Skip to main content
Legal

Data Processing Agreement

Effective date: April 26, 2026  ·  GentleCase, Inc.

Enterprise and signed DPA. This page describes GentleCase's standard data processing terms, which are incorporated by reference into our Terms of Service and apply to all subscribers. Enterprise plan customers who require a countersigned DPA for GDPR Article 28 compliance should email legal@gentlecase.com to request a signed document.

1. Definitions

"Controller" means the law firm that determines the purposes and means of processing personal data of its clients using the GentleCase platform.

"Processor" means GentleCase, Inc., which processes personal data on behalf of the Controller.

"Personal Data" means any information relating to an identified or identifiable natural person processed through the Service, including client names, contact details, immigration identification numbers, and case documents.

"Processing" has the meaning given in applicable data protection law.

2. Roles and Responsibility

The Controller (your law firm) is responsible for determining the lawful basis for processing client personal data, obtaining any necessary consents, and instructing GentleCase on how that data should be processed. GentleCase processes personal data solely on documented instructions from the Controller and in accordance with this DPA and the Terms of Service.

3. Processing Details

4. GentleCase Obligations as Processor

GentleCase will:

5. Security Measures

GentleCase maintains the following technical and organizational measures:

6. Sub-processors

GentleCase uses the following sub-processors to deliver the Service. The Controller hereby provides general authorization to use these sub-processors:

GentleCase will notify the Controller of any intended changes to sub-processors at least 14 days in advance, giving the Controller the opportunity to object.

7. International Data Transfers

All personal data is stored and processed in U.S. Azure regions. GentleCase does not transfer personal data outside the United States except as necessary to provide the Service or as required by law. Enterprise customers may request geo-restricted regions for additional data residency requirements.

8. Data Subject Rights

The Controller is responsible for fulfilling data subject rights requests (access, rectification, erasure, portability, restriction). GentleCase provides platform tools to support these obligations and will assist upon written request. The platform's built-in right-to-deletion workflow provides cryptographically verifiable deletion records.

9. Audit Rights

GentleCase will make available all information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits or inspections conducted by the Controller or a mandated auditor, provided that the Controller gives reasonable advance notice and audits are conducted no more than once per year without cause.

10. Contact

For DPA inquiries, data breach notifications, or to request a countersigned DPA:
legal@gentlecase.com


This document was last reviewed by GentleCase legal counsel on April 26, 2026.