Compliance · RGPD Art. 35
Data Protection Impact Assessment (DPIA)
Impact assessment of the processing carried out by Nexus Legal. Public document, in an adaptable format as a reference for partners and law firms that need to draft their own DPIA when integrating our platform. Last review: 2026-07-02.
1 · Controller and representative
Data controller: Daniel Jiménez
Registered address: Dubai, UAE
Trade name: Nexus Legal
DPO contact: dpo@nexusquantum.legal
EU Representative (Art. 27 RGPD): Ricardo González Álvaro — Calle Zorzaleño 15, La Raya del Palancar, Madrid, Spain — quantumnexusventures@proton.me.
2 · Description of the processing
Nexus Legal analyzes legal documents provided by the user through a multi-agent architecture (Node A generator + Node B auditor + Node C red team, optional). The document is processed entirely in RAM and is NOT persisted to disk or to the controller's database. Only execution metadata is stored (timestamps, model used, cost in credits) and, if the user explicitly requests it, the anonymized output.
- Purposes: legal analysis, assisted drafting, cross-border comparison, legal consultation.
- Type of data: content of legal documents (may include names, addresses, NIE/DNI, financial data, contractual data). Special categories only if the user provides them voluntarily.
- Categories of data subjects: the user themselves (attorney) and third parties mentioned in the documents.
- Estimated volume: ~50 documents/month per average active user.
3 · Necessity and proportionality
Legal basis (Art. 6 RGPD): Art. 6.1.b contract performance (the user contracts the analysis). For third parties mentioned in the documents: Art. 6.1.f legitimate interest of the document controller (the attorney acts on the mandate of their client).
Special data (Art. 9): Nexus does not request this data. If it appears in a document provided by the user, the processing is grounded in Art. 9.2.f (defense of legal claims) or Art. 9.2.g (substantial public interest in the administration of justice), depending on the context of the document.
Data minimization principle: Architectural Zero Retention — the client's document is NOT persisted. The user controls whether to save the anonymized output.
4 · Risks identified
| Risk | Likelihood | Impact | Mitigation |
|---|---|---|---|
| Document leak during processing | Low | High | Processing exclusively in RAM; the file is not stored. The PII Gatekeeper anonymizes before sending to the LLM. |
| Retraining of LLM models with user data | Low | High | Contracts with LLM providers (Anthropic, DeepSeek, Voyage, NVIDIA) with a no-training clause. PII anonymization (Gatekeeper) prior to sending to all external providers. Each provider's "zero retention" endpoints enabled. |
| Unauthorized access to the user's account | Medium | Medium | Supabase Auth with optional 2FA, encrypted sessions, rate limiting, IP allowlist for Enterprise. |
| Fabricated citation of case law/legislation (hallucination) | Medium | High | Audit-trail L1-L5 + L4-N. Verbatim citations from a pre-loaded corpus (not from the model's memory). Adversarial Node B auditor detects inconsistencies. |
| International transfer (EU → third countries) | High (by default) | Medium | SCCs signed with all providers. Storage in Supabase EU-west-2 (London). LLMs accessed via EU endpoints where available. |
5 · Sub-processors (Art. 28.4 RGPD)
- Anthropic, Inc. (LLM Claude Opus/Sonnet/Haiku) — DPA signed, 0-day retention, no training.
- DeepSeek AI Ltd. (LLM DeepSeek V3/V4-Pro) — DPA signed, 0-day retention.
- Voyage AI (embeddings) — 0-day retention, no training.
- NVIDIA Corporation (NVIDIA NIM — AI inference for Case File Mode: metadata, timeline, sentiment, reranking, queries) — PII anonymization (Gatekeeper) prior to sending; no training on API data in accordance with the NVIDIA NIM terms. Formalization of a specific DPA and confirmation of retention: under verification.
- Supabase, Inc. (DB + auth) — DPA signed, eu-west-2 region (London), SOC 2 Type II.
- Railway (app hosting) — europe-west4 region, ISO 27001.
- Resend (transactional email) — DPA signed.
- Cloudflare (CDN + Turnstile) — DPA signed, EU edge.
- Polar (payments, Merchant of Record) — PCI DSS, assumes tax and fraud liability as MoR.
The up-to-date list is kept at /privacy and clients are notified 30 days in advance of any change (Art. 28.2 RGPD).
6 · Data subject rights (Art. 15-22 RGPD)
Exercise of rights: dpo@nexusquantum.legal. Response time: 30 calendar days, extendable to 60 if the request is complex.
- Access (Art. 15): DSR export via the platform itself (button in /settings).
- Rectification (Art. 16): editable from /settings.
- Erasure (Art. 17): "delete account" button in /settings with confirmation via email token (Art. 17.2). Full cascade deletion (auth.users + user_profiles + jobs + credits_ledger + outputs + time_entries…).
- Restriction (Art. 18): temporary account block on request.
- Portability (Art. 20): DSR export in structured JSON.
- Objection (Art. 21): revocable from /settings or by email to the DPO.
- Automated decisions (Art. 22): explicit consent at registration. Safeguards: every output can be reviewed by a human before issuing the professional opinion.
7 · Retention periods
Policy defined in the retention_policies table with a daily cron that runs the automated deletion.
- Client documents: 0 days (native Zero Retention).
- Analysis outputs (if the user opts in): 90 days by default, configurable down to 0 (disable persistence).
- Audit log: 5 years (legal obligation, Ley 25/2007).
- Billing data: 6 years (Ley General Tributaria Art. 70).
- Consent log: 5 years post-revocation (proof of consent, RGPD Art. 7.1).
- User account (profile): until the user requests erasure, or 24 months of inactivity (30 days' prior notice).
8 · Technical and organizational measures (Art. 32 RGPD)
- Encryption in transit: TLS 1.3 mandatory across all surfaces. HSTS enabled.
- Encryption at rest: AES-256 (Supabase) + pgcrypto for sensitive secrets (webhook signing keys).
- Auth: Supabase with optional 2FA, signed encrypted sessions. Master/sub-keys with granular scopes.
- Anti-bot: Cloudflare Turnstile on register/login/forgot-password.
- Rate limiting: per IP + per API key. IP allowlist on Enterprise.
- RLS: Row-Level Security enabled on ALL tables with client data.
- Access logs: 5 years with timestamp + user_id + endpoint + status + masked IP.
- Cross-audit: multi-agent architecture reduces errors and single-model hallucinations.
- Backup: Supabase point-in-time recovery 7 days (Pro plan).
9 · Prior consultation (Art. 36 RGPD)
Following this DPIA, NO high residual risks are identified that would require prior consultation with the supervisory authority. If a future iteration introduces a new high-risk processing (e.g. biometric analysis, health data, mass profiling), this DPIA will be updated and, where appropriate, the AEPD (Spain) will be consulted, the supervisory authority of the country of establishment of the designated EU Art. 27 representative (see §1).
10 · Periodic review
This DPIA is reviewed at least once a year or whenever the following changes: the category of data processed, the sub-processors, the legal basis, or the context of the processing. The date of the last review appears in the header of this document.
Use as a template by partners
This DPIA is intended as an adaptable reference. Any law firm or partner integrating Nexus Legal can use it as a basis, replacing the controller's data and completing the sections specific to their processing. The structure follows the recommendations of the EDPB (formerly WP29) — WP248 rev.01.
If you need the DPIA signed by our DPO for your compliance file, write to dpo@nexusquantum.legal. We issue it as a PDF with an integrity seal (HMAC-SHA256) within 48h.