Skip to content

Legal Document Registry

Canonical registry for contractual, compliance, operational, and audit documents

Registry status: Authoritative registry for legal-document identifiers
Version: 1.0.0
Owner: Legal / CISO / DPO
Last Updated: 2026-07-19
Review Cycle: Quarterly and after each legal-document change


1. Purpose and Authority

This registry defines the current canonical LEG-* legal-document identifiers. Former internal numbering schemes did not represent the actual contractual structure and must not be used as the canonical source for current legal or compliance references.

The registry has three purposes:

  • identify the real legal, compliance, operational, and audit documents used by MazeVault;
  • define how those documents depend on each other;
  • prevent product documentation from making statements that diverge from the contractual baseline.

Provider-specific party names and executed agreement details are intentionally not published in this customer documentation. They are governed by the applicable executed provider, sublicense, DPA, security-annex, support, or order documentation.


2. Identifier Scheme

Prefix Scope Rule
LEG-CTR-* Contractual framework Agreements, contractual annexes, incorporated contractual lists and customer-facing templates
LEG-CMP-* Compliance mappings Regulatory mappings and article-by-article compliance documents
LEG-OPS-* Operational legal/security procedures Incident, continuity, recovery and operational procedures that support legal commitments
LEG-AUD-* Audit and evidence delivery Audit readiness, evidence catalogues and customer evidence delivery
LEG-POL-* Internal organizational policies Reserved for formal policies that actually exist and have owner, approval and review metadata

No document may receive a LEG-POL-* identifier merely because a compliance mapping would benefit from one. Internal policies that are not published remain unnumbered external evidence until they are formally authored and approved.


3.1 Contractual Framework

New ID Document Legal role Source status Source path
LEG-CTR-001 License Terms for MazeVault Applications End-customer use terms and article-level legal baseline Extracted text source; Markdown canonicalization pending legal owner approval Contract repository source; provider-specific executed copies are governed by the applicable agreement
LEG-CTR-002 Non-exclusive License Agreement MV/Recipient MV-to-provider agreement establishing provider rights and obligations Extracted text source; Markdown canonicalization pending legal owner approval Contract repository source; provider-specific executed copies are governed by the applicable agreement
LEG-CTR-002-A1 Annex 1: Applications and Minimum Prices Commercial annex to LEG-CTR-002 PDF source maze-security/contracts/Mazevault_Přílohy 1-4-1.pdf
LEG-CTR-002-A2 Annex 2: Operational Requirements Minimum technical and operating requirements for provider/customer deployments PDF source maze-security/contracts/Mazevault_Přílohy 1-4-1.pdf
LEG-CTR-002-A3 Annex 3: Required Programs Third-party and platform prerequisites PDF source maze-security/contracts/Mazevault_Přílohy 1-4-1.pdf
LEG-CTR-002-A4 Annex 4: Access Handover Protocol CRM/accounting/access handover framework PDF source maze-security/contracts/Mazevault_Přílohy 1-4-1.pdf
LEG-CTR-002-A5 Annex 5: License Terms Attachment reference to LEG-CTR-001 Attachment reference LEG-CTR-001
LEG-CTR-002-A6 Annex 6: Support Policy and Product Lifecycle Attachment reference to LEG-CTR-005 Attachment reference LEG-CTR-005
LEG-CTR-003 Security Annex Template Provider-customer security annex template; MAZEVAULT s.r.o. is manufacturer, not a signing party unless expressly agreed Markdown source maze-security/contracts/security-annex-template.{en,cs}.md
LEG-CTR-004 Data Processing Agreement Provider-customer GDPR Article 28 DPA template Markdown source maze-security/contracts/data-processing-agreement.{en,cs}.md
LEG-CTR-005 Support Policy and Product Lifecycle Support, lifecycle, reference availability/performance, termination and MEK transition standard Markdown source maze-security/contracts/support-policy.{en,cs}.md
LEG-CTR-006 Subprocessor List Incorporated DPA list and DORA/GDPR subcontracting transparency document Markdown source maze-docs/docs/legal/subprocessor-list.{en,cs}.md

3.2 Compliance Mappings

New ID Document Role Source path
LEG-CMP-001 NIS2 / Czech Cybersecurity Act Compliance Mapping Maps supplier and cybersecurity obligations to documents and evidence maze-docs/docs/legal/nis2-czech-cybersecurity-act-compliance.{en,cs}.md
LEG-CMP-002 DORA Compliance Mapping Maps ICT third-party and operational resilience obligations to documents and evidence maze-docs/docs/legal/dora-compliance-mapping.{en,cs}.md
LEG-CMP-003 GDPR Compliance Maps GDPR processor obligations, TOMs, RoPA and breach support to documents and evidence maze-docs/docs/legal/gdpr-compliance.{en,cs}.md

3.3 Operational Procedures

New ID Document Role Source path
LEG-OPS-001 Incident Response Plan Incident classification, escalation, customer notification and regulatory coordination process maze-docs/docs/legal/incident-response-plan.{en,cs}.md
LEG-OPS-002 Business Continuity and Disaster Recovery Plan Recovery strategy, deployment-dependent RTO/RPO targets and DR procedures maze-docs/docs/legal/business-continuity-disaster-recovery.{en,cs}.md

3.4 Audit and Evidence

New ID Document Role Source path
LEG-AUD-001 Compliance Evidence and Reporting Platform evidence capabilities, compliance APIs, audit-log access and SIEM evidence maze-docs/docs/legal/compliance-evidence.{en,cs}.md
LEG-AUD-002 Audit Readiness and Evidence Delivery Guide Customer and regulator audit-request process and evidence packaging guide maze-security/audit-readiness-guide.en.md

4. Canonical Terms

Term Meaning Notes
Manufacturer MAZEVAULT s.r.o., owner of MazeVault intellectual property and upstream software producer Not a provider-customer signing party unless a document expressly says so
Provider The entity licensed by MAZEVAULT s.r.o. to provide sublicences and customer operation/support under an applicable provider agreement Primary customer contractual counterparty where the executed DPA, Security Annex, support agreement or sublicense agreement designates the provider as such
Customer The end-customer entity receiving a sublicense and operating or using the Application Owns or controls customer infrastructure unless the provider contract says otherwise
License Terms LEG-CTR-001 Article-level baseline referenced by support, security and data-processing documents
Provider Agreement LEG-CTR-002 MV-to-provider agreement; includes Annexes 1-6
Principal Sublicense Agreement Provider-customer agreement incorporating the License Terms and applicable annexes Replaces ambiguous uses of MSA/Principal Agreement where the provider-customer sublicense is meant
Security Annex LEG-CTR-003 Security obligations template attached to the provider-customer agreement
DPA LEG-CTR-004 Data Processing Agreement between customer/controller and provider/processor
Support Policy LEG-CTR-005 Support, lifecycle and reference-service-level standard

5. Document Dependency Matrix

Document Incorporates / relies on Incorporated by / supports Consistency rule
LEG-CTR-001 License Terms Provider/customer order or sublicense context LEG-CTR-003, LEG-CTR-004, LEG-CTR-005, product documentation Article citations must be verified against this source before publication
LEG-CTR-002 Provider Agreement Annexes LEG-CTR-002-A1 through LEG-CTR-002-A6 Provider operating model and customer sublicensing framework Customer-facing documents must not convert MV obligations into direct customer obligations unless the agreement does so
LEG-CTR-003 Security Annex License Terms, Support Policy, DPA, Subprocessor List Customer security due diligence, NIS2/DORA/GDPR mappings Must consistently name Provider as customer counterparty and Manufacturer as non-party unless signed otherwise
LEG-CTR-004 DPA Principal Sublicense Agreement, Subprocessor List, Security Annex GDPR Compliance, customer DPA execution package Telemetry and subprocessor statements must match LEG-CTR-006 and License Terms
LEG-CTR-005 Support Policy License Terms, Provider Agreement Annex 2, Security Annex recommendations Product docs, lifecycle docs, audit evidence, availability references Must distinguish reference values from binding customer commitments
LEG-CTR-006 Subprocessor List DPA authorization mechanism and change-notification process GDPR/DORA mappings, audit evidence, customer due diligence Must distinguish customer-managed components from subprocessors
LEG-CMP-* Compliance mappings Contractual and operational documents, technical security docs Customer questionnaires and audit packages Must not cite non-existent policies as formal documents
LEG-OPS-* Operational procedures Support Policy, Security Annex, License Terms Incident/BCP evidence and audit packages Operational targets must be deployment- and responsibility-aware
LEG-AUD-* Audit/evidence docs All registry entries and runtime evidence sources Customer/regulator audit delivery Must distinguish templates, executed agreements, internal policies and runtime evidence

6. Obligation Matrix

Obligation area Primary responsible party Source document Evidence / implementation source Documentation consistency requirement
Software IP, release and upstream fixes Manufacturer LEG-CTR-001, LEG-CTR-002, LEG-CTR-005 Release notes, SBOM, advisory process, CI/CD artifacts Product docs must not imply direct infrastructure operation by Manufacturer
Customer sublicence and primary support Provider LEG-CTR-002, Principal Sublicense Agreement, LEG-CTR-005 Support tickets, deployment records, provider-customer agreement Support commitments are binding only if incorporated by the provider-customer agreement
Customer infrastructure security Customer or Provider depending on deployment model LEG-CTR-001, LEG-CTR-003, LEG-CTR-005 Deployment records, network diagrams, backup/restore evidence Deployment docs must identify who operates OS, network, Kubernetes, database and backups
Backups and MEK custody Customer unless expressly agreed otherwise LEG-CTR-001, LEG-CTR-005, LEG-CTR-003 Backup logs, MEK export records, restore tests Docs must state that MEK loss is unrecoverable without a valid customer-held MEK
Data processing Provider as processor; Customer as controller LEG-CTR-004, LEG-CTR-006 DPA execution package, subprocessor notifications, audit logs GDPR docs must not blur Manufacturer/Provider roles
Licence telemetry To be clarified before final publication LEG-CTR-001, LEG-CTR-004, LEG-CTR-006 License server logs, telemetry schema, DPA/subprocessor records Docs must define fields, interval, legal basis and processor/subprocessor treatment
Incident handling Provider operationally; Manufacturer for upstream software advisories; Customer for its own legal notices unless agreed otherwise LEG-CTR-003, LEG-CTR-004, LEG-OPS-001, LEG-CTR-005 Incident records, notifications, post-incident reports Docs must separate detection, triage, customer notification and regulatory notification clocks
Availability and performance Infrastructure operator; Provider if contractually committed LEG-CTR-005, Principal Sublicense Agreement Monitoring reports, health checks, DR tests RTO/RPO/SLA values must be described as reference or binding according to the agreement
Unsupported configurations Customer/Provider deploying outside minimum requirements LEG-CTR-001, LEG-CTR-002-A2, LEG-CTR-005 Deployment inventory, support case records Requirements docs must describe support/warranty consequences
Subprocessors and ICT suppliers Provider for customer processing chain; Manufacturer for its own subprocessors if processing occurs LEG-CTR-004, LEG-CTR-006 Subprocessor list, supplier assessments, customer notices DORA/GDPR docs must disclose direct chain and customer-managed exclusions accurately

7. Publication Rules

  1. A document may be cited as a legal document only if it appears in Section 3 or has been added through a registry update.
  2. Product documentation may reference legal commitments only through the canonical LEG-* identifier or the exact agreement/article name.
  3. Reference values, examples and recommended operating targets must be labelled as non-binding unless incorporated by the applicable agreement.
  4. Any statement about backups, MEK custody, telemetry, subprocessors, SLA, RTO/RPO, unsupported configurations or incident notification must be checked against the obligation matrix before release.
  5. Generated documentation under maze-docs/site/ is not edited manually; it is regenerated after source updates.

Document Control

Version Date Owner Changes
1.0.0 2026-07-19 Legal / CISO / DPO Initial canonical registry and obligation matrix