Legal Document Registry¶
Canonical registry for contractual, compliance, operational, and audit documents
Registry status: Authoritative registry for legal-document identifiers
Version: 1.0.0
Owner: Legal / CISO / DPO
Last Updated: 2026-07-19
Review Cycle: Quarterly and after each legal-document change
1. Purpose and Authority¶
This registry defines the current canonical LEG-* legal-document identifiers. Former internal numbering schemes did not represent the actual contractual structure and must not be used as the canonical source for current legal or compliance references.
The registry has three purposes:
- identify the real legal, compliance, operational, and audit documents used by MazeVault;
- define how those documents depend on each other;
- prevent product documentation from making statements that diverge from the contractual baseline.
Provider-specific party names and executed agreement details are intentionally not published in this customer documentation. They are governed by the applicable executed provider, sublicense, DPA, security-annex, support, or order documentation.
2. Identifier Scheme¶
| Prefix | Scope | Rule |
|---|---|---|
LEG-CTR-* |
Contractual framework | Agreements, contractual annexes, incorporated contractual lists and customer-facing templates |
LEG-CMP-* |
Compliance mappings | Regulatory mappings and article-by-article compliance documents |
LEG-OPS-* |
Operational legal/security procedures | Incident, continuity, recovery and operational procedures that support legal commitments |
LEG-AUD-* |
Audit and evidence delivery | Audit readiness, evidence catalogues and customer evidence delivery |
LEG-POL-* |
Internal organizational policies | Reserved for formal policies that actually exist and have owner, approval and review metadata |
No document may receive a LEG-POL-* identifier merely because a compliance mapping would benefit from one. Internal policies that are not published remain unnumbered external evidence until they are formally authored and approved.
3. Canonical Legal Document Set¶
3.1 Contractual Framework¶
| New ID | Document | Legal role | Source status | Source path |
|---|---|---|---|---|
LEG-CTR-001 |
License Terms for MazeVault Applications | End-customer use terms and article-level legal baseline | Extracted text source; Markdown canonicalization pending legal owner approval | Contract repository source; provider-specific executed copies are governed by the applicable agreement |
LEG-CTR-002 |
Non-exclusive License Agreement MV/Recipient | MV-to-provider agreement establishing provider rights and obligations | Extracted text source; Markdown canonicalization pending legal owner approval | Contract repository source; provider-specific executed copies are governed by the applicable agreement |
LEG-CTR-002-A1 |
Annex 1: Applications and Minimum Prices | Commercial annex to LEG-CTR-002 |
PDF source | maze-security/contracts/Mazevault_Přílohy 1-4-1.pdf |
LEG-CTR-002-A2 |
Annex 2: Operational Requirements | Minimum technical and operating requirements for provider/customer deployments | PDF source | maze-security/contracts/Mazevault_Přílohy 1-4-1.pdf |
LEG-CTR-002-A3 |
Annex 3: Required Programs | Third-party and platform prerequisites | PDF source | maze-security/contracts/Mazevault_Přílohy 1-4-1.pdf |
LEG-CTR-002-A4 |
Annex 4: Access Handover Protocol | CRM/accounting/access handover framework | PDF source | maze-security/contracts/Mazevault_Přílohy 1-4-1.pdf |
LEG-CTR-002-A5 |
Annex 5: License Terms | Attachment reference to LEG-CTR-001 |
Attachment reference | LEG-CTR-001 |
LEG-CTR-002-A6 |
Annex 6: Support Policy and Product Lifecycle | Attachment reference to LEG-CTR-005 |
Attachment reference | LEG-CTR-005 |
LEG-CTR-003 |
Security Annex Template | Provider-customer security annex template; MAZEVAULT s.r.o. is manufacturer, not a signing party unless expressly agreed | Markdown source | maze-security/contracts/security-annex-template.{en,cs}.md |
LEG-CTR-004 |
Data Processing Agreement | Provider-customer GDPR Article 28 DPA template | Markdown source | maze-security/contracts/data-processing-agreement.{en,cs}.md |
LEG-CTR-005 |
Support Policy and Product Lifecycle | Support, lifecycle, reference availability/performance, termination and MEK transition standard | Markdown source | maze-security/contracts/support-policy.{en,cs}.md |
LEG-CTR-006 |
Subprocessor List | Incorporated DPA list and DORA/GDPR subcontracting transparency document | Markdown source | maze-docs/docs/legal/subprocessor-list.{en,cs}.md |
3.2 Compliance Mappings¶
| New ID | Document | Role | Source path |
|---|---|---|---|
LEG-CMP-001 |
NIS2 / Czech Cybersecurity Act Compliance Mapping | Maps supplier and cybersecurity obligations to documents and evidence | maze-docs/docs/legal/nis2-czech-cybersecurity-act-compliance.{en,cs}.md |
LEG-CMP-002 |
DORA Compliance Mapping | Maps ICT third-party and operational resilience obligations to documents and evidence | maze-docs/docs/legal/dora-compliance-mapping.{en,cs}.md |
LEG-CMP-003 |
GDPR Compliance | Maps GDPR processor obligations, TOMs, RoPA and breach support to documents and evidence | maze-docs/docs/legal/gdpr-compliance.{en,cs}.md |
3.3 Operational Procedures¶
| New ID | Document | Role | Source path |
|---|---|---|---|
LEG-OPS-001 |
Incident Response Plan | Incident classification, escalation, customer notification and regulatory coordination process | maze-docs/docs/legal/incident-response-plan.{en,cs}.md |
LEG-OPS-002 |
Business Continuity and Disaster Recovery Plan | Recovery strategy, deployment-dependent RTO/RPO targets and DR procedures | maze-docs/docs/legal/business-continuity-disaster-recovery.{en,cs}.md |
3.4 Audit and Evidence¶
| New ID | Document | Role | Source path |
|---|---|---|---|
LEG-AUD-001 |
Compliance Evidence and Reporting | Platform evidence capabilities, compliance APIs, audit-log access and SIEM evidence | maze-docs/docs/legal/compliance-evidence.{en,cs}.md |
LEG-AUD-002 |
Audit Readiness and Evidence Delivery Guide | Customer and regulator audit-request process and evidence packaging guide | maze-security/audit-readiness-guide.en.md |
4. Canonical Terms¶
| Term | Meaning | Notes |
|---|---|---|
| Manufacturer | MAZEVAULT s.r.o., owner of MazeVault intellectual property and upstream software producer | Not a provider-customer signing party unless a document expressly says so |
| Provider | The entity licensed by MAZEVAULT s.r.o. to provide sublicences and customer operation/support under an applicable provider agreement | Primary customer contractual counterparty where the executed DPA, Security Annex, support agreement or sublicense agreement designates the provider as such |
| Customer | The end-customer entity receiving a sublicense and operating or using the Application | Owns or controls customer infrastructure unless the provider contract says otherwise |
| License Terms | LEG-CTR-001 |
Article-level baseline referenced by support, security and data-processing documents |
| Provider Agreement | LEG-CTR-002 |
MV-to-provider agreement; includes Annexes 1-6 |
| Principal Sublicense Agreement | Provider-customer agreement incorporating the License Terms and applicable annexes | Replaces ambiguous uses of MSA/Principal Agreement where the provider-customer sublicense is meant |
| Security Annex | LEG-CTR-003 |
Security obligations template attached to the provider-customer agreement |
| DPA | LEG-CTR-004 |
Data Processing Agreement between customer/controller and provider/processor |
| Support Policy | LEG-CTR-005 |
Support, lifecycle and reference-service-level standard |
5. Document Dependency Matrix¶
| Document | Incorporates / relies on | Incorporated by / supports | Consistency rule |
|---|---|---|---|
LEG-CTR-001 License Terms |
Provider/customer order or sublicense context | LEG-CTR-003, LEG-CTR-004, LEG-CTR-005, product documentation |
Article citations must be verified against this source before publication |
LEG-CTR-002 Provider Agreement |
Annexes LEG-CTR-002-A1 through LEG-CTR-002-A6 |
Provider operating model and customer sublicensing framework | Customer-facing documents must not convert MV obligations into direct customer obligations unless the agreement does so |
LEG-CTR-003 Security Annex |
License Terms, Support Policy, DPA, Subprocessor List | Customer security due diligence, NIS2/DORA/GDPR mappings | Must consistently name Provider as customer counterparty and Manufacturer as non-party unless signed otherwise |
LEG-CTR-004 DPA |
Principal Sublicense Agreement, Subprocessor List, Security Annex | GDPR Compliance, customer DPA execution package | Telemetry and subprocessor statements must match LEG-CTR-006 and License Terms |
LEG-CTR-005 Support Policy |
License Terms, Provider Agreement Annex 2, Security Annex recommendations | Product docs, lifecycle docs, audit evidence, availability references | Must distinguish reference values from binding customer commitments |
LEG-CTR-006 Subprocessor List |
DPA authorization mechanism and change-notification process | GDPR/DORA mappings, audit evidence, customer due diligence | Must distinguish customer-managed components from subprocessors |
LEG-CMP-* Compliance mappings |
Contractual and operational documents, technical security docs | Customer questionnaires and audit packages | Must not cite non-existent policies as formal documents |
LEG-OPS-* Operational procedures |
Support Policy, Security Annex, License Terms | Incident/BCP evidence and audit packages | Operational targets must be deployment- and responsibility-aware |
LEG-AUD-* Audit/evidence docs |
All registry entries and runtime evidence sources | Customer/regulator audit delivery | Must distinguish templates, executed agreements, internal policies and runtime evidence |
6. Obligation Matrix¶
| Obligation area | Primary responsible party | Source document | Evidence / implementation source | Documentation consistency requirement |
|---|---|---|---|---|
| Software IP, release and upstream fixes | Manufacturer | LEG-CTR-001, LEG-CTR-002, LEG-CTR-005 |
Release notes, SBOM, advisory process, CI/CD artifacts | Product docs must not imply direct infrastructure operation by Manufacturer |
| Customer sublicence and primary support | Provider | LEG-CTR-002, Principal Sublicense Agreement, LEG-CTR-005 |
Support tickets, deployment records, provider-customer agreement | Support commitments are binding only if incorporated by the provider-customer agreement |
| Customer infrastructure security | Customer or Provider depending on deployment model | LEG-CTR-001, LEG-CTR-003, LEG-CTR-005 |
Deployment records, network diagrams, backup/restore evidence | Deployment docs must identify who operates OS, network, Kubernetes, database and backups |
| Backups and MEK custody | Customer unless expressly agreed otherwise | LEG-CTR-001, LEG-CTR-005, LEG-CTR-003 |
Backup logs, MEK export records, restore tests | Docs must state that MEK loss is unrecoverable without a valid customer-held MEK |
| Data processing | Provider as processor; Customer as controller | LEG-CTR-004, LEG-CTR-006 |
DPA execution package, subprocessor notifications, audit logs | GDPR docs must not blur Manufacturer/Provider roles |
| Licence telemetry | To be clarified before final publication | LEG-CTR-001, LEG-CTR-004, LEG-CTR-006 |
License server logs, telemetry schema, DPA/subprocessor records | Docs must define fields, interval, legal basis and processor/subprocessor treatment |
| Incident handling | Provider operationally; Manufacturer for upstream software advisories; Customer for its own legal notices unless agreed otherwise | LEG-CTR-003, LEG-CTR-004, LEG-OPS-001, LEG-CTR-005 |
Incident records, notifications, post-incident reports | Docs must separate detection, triage, customer notification and regulatory notification clocks |
| Availability and performance | Infrastructure operator; Provider if contractually committed | LEG-CTR-005, Principal Sublicense Agreement |
Monitoring reports, health checks, DR tests | RTO/RPO/SLA values must be described as reference or binding according to the agreement |
| Unsupported configurations | Customer/Provider deploying outside minimum requirements | LEG-CTR-001, LEG-CTR-002-A2, LEG-CTR-005 |
Deployment inventory, support case records | Requirements docs must describe support/warranty consequences |
| Subprocessors and ICT suppliers | Provider for customer processing chain; Manufacturer for its own subprocessors if processing occurs | LEG-CTR-004, LEG-CTR-006 |
Subprocessor list, supplier assessments, customer notices | DORA/GDPR docs must disclose direct chain and customer-managed exclusions accurately |
7. Publication Rules¶
- A document may be cited as a legal document only if it appears in Section 3 or has been added through a registry update.
- Product documentation may reference legal commitments only through the canonical
LEG-*identifier or the exact agreement/article name. - Reference values, examples and recommended operating targets must be labelled as non-binding unless incorporated by the applicable agreement.
- Any statement about backups, MEK custody, telemetry, subprocessors, SLA, RTO/RPO, unsupported configurations or incident notification must be checked against the obligation matrix before release.
- Generated documentation under
maze-docs/site/is not edited manually; it is regenerated after source updates.
Document Control¶
| Version | Date | Owner | Changes |
|---|---|---|---|
| 1.0.0 | 2026-07-19 | Legal / CISO / DPO | Initial canonical registry and obligation matrix |