Data Processing Agreement
Effective date: April 26, 2026 · GentleCase, Inc.
1. Definitions
"Controller" means the law firm that determines the purposes and means of processing personal data of its clients using the GentleCase platform.
"Processor" means GentleCase, Inc., which processes personal data on behalf of the Controller.
"Personal Data" means any information relating to an identified or identifiable natural person processed through the Service, including client names, contact details, immigration identification numbers, and case documents.
"Processing" has the meaning given in applicable data protection law.
2. Roles and Responsibility
The Controller (your law firm) is responsible for determining the lawful basis for processing client personal data, obtaining any necessary consents, and instructing GentleCase on how that data should be processed. GentleCase processes personal data solely on documented instructions from the Controller and in accordance with this DPA and the Terms of Service.
3. Processing Details
- Subject matter: Immigration case management.
- Duration: The term of the subscription plus 90-day post-termination retention period.
- Nature: Storage, retrieval, display, transfer, and deletion of client records and documents.
- Categories of data: Identity (name, DOB, nationality), contact information, immigration status and identification numbers (A-Number, passport, SSN), case documents, and correspondence.
- Data subjects: Immigration clients of the Controller's law firm.
4. GentleCase Obligations as Processor
GentleCase will:
- Process personal data only on documented instructions from the Controller, unless required to do otherwise by applicable law.
- Ensure that personnel authorized to process personal data are bound by confidentiality obligations.
- Implement and maintain appropriate technical and organizational security measures (see Section 5).
- Not engage sub-processors without prior general or specific written authorization from the Controller (see Section 6).
- Assist the Controller in responding to data subject requests as reasonably practicable.
- Notify the Controller without undue delay upon becoming aware of a personal data breach affecting Controller data.
- Delete or return all personal data upon termination of services, at the Controller's choice.
- Provide the Controller with all information necessary to demonstrate compliance with GDPR Article 28.
5. Security Measures
GentleCase maintains the following technical and organizational measures:
- AES-256 encryption at rest for all personal data; field-level encryption for SSN, passport numbers, and A-Numbers.
- TLS 1.3 for all data in transit.
- Encryption keys managed in Azure Key Vault with access logging.
- Client documents stored in Azure Blob Storage with time-limited SAS URLs; files never traverse application servers.
- Tamper-evident audit log capturing every data access, modification, and deletion with user identity and timestamp.
- Role-based access control (Partner / Associate / Paralegal / Admin).
- Multi-factor authentication available; forced password change on first login.
- Session timeout after 8 hours of inactivity.
- SOC 2 Type II audit in progress (target: Q3 2026).
6. Sub-processors
GentleCase uses the following sub-processors to deliver the Service. The Controller hereby provides general authorization to use these sub-processors:
- Microsoft Azure (East US / West US) — cloud infrastructure, blob storage, key management.
- Stripe — payment processing. Stripe does not receive client personal data.
- Postmark — transactional email. Email content does not include client personal data.
GentleCase will notify the Controller of any intended changes to sub-processors at least 14 days in advance, giving the Controller the opportunity to object.
7. International Data Transfers
All personal data is stored and processed in U.S. Azure regions. GentleCase does not transfer personal data outside the United States except as necessary to provide the Service or as required by law. Enterprise customers may request geo-restricted regions for additional data residency requirements.
8. Data Subject Rights
The Controller is responsible for fulfilling data subject rights requests (access, rectification, erasure, portability, restriction). GentleCase provides platform tools to support these obligations and will assist upon written request. The platform's built-in right-to-deletion workflow provides cryptographically verifiable deletion records.
9. Audit Rights
GentleCase will make available all information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits or inspections conducted by the Controller or a mandated auditor, provided that the Controller gives reasonable advance notice and audits are conducted no more than once per year without cause.
10. Contact
For DPA inquiries, data breach notifications, or to request a countersigned DPA:
legal@gentlecase.com
This document was last reviewed by GentleCase legal counsel on April 26, 2026.
