Bishop·
PrivacyTermsSupportCookiesAcceptable useRefundsDPA

Legal

Data Processing Addendum

For firms: Bishop as your Data Processor, and the terms that govern it.

Effective 7 August 2026 · Last updated 7 August 2026

Contents

  1. 1. Definitions
  2. 2. Roles of the parties
  3. 3. Scope and nature of processing
  4. 4. Bishop’s obligations
  5. 5. Customer’s obligations
  6. 6. Sub-processors
  7. 7. Security measures
  8. 8. Personal data breach
  9. 9. Data Principal requests
  10. 10. Audits and information
  11. 11. International transfers
  12. 12. Return and deletion
  13. 13. Liability and term
  14. 14. Governing law

This Data Processing Addendum (“DPA”) forms part of the Terms of Service (the “Agreement”) between Nexno Lextech Private Limited (CIN U85307PN2023PTC221261), which operates the Bishop product (“Bishop”, “we”, “us” or “Processor”), and the customer that subscribes to the Service (“Customer”, “you” or “Fiduciary”). It governs the processing of personal data that we carry out on your behalf when you use the Service. It is designed for the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (together, the “DPDP regime”), and the Information Technology Act, 2000 and the rules made thereunder, and can be supplemented for other applicable laws.

In the event of a conflict between this DPA and the rest of the Agreement on matters of personal data processing, this DPA prevails.

1. Definitions#

Terms used in this DPA carry the meaning given in the DPDP regime. In particular:

  • Data Fiduciary means the person who determines the purpose and means of processing personal data. For data processed through the Service, this is the Customer.
  • Data Processor means a person who processes personal data on behalf of a Data Fiduciary. For data processed through the Service, this is Bishop.
  • Data Principal means the individual to whom personal data relates, including the Customer’s personnel and the individuals whose data appears in connected accounts, documents or browsing activity.
  • Customer Personal Data means personal data within Customer Data that Bishop processes on the Customer’s behalf under the Agreement.
  • Connected surface means any of the four ways Bishop observes activity, namely the mail and calendar API integrations, the Bishop browser extension for Google Chrome and other Chromium based browsers, including Microsoft Edge (the “Browser Extension”), the Bishop add-in for Microsoft Office (the “Office Add-in”), and the Bishop web application.
  • Sub-processor means a third party engaged by Bishop to process Customer Personal Data.
  • Personal data breach means an unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to, Customer Personal Data that compromises its confidentiality, integrity or availability.

2. Roles of the parties#

The parties acknowledge that, for Customer Personal Data, the Customer is the Data Fiduciary and Bishop is the Data Processor. The Customer determines the purposes and means of processing, and Bishop processes Customer Personal Data only on the Customer’s documented instructions, as set out in this DPA and the Agreement.

The Customer is responsible for ensuring that it has a lawful basis, and has provided all required notices and obtained all required consents, for the processing of Customer Personal Data through the Service. This includes:

  • Connecting mail and calendar accounts, and the data of the Customer’s clients and other third parties contained in them.
  • Deploying the Browser Extension to its personnel, notifying them that browser activity will be observed, and configuring block lists, allow lists and capture rules consistently with its own policies and with applicable employment and data protection law.
  • Deploying or assigning the Office Add-in to its personnel.

3. Scope and nature of processing#

The details of the processing are as follows.

  • Subject matter: provision of the Service, namely passive time capture, classification of activity into matters, and preparation of draft time entries.
  • Duration: for the term of the Agreement, plus any limited post termination period needed for export and deletion.
  • Nature and purpose: read-only observation of the connected surfaces, classification using machine learning and large language models, narrative drafting, presentation of draft entries for confirmation, storage, support, and where configured by the Customer, export of confirmed entries to the Customer’s nominated systems.
  • Categories of Data Principals: the Customer’s personnel who use the Service, and individuals whose data appears in connected mail and calendar accounts, documents or browsing activity, including the Customer’s clients and counterparties.
  • Categories of personal data:
  • Identity and contact data.
  • Email metadata and subject lines, never message bodies, and calendar event metadata and content.
  • In Word, Excel and PowerPoint, through the Office Add-in, document identity and activity metadata. Document content is not processed.
  • Through the Browser Extension, page details, namely page address, page title and domain, together with activity timing. Page body content is not processed. Addresses and titles are written by the website and may themselves contain email subject lines, document names, case titles or matter references, and are treated as confidential and potentially privileged accordingly.
  • Matter and activity data, and the draft and confirmed time entries derived from them.
  • This may include confidential and legally privileged information.

A complete statement of what Bishop reads from each connected surface, and what Bishop writes and where, is set out in Sections 4, 5 and 6 of the Privacy Policy, which is incorporated into this DPA by reference.

The Customer must not instruct Bishop to process special categories of data through the Service beyond what is inherent in the connected surfaces, without first agreeing appropriate additional measures.

4. Bishop’s obligations#

Bishop will:

  • Process Customer Personal Data only on the Customer’s documented instructions, including those in the Agreement and this DPA, and as required by applicable law. If Bishop is required by law to process beyond the Customer’s instructions, it will inform the Customer first, unless the law prohibits this.
  • Process Customer Personal Data only as needed to provide the Service, and not for its own purposes, except to create aggregated or de-identified data as permitted by the Privacy Policy and subject to the platform restrictions below.
  • Not write to, alter or delete anything in the Customer’s connected accounts, documents or browsers. Bishop does not send, modify or delete mail or calendar items, does not write custom properties or roaming settings to any mailbox, does not alter the content, properties or formatting of any document, and does not inject scripts into or modify any website visited by the Customer’s personnel.
  • Not use the content of connected surfaces to train, fine tune or improve any general purpose, generalised or non-personalised foundation, artificial intelligence or machine learning model.
  • Where Customer Personal Data is obtained through Google APIs, through the Chrome Web Store distribution of the Browser Extension, through Microsoft Graph, through the Office Add-in, or through the Microsoft Edge Add-ons distribution of the Browser Extension, process it in compliance with the applicable platform developer terms, including the Google API Services User Data Policy and its Limited Use requirements, the Chrome Web Store Developer Program Policies including the Limited Use policy, the Microsoft APIs Terms of Use, the Microsoft Marketplace certification policies, and the Microsoft Edge Add-ons store developer policies. Bishop will not use such data for advertising, will not sell it or transfer it to data brokers or information resellers, will not use it to determine creditworthiness or for lending purposes, and will not use it for generalised model training. These restrictions apply to the raw data and equally to any data aggregated, anonymised, de-identified or derived from it.
  • Restrict human access to Customer Personal Data to what is strictly necessary to provide support the Customer or a User has requested, to investigate a security incident, or to comply with law, in each case under access controls and logging.
  • Ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and access it on a need-to-know basis.
  • Implement and maintain the security measures described in Section 7.
  • Assist the Customer, taking into account the nature of the processing, in meeting the Customer’s obligations under the DPDP regime, including responding to Data Principal requests and to inquiries from the Data Protection Board.
  • Make available information reasonably necessary to demonstrate compliance with this DPA.

5. Customer’s obligations#

The Customer will:

  • Comply with its obligations as Data Fiduciary under the DPDP regime and other applicable law.
  • Provide accurate and lawful instructions, and ensure its instructions and use of the Service comply with applicable law.
  • Notify its personnel of the deployment of the Browser Extension and Office Add-in, and obtain any consents required from them under applicable employment and data protection law.
  • Configure block lists, allow lists, capture rules and retention settings consistently with its own policies and professional obligations.
  • Be responsible for the accuracy, quality and legality of Customer Personal Data and the means by which the Customer acquired it.
  • Ensure it is entitled to transfer, or grant access to, Customer Personal Data to Bishop for processing under this DPA.

6. Sub-processors#

The Customer authorises Bishop to engage Sub-processors to process Customer Personal Data, subject to the following:

  • Bishop imposes on each Sub-processor data protection obligations no less protective than those in this DPA, by written contract, including the platform restrictions in Section 4.
  • Bishop remains responsible to the Customer for the performance of each Sub-processor’s obligations.
  • Bishop will give the Customer reasonable prior notice of the addition or replacement of a Sub-processor, for example through the Sub-processor page or by email. If the Customer reasonably objects on data protection grounds, the parties will work in good faith to find a solution, and if none is found the Customer may terminate the affected part of the Service.

7. Security measures#

Bishop will implement and maintain reasonable technical and organisational security measures appropriate to the risk, including:

  • Encryption of Customer Personal Data in transit and at rest.
  • Read-only access scopes and permissions on every connected surface, so that Bishop cannot send, alter or delete data in the Customer’s accounts, documents or browsers.
  • Access controls based on least privilege, with authentication and role-based permissions, and logging of access.
  • Tenant isolation and segregation of customer environments.
  • Network, application and endpoint security controls, vulnerability management and monitoring.
  • Secure software development and change management practices, including review of Browser Extension and Office Add-in releases before publication.
  • Business continuity and backup measures.
  • Personnel training and confidentiality undertakings.

Bishop is pursuing SOC 2 and ISO 27001 certification, Microsoft Entra publisher verification, and Microsoft 365 Certification. Bishop may update its security measures provided the level of protection is not materially reduced. A summary of current measures can be made available on request.

8. Personal data breach#

Bishop will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will include, to the extent known, the nature of the breach, the categories and approximate number of Data Principals and records affected, the likely consequences, and the measures taken or proposed. Bishop will cooperate with the Customer and take reasonable steps to mitigate the breach and assist the Customer in meeting its own notification obligations to the Data Protection Board and affected Data Principals under the DPDP regime, including the requirement to notify affected individuals within the prescribed period.

9. Data Principal requests#

Bishop will, taking into account the nature of the processing, provide reasonable assistance to enable the Customer to respond to requests from Data Principals exercising their rights of access, correction, completion, erasure, grievance redressal and nomination. If Bishop receives a request directly from a Data Principal relating to Customer Personal Data, it will, unless legally required to respond, refer the request to the Customer and not respond directly except to confirm that the request has been forwarded.

10. Audits and information#

Bishop will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, including relevant certifications and audit summaries. Where the Customer reasonably requires further verification, the Customer may, no more than once per year and on reasonable prior notice, conduct an audit, or appoint an independent auditor bound by confidentiality to do so, during business hours and in a manner that does not disrupt Bishop’s operations or compromise the confidentiality of other customers. The parties will agree the scope in advance, and the Customer will bear its own costs.

11. International transfers#

Bishop primarily processes and stores Customer Personal Data in India. Where Customer Personal Data is processed outside India by a Sub-processor, Bishop will do so in compliance with the DPDP regime, including any restrictions notified by the Government of India on transfers to particular countries, and will ensure appropriate contractual safeguards are in place. The Customer may specify regional processing requirements where the Service supports them.

12. Return and deletion#

On termination or expiry of the Agreement, or earlier on the Customer’s written request, Bishop will, at the Customer’s choice, make Customer Personal Data available for export for a limited period and then delete it, or delete it directly, unless retention is required by applicable law. Bishop will delete Customer Personal Data from active systems and, in the ordinary course, from backups in line with its backup cycle. On request, Bishop will confirm deletion in writing.

Uninstalling the Browser Extension or removing the Office Add-in stops further collection through that surface immediately, and clears the local device storage described in Section 6.2 of the Privacy Policy.

13. Liability and term#

The liability of each party under this DPA is subject to the limitations and exclusions of liability in the Agreement. This DPA takes effect on the effective date and remains in force for as long as Bishop processes Customer Personal Data under the Agreement. It binds and benefits the parties and their permitted successors and assigns. Provisions that by their nature should survive termination will survive.

14. Governing law#

This DPA is governed by the laws of India and is subject to the dispute resolution and jurisdiction provisions of the Agreement.

Questions about this page? Write to prathikx@gmail.com.

Bishop·

Passive time tracking for law firms.

How it worksSecurityFAQContact

Built for Indian Tier-1 practices.  ·  © 2026 Bishop

PrivacyTermsSupportCookiesAcceptable useRefundsDPA

Bishop is a product of Nexno Lextech Private Limited, Pune, India · CIN U85307PN2023PTC221261