Data Processing Addendum
Effective September 15, 2026 · Version v1.20
Version v1.20 · Effective September 15, 2026 · Published September 15, 2026
Effective September 15, 2026 · Version v1.20
Version v1.20 · Effective September 15, 2026 · Published September 15, 2026
This Data Processing Addendum ("DPA") supplements and forms part of the Terms of Service (the "Agreement") between OCTICASE, INC. ("Provider") and the Customer identified on the applicable Subscription Confirmation ("Customer"). It applies to business Customers of every Customer Type defined in the Agreement, including Law Firm, Medical / Case-Review, Records / Vendor and Settlement / Claims Customers, and Unverified Customers under Section 2.11 and Schedule E of the Agreement. It does not apply to Consumer Customers; Provider's processing of a Consumer Customer's Personal Data is governed by the Consumer Terms of Service and the Privacy Policy, under which Provider acts as the controller. It also applies, for the engagement records they hold through the Services, to an expert, consultant, vendor or partner that has accepted the Expert and Vendor Portal Terms, the Expert and Consultant Services Agreement or a Partner Agreement: this DPA applies to such a professional as "Customer", and to those records as Customer Data, whether or not it also holds a subscription, as Section 1A(f) of the Business Associate Agreement provides for PHI. For a professional that holds no subscription, references to the Agreement are to the agreement it has accepted, and references to Sections 7.3, 9.4, 12 and 16 of the Agreement are to the de-identification license, compulsory-process, limitation-of-liability and dispute-resolution provisions of that agreement.
This DPA addresses Customer's role as a controller (or business) of Personal Data and Provider's role as a processor (or service provider) when Provider processes Personal Data on Customer's behalf in connection with the Services. Where Provider acts as a controller of certain limited categories of information (such as account and billing data), Provider's handling of that data is described in Provider's Privacy Policy.
In the event of conflict between this DPA and the Agreement, this DPA controls with respect to the processing of Personal Data. Where PHI is processed under HIPAA, the Business Associate Agreement controls with respect to the handling of PHI.
"Applicable Data Protection Law" means all data protection and privacy laws applicable to the processing of Personal Data under this DPA. The Services are offered to United States customers, so these are the United States federal and state data protection and privacy laws that apply to a party, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA") and the comprehensive consumer privacy statutes of any other state as they take effect.
"Controller" means the entity that determines the purposes and means of processing Personal Data; equivalent to "business" under CCPA/CPRA.
"Customer Personal Data" means Personal Data within Customer Data, regardless of Customer Type.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data transmitted, stored, or otherwise processed by Provider or a Sub-processor. It does not include an unsuccessful attempt or an activity that does not compromise the security of Customer Personal Data, including pings and other broadcast attacks on a firewall, port scans, unsuccessful log-in attempts, denial-of-service attacks, and packet sniffing that does not result in access beyond headers.
"Personal Data" means personal data, personal information, or analogous terms as defined in Applicable Data Protection Law.
"Processing" means any operation performed on Personal Data, whether by automated means or not.
"Processor" means the entity that processes Personal Data on behalf of the Controller; equivalent to "service provider" or "contractor" under CCPA/CPRA.
"Sub-processor" means any third party engaged by Provider to process Personal Data on Provider's behalf.
"Data Subject Request" means a request from a data subject to exercise rights under Applicable Data Protection Law.
Capitalized terms not defined here have the meaning given in the Agreement.
Customer is the Controller (or business) of Customer Personal Data. Provider is the Processor (or service provider) and processes Customer Personal Data only for the purposes set forth in this DPA, the Agreement, and Customer's documented instructions. This applies to Customer of any Customer Type within the scope of this DPA.
To the extent that Provider acts as a Controller of certain Personal Data (e.g., information about Customer's billing account or about Authorized Users that Provider collects directly to authenticate them and operate the Services), Provider's handling of that information is governed by the Privacy Policy. This DPA does not transfer that information to a Processor relationship.
Transfer, sharing and collaboration between Customers. Where Customer transfers a matter to another Customer, gives another Customer access to it or collaborates with another Customer on it under Section 4.14 of the Agreement, the disclosure to that other Customer is made on Customer's instruction and is Customer's own disclosure. On a transfer, Customer remains the Controller of the transferred data until the receiving Customer accepts, and the receiving Customer is the Controller from acceptance; on view-only access or collaboration, Customer remains the Controller, and the other Customer processes the matter on Customer's instruction under its own DPA with Provider, retaining after revocation, or after access ends under Section 4.14 of the Agreement, only what it lawfully exported while access was open. Provider is the Processor of each Customer for the Customer Personal Data that Customer holds through the Services and is not a party to the arrangement between them. Data that an Unverified Customer holds for a law firm it has identified under Section 2.11 of the Agreement is that firm's Customer Personal Data; the firm is its Controller and the Unverified Customer processes it on the firm's instruction.
Platform Engagements and the Expert and Vendor Portal. Where Customer transmits Customer Personal Data to an expert, consultant, vendor or partner through the Expert and Vendor Portal or through a Platform Engagement with an expert, consultant or partner under Section 4.16 of the Agreement, the disclosure is made on Customer's instruction and is Customer's own disclosure; the recipient processes that data for Customer under the Expert and Vendor Portal Terms, the Default Engagement Terms or the partner's published terms (and, where those terms are silent, the Default Engagement Terms) (and, where PHI is involved, under its own Business Associate Agreement with Provider), and not as Provider's Sub-processor. Provider is the Processor of Customer for the engagement record Customer holds and of the recipient for the engagement record the recipient holds through the Services. Where Provider enables payouts to Sellers, the identity, tax and bank information a Seller provides to Provider's payment processor to receive them is collected by that processor as an independent Controller under its own privacy notice, as the Subprocessor List and the Privacy Policy describe. Payouts are not enabled today and no such information has been collected.
Subject matter: provision of the Services as described in the Agreement. Duration: from the Effective Date of the Agreement until deletion of Customer Personal Data in accordance with this DPA.
Provider processes Customer Personal Data as necessary to: (a) provide and operate the Services for Customer; (b) prevent fraud and abuse; (c) provide support; (d) comply with legal obligations applicable to Provider; (e) as further instructed by Customer in writing; and (f) create de-identified and aggregated data under Section 4.9. Provider does that on Customer's instruction, under the license Customer grants in Section 7.3 of the Agreement, and not as a business purpose that Provider designates for itself for the purposes of Section 6; the use of the resulting de-identified data to train, retrain or fine-tune any model requires Customer's separate agreement, given or withheld on Screen B1 of our Consent Screens, as Section 4.9 provides.
As detailed in Annex I.
Customer's use of the Services as described in the Agreement constitutes its complete documented instructions. Provider will inform Customer if, in Provider's opinion, an instruction violates Applicable Data Protection Law, but is not obligated to verify the lawfulness of Customer's instructions.
Customer represents that it has all rights, consents, and lawful bases necessary to provide Customer Personal Data to Provider for the purposes described.
Provider shall ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations no less protective than those in the Agreement.
Provider implements the technical and organizational measures set forth in Annex II to ensure a level of security appropriate to the risk. Provider may update Annex II to reflect ongoing security improvements; updates will not materially decrease the level of protection.
Customer authorizes Provider to engage the Sub-processors identified in the Subprocessor List that forms part of the Agreement, which Provider makes available on request and, from the date the Beta opens, publishes at https://trust.octicase.com/subprocessors. The Subprocessor List is the authoritative version and identifies every Sub-processor then engaged, including any whose engagement is not yet reflected on that page. Provider will: (a) maintain the public list and update it before engaging a new Sub-processor; (b) notify Customer at least thirty days before engaging a new Sub-processor (notification may be by email, in-app, or RSS); (c) impose data protection obligations on each Sub-processor no less protective than those in this DPA; and (d) remain liable for the acts and omissions of Sub-processors. Customer may object to a new Sub-processor on reasonable grounds within thirty days of notification by emailing privacy@octicase.com; the parties will work in good faith to resolve, failing which Customer may terminate the affected Services. Where Customer terminates the affected Services because an objection is not resolved, Provider will refund the pro-rata portion of any prepaid fees covering the period after the effective date of that termination.
Scope note on placed personnel. As Section 5 provides, Provider engages no supplier of personnel, and no case manager has been placed with any Customer under Section 2.9 (Placed Personnel) of the Agreement; no third party processes Customer Personal Data in that capacity. Should Provider engage a supplier of personnel and case managers be placed under that Section, they will work on Customer's matters directly, their access to Personal Data will be operational rather than incidental to maintenance, and it will be authorized on the same basis as any other Sub-processor under this Section, disclosed in the Subprocessor List and notified under this Section before any placement begins. For the avoidance of doubt, an Authorized User identified by Customer under Section 2.10 of the Agreement, including an individual who is also an Authorized User of another Customer, acts under Customer's account and on Customer's instructions, and is not Provider's Sub-processor. The same applies to another Customer, an Unverified Customer, or an expert, consultant, vendor or partner that receives Customer Personal Data on Customer's instruction under Section 2 of this DPA, through the Expert and Vendor Portal or a Platform Engagement: each receives it for Customer, not for Provider, and is not Provider's Sub-processor.
Provider will assist Customer in responding to Data Subject Requests, taking into account the nature of processing. Where a Data Subject Request relates to Customer Personal Data, Provider will: (a) without undue delay, forward to Customer any Request received directly; (b) make available to Customer the technical means to respond; and (c) not respond directly to the data subject without Customer's authorization, except where required by law or to confirm receipt.
Provider will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with regulators, to the extent that assistance is required by a data protection law applicable to Customer and relates to the processing Provider performs on Customer's behalf.
Provider will notify Customer without undue delay after becoming aware of a Personal Data Breach, and in any event within seventy-two (72) hours. Provider's internal escalation target is shorter and is described in Annex II, but the seventy-two hour period is the contractual commitment. Notice is given to the security or privacy contact identified on the Subscription Confirmation and, failing that, to the administrative contact on Customer's account, by email and, where the matter is urgent, by telephone as well. The notification will include the nature of the breach, categories and approximate number of data subjects, likely consequences, and mitigation measures. Where the breach involves PHI, the Business Associate Agreement applies the same seventy-two hour period, so a single deadline governs.
Costs. Where a Personal Data Breach arises from Provider's act or omission or that of its Sub-processor, Provider will bear the reasonable and documented costs Customer incurs in meeting its notification obligations under applicable breach notification laws, including forensic investigation attributable to the breach, notification to affected individuals and regulators, and credit monitoring where it is customary for the categories of information involved. Those costs are subject to Section 12 of the Agreement, including Section 12.3A. Where the breach involves PHI, the equivalent provision of the Business Associate Agreement applies instead, so the two provisions do not accumulate.
On termination of the Agreement, Customer may retrieve Customer Personal Data through the export function described in the Agreement for thirty (30) days after the effective date of termination. Provider will notify Customer before deletion begins. After that period, Provider will delete or return Customer Personal Data at Customer's choice, and absent a contrary instruction will delete it from active production systems within sixty (60) days of the effective date of termination. Where an Unverified Customer holds Customer Personal Data for a law firm it has identified, the retrieval window and the choice between deletion and return on termination of either account belong to that firm, and Provider gives the pre-deletion notice to that firm, as the Data Retention and Deletion Policy provides.
Platform Engagement transaction records and the access records of Section 4.14 of the Agreement are retained for the periods the Data Retention and Deletion Policy states and are exportable as Section 7.5 of the Agreement provides; the record and deliverables of an open Platform Engagement remain accessible as Section 4.16 of the Agreement provides, even where that is later than the retrieval window. For a professional within the scope paragraph of this DPA, the export period its Expert and Consultant Services Agreement or Partner Agreement gives applies instead of the thirty-day window, and its engagement records remain the engaging Customer's Customer Data for the purposes of deletion.
Deletion from active production systems does not immediately erase encrypted backups. Backups are overwritten in the ordinary retention cycle described in Annex II, and during that period the data is not accessed or used for any purpose. Audit logs of access and changes are retained for the documentation retention period stated in Annex II.
Provider will retain Customer Personal Data beyond these periods only where retention is required by law, or where either party has notified the other that the data is subject to a litigation hold, a preservation obligation, or compulsory legal process. Provider will delete data held on that basis once the obligation ends.
Provider will make available to Customer information necessary to demonstrate compliance with this DPA. Once Provider holds a SOC 2 report or equivalent third-party audit, Provider will make the then-current report available once per year on Customer's reasonable request; until then, Provider will make available its security documentation and the current status of its assessment. Customer may conduct an audit beyond review of audit reports only where required by Applicable Data Protection Law and at Customer's expense, on reasonable advance notice and during business hours.
Where Customer enables AI features, Provider and its AI Sub-processors process Customer Personal Data solely to generate outputs for Customer. Neither Provider nor any AI Sub-processor will use Customer Personal Data to train, retrain, fine-tune, or otherwise improve any foundation model or any model that serves another customer. No AI Sub-processor retains Customer Personal Data beyond the period necessary to return the output and to meet its own abuse-monitoring obligations. No AI Sub-processor, and no further sub-processor engaged by it, processes Customer Personal Data unless it is engaged under terms that impose these restrictions, and under a Business Associate Agreement where PHI may be processed, and Provider will not enable an AI feature until that is in place throughout the chain.
De-identification and re-identification. Customer authorizes Provider to create de-identified and aggregated data from Customer Personal Data under, and subject to the conditions of, Section 7.3 of the Agreement, and Provider may retain, use, analyze, combine and license that data, including to third parties and for commercial purposes, as that Section provides. Where Customer holds Customer Personal Data under Section 4.14 of the Agreement on another Customer's instruction, as an Unverified Customer for a firm it has identified, or as the recipient of a Platform Engagement, the authorization is given by the Customer that controls the matter, as Section 7.3 of the Agreement provides, and not by the recipient. Provider de-identifies so that the information cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual or household, takes reasonable measures to ensure that it cannot be associated with one, and publicly commits to maintain and use it only in de-identified form and not to attempt to re-identify it, as Cal. Civ. Code Section 1798.140(m) requires; for information derived from PHI or from medical information, the standard of 45 CFR 164.514(b) applies, under the Business Associate Agreement where it applies and otherwise under Section 7.3(b) of the Agreement. Provider shall not re-identify, nor attempt to re-identify, any information de-identified from Customer Personal Data, and shall not disclose to any person the keys, parameters or other details that would permit re-identification; the method of de-identification itself is published in the Privacy Policy, as Section 7.3(e) of the Agreement requires. Any license of de-identified data to a third party is made under a written contract, our Data Product License Agreement, that prohibits re-identification and any attempt at it, requires the same of the recipient's own recipients, and, where the data was derived from health information, contains the terms that Cal. Civ. Code Section 1798.148 requires. Provider shall not use information de-identified from Customer Personal Data to train, retrain or fine-tune any model, unless Customer agrees to that use in writing. Customer gives or withholds that agreement on a separate screen presented at onboarding and available at any time in Customer's account settings, whose wording is Screen B1 of our Consent Screens, which states the categories of data concerned, that the models trained on them are Provider's and serve Provider's other customers, and how to withdraw. Withdrawal is effective for data created after it and does not require Provider to retrain or discard a model already trained, except where a court, a regulator or applicable law requires it, in which case Provider will do so; Provider states this on that screen rather than leaving it to be discovered. Provider records the agreement, the version of the text shown and the date, and never applies it retroactively, as Section 7.3(d) of the Agreement provides. These restrictions are stated expressly because de-identified information is no longer Personal Data and would otherwise fall outside this DPA; they are the same rules that Section 2 of the Business Associate Agreement states for information derived from PHI. De-identified and aggregated data created under this paragraph is not Customer Personal Data, is not subject to Sections 4.4, 4.7 or 8.3, and survives deletion of the Customer Personal Data from which it was derived, as Section 7.3 of the Agreement provides.
Section 9.4 of the Agreement governs Provider's response to a subpoena, court order, warrant, or other compulsory legal process for Customer Data, including Provider's obligation to notify Customer before responding where the law permits, to cooperate with Customer's lawful efforts to challenge the request, and to limit its response to the data legally required.
The parties acknowledge that Customer Personal Data may include material subject to the attorney-client privilege, the work product doctrine, or an equivalent professional confidentiality obligation. Provider's access to that material as a processor is for the sole purpose of providing the Services and is not intended to, and does not, waive any privilege or protection.
Customer Personal Data is hosted in the United States. Provider is OCTICASE, INC., organized under the laws of Delaware. Provider's own personnel are located in the Republic of Panama and access Customer Personal Data hosted in the United States for support, administration and security operations. That access is subject to the confidentiality obligations in Section 4.1 and the technical and organizational measures in Annex II. Provider engages no supplier of personnel; should Provider in future engage a contractor who will access Customer Personal Data, that contractor is a Sub-processor under Section 4.3 and is added to the Subprocessor List with the notice that Section provides.
Provider does not transfer Customer Personal Data on the basis of the European or United Kingdom transfer regimes, because those regimes do not govern the processing described above. If Customer establishes that the GDPR or the UK GDPR applies to its use of the Services, the parties will execute the standard contractual clauses adopted by the European Commission in Decision 2021/914, Module Two (Controller to Processor), together with the UK International Data Transfer Addendum where applicable, and those clauses will govern the affected transfers. Every dispute between Provider and Customer remains governed by Section 16 of the Agreement.
Where Customer Personal Data includes personal information or personal data regulated by a United States state privacy law, Provider acts as Customer's service provider or processor, as that law denominates the role, and Customer acts as the business or controller. This includes the CCPA/CPRA and the comprehensive privacy laws of any other state as they take effect. Provider:
Provider will comply with the obligations that each applicable state privacy law places on a service provider or processor, will assist Customer with consumer rights requests, and will make available the information reasonably necessary for Customer to demonstrate compliance. Where a state law uses the controller and processor vocabulary rather than the business and service provider vocabulary, this Section applies with the corresponding terms substituted.
Where Customer Personal Data includes PHI subject to HIPAA, the Business Associate Agreement between Provider and Customer governs the handling of that PHI. The BAA controls in the event of conflict between this DPA and the BAA with respect to PHI. The BAA does not apply to Consumer Customers managing only their own health information; that Personal Data is governed by the Consumer Terms of Service and the Privacy Policy.
Each party's liability under this DPA is subject to the limitation of liability provisions in the Agreement.
In the event of conflict, the order of precedence is: (i) the BAA, for matters concerning PHI; (ii) this DPA; and (iii) the Agreement. Where standard contractual clauses have been executed under Section 5, they control as to the transfers they govern, and that precedence does not displace Section 16 of the Agreement for any dispute between Provider and Customer.
This DPA is effective on the Effective Date of the Agreement and continues until Customer Personal Data is deleted or returned in accordance with Section 4.7.
This DPA is governed by the laws of the State of Delaware. Disputes arising under this DPA are subject to the dispute resolution provisions of Section 16 of the Agreement, provided that Section 16.8 (non-waivable consumer protections) controls to the extent it applies.
Controller / Business: Customer
Address: as set out in the Subscription Confirmation or, where Customer takes part in the Beta without a subscription, as recorded on Customer's account at registration. Contact person: the security or privacy contact so identified and, failing that, the administrative contact on Customer's account.
Activities relevant to the processing: receipt of Services from Provider in accordance with the Agreement.
Role: Controller / Business, as denominated by Applicable Data Protection Law. Where data is held by an Unverified Customer for a law firm it has identified, the firm is the Controller; where a matter has been transferred under Section 4.14 of the Agreement, the receiving Customer is the Controller from acceptance.
Processor / Service Provider: Provider
OCTICASE, INC., 2140 S Dupont Highway, Camden, Kent County, Delaware 19934, c/o PARACORP Incorporated
Activities: provision of the Services.
Role: Processor / Service Provider, as denominated by Applicable Data Protection Law.
Categories of Data Subjects:
Categories of Personal Data:
Frequency of Transfer:
Continuous, during the term of the Agreement.
Nature of Processing:
Hosting, storage, processing for service operation, AI-assisted analysis (where enabled), transmission, support, security; transmission to recipients on Customer's instruction under Section 2; creation of de-identified and aggregated data under Section 4.9.
Purpose:
Provision of the Services.
Period for Retention:
As described in Section 4.7 of this DPA and Provider's Data Retention and Deletion Policy.
For Sub-processor Transfers:
Subject matter, nature, and duration as set forth above; performed only as necessary to provide the Services.
Where data subjects are in California, the California Privacy Protection Agency and the California Attorney General. Where data subjects are in another state, the regulator designated by that state's privacy law, which is ordinarily the state Attorney General.
Provider implements and maintains the technical and organizational measures listed below.
| Measure | Description |
|---|---|
| Encryption at Rest | AES-256 for all Customer Data and PHI stored in databases and object storage. |
| Encryption in Transit | TLS 1.2 or higher for all data in transit, including between regions and to subprocessors. |
| Access Control | Role-based access; principle of least privilege; quarterly access reviews; MFA mandatory for staff. Single sign-on for Customers is planned and is not available today; Customers authenticate with a password and MFA as the Authentication row describes. |
| Audit Logging | Comprehensive audit logs of access and changes, retained six years, consistent with Provider's documentation retention practice under 45 CFR 164.316(b)(2). |
| Authentication | MFA required for staff and configurable for Customers; password policy with complexity requirements; 5-attempt lockout. |
| Vulnerability Management | Documented patch SLAs by severity. Provider will establish a quarterly vulnerability scanning program and will commission an annual third-party penetration test. Neither the scanning program nor the penetration test is in place as of the date of this DPA, and Provider makes no representation that a vulnerability scan or a third-party penetration test has been performed. |
| Backup and Recovery | Weekly encrypted logical database backups retained thirteen months, with multi-AZ replication; documented recovery objectives, namely a recovery point objective of twenty-four (24) hours, supported by the point-in-time recovery backups described in the Data Retention and Deletion Policy and not with the weekly logical backup, which is retained for archive and is not the recovery path, and a recovery time objective of seventy-two (72) hours, which is the objective that applies today because recovery requires a full rebuild of the primary infrastructure. Incremental disaster-recovery replication to a second cloud provider is planned and is not in operation; no copy of Customer Data or PHI is held with a second cloud provider today. Where that replication is placed in operation it will be under an executed Business Associate Agreement, and the recovery time objective for a recovery that uses the disaster-recovery replica will be five (5) hours. Provider will test disaster recovery at least annually; no such test has been performed to date. |
| Incident Response | Documented incident response plan aligned with NIST SP 800-61. Internal escalation target of 24 hours for confirmed incidents; contractual notification to Customer as stated in Section 4.6. |
| Workforce Security | Background checks per local law; HIPAA training for all workforce; offboarding within 24 hours of departure. |
| Subprocessor Security | Due diligence at onboarding, recorded in the Subprocessor List. A Business Associate Agreement is executed with each Sub-processor that Provider engages to process PHI. One Sub-processor engaged for transactional and inbound email is not covered by a Business Associate Agreement today; Provider routes no PHI to it, and will either execute one or place the inbound filtering control in operation before that route can carry clinical content, as the Subprocessor List states. Provider reviews each Sub-processor annually; the first review cycle falls due one year after the date the Services launch. |
Provider's full Information Security Policy is available to Customers under NDA on request to legal@octicase.com. A summary is available from Provider on request and, from the date the Services launch, at https://trust.octicase.com/security.
The current list of authorized Sub-processors is the Subprocessor List forming part of the Agreement, available from Provider on request and, from the date the Beta opens, published and maintained at https://trust.octicase.com/subprocessors. Provider may engage new Sub-processors subject to the notice and objection process in Section 4.3 of this DPA.
-- END OF DATA PROCESSING ADDENDUM --