DATA PROCESSING ADDENDUM
Effective Date: August 17, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement governing services between Hines Reporters.com, Inc. (“Hines,” “Processor,” “Service Provider,” “Contractor,” “we,” or “us”) and the customer obtaining Services from Hines (“Customer,” “Controller,” “Business,” “you,” or “your”).
This DPA applies to the extent Hines Processes Personal Information on behalf of Customer in connection with Hines’ court reporting and litigation-support services.
If this DPA conflicts with the underlying agreement concerning Processing of Personal Information, this DPA controls with respect to that conflict.
1. Definitions
Applicable Data Protection Law means privacy, data protection, data security, and breach-notification laws applicable to Processing under the Agreement, including, where applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), other applicable U.S. state privacy laws, the European Union General Data Protection Regulation (“GDPR”), the United Kingdom GDPR, and other applicable privacy laws.
Data Subject means an identified or identifiable individual to whom Personal Information relates.
Personal Information means personal information, personal data, personally identifiable information, or substantially similar information protected under Applicable Data Protection Law and Processed by Hines on Customer’s behalf.
Process or Processing means any operation performed on Personal Information, including collection, recording, organization, storage, access, use, transmission, disclosure, alteration, retrieval, deletion, or destruction.
Security Incident means unauthorized or unlawful access to, acquisition, disclosure, alteration, destruction, or loss of Personal Information Processed by Hines on Customer’s behalf.
Subprocessor means a third party engaged by Hines to Process Personal Information on behalf of Customer.
2. Scope and Roles
Customer may provide Hines with Personal Information concerning attorneys, employees, clients, witnesses, parties, experts, medical providers, litigation participants, or other individuals.
To the extent Applicable Data Protection Law characterizes Customer as a controller or business and Hines as a processor, service provider, or contractor, the parties agree that Hines will Process Personal Information on Customer’s behalf in accordance with this DPA.
Nothing in this DPA prevents Hines from Processing information as an independent controller or business where Hines has an independent legal right or obligation to do so.
3. Processing Instructions
Hines will Process Personal Information:
- to provide the Services;
- according to Customer’s documented instructions;
- as necessary to perform obligations under the Agreement;
- to comply with applicable law, regulation, court order, professional requirement, or legal process; and
- as otherwise permitted by Applicable Data Protection Law.
Hines will notify Customer if, in Hines’ reasonable opinion, a Customer instruction violates Applicable Data Protection Law, unless Hines is prohibited from providing such notice.
4. Details of Processing
Subject Matter
Court reporting, deposition, videography, interpreting, transcription, remote proceeding, exhibit, trial-support, conference, and related litigation-support services.
Duration
For the duration of the parties’ service relationship and any subsequent period during which Hines lawfully retains Personal Information.
Nature and Purpose
Processing necessary to schedule, administer, perform, document, transcribe, record, produce, store, transmit, deliver, bill for, and support litigation-related Services.
Categories of Data Subjects
May include:
- Customer employees and personnel;
- attorneys;
- clients;
- witnesses and deponents;
- litigants and parties;
- experts;
- medical professionals;
- court personnel;
- vendors and contractors; and
- other individuals identified in litigation materials.
Categories of Personal Information
May include:
- names and contact information;
- professional information;
- case and litigation information;
- testimony;
- transcripts;
- audio and video;
- photographs;
- exhibits;
- medical information;
- financial information;
- identification information;
- communications;
- electronic identifiers; and
- other information contained in litigation records.
Because litigation records may concern virtually any aspect of an individual’s life, Personal Information may include sensitive or special-category information where provided by Customer or generated during a proceeding.
5. Confidentiality
Hines will ensure that personnel authorized to Process Customer Personal Information are subject to appropriate confidentiality obligations.
Hines will limit access to persons who reasonably require access to perform Services or satisfy legal obligations.
6. CCPA Service Provider and Contractor Requirements
To the extent the CCPA applies and Hines acts as Customer’s service provider or contractor, Hines will:
- Process Personal Information only for the business purposes specified in the Agreement and this DPA;
- not sell or share Personal Information as those terms are defined by the CCPA;
- not retain, use, or disclose Personal Information outside the direct business relationship between Hines and Customer except as permitted by the CCPA;
- not retain, use, or disclose Personal Information for purposes other than the business purposes specified in the Agreement except as permitted by law;
- comply with applicable restrictions regarding combining Personal Information received from Customer with information received from other sources;
- provide the level of privacy protection required by the CCPA;
- notify Customer if Hines determines it can no longer meet applicable CCPA obligations; and
- permit Customer to take reasonable and appropriate steps as authorized by law to ensure Hines uses Personal Information consistently with Customer’s obligations.
7. Security
Hines will maintain reasonable administrative, technical, organizational, and physical safeguards appropriate to the nature of the Personal Information and risks associated with Processing.
Such measures may include, as appropriate:
- access controls;
- authentication controls;
- confidentiality requirements;
- secure file transfer;
- reasonable system and network protections;
- backup procedures;
- security monitoring;
- incident-response procedures;
- personnel security practices; and
- secure disposal procedures.
The parties acknowledge that security practices may evolve over time in response to technological and operational developments.
8. Security Incidents
Hines will notify Customer without undue delay after confirming a Security Incident affecting Personal Information Processed by Hines on Customer’s behalf where notification is required by Applicable Data Protection Law or the Agreement.
To the extent reasonably available, Hines will provide information regarding:
- the nature of the Security Incident;
- categories of affected information;
- categories or approximate number of affected individuals where known;
- likely consequences where reasonably ascertainable; and
- remediation or mitigation measures undertaken.
Hines will reasonably cooperate with Customer regarding legally required investigation, mitigation, and notification.
Notification of a Security Incident does not constitute an admission of fault or liability.
9. Data Subject Requests
Taking into account the nature of Processing, Hines will provide reasonable assistance to Customer in responding to verified requests from Data Subjects exercising rights under Applicable Data Protection Law.
If Hines receives a request relating to Personal Information Processed solely on Customer’s behalf, Hines may direct the requester to Customer unless law requires Hines to respond directly.
Customer remains responsible for determining whether a request is valid and what response is legally required.
10. Regulatory Assistance
Taking into account the nature of Processing and information available to Hines, Hines will provide reasonable assistance with Customer’s legally required:
- privacy impact assessments;
- security assessments;
- regulatory inquiries;
- consultations with supervisory authorities; and
- compliance obligations relating to Hines’ Processing.
11. Subprocessors
Customer authorizes Hines to engage Subprocessors reasonably necessary to provide the Services.
Hines will take reasonable steps to ensure that Subprocessors handling Personal Information are subject to contractual privacy and security obligations appropriate to their services.
Hines remains responsible for its Subprocessors to the extent required by Applicable Data Protection Law.
Upon reasonable request, Hines will provide information regarding material categories of Subprocessors used to Process Customer Personal Information.
Where legally required, Hines will provide reasonable advance notice before engaging a new Subprocessor and will work in good faith with Customer concerning legitimate data-protection objections.
12. Audits and Compliance Information
Upon reasonable written request, Hines will provide information reasonably necessary to demonstrate compliance with this DPA.
Where Applicable Data Protection Law requires an audit right, Customer may conduct an audit subject to reasonable confidentiality, security, timing, scope, and operational restrictions.
Unless required because of a confirmed Security Incident or regulatory requirement, on-site audits will ordinarily be limited to once in any twelve-month period.
Customer will bear its audit costs unless applicable law requires otherwise.
13. International Transfers
If Personal Information subject to international data-transfer restrictions is transferred to a jurisdiction requiring a transfer mechanism, the parties will implement an appropriate lawful mechanism.
Where legally required, the European Commission’s applicable Standard Contractual Clauses (“SCCs”) will be incorporated into this DPA.
For controller-to-processor transfers subject to the GDPR, Module Two of the SCCs will apply unless another module is appropriate to the parties’ actual roles.
Where UK law applies, the applicable UK International Data Transfer Addendum or other legally recognized mechanism will supplement the SCCs as necessary.
ATTORNEY REVIEW NOTE: Counsel should determine whether Hines actually needs EU/UK transfer language based upon its customers, vendors, storage locations, and international operations.
14. HIPAA
Where Hines Processes Protected Health Information as a Business Associate within the meaning of HIPAA, the parties will enter into a Business Associate Agreement where legally required.
In the event of a conflict concerning Protected Health Information, the Business Associate Agreement will control.
15. Return and Deletion
Upon termination of Services and Customer’s written request, Hines will return or securely delete Personal Information Processed on Customer’s behalf to the extent reasonably practicable, except where retention is:
- required by law;
- required by court rule or professional regulation;
- necessary to preserve reporter notes, transcripts, exhibits, recordings, or other records for legally mandated periods;
- necessary for legal claims or dispute resolution; or
- maintained in backup systems subject to ordinary retention cycles.
Any retained Personal Information will remain protected by the applicable provisions of this DPA.
16. Customer Responsibilities
Customer represents that:
- it has a lawful basis to provide Personal Information to Hines;
- its instructions comply with Applicable Data Protection Law;
- it will provide legally required notices and obtain legally required consents;
- it will not instruct Hines to Process Personal Information unlawfully; and
- it will maintain appropriate security for systems and credentials under its control.
17. Liability
Liability arising under this DPA will be governed by the liability provisions of the underlying Agreement except where Applicable Data Protection Law prohibits such limitation.
18. Term and Survival
This DPA becomes effective when it applies to Processing performed under the Agreement.
Privacy, confidentiality, security, deletion, and other obligations that by their nature continue after termination will survive for as long as Hines retains Personal Information subject to those obligations.
19. Governing Law
Unless Applicable Data Protection Law requires otherwise, this DPA is governed by the governing-law provision of the Agreement.
If no governing-law provision exists, California law will govern without regard to conflict-of-laws principles.
20. Contact
Questions regarding this DPA may be directed to:
Hines Reporters.com, Inc.
888 S. Figueroa Street, Suite 940
Los Angeles, CA 90017
Email: privacy@hinesreporters.com
