Last updated: March 2026 | Version 1.0
This Data Processing Agreement (“DPA”) forms part of the Agreement between Causio (“Processor”) and the subscribing law firm (“Controller”) for the provision of AI-powered legal case management services. This DPA is entered into pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
“Personal Data” means any information relating to an identified or identifiable natural person as defined in Article 4(1) GDPR.
“Processing” means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, erasure, or destruction.
“Data Subject” means the identified or identifiable natural person to whom the Personal Data relates, including but not limited to clients of the Controller, case participants, and authorized users.
“Sub-processor” means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
Subject Matter: Provision of AI-powered legal case management services, including case data storage, AI analysis, document processing, voice transcription, and real-time collaboration tools.
Duration: Processing shall continue for the duration of the Agreement between the Controller and Processor, plus any retention period required by law or agreed upon in writing.
Nature and Purpose: The Processor processes Personal Data to provide the Controller with case management, AI-driven legal analysis, document intelligence, client portal services, and associated functionality as described in the Agreement.
Types of Personal Data: Names, contact information, case details, legal documents, voice recordings, financial information related to cases, correspondence, evidence materials, and any other data uploaded by the Controller or their clients.
Categories of Data Subjects: Lawyers and staff of the Controller, clients of the Controller, case participants (witnesses, opposing parties), and other individuals whose data is included in case materials.
The Processor shall assist the Controller in fulfilling its obligations to respond to requests from Data Subjects exercising their rights under Chapter III of the GDPR, including:
The Processor shall notify the Controller without undue delay upon receiving a request from a Data Subject. The Processor shall not respond to such requests directly unless authorized by the Controller.
The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
The Controller hereby provides general authorization for the Processor to engage the Sub-processors listed below. The Processor shall notify the Controller of any intended changes to Sub-processors, providing the Controller with an opportunity to object within 30 days.
| Sub-processor | Purpose |
|---|---|
| Convex, Inc. | Real-time database, server functions, file storage |
| Clerk, Inc. | Authentication, user management, SSO |
| Stripe, Inc. | Payment processing, subscription management |
| Anthropic, PBC | AI analysis (Claude API) — case analysis, evidence scoring |
| OpenAI, Inc. | Voice transcription (Whisper), text embeddings |
| Resend, Inc. | Transactional email delivery |
All Sub-processors are bound by data processing agreements with equivalent or stricter data protection obligations than those set forth in this DPA.
Where Personal Data is transferred outside the European Economic Area (EEA), the Processor shall ensure that such transfers are subject to appropriate safeguards as required by Chapter V of the GDPR, including:
The Processor is actively working toward full EU data residency for all core processing operations. The Controller will be notified when this migration is complete.
The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data breach. Such notification shall include:
The Processor shall cooperate with the Controller and take reasonable commercial steps to assist in the investigation, mitigation, and remediation of each breach.
This DPA shall remain in effect for the duration of the Agreement. Upon termination of the Agreement:
For questions regarding this Data Processing Agreement or our data protection practices, contact our Data Protection Officer:
Email: dpo@causio.eu
Address: Carrer de Balmes, 191, 08006 Barcelona, Spain