Legal
Service Provider Addendum (CCPA)
The written contract that lets a covered California firm treat TKJ as its service provider.
DRAFT for review by a California attorney — not executable. Built on
Civ Code § 1798.140(ag)(1)–(2) and § 1798.100(d), read verbatim
13 August 2026. SeeUS-CA-VERIFICATION-RECORD.md§4.Why this exists even though the CCPA does not apply to TKJ
TKJ is not a “business” under § 1798.140(d)(1) — it meets none of the three
thresholds. But its customers may be, and the CCPA reaches TKJ through their
contracts: a business that discloses personal information to a service provider
must have an agreement containing the § 1798.100(d) terms, and a person only
qualifies as a “service provider” if there is a written contract containing the
four prohibitions in § 1798.140(ag)(1).Without this addendum, a Californian law firm cannot treat TKJ as its service
provider — which would make every disclosure to TKJ a disclosure to a third
party, with consequences the firm will not accept. This document is what makes
TKJ contractable by a covered California firm.Not a DPA, and not modelled on one. The mandatory content is the four
prohibitions plus the five § 1798.100(d) terms — a shorter and differently-shaped
list than UK GDPR Art 28(3), POPIA s 21 or GAID Art 34(2). Do not import those.
Version: [[ x.y ]] · Addendum to the SaaS Subscription Agreement between
TKJ Global Media Ltd (“TKJ”, the Service Provider) and the firm named in
the Order (the Business).
1. Roles and application
This Addendum applies where the Business is a “business” as defined in Civ Code
§ 1798.140(d) and discloses personal information to TKJ for a business purpose.
TKJ acts as the Business’s service provider within § 1798.140(ag). TKJ does
not determine the purposes or means of processing the Business’s personal
information.
TKJ records that TKJ itself is not a “business” within § 1798.140(d)(1): it
meets none of the three thresholds and does not sell or share personal information.
2. The four prohibitions — § 1798.140(ag)(1)
TKJ shall not:
2.1 sell or share the personal information (§ 1798.140(ag)(1)(A));
2.2 retain, use or disclose the personal information for any purpose other
than the business purposes specified in this Agreement for the Business, including
retaining, using or disclosing it for a commercial purpose other than those
business purposes, or as otherwise permitted by the CCPA
(§ 1798.140(ag)(1)(B));
2.3 retain, use or disclose the personal information outside the direct
business relationship between TKJ and the Business (§ 1798.140(ag)(1)(C)); or
2.4 combine the personal information TKJ receives from or on behalf of the
Business with personal information it receives from or on behalf of another person,
or collects from its own interaction with a consumer, except as the CCPA and the
CPPA’s regulations permit (§ 1798.140(ag)(1)(D)).
2.5 For the avoidance of doubt, and because law firms ask: TKJ does not use the
Business’s personal information to train, fine-tune or improve any model, to build
benchmarks, or to develop any other product. This is not merely a policy — there
is no such pipeline in the software.
3. Business purposes — § 1798.100(d)(1)
The personal information is disclosed to TKJ only for the limited and specified
purpose of providing, supporting, securing and maintaining the practice
management service described in the Agreement, and for no other purpose.
4. Same level of privacy protection — § 1798.100(d)(2)
TKJ shall comply with its applicable obligations under the CCPA and shall
provide the same level of privacy protection as the CCPA requires of the
Business in respect of the personal information.
5. The Business’s oversight rights — § 1798.100(d)(3), (5) and § 1798.140(ag)(1)
5.1 The Business may take reasonable and appropriate steps to help ensure
that TKJ uses the personal information in a manner consistent with the Business’s
obligations under the CCPA.
5.2 As § 1798.140(ag)(1) contemplates, the Business may monitor TKJ’s
compliance through measures including manual reviews, automated scans, and
assessments, audits or other technical and operational testing, not more than
once every 12 months except following a security incident affecting the
Business’s data or where a regulator requires it.
5.3 On notice — including notice under clause 6 — the Business may take
reasonable and appropriate steps to stop and remediate unauthorized use of the
personal information (§ 1798.100(d)(5)).
5.4 TKJ shall make available the information reasonably necessary to
demonstrate compliance with this Addendum, including its security documentation and
the results of its restoration and decryption drills.
6. Notification if TKJ can no longer comply — § 1798.100(d)(4)
TKJ shall notify the Business promptly if it makes a determination that it can no
longer meet its obligations under the CCPA in respect of the Business’s personal
information.
This clause is short and easily overlooked. It is a distinctively Californian
obligation with no counterpart in the UK, South African, Nigerian or Australian
instruments, and it is a positive duty to self-report a compliance failure — not
merely to answer when asked.
7. Sub-processing — § 1798.140(ag)(2)
7.1 If TKJ engages any other person to assist it in processing personal
information for a business purpose on behalf of the Business, TKJ shall notify
the Business of that engagement, and the engagement shall be pursuant to a
written contract binding that person to observe all of the requirements in
clause 2. The same applies to any person engaged in turn by that person.
7.2 TKJ shall maintain a list of such persons and make it available to the
Business on request.
7.3 The AI assistant, specifically. Where the Business uses the assistant with
TKJ’s platform key, TKJ engages an AI provider to assist in processing, and
clause 7.1 applies to that engagement. Where the Business uses its own key
(BYOK), the content travels under the Business’s own agreement with that
provider and TKJ engages no one.
[[ ⚠ Q-USDOC2 — BEFORE THE PLATFORM-KEY MODE IS OFFERED TO A CALIFORNIAN FIRM:docs/ANTHROPIC-DATA-PATH.md
confirm that the contract with the AI provider binds it to all four
§ 1798.140(ag)(1) prohibitions, and name it in the clause 7.2 list. What the
assistant actually transmits — including a matter's trust balance and up to
60,000 characters of a selected document — is documented and code-verified in. **BYOK avoids this question entirely and is the
better position for a law firm**, as that document already recommends. ]]
8. Consumer requests
TKJ shall not respond directly to a consumer request relating to the Business’s
personal information. TKJ shall forward the request to the Business promptly and
direct the consumer to the Business, and shall assist the Business in responding.
Where a request concerns information in a law firm’s client files, TKJ will
take no action that could waive or compromise the attorney–client privilege — which
belongs to the firm’s clients, not to the firm and not to TKJ.
9. Security
TKJ shall implement and maintain reasonable security procedures and practices
appropriate to the nature of the personal information, as described in the Schedule
to this Addendum.
[[ G-USDOC2 — Civ Code § 1798.81.5, referenced by § 1798.100(e), has NOT been
read. Confirm this clause against it. ]]
10. Security incidents
[[ ⚠ G-USDOC3 — INCOMPLETE. California's breach-notification statute and
Civ Code § 1798.150 (private right of action, with statutory damages) have NOT been
read. Do not import the UK, South African, Nigerian or Australian clause: the
trigger, the timing and — critically — the remedies differ, and § 1798.150 exposes
a business to statutory damages the other regimes do not create. Read them and
complete this clause. ]]
Interim position, safe to state now: TKJ will notify the Business
immediately on becoming aware of unauthorized access to, or disclosure or loss
of, the Business’s personal information, and will provide the information the
Business needs to make its own assessment and notifications.
11. Return and deletion
Governed by clause 6.6 of the Agreement (Regulated Records), which this Addendum
does not modify: export available for 90 days; Regulated Records are not deleted
until the Business confirms in writing; and read and export access continues
during suspension for non-payment.
California requires a law firm to retain client trust account records for five
years, running from events such as the final distribution or the conclusion of the
representation — not from the end of a software subscription.
Schedule — Security measures
- Isolation between firms enforced at the database level, not by application
logic alone. - Encryption in transit; backups encrypted before leaving the host, to a key
the hosting environment does not hold. - Access control limited to personnel who require it, authenticated, with
logging of TKJ access to Business data. - Append-only trust and billing ledgers — history cannot be rewritten.
- Backups held separately and periodically tested by restoration; off-host
decryption drills performed and recorded. - The service refuses to start on a configuration that would disable isolation.
- Automated evaluation suites run before changes ship, including an adversarial
suite proving the assistant cannot move money or issue a bill.
No certification is claimed. TKJ holds no SOC 2 report and no ISO 27001
certificate.
Open items
| ref | item |
|---|---|
Q-USDOC2 |
AI provider as a sub-processor — clause 7.3, before platform key is offered |
G-USDOC2 |
§ 1798.81.5 unread — clause 9 |
G-USDOC3 |
Breach statute and § 1798.150 unread — clause 10 incomplete |
G-USDOC5 |
CPPA regulations unread — referenced in §§ 1798.140(ag)(1)(D) and 1798.140(e) |
Q-USDOC1 |
Whether TKJ certifies under § 1798.140(d)(4) — changes clause 1 |
| — | US instance deployed; registration closed |