Skip to content

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the agreement between the customer firm and CaseAgent for use of the CaseAgent workspace and agent. It sets out how CaseAgent processes personal data on the firm's behalf, in line with Article 28 of the EU General Data Protection Regulation (GDPR), the UK GDPR, and the service provider and processor requirements of US state privacy laws such as the California Consumer Privacy Act as amended by the CPRA (CCPA).

Last updated: October 8, 2026

How this DPA is accepted

On the Enterprise plan, the firm owner accepts this DPA inside the workspace on the Agreements page. The workspace records the name, title and firm of the person accepting and the time of acceptance. Any other customer may email [email protected] to receive a copy of this DPA for signature.

01

Scope and roles

This DPA applies to personal data that the customer firm, its attorneys and its staff upload to, create in, or otherwise make available through the CaseAgent workspace and agent ("Customer Personal Data"). It applies for as long as CaseAgent processes Customer Personal Data on the firm's behalf.

For the purposes of the GDPR and the UK GDPR, the customer firm is the controller and CaseAgent is the processor. For the purposes of the CCPA and similar US state privacy laws, the customer firm is the business and CaseAgent is the service provider or processor. Where the firm itself acts as a processor for its own clients, CaseAgent acts as the firm's sub-processor, and the firm is responsible for passing on any instructions from its clients.

If this DPA conflicts with the Terms of Service on the processing of Customer Personal Data, this DPA prevails. Details of the processing are set out in Annex 1, and the security measures in Annex 2.

02

Processing instructions

CaseAgent processes Customer Personal Data only on the documented instructions of the firm. The firm's instructions are this DPA, the Terms of Service, and the firm's own use and configuration of the workspace (for example, opening a matter, uploading a document, running the agent, inviting a seat or exporting work product). Any additional instruction must be agreed in writing.

CaseAgent does not sell or share Customer Personal Data, does not use it for its own purposes, does not combine it with personal data it receives from other sources except as the service requires, and does not retain, use or disclose it outside the direct business relationship with the firm. Customer Personal Data is never used to train AI models, CaseAgent's or any provider's.

If CaseAgent believes an instruction infringes applicable data protection law, it informs the firm promptly. If the law requires CaseAgent to process Customer Personal Data other than on the firm's instructions, CaseAgent informs the firm before processing, unless the law prohibits that notice.

The firm is responsible for the lawfulness of the personal data it provides and for having a lawful basis, and any notices or consents required, for CaseAgent's processing under this DPA.

03

Confidentiality of personnel

CaseAgent ensures that every person it authorizes to process Customer Personal Data is bound by a written duty of confidentiality or an appropriate statutory obligation of confidentiality.

CaseAgent staff do not browse client files. Access to Customer Personal Data is limited to the personnel who need it, and is used only for support the firm requests or for incidents that require it.

04

Security measures

CaseAgent implements the technical and organizational measures described in Annex 2, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the risks to the rights and freedoms of individuals.

Annex 2 describes the measures as they actually operate. CaseAgent does not claim certifications it does not hold. CaseAgent is not SOC 2 audited, and data stored in the database and on disk is not encrypted at rest. The firm should take these facts into account when deciding what data to place in the workspace. More detail is on the security page.

CaseAgent may update its security measures over time, provided that an update does not reduce the overall level of protection of Customer Personal Data.

05

Sub-processors

The firm gives CaseAgent general written authorization to engage sub-processors in the following categories:

  • Cloud hosting. Servers and storage on which the workspace, the database and uploaded documents run.
  • Transactional email. Delivery of sign-in codes, seat invitations, deadline reminders and service notices.
  • Payment processing. Collection of subscription payments and issuing of invoices and receipts. Card details go directly to the payment processor and are not stored by CaseAgent.
  • AI model provider. Processing of matter content sent by the agent to generate drafts, summaries and analysis for the firm, under terms that do not allow the content to be used to train models.

CaseAgent imposes on each sub-processor, by written contract, data protection obligations that offer at least the same level of protection as this DPA, and remains liable to the firm for the performance of each sub-processor's obligations.

CaseAgent gives the firm owner at least 30 days' notice by email before engaging a sub-processor in a new category. The firm may object on reasonable data protection grounds within that period by emailing [email protected]. The parties then discuss the objection in good faith. If it cannot be resolved, the firm may cancel the affected subscription, and CaseAgent refunds any prepaid fees for the period after cancellation takes effect.

06

Assistance with data subject requests

Taking into account the nature of the processing, CaseAgent assists the firm by appropriate technical and organizational measures, insofar as possible, to respond to requests from individuals exercising their rights of access, rectification, erasure, restriction, portability and objection, and the equivalent rights under US state privacy laws.

The firm can find, correct, export and delete matter data directly in the workspace. Where the firm needs more help, it may email [email protected]. If CaseAgent receives a request directly from an individual about Customer Personal Data, it forwards the request to the firm without undue delay and does not respond to it except on the firm's instructions.

CaseAgent also provides reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, to the extent they relate to CaseAgent's processing and the information is available to CaseAgent.

07

Personal data breach notice

CaseAgent notifies the firm owner by email without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data.

The notice describes, to the extent known at the time, the nature of the breach, the categories and approximate number of individuals and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Where not all information is available at once, CaseAgent provides it in phases as it becomes available.

CaseAgent takes reasonable steps to contain and remedy the breach and cooperates with the firm so that it can meet its own notification obligations to supervisory authorities, clients and affected individuals. A notice under this section is not an admission of fault or liability.

08

Deletion or return at end of service

The firm can export its work product in standard formats at any time while the subscription is active. When the service ends, the firm may ask CaseAgent to return Customer Personal Data by emailing [email protected].

Within 30 days after the end of the service, CaseAgent deletes Customer Personal Data from the workspace, unless the law requires CaseAgent to keep it. Any data kept under such a legal requirement remains protected by this DPA and is processed only for the purpose that requires its retention. On request, CaseAgent confirms the deletion in writing.

09

Audits

CaseAgent makes available to the firm the information reasonably necessary to demonstrate compliance with this DPA. The firm may exercise its audit right once a year by sending a written security and data protection questionnaire to [email protected]. CaseAgent answers the questionnaire completely and in good faith within a reasonable period, normally 30 days.

An additional audit is available where a supervisory authority requires it, or after a personal data breach affecting the firm's data. Such an audit is agreed in advance as to scope, timing and confidentiality, is carried out at the firm's cost, and must not give access to other customers' data.

10

International transfers

Where processing under this DPA involves a transfer of personal data from the European Economic Area, the United Kingdom or Switzerland to a country that has not received an adequacy decision, the parties rely on the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914 (module two, controller to processor, or module three, processor to processor, as applicable), together with the UK International Data Transfer Addendum and the Swiss amendments where relevant. The Standard Contractual Clauses are incorporated into this DPA by reference, and Annexes 1 and 2 supply the information their appendix requires.

CaseAgent requires the same transfer safeguards from any sub-processor that receives Customer Personal Data in such a country.

11

Acceptance, term and contact

On the Enterprise plan, the firm owner accepts this DPA in the workspace on the Agreements page. The workspace records the name, title and firm of the person accepting and the time of acceptance, and that record is the firm's signature of this DPA. Any other customer may email [email protected] to receive this DPA.

This DPA remains in force for as long as CaseAgent processes Customer Personal Data for the firm. Sections that by their nature should survive, including confidentiality, deletion and breach notice, survive its end. The limitation of liability in the agreement between the parties applies to this DPA.

Questions about this DPA go to [email protected]. How the general site collects data is described in the privacy policy.

A1

Annex 1. Details of processing

  • Controller (data exporter). The customer firm, represented by its firm owner.
  • Processor (data importer). CaseAgent.
  • Subject matter and nature. Hosting, storage and organization of matters, documents and deadlines, and AI processing of matter content to produce drafts, summaries, analysis and deadline reminders for review by the firm's attorneys.
  • Purpose. Providing the CaseAgent workspace and agent to the firm, including support, security and billing.
  • Duration. The term of the firm's subscription, plus up to 30 days for deletion as set out in section 08.
  • Frequency. Continuous, for as long as the firm uses the service.
  • Categories of data subjects. The firm's attorneys and staff who hold seats; the firm's clients; opposing parties, witnesses, experts, court personnel and other individuals named in the firm's matters and documents.
  • Categories of personal data. For seat holders, name, email address, role, sign-in records, IP addresses and audit log entries. For individuals named in matters, any personal data contained in the documents and notes the firm uploads or creates, such as names, contact details, dates, case facts and correspondence.
  • Special categories and criminal data. Matter documents may contain health data, data revealing other special categories, or data on criminal convictions and offences, as determined solely by the firm. The measures in Annex 2 apply to that data.
  • Sub-processor categories. Cloud hosting, transactional email, payment processing and AI model provider, as set out in section 05.

A2

Annex 2. Security measures

  • Encryption in transit. All traffic between the browser and CaseAgent is encrypted with TLS. There is no unencrypted path into or out of the workspace.
  • No encryption at rest. Data in the database and on disk is not encrypted at rest. Protection of stored data relies on the access controls, isolation and personnel measures in this annex.
  • Per-firm isolation. Each firm's matters live in their own isolated space, so one firm's data is not used in another firm's context, results or drafts.
  • Personal sign-in. Every person opens the workspace with their own private link or a code sent to their own inbox. Switching a seat off stops that link at once without affecting other seats.
  • Role-based permissions. Owner, admin and member roles, checked by the server on every action.
  • Audit log. On the Enterprise plan, the workspace records who opened a matter, added, viewed or removed a document, ran the agent, downloaded or reviewed work product, or changed a deadline, a seat or the plan, with the time (UTC) and IP address. Entries are never edited and can be exported as CSV.
  • Least-privilege staff access. CaseAgent staff do not browse client files. Operational access is limited and reserved for support the firm requests or incidents that require it.
  • No model training. Customer Personal Data is never used to train AI models, CaseAgent's or any provider's.
  • Payment data. Card details are handled by the payment processor and are not stored by CaseAgent.
  • Portability. The firm can export its work product in standard formats at any time.
  • Vulnerability reports. Security reports sent to [email protected] are acknowledged and investigated, and good-faith research is welcomed.
CaseAgent, 2026

Need the DPA signed for your firm?

Enterprise firm owners accept it on the Agreements page in the workspace. Every other customer can request it at [email protected]. Plan details are on the pricing page.