Legal

Data Processing Addendum

Controller-to-processor terms for Customer Personal Data processed through Caseflow.

Legal

Data Processing Addendum

Controller-to-processor terms for Customer Personal Data processed through Caseflow.

Last updated: August 28, 2026

1. Application and Definitions

When incorporated into an order or other agreement, this Data Processing Addendum (DPA) forms part of that agreement where Caseflow processes Customer Personal Data on behalf of a customer subject to the GDPR, UK GDPR, Swiss data-protection law, or another law requiring processor terms. Customer is the Controller and the Caseflow contracting provider is the Processor, except where either party acts in another role for a specific activity.

Customer Personal Data means personal data contained in Customer Content and processed by Caseflow on Customer’s behalf. Data Protection Law means the law applicable to that processing. Terms such as Controller, Processor, Data Subject, Personal Data Breach, and processing have the meanings in applicable law.

2. Instructions and Compliance

Processor will process Customer Personal Data only on documented instructions from Controller, including the agreement, product configuration, and authorized user actions, unless law requires otherwise. Processor will notify Controller before legally required processing unless prohibited. Processor will inform Controller if an instruction appears to violate Data Protection Law and may suspend the affected processing while the parties resolve it.

3. Processing Details

  • Subject and duration: providing, securing, supporting, and deleting the Service for the agreement term and the deletion period described below.
  • Nature and purpose: hosting, storage, organization, retrieval, sharing, communication, document processing, workflow automation, support, backup, security, and user-invoked AI processing.
  • Data subjects: users, staff, clients, counterparties, witnesses, contacts, vendors, beneficiaries, heirs, family members, message recipients, subjects of investigations, and other people identified in Customer Content.
  • Data types: identity, contact, professional, relationship, communication, case, document, evidence, location, financial, technical, and any special-category or criminal-offence data that Controller chooses to submit.

4. Confidentiality and Security

Processor ensures that personnel authorized to process Customer Personal Data are bound by confidentiality and receive appropriate privacy and security instruction. Processor maintains risk-appropriate technical and organizational measures, including access control, authentication, backend authorization, scoped sharing, transport encryption, provider-managed encryption at rest, logging, upload validation, short-lived controlled document links, backup and recovery processes, vulnerability and dependency management, and incident response. Controller remains responsible for user access, endpoint security, configuration, and lawful instructions.

5. Subprocessors

Controller grants general authorization for the subprocessors on the Subprocessors page. Processor will impose materially equivalent data-protection obligations on subprocessors and remains responsible for their performance as required by law. Processor will provide reasonable notice of a new core subprocessor and a process for objections based on reasonable data-protection grounds.

6. Data Subject and Compliance Assistance

Taking into account the nature of processing and information available, Processor will provide reasonable assistance with Data Subject requests, security obligations, breach notifications, data-protection impact assessments, prior consultations, and regulator inquiries. Controller is responsible for responding to requests and may be charged reasonable costs for exceptional assistance not caused by Processor’s breach.

7. Personal Data Breach

Processor will notify Controller without undue delay after confirming a Personal Data Breach affecting Customer Personal Data and will provide available information reasonably needed for Controller’s obligations. Notification is not an admission of fault. Processor will investigate, contain, mitigate, and document the incident and provide material updates. Controller is responsible for notifications to authorities and affected people unless law assigns that duty to Processor.

8. International Transfers

Where Processor transfers EEA Customer Personal Data to a recipient without an adequacy basis, the 2021 EU Standard Contractual Clauses apply as appropriate, generally Module Two for Controller-to-Processor transfers, with the Controller as data exporter and the relevant Caseflow provider as data importer. The UK Addendum and Swiss adaptations apply where required. The DPA and Subprocessors page complete the applicable annex information. If a valid successor mechanism becomes available, it may be used.

9. Return and Deletion

During the term, Controller may use available export tools. After termination or Controller’s instruction, Processor will delete or return Customer Personal Data within a reasonable operational period unless law requires retention. Residual copies may remain in isolated backups until overwritten and in security, billing, or legal-hold records for their required periods, without further use except for those purposes.

10. Information and Audits

Processor will make information reasonably necessary to demonstrate compliance available through trust materials, questionnaires, and contractual documentation. If that is insufficient, Controller may request an audit no more than once annually, or after a material incident, with reasonable notice, confidentiality, minimal disruption, and at Controller’s cost unless the audit identifies a material Processor breach. Audits may not compromise other customers, security, or privileged information.

11. Conflict and Contact

This DPA prevails over conflicting agreement terms for Customer Personal Data. Liability remains governed by the agreement except where Data Protection Law requires otherwise. DPA requests and transfer questions should be submitted through support and must identify the customer organization and applicable order.

Caseflow public contact: Atul Goel · Wittenkamp 24, 22307 Hamburg, Germany · +49-15560061837 · info@caseflow.my.