notice of non-renewal at least thirty (30) days before the end of the relevant Subscription Term.
12.3 Termination for Cause. Either party may terminate this Agreement for cause upon thirty (30) days’ written notice of a material breach if the breach remains uncured at the end of that period, or immediately upon specified insolvency events. Iqidis may also terminate immediately upon notice for material violations of the AUP, Section 4.2, or Section 4.3.
12.4 Termination by Customer. If Customer is subscribed month-to-month without a separate subscription agreement or order form, Customer may cancel by contacting Iqidis support or through supported account functionality, effective at the end of the current billing cycle. Contracted subscriptions with a defined term are governed by the applicable agreement or Order Form and, unless expressly stated otherwise, are non-cancellable during the term and Fees are non-refundable.
12.5 Effect of Termination. Upon termination or expiration: (a) rights and licenses granted to Customer and its Authorized Users terminate; (b) use of the Services must cease; (c) unpaid Fees become due; and (d) each party will handle the other party’s Confidential Information as required by this Agreement. Sections that by their nature should survive, including provisions concerning intellectual property, confidentiality, disclaimers, liability, indemnification, dispute resolution, and professional responsibility, will survive.
12.6 Post-Termination Data Deletion. Following termination and any applicable Retention Period, Iqidis will delete Customer Content from active production systems within thirty (30) days unless a different period is required by law or agreed in writing. Iqidis is not a system of record. Customer remains responsible for exporting client files and satisfying its legal, ethical, professional, and regulatory record-keeping obligations. Residual copies may persist in secure backup archives for a limited period before being overwritten in the ordinary course.
13. Governing Law and Dispute Resolution
13.1 Governing Law. This Agreement, including incorporated policies, and disputes arising out of or related to the Services are governed by the laws of the State of New York without regard to conflicts-of-law principles, except where a DPA specifies another law for international data transfer mechanisms.
13.2 Informal Resolution. The parties will first attempt to resolve disputes informally for at least sixty (60) days after written notice of the dispute.
13.3 Binding Arbitration. If a dispute is not resolved informally, it shall be resolved by binding arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules then in effect, in New York County, New York, before a single arbitrator, except for disputes expressly excluded below. The arbitrator’s decision is final and binding and may be entered in any court of competent jurisdiction.
13.4 Exceptions to Arbitration. Disputes concerning enforcement or validity of intellectual property rights, or claims for injunctive or equitable relief, are not subject to arbitration and may be brought in state or federal courts located in New York County, New York. The parties consent to jurisdiction and venue in those courts for such purposes.
13.5 Class Action Waiver. TO THE MAXIMUM EXTENT PERMITTED BY LAW, ARBITRATION OR COURT PROCEEDINGS SHALL BE CONDUCTED SOLELY ON AN INDIVIDUAL BASIS AND NOT AS A CLASS, CONSOLIDATED, OR REPRESENTATIVE ACTION.
13.6 Jury Trial Waiver. EACH PARTY WAIVES ITS RIGHT TO A JURY TRIAL IN CONNECTION WITH A DISPUTE ARISING OUT OF OR RELATING TO THIS AGREEMENT TO THE MAXIMUM EXTENT PERMITTED BY LAW.
14. Professional Responsibility and Ethics
14.1 User Responsibility. User acknowledges that it is a legal professional or entity employing legal professionals and remains responsible for professional conduct and compliance with applicable laws, rules, regulations, ethical obligations, court requirements, client obligations, and professional standards governing legal practice.
14.2 Independent Judgment. The Services are assistive tools. Users must exercise independent professional judgment in using the Services and evaluating Output. Users remain responsible for advice given, work product created, filings made, and decisions taken in the course of professional practice.
14.3 Verification. Users are responsible for reviewing and verifying the accuracy, completeness, and appropriateness of material Output before relying on it or incorporating it into work product or advice. Where relevant, review should include the underlying authorities and record materials, citation accuracy, quotations, factual assertions, dates, amounts, jurisdiction, procedural posture, and subsequent treatment.
14.4 Court, Client, and Other External Use. Before submitting or providing Output to a court, tribunal, regulator, client, counterparty, or other third party in a professional context, the responsible legal professional must perform the review required by applicable law, professional obligations, court rules, client requirements, and the circumstances of the matter. The presence of citations, source links, formatting, proposed orders, signature blocks, or verification indicators does not constitute Iqidis approval of the work product.
14.5 Confidentiality and Privilege. Iqidis is designed with enterprise-oriented security and data privacy controls. Users remain responsible for ensuring their use of the Services complies with applicable confidentiality and attorney-client privilege obligations. If Iqidis becomes aware of a data security incident affecting Customer Content, Iqidis will notify Customer and cooperate as described in the Privacy Policy, DPA, and applicable agreement.
14.6 Firm Governance and Supervision. Organization Customers are responsible for implementing reasonable policies, training, supervision, and internal controls appropriate to their use of AI-enabled legal tools and applicable professional obligations. Customer is responsible for communicating organization-level requirements to Authorized Users and for configuring available controls as appropriate.
14.7 Material Incidents. If Customer becomes aware of a material incident involving the Services that has resulted in or could reasonably result in a court or regulatory filing issue, sanctions or professional-responsibility inquiry, client claim, material security or privacy concern, or media inquiry concerning the technical operation of the Services, Customer will promptly notify Iqidis at info@iqidis.ai where legally permitted. The parties will reasonably cooperate to establish relevant technical facts and preserve information as appropriate. Nothing in this Section requires either party to waive attorney-client privilege, work-product protection, client confidentiality, or another legal protection.
14.8 External Technical Statements and Required Disclosures. Where legally permitted and reasonably practicable, before making a public factual statement that attributes a material incident to Irys or describes the technical operation of the Services in connection with such an incident, Customer will provide Iqidis a reasonable opportunity to confirm the technical accuracy of that description.
Nothing in this Agreement restricts truthful reviews or opinions or limits any disclosure required by law, court order, subpoena, regulator, professional-responsibility rule, client obligation, insurer, or other legally binding duty. Customer remains solely responsible for determining and satisfying its own legal and professional disclosure obligations.
14.9 Compliance. User agrees to use the Services in a manner consistent with applicable professional standards, ethical guidelines, law, and this Agreement.
15. Export Compliance
User agrees to comply with applicable U.S. and foreign export-control and trade-sanctions laws and regulations and shall not use, export, re-export, transfer, or access the Services in violation of those laws.
16. Miscellaneous
16.1 Entire Agreement. This Agreement, together with the Privacy Policy, AUP, Cookie Policy, Disclaimer, DPA, applicable product-specific addenda, and applicable order forms, constitutes the entire agreement concerning the Services and supersedes prior agreements or understandings concerning the same subject matter. In the event of a conflict, the order of precedence is: (i) an applicable order form, but only to the extent it expressly modifies a specific provision; (ii) an applicable product-specific addendum for its subject matter; (iii) this Agreement; and (iv) other incorporated policies.
16.2 Modifications. Iqidis may modify this Agreement from time to time by posting a revised version on its website or notifying User by email or through the Services. Material changes will be communicated with reasonable advance notice. Continued use after the effective date of a valid modification constitutes acceptance to the extent permitted by law. Iqidis may request affirmative acceptance of updated terms through the Services.
16.3 Assignment. Neither party may assign this Agreement without the other party’s prior written consent, not to be unreasonably withheld, except that Iqidis may assign this Agreement in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all relevant assets.
16.4 Relationship of the Parties. The parties are independent contractors. This Agreement does not create a partnership, franchise, joint venture, agency, fiduciary, or employment relationship.
16.5 Marketing Identification and Feedback Use. Customer grants Iqidis a worldwide, royalty-free, non-exclusive license to use Customer’s name, trademarks, and logos to identify Customer as a customer of Iqidis on Iqidis websites and in marketing materials. Customer may revoke this permission prospectively by written notice to info@iqidis.ai, subject to a commercially reasonable removal period. Iqidis will generally seek prior approval before high-visibility uses such as press releases, published case studies, or media announcements. Feedback remains subject to Section 6.3.
16.6 Notices. Notices under this Agreement shall be in writing and may be delivered personally, by email, recognized overnight delivery service, or certified or registered mail. Notices to Iqidis shall be sent to IQIDIS, INC., Attn: Legal Department, 3 Columbus Circle, Floor 15, New York, NY 10019, with a copy to info@iqidis.ai. Notices to Customer may be sent to the account administrator, billing contact, legal contact, or email address associated with the Account. Notice to a Customer’s designated account administrator constitutes notice to Customer and its Authorized Users to the extent permitted by applicable law and agreement.
16.7 Waiver. No failure or delay in exercising a right under this Agreement constitutes a waiver of that right.
16.8 Severability. If a provision is held unenforceable, it will be modified and enforced to the maximum lawful extent, and the remaining provisions will remain in effect.
16.9 Force Majeure. Neither party is liable for delay or failure in performance, other than payment obligations, caused by events beyond its reasonable control.
16.10 Headings. Headings are for convenience only and do not affect interpretation.
17. Contact Us
IQIDIS, INC.
3 Columbus Circle, Floor 15
New York, NY 10019
Email: info@iqidis.ai
Acceptable Use Policy
Effective: August 28, 2026. Owner: Legal & Security, Iqidis, Inc. · Contact: info@iqidis.ai
1. Introduction
This Acceptable Use Policy (“AUP”) governs use of the Irys legal AI platform, our websites, and related applications and services (collectively, the “Services”) provided by Iqidis, Inc. (“Iqidis,” “we,” “us,” or “our”).
This AUP forms part of the Iqidis Terms of Service (“Terms”). Capitalized terms not defined here have the meanings given in the Terms.
Irys is designed to assist legal professionals with research, drafting, analysis, document review, and related workflows. Users must use the Services lawfully, securely, and consistently with applicable professional obligations.
AI-generated Output may contain errors or inaccuracies and requires appropriate professional review before reliance.
2. Prohibited Uses
You may not use, or permit another person to use, the Services in a manner that violates applicable law, the Terms, or this AUP.
2.1 Illegal or Unlawful Activity. You may not use the Services to:
- engage in or facilitate unlawful activity;
- knowingly violate applicable laws, regulations, court orders, or legal restrictions;
- infringe or misappropriate intellectual property, privacy, confidentiality, or other rights of Iqidis or third parties; or
- distribute or facilitate illegal goods or services.
2.2 Malicious, Fraudulent, or Abusive Conduct. You may not use the Services to:
- transmit malware, viruses, spyware, ransomware, or other malicious code;
- conduct phishing, spoofing, credential theft, fraud, or impersonation;
- gain or attempt unauthorized access to accounts, systems, networks, or data;
- interfere with, disrupt, overload, or degrade the Services;
- harass, threaten, exploit, or intentionally cause unlawful harm to another person; or
- intentionally generate or distribute unlawful content.
Nothing in this Section prohibits legitimate legal research, investigation, analysis, representation, compliance work, or review of sensitive or disturbing materials where conducted lawfully and for a bona fide professional purpose.
2.3 Misuse of the Services. You may not:
- reverse engineer, decompile, disassemble, or attempt to derive proprietary source code, system prompts, model configurations, algorithms, architecture, or other protected technical information, except to the extent a restriction is prohibited by applicable law;
- use the Services to develop, train, improve, or materially assist a competing product in violation of the Terms;
- conduct unauthorized benchmarking, vulnerability testing, load testing, scraping, probing, or competitive analysis;
- automate access except through officially supported APIs, integrations, or interfaces;
- circumvent or attempt to circumvent usage limits, access controls, security measures, safety controls, warnings, verification requirements, or other technical restrictions;
- share account credentials or use another person’s credentials without authorization;
- use fake, deceptive, impersonated, or disposable identities or credentials to obtain unauthorized access, conduct competitive testing, or evade restrictions; or
- falsely represent that Iqidis has reviewed, approved, certified, or endorsed legal work product where it has not done so.
2.4 Unauthorized Practice and Professional Misuse. Users may not use the Services in a manner that constitutes the unauthorized practice of law or violates applicable professional, ethical, court, regulatory, or client obligations.
Irys does not authorize any person to provide legal services they are not otherwise legally permitted to provide.
3. Responsible Professional Use
3.1 Professional Judgment. The Services are assistive tools.
Users remain responsible for their professional judgment, legal analysis, advice, work product, decisions, and compliance with applicable professional obligations.
3.2 Review and Verification. Users are responsible for appropriately reviewing and verifying material Output before relying on it.
Depending on the task, review may include confirming:
- legal authorities and citations;
- quotations;
- proposition support;
- subsequent treatment;
- factual assertions;
- dates, amounts, and calculations;
- jurisdiction and procedural posture;
- record references; and
- other material information.
A document should not be treated as professionally approved or filing-ready solely because it is formatted as a legal document, includes citations, contains source links, or has passed an automated verification feature.
3.3 Court, Regulatory, and Client-Facing Work. Before submitting or relying upon Output in a court filing, regulatory submission, client deliverable, legal opinion, sworn statement, or other consequential professional work product, users must conduct the review required by their applicable professional, legal, court, firm, and client obligations.
Users are responsible for determining whether AI use must be disclosed under applicable rules, orders, policies, or client requirements.
3.4 Safeguards and Organization Policies. Users must not knowingly bypass or disregard applicable Irys safeguards or organization-mandated controls.
Organizations are responsible for managing user access and for establishing any internal policies, training, supervision, and workflows required for their use of AI-enabled legal tools.
3.5 Confidentiality and Privilege. Users are responsible for ensuring they are authorized to provide information to the Services and for complying with applicable confidentiality, privilege, privacy, client, and professional-responsibility obligations.
Data handling is governed by the applicable Privacy & Data Policy, Terms of Service, and Data Processing Addendum where applicable.
4. Security Responsibilities
Users must take reasonable steps to protect their Accounts and access to the Services, including:
- safeguarding credentials;
- using available authentication controls appropriate to their organization;
- promptly removing access when authorization ends; and
- promptly notifying Iqidis of suspected unauthorized access, credential compromise, or other security concerns.
Security concerns may be reported to info@iqidis.ai.
5. Enforcement
Iqidis may investigate suspected violations of this AUP and take action reasonably appropriate to protect the Services, customers, users, third parties, and Iqidis.
Depending on the circumstances, actions may include:
- issuing a warning;
- limiting or suspending access;
- terminating an Account or affected Services in accordance with the Terms;
- disabling access to prohibited material;
- preserving information where legally required;
- cooperating with lawful governmental or regulatory requests; or
- pursuing available legal remedies.
Iqidis may take immediate action where reasonably necessary to address security threats, unlawful activity, fraud, abuse, or material risk to the Services or others.
6. Monitoring and Technical Information
Iqidis may collect and analyze technical and operational information reasonably necessary to operate, secure, protect, and enforce appropriate use of the Services.
Such processing is subject to the Iqidis Privacy & Data Policy.
Nothing in this AUP authorizes unrestricted monitoring of Customer Content.
7. Reporting Violations
Suspected violations of this AUP may be reported to:
info@iqidis.ai
Iqidis may investigate reported concerns and take appropriate action.
8. Changes to This AUP
Iqidis may update this AUP in accordance with the modification provisions of the Terms of Service.
Material changes will be communicated with reasonable advance notice where appropriate.
Continued use of the Services after the effective date of an updated AUP constitutes acceptance to the extent provided in the Terms.
9. Contact
Iqidis, Inc.
3 Columbus Circle, Floor 15
New York, NY 10019
Email: info@iqidis.ai
Cookies Policy
Effective: August 15, 2026. Owner: Legal & Security, Iqidis, Inc. · Contact: info@iqidis.ai
This Cookie Policy explains how Iqidis, Inc. (“Iqidis,” “we,” “us,” or “our”) uses cookies and similar technologies on our websites and online services.
It should be read together with our Privacy & Data Policy and Terms of Service.
1. Cookies and Similar Technologies
Cookies are small files stored on your device by websites and online services.
Similar technologies may include local storage, pixels, SDKs, and other technologies used to store or access information on a device.
Cookies may be placed by Iqidis or by third parties that provide services to us.
2. How We Use Cookies
We may use cookies and similar technologies for the following purposes:
Strictly Necessary
To operate and secure the Services, maintain sessions, authenticate users, route traffic, prevent fraud or abuse, and remember privacy choices.
These technologies are used where necessary for the Services to function and generally cannot be disabled through our cookie controls.
Functionality
To remember preferences and provide optional functionality.
Analytics and Measurement
To understand how our websites and Services are used, identify errors, measure performance, and improve usability.
Where applicable law requires consent for a cookie or similar technology, we will not activate that technology until the required consent has been obtained.
3. Advertising and Sale or Sharing of Personal Information
We do not currently use cookies for targeted advertising or to sell or share personal information for cross-context behavioral advertising.
If our practices change, we will update this Policy and provide any consent, notice, or opt-out mechanisms required by applicable law.
4. Cookie Choices
Where available, you may manage non-essential cookies through our Cookie Settings or cookie consent banner.
You may withdraw or modify your choices at any time through the available controls.
You can also control or delete cookies through your browser or device settings. Disabling certain technologies may affect some Services or functionality.
5. Global Privacy Control and Similar Signals
Where applicable law requires us to recognize a qualifying browser-based opt-out preference signal, such as Global Privacy Control (GPC), we will process that signal as required by applicable law.
We do not currently respond to legacy Do Not Track (DNT) browser signals.
6. Cookies Currently in Use
The cookies and similar technologies used by Iqidis may change as the Services evolve.
Where a Cookie Consent Manager is available, it provides the most current information about non-essential cookies, including their:
- category;
- purpose;
- provider; and
- applicable duration.
Strictly necessary technologies are limited to purposes reasonably necessary to operate, secure, authenticate, and maintain the Services and user preferences.
7. Retention
Session cookies generally expire when the applicable browser session ends.
Persistent cookies remain for the period appropriate to their purpose or until they are deleted, expire, or consent is withdrawn.
Where available, the Cookie Consent Manager provides more specific information about cookie duration.
8. Third-Party Services
Some portions of our websites or Services may rely on third-party providers that use cookies or similar technologies.
Those providers may process information in accordance with their own privacy practices as well as applicable agreements with Iqidis.
Additional information about our service providers is available in our Service Providers & Subprocessors Policy.
9. International Processing
Information associated with cookies or similar technologies may be processed in locations described in our Privacy & Data Policy.
Where required, Iqidis uses appropriate safeguards for international transfers of Personal Data.
10. Changes to This Policy
We may update this Cookie Policy to reflect changes in our Services, technology, legal requirements, or practices.
Material changes will be communicated where required by applicable law.
The current version will identify its effective date.
11. Contact
Iqidis, Inc.
3 Columbus Circle, Floor 15
New York, NY 10019
Email: info@iqidis.ai
This whitepaper is compiled for reference purposes only. In the event of any conflict between this document and the original individual policies published on the Iqidis platform, the original policies shall control. For the most current version of any policy, visit iqidis.ai.
Questions about these policies?
Contact us at info@iqidis.ai, or write to:
Iqidis, Inc.
Attn: Legal & Security
3 Columbus Circle, Floor 15
New York, NY 10019