Data Processing Agreement (DPA)
Date of publication and entry into force:
July 29, 2026
This Data Processing Agreement (hereinafter: the “DPA”) forms an integral part of the Terms of Service of the Lexra application and governs the processing of personal data carried out by “TESLA QUANTUM CORE” limited liability company, with its registered seat in Banja Luka, adress Jovana Dučića no. 14, 78000 Banja Luka, Bosnia and Herzegovina, registration number (MB): 11261094, tax identification number (PIB): 440528300000 (hereinafter: the “Company” or the “Processor”), in its capacity as processor, on behalf of the customer of the Application acting as the controller of the processing (hereinafter: the “Customer” or the “Controller”).
By accepting the Terms of Service, creating a user account, subscribing to the Service or using the Application, the Customer confirms that it has read, understood and accepted the provisions of this DPA, and a data processing agreement within the meaning of Article 28 of Regulation (EU) 2016/679 (GDPR) is deemed to have been concluded between the Customer and the Company.
This DPA applies for the entire duration of the use of the Application and remains in force for as long as the Company processes personal data on behalf of the Customer.
Article 1
This DPA forms an integral part of the Terms of Service of the Application. By accepting the Terms of Service, creating a user account, subscribing to the Service or using the Application, the Customer accepts the provisions of this DPA.
Article 2
The provisions of this DPA establish the rights and obligations of the Processor and the Controller in connection with the processing of the Controller’s personal data by the Processor during the use of the Application, in accordance with Commission Implementing Decision (EU) 2021/915 of 4 June 2021 on standard contractual clauses between controllers and processors under Article 28(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council and Article 29(7) of Regulation (EU) 2018/1725 of the European Parliament and of the Council. The Company and the Customer mutually undertake to apply the Standard Contractual Clauses annexed to this DPA (Annex 1).
Article 3
The Customer and the Company confirm that they are aware of the rights and obligations arising from this DPA and accept them by accepting the Terms of Service, creating a user account, subscribing to the Service or using the Application.
This DPA is concluded in electronic form and forms an integral part of the Terms of Service. The Company may amend or supplement this DPA from time to time in order to keep it aligned with applicable law, regulatory requirements or changes in the provision of the Service. Changes to this DPA are subject to the change rules set out in the Terms of Service: customers are notified of material changes at least 30 days before they take effect, and changes that are not material take effect on the day of publication on the lexra.io website.
Annex 1 — STANDARD CONTRACTUAL CLAUSES
SECTION I
Clause 1 — Purpose and scope
- The purpose of these Standard Contractual Clauses (hereinafter: the “Clauses”) is to ensure compliance with Article 28(3) and (4) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
- The Controller and the Processor have agreed to these Clauses in order to ensure compliance with Article 28(3) and (4) of Regulation (EU) 2016/679 and/or Article 29(3) and (4) of Regulation (EU) 2018/1725.
- These Clauses apply to the processing of personal data as specified in Annex 1.1 (Description of the processing).
- Annexes 1.1 to 1.3 form an integral part of the Clauses.
- These Clauses are without prejudice to the obligations to which the Controller is subject by virtue of Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725.
Clause 2 — Invariability of the Clauses
- The Parties undertake not to modify the Clauses, except for adding information to the Annexes or updating information in them.
- This does not prevent the Parties from including the standard contractual clauses laid down in these Clauses in a broader contract, or from adding other clauses or additional safeguards, provided that they do not directly or indirectly contradict the Clauses or detract from the fundamental rights or freedoms of data subjects.
Clause 3 — Interpretation
- Where these Clauses use the terms defined in Regulation (EU) 2016/679 or Regulation (EU) 2018/1725 respectively, those terms shall have the same meaning as in that Regulation.
- These Clauses shall be read and interpreted in the light of the provisions of Regulation (EU) 2016/679 or Regulation (EU) 2018/1725 respectively.
- These Clauses shall not be interpreted in a way that runs counter to the rights and obligations provided for in Regulation (EU) 2016/679 / Regulation (EU) 2018/1725 or in a way that prejudices the fundamental rights or freedoms of the data subjects.
Clause 4 — Hierarchy
In the event of a contradiction between these Clauses and the provisions of related agreements between the Parties existing at the time when these Clauses are agreed or entered into thereafter, these Clauses shall prevail.
Clause 5 — Docking clause
This optional clause of Commission Implementing Decision (EU) 2021/915 has not been agreed and does not apply. For consistency with the official text of the Standard Contractual Clauses, the numbering of the remaining Clauses is unchanged.
SECTION II — OBLIGATIONS OF THE PARTIES
Clause 6 — Description of the processing
The details of the processing operations, in particular the categories of personal data and the purposes for which the personal data is processed on behalf of the Controller, are specified in Annex 1.1.
Clause 7 — Obligations of the Parties
7.1. Instructions
- The Processor shall process personal data only on documented instructions from the Controller, unless required to do so by Union or Member State law to which the Processor is subject. In this case, the Processor shall inform the Controller of that legal requirement before processing, unless the law prohibits this on important grounds of public interest. Subsequent instructions may also be given by the Controller throughout the duration of the processing of personal data. These instructions shall always be documented.
- The Processor shall immediately inform the Controller if, in the Processor’s opinion, instructions given by the Controller infringe Regulation (EU) 2016/679 / Regulation (EU) 2018/1725 or the applicable Union or Member State data protection provisions.
7.2. Purpose limitation
The Processor shall process the personal data only for the specific purposes of the processing, as set out in Annex 1.1, unless it receives further instructions from the Controller.
Processing by the Processor is carried out exclusively on an occasional basis and to the extent necessary for the provision of technical support, system administration and the resolution of technical issues, without continuous or systematic processing of personal data in the course of providing the Service.
7.3. Duration of the processing of personal data
Processing by the Processor shall only take place for the duration specified in Annex 1.1.
After the end of the processing or the termination of the agreement, the Processor shall, at the choice of the Controller, delete or return all personal data at the latest within 90 days, unless applicable law requires longer storage. In that case, the data shall be retained exclusively to the extent and for the period required by law.
7.4. Security of processing
- The Processor shall at least implement the technical and organisational measures specified in Annex 1.2 to ensure the security of the personal data, including protection against a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access to the data (personal data breach). In assessing the appropriate level of security, the Parties shall take due account of the state of the art, the costs of implementation, the nature, scope, context and purposes of processing and the risks involved for the data subjects.
- The Processor shall grant access to the personal data undergoing processing to members of its personnel only to the extent strictly necessary for implementing, managing and monitoring of the contract. The Processor shall ensure that persons authorised to process the personal data received have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
7.5. Sensitive data
If the processing involves personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data or biometric data for the purpose of uniquely identifying a natural person, data concerning health or a person’s sex life or sexual orientation, or data relating to criminal convictions and offences (“sensitive data”), the Processor shall apply specific restrictions and/or additional safeguards.
7.6. Documentation and compliance
- The Parties shall be able to demonstrate compliance with these Clauses.
- The Processor shall deal promptly and adequately with inquiries from the Controller about the processing of data in accordance with these Clauses.
- The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations that are set out in these Clauses and stem directly from Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725. At the Controller’s request, the Processor shall also permit and contribute to audits of the processing activities covered by these Clauses, at reasonable intervals or if there are indications of non-compliance. In deciding on a review or an audit, the Controller may take into account relevant certifications held by the Processor.
- The Controller may choose to conduct the audit by itself or mandate an independent auditor. Audits may also include inspections at the premises or physical facilities of the Processor and shall, where appropriate, be carried out with reasonable notice.
- The Parties shall make the information referred to in this Clause, including the results of any audits, available to the competent supervisory authority on request.
- The Processor shall maintain a record of processing activities in accordance with Article 30 of the GDPR, covering all relevant categories of processing activities carried out on behalf of the Controller.
7.7. Use of sub-processors
- GENERAL WRITTEN AUTHORISATION: The Processor has the Controller’s general authorisation for the engagement of sub-processors from the list in Annex 1.3. The Processor shall specifically inform the Controller in writing of any intended changes to that list through the addition or replacement of sub-processors at least one month in advance, thereby giving the Controller sufficient time to be able to object to such changes prior to the engagement of the sub-processor(s) concerned. The Processor shall provide the Controller with the information necessary to enable the Controller to exercise its right to object.
- If the Controller, on grounds relating to data protection, raises a reasoned objection before the expiry of the period referred to in point (a), the Parties shall endeavour in good faith to find a solution. If no solution is reasonably possible, the Controller may terminate the agreement in the part concerning the processing of personal data in accordance with Clause 10, or cancel the Subscription in accordance with the Terms of Service. If the Controller does not raise an objection within that period, the Controller is deemed to have agreed to the change in question.
- Where the Processor engages a sub-processor to carry out specific processing activities (on behalf of the Controller), it shall do so by way of a contract which imposes on the sub-processor, in substance, the same data protection obligations as those binding the Processor under these Clauses. The Processor shall ensure that the sub-processor complies with the obligations to which the Processor is subject pursuant to these Clauses and to Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725.
- At the Controller’s request, the Processor shall provide a copy of such a sub-processor agreement and any subsequent amendments to the Controller. To the extent necessary to protect business secrets or other confidential information, including personal data, the Processor may redact the text of the agreement prior to sharing the copy.
- The Processor shall remain fully responsible to the Controller for the performance of the sub-processor’s obligations in accordance with its contract with the Processor. The Processor shall notify the Controller of any failure by the sub-processor to fulfil its contractual obligations.
- The Processor shall agree a third-party beneficiary clause with the sub-processor whereby — in the event the Processor has factually disappeared, ceased to exist in law or has become insolvent — the Controller shall have the right to terminate the sub-processor contract and to instruct the sub-processor to erase or return the personal data.
7.8. International transfers
- Any transfer of data to a third country or an international organisation by the Processor shall be done only on the basis of documented instructions from the Controller or in order to fulfil a specific requirement under Union or Member State law to which the Processor is subject, and shall take place in compliance with Chapter V of Regulation (EU) 2016/679 or Regulation (EU) 2018/1725.
- The Controller agrees that where the Processor engages a sub-processor in accordance with Clause 7.7 for carrying out specific processing activities (on behalf of the Controller) and those processing activities involve a transfer of personal data within the meaning of Chapter V of Regulation (EU) 2016/679, the Processor and the sub-processor can ensure compliance with Chapter V of Regulation (EU) 2016/679 by using standard contractual clauses adopted by the Commission in accordance with Article 46(2) of Regulation (EU) 2016/679, provided the conditions for the use of those standard contractual clauses are met.
Clause 8 — Assistance to the Controller
- The Processor shall promptly notify the Controller of any request it has received from the data subject. It shall not respond to the request itself, unless authorised to do so by the Controller.
- The Processor shall assist the Controller in fulfilling its obligations to respond to data subjects’ requests to exercise their rights, taking into account the nature of the processing. In fulfilling its obligations in accordance with points (a) and (b), the Processor shall comply with the Controller’s instructions.
- In addition to the Processor’s obligation to assist the Controller pursuant to point (b), the Processor shall furthermore assist the Controller in ensuring compliance with the following obligations, taking into account the nature of the data processing and the information available to the Processor: (1) the obligation to carry out an assessment of the impact of the envisaged processing operations on the protection of personal data (a “data protection impact assessment” — DPIA) where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons; (2) the obligation to consult the competent supervisory authority prior to processing where a data protection impact assessment indicates that the processing would result in a high risk in the absence of measures taken by the Controller to mitigate the risk; (3) the obligation to ensure that personal data is accurate and up to date, by informing the Controller without delay if the Processor becomes aware that the personal data it is processing is inaccurate or has become outdated; (4) the obligations laid down in Article 32 of Regulation (EU) 2016/679.
- The Parties shall set out in Annex 1.2 the appropriate technical and organisational measures by which the Processor is required to assist the Controller in the application of this Clause as well as the scope and the extent of the assistance required.
Clause 9 — Notification of personal data breach
In the event of a personal data breach, the Processor shall cooperate with and assist the Controller for the Controller to comply with its obligations under Articles 33 and 34 of Regulation (EU) 2016/679 or under Articles 34 and 35 of Regulation (EU) 2018/1725, where applicable, taking into account the nature of processing and the information available to the Processor.
9.1. Data breach concerning data processed by the Controller
In the event of a personal data breach concerning data processed by the Controller, the Processor shall assist the Controller:
- in notifying the personal data breach to the competent supervisory authority, without undue delay after the Controller has become aware of it, where relevant (unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons);
- in obtaining the following information which, pursuant to Article 33(3) of Regulation (EU) 2016/679, shall be stated in the Controller’s notification, and must at least include: (1) the nature of the personal data breach including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned; (2) the likely consequences of the personal data breach; (3) the measures taken or proposed to be taken by the Controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects. Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay;
- in complying, pursuant to Article 34 of Regulation (EU) 2016/679, with the obligation to communicate without undue delay the personal data breach to the data subject, when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons.
9.2. Data breach concerning data processed by the Processor
In the event of a personal data breach concerning data processed by the Processor, the Processor shall notify the Controller without undue delay after becoming aware of the breach, and at the latest within 72 hours. Such notification shall contain, at least:
- a description of the nature of the breach (including, where possible, the categories and approximate number of data subjects and data records concerned);
- the details of a contact point where more information concerning the personal data breach can be obtained;
- its likely consequences and the measures taken or proposed to be taken to address the breach, including to mitigate its possible adverse effects.
Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay. The Parties shall set out in Annex 1.2 all other elements to be provided by the Processor when assisting the Controller in the compliance with the Controller’s obligations under Articles 33 and 34 of Regulation (EU) 2016/679.
SECTION III — FINAL PROVISIONS
Clause 10 — Non-compliance with the Clauses and termination
- Without prejudice to any provisions of Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725, in the event that the Processor is in breach of its obligations under these Clauses, the Controller may instruct the Processor to suspend the processing of personal data until the latter complies with these Clauses or the contract is terminated. The Processor shall promptly inform the Controller in case it is unable to comply with these Clauses, for whatever reason.
- The Controller shall be entitled to terminate the contract insofar as it concerns processing of personal data in accordance with these Clauses if: (1) the processing of personal data by the Processor has been suspended by the Controller pursuant to point (a) and compliance with these Clauses is not restored within a reasonable time and in any event within one month following suspension; (2) the Processor is in substantial or persistent breach of these Clauses or its obligations under Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725; (3) the Processor fails to comply with a binding decision of a competent court or the competent supervisory authority(ies) regarding its obligations pursuant to these Clauses or to Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725.
- The Processor shall be entitled to terminate the contract insofar as it concerns processing of personal data under these Clauses where, after having informed the Controller that its instructions infringe applicable legal requirements in accordance with Clause 7.1(b), the Controller insists on compliance with the instructions.
- Following termination of the contract, the Processor shall, at the choice of the Controller, delete all personal data processed on behalf of the Controller and certify to the Controller that it has done so, or return all the personal data to the Controller and delete existing copies unless Union or Member State law requires storage of the personal data. Until the data is deleted or returned, the Processor shall continue to ensure compliance with these Clauses.
ANNEX 1.1 — DESCRIPTION OF THE PROCESSING
Categories of data subjects
Individuals whose personal data is contained in the records that the Customer enters into the Application, in particular: the Customer’s clients and parties; opposing parties and their counsel; legal representatives; witnesses and expert witnesses; the Customer’s employees and associates; other individuals referred to in the Customer’s matters and records.
Categories of personal data processed
Personal data of individuals referred to in the Customer’s records entered into the Application (e.g. identification data, contact data, data on legal matters and proceedings, data contained in documents).
Sensitive data processed (if applicable) and applied restrictions or safeguards
If the Customer’s records contain sensitive data, that data is processed under strict purpose limitation and with additional safeguards applied.
For pseudonymisation and during storage, particularly sensitive data is protected using the Always Encrypted mechanism with secure enclaves enabled, which ensures that the data is stored and processed in encrypted form, with the cryptographic keys unavailable to the database management systems and to the cloud provider’s personnel. The keys are generated and stored in the Azure Key Vault service.
As regards the protection of data in transit: sensitive data, including authentication information and security tokens, is not transmitted in readable form over unprotected channels, nor exposed in URL parameters or other insecure communication mechanisms. Data transfer between the application and infrastructure components of the system is protected by appropriate security mechanisms, in accordance with the capabilities and standards of the cloud infrastructure used.
Sensitive payment card data or data relating to other means of payment is not stored or processed within the system; it is processed exclusively by the external payment service provider (PayPal), in accordance with its security and regulatory requirements.
Access to special categories of personal data is restricted exclusively to authorised persons for whom such access is necessary for the performance of their tasks.
Nature of the processing
The nature of the processing of personal data in the Application involves structured processing necessary for the digital organisation and management of the Customer’s records: storage, structuring, display, alteration, retrieval, export and erasure of data, as well as occasional access to data for the purposes of technical support and system maintenance.
Location of the processing
Personal data is stored and processed through the cloud infrastructure of the sub-processors (Microsoft Azure and Amazon Web Services), in the region that geographically corresponds to the Controller’s location or that the Controller selects, and for Controllers from the European Union (EU/EEA) primarily within the EU/EEA, unless the Controller expressly approves otherwise.
Purpose of the processing on behalf of the Controller
The functionality of the Application — enabling the use of the Application for the management of legal matters, the organisation and storage of records, user account management, the provision of technical support and the assurance of system security.
Duration of the processing
For the duration of the subscription period, with subsequent retention and deletion in accordance with Clause 7.3 (at the latest 90 days after termination), unless legal provisions require longer retention.
ANNEX 1.2 — TECHNICAL AND ORGANISATIONAL MEASURES (TOM)
Specific technical and organisational measures implemented for the purposes of protection:
Measures of pseudonymisation and encryption of personal data
Personal data processed within the Application is stored in a cloud environment (Microsoft Azure and Amazon Web Services) and protected by encryption of data at rest using the built-in encryption mechanisms of the cloud platform (AES-256).
For particularly sensitive data, the Always Encrypted mechanism with secure enclaves enabled is used, ensuring that the data is stored and processed in encrypted form, with the cryptographic keys unavailable to the database management systems and to the cloud provider’s personnel. The keys are generated and stored in the Azure Key Vault service.
Encryption of data in transit is ensured through the use of secure communication protocols (TLS).
System audit logs, including the columns containing previous and new data values (OldValues and NewValues), are stored exclusively in encrypted form and serve exclusively for internal control, forensic analysis and demonstrating system integrity. The content of the audit logs is not accessible to end users through the user interface, nor is it used for the operational purposes of the Application. Access to audit data is restricted to strictly authorised administrative processes.
Additional pseudonymisation is achieved through the use of internal identifiers (IDs) in technical records and logs, instead of direct personal data, as well as through strict role-based access control.
Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services
Measures relating to the security, availability and resilience of the infrastructure are ensured through the use of the Microsoft Azure and Amazon Web Services cloud platforms, which, as sub-processors, provide the physical security of data centres, the protection of network and server infrastructure, the isolation of customer environments, high availability of key services, continuous system monitoring and built-in data backup mechanisms, in accordance with their standard security and operational practices.
At the application level, the Processor applies additional protection measures to preserve the confidentiality and integrity of data, including encryption of personal data, strict role-based access control, and the keeping of protected audit logs recording all relevant actions on the data. Access to data and system functionality is granted exclusively to authorised users, in accordance with their business roles and responsibilities.
System availability and continuity of processing are ensured through the proper configuration of the cloud services used, the monitoring of application and infrastructure components, and defined procedures for restoring system functionality and access to data in the event of a technical or security incident, within the guarantees and capabilities provided by the cloud infrastructure used.
This approach ensures a clear division of responsibilities between the cloud provider and the Processor: the cloud provider ensures infrastructure security and availability measures, while the Processor applies application-level and organisational protection measures, in accordance with the requirements of the GDPR.
Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident
Technical and organisational measures are applied based on the use of managed cloud infrastructure and defined system recovery procedures. The cloud services used provide built-in backup mechanisms and data recovery capabilities, including the automated creation of backups of the database and other relevant system components, as well as the ability to restore data to a previous state in the event of loss, corruption or accidental deletion.
At the application level, the Processor ensures that system components are designed and configured so as to enable the restoration of system functionality and access to personal data within a reasonable time. In the event of an incident, procedures are in place for restoring the operation of the Application, including restarting services and restoring data from available backups.
System recovery measures are periodically verified through technical tests and controlled restoration procedures, ensuring that the mechanisms for restoring data availability are functional and effective.
Processes for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures
At the infrastructure level, the cloud services used are subject to continuous monitoring, regular security updates and internal security controls carried out by the cloud provider in accordance with applicable industry standards and certifications. Information about security incidents and relevant infrastructure changes is available through the cloud provider’s official channels.
At the application level, the Processor periodically verifies the correctness and effectiveness of the technical protection measures, including access control, data encryption, audit logs and system recovery procedures. Testing includes verification of the correctness of the system configuration, log review and control of the application of the defined security policies.
Measures for user identification and authorisation
User identification is performed through unique user accounts, and authentication through a username and password. Passwords are not stored in readable form; they are processed and stored using appropriate cryptographic mechanisms in line with modern security practices.
Upon successful authentication, the user is issued a security token (JWT — JSON Web Token) used to authorise further requests to the system. Tokens have a limited lifetime and are regularly refreshed at short intervals, reducing the risk of unauthorised use in the event of compromised credentials or sessions.
User authorisation is based on the principle of assigning roles and permissions (role-based access control), whereby access to system functionality and personal data is restricted in accordance with the user’s business role (e.g. lawyer, administrative staff, administrator) and the principle of least privilege.
The system is designed as a multi-tenant solution, in which the data of different customer offices is logically separated at the application and database level. All business records contain an office identifier (OfficeId), which is used to strictly restrict access to data exclusively to users belonging to the same office. The application logic prevents the access to, display or processing of data not associated with the office of the logged-in user.
The administration of user accounts and the assignment of permissions is restricted to authorised administrative users within the individual office, and all relevant actions relating to authentication, authorisation and user management are recorded in protected audit logs.
Measures for the protection of data during transmission
All communication between client applications and the server components of the system takes place over secure communication channels based on encryption of data in transit (TLS), preventing unauthorised access, interception or alteration of data during transmission over public or private networks.
Authentication and authorisation of user requests is implemented using security tokens (JWT), which are issued upon successful authentication and used to verify identity and access rights with every request. Tokens have a limited validity period and are regularly refreshed. Authentication data and security tokens are not transmitted in readable form over unprotected channels, nor exposed in URL parameters.
Measures for the protection of data during storage
Personal data is stored in a cloud environment and protected by encryption of data at rest using the built-in encryption mechanisms of the cloud platform. Encryption is applied at the level of the database, data storage and backups.
System audit logs, including records of data access and changes, are stored in encrypted form and protected against unauthorised reading, alteration or deletion. Access to stored data is restricted exclusively to authorised application processes and users, in accordance with assigned roles and the principle of least privilege.
The data of different customer offices is logically separated using the office identifier (OfficeId), ensuring that stored data is accessible exclusively to the users of the relevant office.
Payment data stored within the Application is limited exclusively to technical and business metadata (e.g. transaction identifier, payment status, amount and time of the transaction).
Measures for ensuring the physical security of locations at which personal data is processed
Personal data is stored and processed exclusively in the data centres of the Microsoft Azure and Amazon Web Services cloud platforms, which, as sub-processors, apply strict physical security measures in accordance with industry standards. These measures include controlled and restricted physical access to facilities, monitoring of premises, identification and authorisation of personnel, and protection against unauthorised entry, theft or damage to equipment.
The data centres of these providers are designed and maintained in a manner that ensures protection against physical threats, including natural disasters, technical failures and other emergencies, through infrastructure redundancy, controlled environmental conditions and constant monitoring.
The Processor has no physical access to the server infrastructure or the locations where the data is stored, which further reduces the risk of unauthorised physical access. The physical security of the locations is entirely entrusted to the cloud providers, in accordance with their contractual obligations and security practices.
The physical security of the locations where payment data is processed is ensured by the external payment service provider (PayPal), in accordance with its security standards and regulatory requirements. The Processor has no physical access to the payment provider’s infrastructure.
Measures for ensuring events logging
The system records security- and business-relevant events, including data access, the creation, modification and deletion of records, and administrative and authentication actions of users. Each event record contains basic technical information (user identity, time of the action, type of action and the office identifier — OfficeId), enabling activity tracking within the relevant office.
Audit logs that may contain data related to the processing of personal data are stored in encrypted form and protected against unauthorised reading, alteration or deletion. Access to the logs is restricted exclusively to authorised administrative processes and users, in accordance with the principle of least privilege.
The content of binary documents stored in external or built-in storage systems is not recorded in the audit logs; logging is limited to technical and reference data (e.g. document identifier, type of action), applying the principle of data minimisation.
Where external services are used for document storage or payment processing, the system records exclusively information about the operations performed and their status, without logging sensitive data processed within the external providers’ systems.
Measures for ensuring system configuration, including default configuration
The system is designed and configured in accordance with the “secure by default” principle, so that the basic security measures are active without the need for additional configuration by the user.
The default configuration restricts access to functionality and personal data exclusively to authorised users and roles, with privileges assigned according to the principle of least privilege. Access to administrative functions and sensitive data is permitted only to users with the appropriate permissions.
By default, the system applies data encryption, access control, logging of relevant events and logical isolation of data between different offices through the office identifier (OfficeId). Insecure or unnecessary access paths and functionality not required for lawful data processing are disabled.
Changes to system and security configurations are restricted to authorised administrative processes, and all relevant changes are recorded in protected audit logs.
Measures for internal IT and IT security governance and management
The management of IT systems and security configurations is restricted to authorised persons, with clearly defined and assigned responsibilities in accordance with internal procedures. Access to administrative functions and infrastructure resources is permitted exclusively to authorised technical users, with access control applied and relevant actions recorded.
The system is regularly maintained through the application of security updates, the monitoring of technical notices and recommendations for the technologies and services used, and the supervision of the operation of the application and infrastructure components. Where security risks or incidents are identified, appropriate measures are taken to remedy the problem and reduce the potential impact on the processing of personal data.
Internal IT security governance also includes the control of the use of sub-processors, the monitoring of changes to their terms and security practices, and the assessment of the impact of those changes on the security of the system.
Measures for certification/assurance of processes and products
The cloud infrastructure used (Microsoft Azure and Amazon Web Services) applies certified security and organisational standards in accordance with applicable industry norms, including standards relating to physical security, infrastructure security, system availability and risk management. Information about the cloud providers’ current certifications and security practices is available through their official documentation.
At the application level, the security of the product and of processes is ensured through the application of the “security by design” and “privacy by design” principles, and through the consistent implementation of technical and organisational data protection measures, including access control, encryption, audit logs and the minimisation of data processing.
The security of processes and products is regularly assessed through internal technical reviews, the monitoring of security recommendations for the technologies used, and the adaptation of the system to applicable regulatory requirements.
Measures for ensuring data minimisation
The system is designed and implemented so that only the personal data necessary for achieving the lawful purpose of the processing is processed and stored.
Personal data is collected and processed to an extent appropriate to the functionality of the system and the business needs of the Controller, without processing data that is not relevant or necessary for the use of the Application. The fields and functionality of the system are limited to the data needed for the management of legal matters, user management and the performance of contractual obligations.
The content of documents is not stored in the Application’s database; it is kept in the selected storage systems, while the database stores only the necessary document metadata.
Audit logs do not contain complete personal data or the binary content of documents, but exclusively the technical and reference information necessary for activity tracking and ensuring system integrity.
Payment data is limited to technical and business metadata, while sensitive payment data is processed exclusively by the external payment service provider and is not stored within the system.
Measures for ensuring data quality
The system allows the entry, modification and updating of personal data exclusively by authorised users, in accordance with their roles and business responsibilities, reducing the risk of unauthorised or inaccurate changes.
The application logic includes basic validation of the data entered (mandatory fields, data format, consistency of entries), preventing the entry of incomplete or manifestly inaccurate information. Where applicable, users are able to update and correct data in the course of the regular use of the system.
All changes to relevant data are recorded through audit logs, which enable the tracking of change history and the identification of the source of a change. Data that is no longer accurate, relevant or necessary can be modified, corrected or removed in accordance with the defined procedures and user roles.
Measures for ensuring limited data retention
The system enables the management of the data lifecycle, including the modification, archiving and deletion of data, in accordance with the decisions and internal rules of the Controller. Data is not automatically retained longer than necessary for the lawful purpose of the processing.
Personal data associated with legal matters, users and documents can be removed or anonymised after the expiry of the retention period defined by the Controller, except where further retention is necessary due to legal obligations or for the establishment, exercise or defence of legal claims.
Audit logs are kept for a period limited to what is necessary to ensure system security, demonstrate the integrity of processing and comply with legal obligations, after which they are deleted or archived in accordance with the defined rules.
The system enables the Customer to delete the user account, which initiates the procedure for removing all personal data associated with the account that is no longer necessary for the purposes of the processing; data related to work in the system (matters, document references and related records) is permanently removed from the system. Data relating exclusively to the user account itself, or which must be retained to comply with legal obligations (including records of completed payments), is kept to a limited extent and exclusively for the period prescribed by applicable law, after which it is deleted or anonymised.
Measures for ensuring accountability
Roles and responsibilities in relation to the processing of personal data are clearly defined: the Controller is responsible for the lawfulness and purpose of the processing, while the Processor processes personal data exclusively on the documented instructions of the Controller and in accordance with the obligations assumed under this DPA.
The system provides mechanisms for recording relevant processing activities through audit logs that enable the tracking of data access, changes and administrative actions. These logs serve as evidence of lawful and controlled processing and are available exclusively to authorised persons.
Measures for ensuring data portability and ensuring erasure
The system enables the export of personal data in a structured, commonly used and machine-readable format, to the extent technically feasible and consistent with the purpose of the processing. Portability applies to data entered into the system by the individual or processed on the basis of their activity, while data from internal records, audit logs or data that must be retained to comply with legal obligations is not covered by portability.
The system enables the deletion of the user account, which initiates the removal of the personal data associated with the account that is no longer necessary for the purposes of the processing. Deletion covers the removal of operational data, matters and related records, except for data whose retention is necessary to comply with legal obligations or to protect legal claims.
Data on completed payments and the basic technical records needed to demonstrate the lawfulness of processing are retained to a limited extent and for the period prescribed by applicable law, after which they are deleted or anonymised. Sensitive payment card data is not stored or processed within the system; it is processed exclusively by the external payment service provider.
Where external document storage services are used, the deletion and portability of the binary content of documents are subject to the rules and functionality of the selected external provider, while the system enables the removal of document references and metadata from its own database.
ANNEX 1.3 — LIST OF SUB-PROCESSORS
