Data processing agreement (DPA)
Last updated:
This addendum governs the processing that LegalTech ("the Provider", "the Processor") performs for the law firm ("the Firm", "the Controller") in the course of supplying CaseFlow, and is an integral part of the licence agreement. Its terms have the meaning given in Israel's Protection of Privacy Law, 5741-1981, and the Protection of Privacy Regulations (Data Security), 5777-2017. The full signable text is delivered to the Firm with the order; this page presents its main provisions.
1. Scope and the founding principle
1.1 The Firm's case data (clients, parties, documents, calendar, charges) is stored encrypted on the Firm's computers and never reaches the Provider. For that data the Provider is not a processor, and this addendum does not apply to it.
1.2 The addendum applies to the processing activities the Provider actually performs on its servers, listed in section 2, and only to them.
2. Processing activities
| Activity | Data types | Source | Retention |
|---|---|---|---|
| Licensing and activation | Licensee name, e-mail, licence key, one-way computer fingerprint, version, IP address on licence events | The Firm | Life of the licence relationship |
| Remote signing (optional) | The PDF to be signed, signer's name, e-mail, phone, signature placements, IP and viewing/signing times | The Firm and the signer | Life of the licence relationship, or until a deletion request |
| Managed AI (optional) | The text the lawyer chooses to send; usage and cost meters | The Firm | Content not stored; meters for the life of the licence relationship |
| Remote support (optional, arranged in advance) | The screen of the Firm's seat during a support session the Firm approved, through a relay the Provider runs | The Firm | Not stored; session log (time, duration) one year |
| Support requests | Name, e-mail, phone, content of the request | The Firm | Until resolved, at most one year |
3. The Controller's instructions
3.1 The Provider processes the data only on the Firm's documented instructions, as reflected in the licence agreement, this addendum and the settings the Firm chooses in the software.
3.2 The Provider does not use the data for its own purposes, does not sell it and does not train models on it.
4. Sub-processors
4.1 The Provider may use the following sub-processors, all in the European Union: Hetzner Online GmbH (server hosting, Falkenstein, Germany); the AI model provider for managed AI, in an EU processing region; an e-mail delivery provider (acknowledgements and licence correspondence).
4.2 The Provider gives the Firm 30 days' notice of a replaced or added sub-processor, and the Firm may object on reasonable grounds.
4.3 No data is transferred to the United States.
5. Data security
5.1 The Provider complies with the Data Security Regulations at the security level applicable to its database, including: encrypted traffic, isolation of the service environment, access limited to the development team, security event logging, and regular security updates.
5.2 The Firm is responsible for the security of its own seats, its backups and access control on the office computers, since the case data lives there and not with the Provider.
6. Security incidents
The Provider notifies the Firm of a serious security incident concerning the data in section 2 without delay, and no later than 72 hours from discovery, with a description of the incident, the data affected and the steps taken, and assists the Firm in reporting to the Privacy Protection Authority where required.
7. Assistance with data-subject rights
The Provider assists the Firm in answering data-subject requests (access, correction, deletion) within 10 business days of the Firm's request.
8. Audit
Once a year and by prior arrangement, the Firm may obtain from the Provider a report on security measures and sub-processors, and in case of a substantiated suspicion of a breach, conduct an audit through an agreed reviewer under a non-disclosure agreement.
9. Termination and deletion
At the end of the licence agreement the Provider deletes the data in section 2 within 30 days, except what the law requires to keep, and confirms this in writing at the Firm's request. The case data stays on the Firm's computers and needs no return, because it was never with the Provider.
10. Contact
For matters concerning this addendum: privacy@caseflow.co.il.