Este documento está disponible solo en inglés, y la versión en inglés es el texto vigente.

Data Processing Agreement

Effective date: September 10, 2026
Last updated: September 10, 2026

This Data Processing Agreement ("DPA") is entered into between Esqase, Inc. ("Esqase," "Processor") and the law firm or organization that has accepted the Esqase Terms of Service ("Firm," "Controller"). This DPA forms part of the Terms of Service and governs Esqase's processing of personal data on the Firm's behalf in connection with the Service. Capitalized terms not defined in this DPA have the meanings given to them in the Terms of Service, including Account, Authorized User, Client Data, External User, Firm, Public-Facing Features, Service, Subscription, and User Content.

1. Definitions

In this DPA:

  • "Applicable Data Protection Law" means all privacy and data protection laws applicable to the processing of Personal Data under this DPA, each as amended, replaced, or supplemented from time to time, including where applicable: the EU General Data Protection Regulation (GDPR) (EU 2016/679); the UK GDPR, the Data Protection Act 2018, and the Data (Use and Access) Act 2025; the Swiss Federal Act on Data Protection; the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and the regulations made under it; the comprehensive consumer privacy laws of other U.S. states as they come into effect, including those of Colorado, Connecticut, Texas, and Virginia; and other applicable national, federal, or state laws.
  • "Controller" means the Firm, who determines the purposes and means of processing Personal Data.
  • "Data Subject" means an identified or identifiable natural person whose Personal Data is processed.
  • "Personal Data" means any information relating to a Data Subject that is processed through the Service on behalf of the Firm. Personal Data is the subset of Client Data, as that term is defined in the Terms of Service, that relates to an identified or identifiable natural person.
  • "Processing" means any operation performed on Personal Data, including collection, storage, retrieval, use, transmission, or deletion.
  • "Processor" means Esqase, acting on the Controller's instructions.
  • "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, Personal Data processed under this DPA. It does not include an unsuccessful attempt or an activity that does not compromise the security of Personal Data, such as a ping, a port scan, a failed log-in attempt, or a denial-of-service attack that does not result in access to Personal Data.
  • "Subprocessor" means a third-party engaged by Esqase to process Personal Data on behalf of the Firm.

2. Scope and Roles

2.1 Controller and Processor

The Firm is the Controller of Personal Data uploaded to or generated within the Service. Esqase is the Processor and processes Personal Data only on the Firm's instructions and for the purposes of providing the Service. Account, billing, and usage data that Esqase collects for its own purposes (such as Authorized User registration, subscription billing, and product usage analytics) is processed by Esqase as a controller and is governed by the Privacy Policy, not this DPA.

2.2 Categories of Personal Data

The Firm may submit Personal Data to the Service, which may include:

  • Contact information (name, email, phone, address)
  • Matter and case details, including leads and intake form submissions
  • Billing and financial records, including trust and operating account transactions
  • Documents and their contents
  • Communications, including email, phone and meeting logs, notes, comments, and internal messages between the Firm's members, and files shared through them
  • Calendar events and scheduling information
  • eSignature audit-trail data (signer identity, IP address, timestamp, and device information)
  • Credentials used to verify an External User's access to a link the Firm has shared
  • Technical identifiers collected when an External User opens a page the Firm shares, including IP address, browser and device information, and the cookies described in the Cookie Policy
  • Device tokens used to deliver push notifications
  • User account information for Authorized Users, to the extent processed within the Service on the Firm's behalf
  • Any other Personal Data the Firm submits through the Service or its API

2.3 Categories of Data Subjects

Data Subjects may include the Firm's clients and prospective clients, its contacts, opposing parties and their representatives, witnesses and other third parties whose details the Firm records, Authorized Users, and External Users who interact with the Firm through the Public-Facing Features described in Section 8 of the Terms of Service, including document signers, document recipients, form submitters, payers, and booking invitees.

2.4 Purpose of Processing

Esqase processes Personal Data solely to provide, operate, maintain, and improve the Service as directed by the Firm, and as further described in this DPA and the Privacy Policy.

2.5 Automated Content Analysis and Search Indexing

The Service uses Google's Vertex AI to make Personal Data findable:

  • Document indexing. The contents of documents the Firm uploads to or writes in the Service are sent to a Google Gemini model on Vertex AI, which returns a short description of the document and keywords. Esqase stores that output with the document and uses it for search. A Firm Owner can turn this processing off for the whole Firm in the Service's settings, after which documents added or updated are not sent. Turning it off does not delete output already stored. For a Firm that has accepted a Business Associate Agreement or the data processing agreement Esqase publishes for the Firm's country, this is switched off for the whole Firm on acceptance, and a personal injury case carries a second switch of its own that starts off, so a document on a personal injury matter is sent only when both are on.
  • Search embeddings. Text drawn from records including contacts, matters, tasks, events, notes, documents, invoices, payments, activities, communication logs, form submissions, firm members, and invitations is sent to a Google text embedding model on Vertex AI, which returns the numeric representations that power search. Search terms entered in the Service are sent to the same model so that a query can be compared against those records. This processing is required for search to function and is not covered by the switch described above.

Esqase does not use Personal Data to train or fine-tune any artificial intelligence or machine learning model, and its agreement with Google prohibits Google from using Personal Data to train or fine-tune Google's models without Esqase's prior permission or instruction, which Esqase does not give. Model output is stored within the Firm's own tenant and is not used for any other Firm. No decision about any Data Subject is made by these models.

Document indexing on Vertex AI follows the Firm's country: Firms in the European Economic Area and the United Kingdom are processed in Google's European region, Firms in Australia and New Zealand in Google's Australian region, and all other Firms, including Firms in the United States, in the United States. Search embeddings follow the same routing. The Firm's records themselves are stored in the United States, whatever the Firm's country.

2.6 Special Categories of Personal Data

The Service is built for legal practice, and the Firm may submit Personal Data that Applicable Data Protection Law treats as sensitive. This includes data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, and trade union membership, genetic and biometric data, data concerning health or sex life, and data relating to criminal convictions, offenses, and proceedings (Articles 9 and 10 of the GDPR and of the UK GDPR) and "sensitive personal information" as defined by the CCPA.

Esqase does not request, require, or separately process that data. It processes it only as part of the Personal Data the Firm chooses to submit, and applies the measures in Section 5 to all Personal Data without distinction. The Firm is responsible for establishing a lawful basis for processing that data.

3. Processing Instructions

3.1 Compliance with Instructions

Esqase will process Personal Data only in accordance with the Firm's documented instructions, including those set forth in the Terms of Service, this DPA, and Section 17.3, and including with regard to transfers of Personal Data to a third country or an international organization, unless required to do otherwise by applicable law. If Esqase is required by law to process Personal Data other than as instructed, it will notify the Firm to the extent permitted by law.

3.2 Unauthorized Instructions

If Esqase reasonably believes that an instruction from the Firm violates Applicable Data Protection Law, it will inform the Firm immediately. Esqase is not required to follow instructions that it believes would cause it to violate applicable law.

3.3 CCPA and CPRA Service Provider Commitments

To the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"), applies to Personal Data processed under this DPA, Esqase acts as a "service provider" to the Firm, which acts as a "business." The Firm discloses Personal Data to Esqase only for the business purpose of providing, operating, maintaining, securing, and supporting the Service as described in the Terms of Service and this DPA, and not for monetary or other valuable consideration. Esqase will:

  • not sell or share Personal Data, as "sell" and "share" are defined in the CCPA;
  • not retain, use, or disclose Personal Data for any purpose other than the business purpose stated above, including not retaining, using, or disclosing it for a commercial purpose other than that business purpose, and not doing so outside the direct business relationship between Esqase and the Firm, except where the CCPA expressly permits a service provider to do so;
  • not combine Personal Data with personal information it receives from or on behalf of another person, or that it collects from its own interaction with a consumer, except where the CCPA expressly permits a service provider to do so;
  • comply with the obligations the CCPA places on service providers, and provide the same level of privacy protection to Personal Data as the CCPA requires of the Firm;
  • allow the Firm to take reasonable and appropriate steps to confirm that Esqase uses Personal Data in a manner consistent with the Firm's obligations under the CCPA, which the Firm may exercise through Section 11;
  • notify the Firm promptly, and in any event within ten business days, after determining that it can no longer meet its obligations under the CCPA, and allow the Firm, on notice, to take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Data; and
  • enable the Firm to comply with consumer requests under the CCPA, as provided in Section 7.

Esqase certifies that it understands the restrictions in this Section and will comply with them.

3.4 Other U.S. State Privacy Laws

Where a comprehensive consumer privacy law of another U.S. state applies to Personal Data processed under this DPA, Esqase acts as a "processor" (or the equivalent term that law uses) to the Firm as "controller." The processing details those laws require to be stated in the contract are recorded in Annex A. Esqase will: process Personal Data only on the Firm's instructions; ensure that each person who processes it is bound by a duty of confidentiality (Section 4); assist the Firm with consumer rights requests, with the security of processing, with breach notification, and with any data protection assessment the law requires (Sections 5, 7, 8, and 9); at the Firm's direction, delete or return Personal Data at the end of the provision of the Service (Section 12); make available to the Firm the information it reasonably needs to demonstrate compliance and allow assessments as provided in Section 11; and engage a Subprocessor only under a written contract imposing obligations equivalent to those in this DPA (Section 6.4).

3.5 De-identified and Aggregated Data

Esqase may create de-identified and aggregated data from Personal Data and use it to operate, secure, maintain, and improve the Service, as Section 5.5 of the Terms of Service permits. Esqase will maintain that data in a form that cannot reasonably be used to infer information about, or otherwise be linked to, a particular individual or Firm, will not attempt to re-identify it, and will not disclose it in a way that identifies the Firm as its source. This use is an instruction of the Firm for the purposes of Section 3.1, and is not a sale or share of Personal Data for the purposes of Section 3.3.

4. Confidentiality

Esqase will ensure that persons authorized to process Personal Data are subject to appropriate confidentiality obligations and are trained on data protection requirements. Access to Personal Data is restricted to Esqase personnel who need it to provide the Service.

5. Security

5.1 Technical and Organizational Measures

Esqase will implement and maintain appropriate technical and organizational security measures to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. These measures include:

MeasureDescription
Encryption in transitAll data transmitted between clients and servers uses TLS, and every Esqase application sends HTTP Strict Transport Security, so a browser will not fall back to an unencrypted connection.
Encryption at restThe database and the file storage are encrypted at rest with keys managed by the underlying cloud platform. Two-factor authentication seeds and document share tokens are additionally encrypted by Esqase at the application layer, with AES-256-GCM, before they are stored.
Access controlRole-based access control enforced in the database on every statement. Row level security is enabled and forced on every table, and the application connects as a database role that cannot bypass it, so a read or a write outside the Firms the acting user belongs to fails at the data layer rather than in the interface.
AuthenticationSign-in by email and password with email verification. Optional two-factor authentication by authenticator app or emailed one-time code, with single-use recovery codes, which a Firm Owner can require for every member of the Firm. Sessions are verified on the server on every request and are subject to both an absolute lifetime and an idle timeout.
Tenant segregationEvery record carries the identity of the Firm that owns it, and access is checked against that identity at the database layer on every read and write.
Database least privilegeEach application service connects to the database as its own identity, authenticated by the cloud platform rather than by a password; no database password exists in Esqase's systems. Those identities are members of one of four database roles, none of which can bypass row level security or act as a database superuser, and the application refuses to open a connection whose role could. Every connection carries a statement timeout, an idle-transaction timeout, and a lock timeout.
Key managementEncryption keys and third-party credentials are held in a managed secret store, separately from the data they protect.
Backup and recoveryProduction data is backed up through the managed backup facilities of the underlying cloud platform, and backups are purged as described in Section 12.
Secure developmentSeparate development, staging, and production environments, code review before changes are merged, and automated dependency scanning.
Bot and abuse protectionApplication attestation and bot detection on Esqase applications, including the public pages a Firm shares with its clients.
Network perimeterRequests to the Esqase applications reach them only through Google Cloud's global load balancer, which terminates TLS and applies Google Cloud Armor's protections against attack and automated abuse. The application services accept no connection from the public internet. A small number of background endpoints sit outside the load balancer. One of them, the billing provider's webhook, is reachable from the public internet and verifies the provider's cryptographic signature on every request before it is processed.
Subprocessor managementSecurity review before a Subprocessor is engaged, written data protection terms with each Subprocessor, and periodic review (Section 6.4).
Physical securityProduction infrastructure runs in Google Cloud data centers, which operate their own physical and environmental controls.
Audit loggingEvery create, update, delete, and restore of a record is written to a single append-only audit log in the same database transaction as the change, with the identity of the actor, the time, the action, and the record. Opening and downloading a record are recorded the same way. A database trigger refuses any attempt to delete an audit row.
Vulnerability managementRegular dependency updates and security monitoring.
Personnel trainingSecurity awareness training for Esqase personnel.
Incident responseDocumented procedures for detecting, responding to, and notifying of Security Incidents.

5.2 Updates to Measures

Esqase may update its security measures from time to time to reflect evolving risks, provided that updates will not materially reduce the overall level of protection.

6. Subprocessors

6.1 Authorization

The Firm hereby grants Esqase a general authorization to engage Subprocessors to process Personal Data, subject to the requirements of this Section 6.

6.2 Current Subprocessors

Esqase's current Subprocessors, with the purpose and location of each, are listed at esqase.com/subprocessors, which forms part of this DPA. That page is the authoritative list and is updated whenever a Subprocessor is added or replaced. A Firm may subscribe to notice of changes by writing to legal@esqase.com.

6.3 Changes to Subprocessors

Esqase will provide at least 14 days' prior written notice (by email or by notice in the Service) before adding or replacing a Subprocessor that will process Personal Data. A Firm may subscribe to those notices at legal@esqase.com. If the Firm has reasonable objections relating to the protection of Personal Data, it must notify Esqase at legal@esqase.com within 14 days of the notice, with the grounds for the objection. The parties will work in good faith to resolve the objection, and Esqase may make the Service available without the objected-to Subprocessor or take corrective steps. If the objection is not resolved, the Firm may terminate the affected portion of the Service, or the Subscription where the affected portion cannot reasonably be separated, and Esqase will refund the prorated portion of any prepaid fees covering the period after the termination date.

6.4 Subprocessor Obligations

Esqase will enter into written agreements with each Subprocessor imposing data protection obligations at least as protective as those in this DPA. Esqase remains fully liable to the Firm for the performance of each Subprocessor's data protection obligations, subject to Section 13.

7. Data Subject Rights

7.1 Assistance

Esqase will provide the Firm with reasonable technical and organizational assistance to help the Firm fulfill its obligations to respond to Data Subjects' requests to exercise their rights under Applicable Data Protection Law (including rights of access, correction, deletion, restriction, portability, and objection).

7.2 Requests Received by Esqase

If Esqase receives a Data Subject request directly, it will promptly inform the Firm and will not respond to the request on the Firm's behalf without the Firm's instruction, unless required by law.

8. Security Incident Notification

8.1 Notification

Esqase will notify the Firm without undue delay, and in any event within 48 hours, after Esqase becomes aware of, or forms a reasonable belief as to, a Security Incident affecting Personal Data processed under this DPA. Esqase will not delay the initial notification in order to complete its investigation, and will provide the information described in Section 8.2 as it becomes available. A notification under this Section is not an acknowledgement by Esqase of fault or liability. The Firm remains responsible for determining whether the Security Incident is notifiable to a supervisory authority or to Data Subjects and for making any such notification.

8.2 Notice Content

The notification will include, to the extent known: the nature of the Security Incident; the categories and approximate number of Data Subjects affected; the categories and approximate volume of Personal Data affected; likely consequences; and measures taken or proposed to address the incident.

8.3 Cooperation

Esqase will cooperate with the Firm and take reasonable steps to mitigate the impact of any Security Incident.

9. Data Protection Impact Assessments

Upon the Firm's reasonable request, Esqase will provide reasonable assistance to the Firm in conducting data protection impact assessments (DPIAs) and prior consultation with supervisory authorities, to the extent that such assistance is required and relates to Esqase's processing activities.

10. International Data Transfers

10.1 Locations

Personal Data is stored and processed in the locations recorded in Annex A. Where Personal Data is transferred to a country that Applicable Data Protection Law does not recognize as providing an adequate level of protection, the transfer is made under a mechanism described in this Section.

10.2 EEA Transfers

For a transfer of Personal Data subject to the GDPR out of the European Economic Area, the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (the "EU SCCs") are incorporated into this DPA by reference and apply, with:

  • Module Two (controller to processor) applying where the Firm acts as a controller, and Module Three (processor to processor) applying where the Firm acts as a processor;
  • Clause 7 (the docking clause) not applying;
  • Clause 9, Option 2 (general written authorization) applying, with the notice period set out in Section 6.3;
  • the optional wording in Clause 11(a) not applying;
  • Clause 17, Option 1 applying, with the EU SCCs governed by the law of Ireland;
  • Clause 18(b) applying, with disputes resolved before the courts of Ireland;
  • Annex I.A completed with the parties identified in Section 22 and in the Firm's Account;
  • Annex I.B completed with Annex A of this DPA;
  • Annex I.C completed with the supervisory authority of the EEA member state in which the Firm is established or, where the Firm is not established in the EEA, of the member state in which the relevant Data Subjects are located;
  • Annex II completed with Section 5.1; and
  • Annex III completed with the list referred to in Section 6.2.

10.3 UK Transfers

For a transfer of Personal Data subject to the UK GDPR, the EU SCCs as incorporated by Section 10.2 apply as varied by the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018 (the "UK Addendum"), which is incorporated into this DPA by reference. Tables 1 to 3 of the UK Addendum are completed with the information in Section 10.2, Section 6.2, and Annex A. In Table 4, both "Importer" and "Exporter" are selected.

10.4 Swiss Transfers

For a transfer of Personal Data subject to the Swiss Federal Act on Data Protection, the EU SCCs as incorporated by Section 10.2 apply, with references to the GDPR read as references to the Swiss Federal Act on Data Protection, references to a member state read as including Switzerland, and the Federal Data Protection and Information Commissioner as the competent supervisory authority.

10.5 Changes to Transfer Mechanisms

If a transfer mechanism used under this Section is invalidated, replaced, or superseded, Esqase will apply the replacement mechanism or another lawful mechanism to the transfer, without any need to amend this DPA. The Firm may request a copy of the completed transfer documentation at legal@esqase.com.

11. Audit Rights

11.1 Information and Audit

Esqase will make available to the Firm, on reasonable request and no more than once in any twelve-month period (unless a Security Incident has occurred, or Applicable Data Protection Law or a supervisory authority requires otherwise), the information reasonably necessary to demonstrate compliance with this DPA. Esqase will ordinarily satisfy a request by providing its current security documentation, a description of the controls it maintains and monitors under its security program, its subprocessor list, and a completed security questionnaire. Where that documentation does not answer the Firm's request, Section 11.2 applies.

11.2 Audit Process

An audit under this Section may be conducted by the Firm or by an independent auditor the Firm mandates, whom Esqase may approve in advance, such approval not to be unreasonably withheld. The audit will be conducted with at least 30 days' prior written notice, during normal business hours, at the Firm's expense, under an agreed scope, and in a manner that minimizes disruption to Esqase's operations, and it may not extend to the data or systems of any other customer. Esqase may require the Firm and its auditors to execute a reasonable confidentiality agreement before Esqase discloses audit-relevant information.

12. Return and Deletion of Data

12.1 Export

While the Firm's Subscription is active, and during the recovery period described in Section 12.2, the Firm may export a copy of its core records (firm profile, members, contacts, matters, and leads, and, for a Firm on the Professional plan or a Firm that has been on it, its personal injury records) from the billing settings as a machine-readable file, and may download documents, invoices, and other records individually through the Service. On the Firm's written request made during that period, Esqase will provide the remaining categories of Personal Data it holds for the Firm in a structured, commonly used, and machine-readable format.

12.2 Deletion

Esqase retains Personal Data for 30 days after the Firm's Account is terminated so that the Firm can recover it, as described in Section 18.5 of the Terms of Service. Esqase will delete or anonymize Personal Data in its active systems at the end of that 30-day period. Backup copies may persist for up to 90 days before being purged. On the Firm's written request, Esqase will delete Personal Data sooner, and will confirm in writing when the deletion is complete.

12.3 Retention Required by Law

Esqase may retain Personal Data where applicable law requires it. Where it does, Esqase will retain only what the law requires, keep it isolated from further processing, continue to protect it under Section 5, and notify the Firm of the retention obligation.

13. Limitation of Liability

Each party's liability under this DPA is subject to the limitations set out in the Terms of Service, to the extent permitted by Applicable Data Protection Law.

14. Precedence

In the event of a conflict between this DPA and the Terms of Service with respect to the processing of Personal Data, this DPA will prevail. In all other respects, the Terms of Service govern.

15. Governing Law

This DPA is governed by the laws of the State of Delaware, United States, without regard to conflict-of-law principles, and disputes arising out of or relating to it are resolved as provided in Section 19 of the Terms of Service. The EU SCCs incorporated by Section 10.2 are governed by the law of Ireland, and disputes arising from them are resolved before the courts of Ireland, as those clauses require. Nothing in this Section limits a right that Applicable Data Protection Law gives a Data Subject to bring a claim in another forum.

16. Term

This DPA remains in effect for as long as Esqase processes Personal Data on behalf of the Firm. Sections 3.3, 3.4, 3.5, 4, 5, 8, 11, 12, 13, 14, 15, 18, 20, and 22, and Annex A, survive termination for as long as Esqase holds Personal Data and for as long thereafter as is necessary to give them effect.

17. Firm Obligations

17.1 Lawful Basis and Notices

The Firm is responsible for the accuracy, quality, and legality of the Personal Data it submits to the Service, for the means by which it obtained that Personal Data, and for having a lawful basis for the processing it instructs. The Firm will give all notices to, and obtain all rights and consents from, Data Subjects that are necessary for Esqase and its Subprocessors to process Personal Data as described in this DPA, as Section 4.6 of the Terms of Service also provides.

17.2 Configuration and Sharing

The Firm decides which Authorized Users and External Users may access which content, including through document sharing, eSignature requests, booking pages, intake forms, and payment pages. Esqase acts on those configuration choices as instructions from the Firm.

17.3 Completeness of Instructions

The Firm's documented instructions consist of the Terms of Service, this DPA, and the configuration choices and actions the Firm and its Authorized Users take in the Service, including through the Esqase API. Taken together, those are the Firm's complete documented instructions for the processing of Personal Data, and Esqase may treat them as such.

18. Government and Law Enforcement Requests

If Esqase receives a subpoena, court order, warrant, or other legally binding demand from a public authority for Personal Data processed under this DPA, Esqase will:

  • notify the Firm before disclosing anything, unless notice is prohibited by law, in which case Esqase will use reasonable efforts to obtain a waiver of the prohibition and will document the efforts it made so it can show them to the Firm as soon as it is permitted to;
  • challenge the demand where there is a reasonable basis to consider it unlawful under applicable law, and seek interim measures to suspend its effect until the challenge is resolved;
  • disclose only the minimum amount of Personal Data it is legally compelled to disclose; and
  • provide the Firm, on request and to the extent permitted by law, with the information it holds about the demands it has received.

Where Esqase is able to do so, it will refer a public authority that seeks Personal Data to the Firm rather than responding itself. This Section states, for processing under this DPA, the commitment Esqase also makes in Section 5.6 of the Terms of Service. Nothing in this Section requires Esqase to violate applicable law.

19. Country-Specific Terms

Where Esqase publishes a data processing agreement or a supplement for the country in which the Firm is established, that document states the additional terms that then apply to this DPA, including the Firm's prior instruction for subprocessing, the instruction to transfer, breach reporting, and the data protection contact, and it applies as that document describes. Esqase publishes those documents at esqase.com/legal.

20. Changes to This DPA

Esqase may update this DPA where the change is required by Applicable Data Protection Law, reflects a change to the Service, or updates the Subprocessor list referred to in Section 6.2. Esqase will post the updated DPA at esqase.com/dpa and revise the Last updated date. Where a change materially reduces the protections in this DPA, Esqase will notify the Firm by email or by notice in the Service at least 14 days before it takes effect. A change to the Subprocessor list is made on the notice period in Section 6.3. No change to this DPA reduces a protection that Applicable Data Protection Law requires.

21. Acceptance

This DPA is entered into when the Firm accepts the Terms of Service, whether by creating an Account, by clicking to accept, or by using the Service, and it takes effect on that date. No signature is required for this DPA to bind the parties, and the person accepting the Terms of Service on the Firm's behalf represents that they are authorized to bind the Firm to this DPA. A Firm that requires a countersigned copy may request one at legal@esqase.com; a countersigned copy records the same terms and does not vary them.

22. Contact

For data protection inquiries, to exercise a right under this DPA, or to request a copy of the transfer documentation referred to in Section 10, contact:

Esqase, Inc.
Attention: Data Protection Officer
2810 N Church St STE 89268
Wilmington, DE 19802, United States
legal@esqase.com

Esqase's designated Data Protection Officer is Kristoffer Bello, reachable at the address above.

Esqase acknowledges a request under this DPA within five business days and responds within the period Applicable Data Protection Law allows.

Annex A. Details of Processing

This Annex records the details of processing required by Article 28(3) of the GDPR and of the UK GDPR and by Annex I.B of the EU SCCs.

ItemDetail
Subject matterEsqase's provision of the Service to the Firm under the Terms of Service.
DurationThe term of the Firm's Subscription, followed by the retention and deletion periods in Section 12.
Nature of the processingCollection, recording, organization, structuring, storage, retrieval, use, transmission, disclosure to the recipients the Firm designates, indexing and search (Section 2.5), backup, restriction, erasure, and destruction, carried out by automated means.
Purpose of the processingProviding, operating, maintaining, securing, and supporting the Service as directed by the Firm (Section 2.4).
Categories of Personal DataAs listed in Section 2.2.
Sensitive or special categoriesAs described in Section 2.6.
Categories of Data SubjectsAs listed in Section 2.3.
Frequency of processing and transferContinuous, for as long as the Firm uses the Service.
Geographic location of processingStorage and primary processing take place in the United States on Google Cloud infrastructure. Subprocessor locations are published at esqase.com/subprocessors. Document indexing and search embeddings on Vertex AI follow the Firm's country as described in Section 2.5. A request to an Esqase application reaches a Google Cloud global load balancer in front of services running in the United States.
Retention criteriaPersonal Data is retained while the Firm's Account is active and then in accordance with Section 12, unless a longer period is required by applicable law.
Subprocessor processingEach Subprocessor listed at esqase.com/subprocessors processes the Personal Data necessary for the purpose stated in that list, for the duration of Esqase's engagement of that Subprocessor.

Una sola plataforma para todo su despacho