Legal
Data Processing Agreement
Last updated: Version 2.2/2026 Previous versions
Valid for new clients from 5 October 2026 and for existing clients from 22 October 2026. Until then, version 2.1 applies to existing clients; objection period until 21 October 2026.
Contents
- Preamble
- 1.Subject Matter, Duration and Specification of the Commissioned Processing
- 2.Scope of Application and Responsibility
- 3.Obligations of the Processor
- 4.Obligations of the Client
- 5.Data Subject Requests
- 6.Means of Proof
- 7.Sub-processors and Subcontracting Relationships
- 8.Information Obligations, Text Form, Choice of Law
- 9.Liability and Damages
- Annex 1: Nature and Purpose of Processing
- Annex 2: Technical and Organizational Measures
- Annex 3: Sub-processors
between
Client
hereinafter referred to as "Client" or "Controller" -
and
incaseof.law GmbH, Rathausstraße 21/13, 1010 Vienna, Austria, registered with the Commercial Court of Vienna under FN 505409 z
hereinafter referred to as "Processor" -
regarding processing of personal data in accordance with Art. 28 para. 3 of the General Data Protection Regulation (GDPR, EU Regulation 2016/679).
Preamble
This Data Processing Agreement (hereinafter "DPA") specifies the obligations of the contracting parties regarding the protection of personal data resulting from commissioned processing. This DPA applies to all activities related to the main agreement concluded between the parties on the day of the Client’s registration at incaseof.law GmbH (in accordance with the GTC) (hereinafter "Main Agreement") where employees of the Processor or persons commissioned by the Processor process personal data (hereinafter "Data") of the Client. The terms used in this DPA are to be understood according to their definition in the GDPR.
1. Subject Matter, Duration and Specification of the Commissioned Processing
The Main Agreement and the breakdown in Annex 1 specify the subject matter and duration of the engagement, as well as the nature and purpose of the processing. The term of this DPA shall correspond to the term of the Main Agreement, unless obligations extending beyond that term arise from the provisions of this DPA.
2. Scope of Application and Responsibility
2.1. The Processor processes personal data on behalf of the Client within the meaning of Art. 4 No. 8 and Art. 28 of the GDPR. This includes activities specified in the Main Agreement and in the description under Section 1. The Client is solely responsible within the framework of the Main Agreement for compliance with the legal provisions of data protection laws, in particular for the lawfulness of the data transfer to the Processor and for the lawfulness of data processing ("Controller" within the meaning of Art. 4 No. 7 GDPR).
2.2. Instructions are initially set forth in the Main Agreement and may subsequently be amended, supplemented, or replaced by individual instructions (hereinafter "Individual Instruction") from the Client in written form or an electronic format (text form) to the contact point designated by the Processor. Individual Instructions not provided for in the Main Agreement will be treated as a request for change of service. Oral Individual Instructions must be confirmed immediately in writing or text form.
3. Obligations of the Processor
3.1. The Processor may process data only within the scope of the order and the instructions of the Client, unless an exception within the meaning of Art. 28 para. 3 lit. a) GDPR applies. The Processor shall inform the Client without undue delay if it believes that an instruction infringes applicable laws. The Processor may suspend the implementation of the instruction until it has been confirmed or amended by the Client. The Processor may refuse to carry out an instruction that is evidently unlawful.
3.2. Within its area of responsibility, the Processor shall organize its internal operations in such a way that they meet the specific requirements of data protection. It shall implement technical and organizational measures for the appropriate protection of the Client's data, which meet the requirements of the General Data Protection Regulation (Art. 32 GDPR). The Processor must implement technical and organizational measures that permanently ensure the confidentiality, integrity, availability, and resilience of the systems and services related to the processing. The Client is aware of these technical and organizational measures and bears the responsibility for ensuring that they provide an adequate level of protection for the risks of the data to be processed. These technical and organizational measures are listed in the attached Annex 2. The Processor reserves the right to change the security measures taken, provided that the contractually agreed level of protection is not reduced.
3.3. The Processor shall, to the extent agreed, support the Client to the best of its ability in fulfilling requests and claims of data subjects in accordance with Chapter III of the GDPR, and in complying with the obligations listed in Art. 33 to 36 GDPR.
3.4. The Processor ensures that its employees involved in data processing and other persons working for the Processor are prohibited from processing data outside the scope of the instruction. Furthermore, the Processor ensures that persons authorized to process data have committed themselves to confidentiality or are subject to an appropriate statutory duty of secrecy. The duty of confidentiality/secrecy shall continue to apply even after the termination of the engagement.
3.5. The Processor shall inform the Client without undue delay if it becomes aware of any breaches of the Client's data protection.
3.6. The Processor shall take the necessary measures to secure the data and to mitigate possible adverse consequences for the data subjects, and shall promptly coordinate with the Client in this regard.
3.7. The Processor shall provide the Client with the contact person for data protection issues within the framework of the Main Agreement.
3.8. The Processor shall correct or erase the data if the Client instructs it to do so and if this is within the scope of the instructions. If a data protection-compliant deletion or restriction of data processing is not possible, the Processor shall undertake the data protection-compliant destruction of data carriers and other materials based on an individual commission by the Client or return these data carriers to the Client, unless already agreed in the Main Agreement. In special cases to be determined by the Client, storage or handover, remuneration, and protective measures shall be agreed separately.
3.9. Data, data carriers, and all other materials must be either returned or deleted at the Client's request after the termination of the engagement. If additional costs arise due to deviating specifications for the return or deletion of data, these shall be borne by the Client.
3.10. In the event of a claim being made against the Client by a data subject regarding any claims under Art. 82 GDPR, the Processor undertakes to support the Client in defending against the claim to the best of its abilities.
4. Obligations of the Client
4.1. The Client must inform the Processor immediately and completely if it discovers errors or irregularities in the results of the order with regard to data protection regulations.
4.2. In the event of a claim being made against the Client by a data subject regarding any claims under Art. 82 GDPR, Section 3.10 shall apply accordingly.
4.3. The Client shall provide the Processor with the contact person for data protection issues within the framework of the Main Agreement.
5. Data Subject Requests
If a data subject contacts the Processor with demands in accordance with Chapter III GDPR (right to information, rectification or erasure of their data) for rectification, erasure or information, the Processor will refer the data subject to the Client and await the Client's instructions, provided that an assignment to the Client is possible based on the data subject's information. The Processor will forward the data subject's request to the Client without undue delay. The Processor will support the Client in fulfilling its obligations according to Art. 12-22 GDPR to the best of its abilities. The Processor is not liable if the data subject's request is not answered, not answered correctly or not answered in due time by the Client.
6. Means of Proof
6.1. The Processor shall demonstrate to the Client compliance with the obligations set out in this DPA by appropriate means.
6.2. Should inspections by the Client or an auditor commissioned by the Client be required in individual cases, these shall be carried out during usual business hours without disruption of operations, after notification and taking into account a reasonable lead time. The Processor may make these dependent on prior notification with a reasonable lead time and on the signing of a confidentiality agreement regarding the data of other clients and the technical and organizational measures implemented. Should the auditor commissioned by the Client be in a competitive relationship with the Processor, the Processor has a right of objection against this auditor. For supporting the conduct of an inspection, the Processor may demand its usual remuneration. The effort of an inspection for the Processor is generally limited to one day per calendar year.
6.3. Should a data protection supervisory authority or other sovereign supervisory authority of the Client carry out an inspection, Section 6.2 shall apply accordingly. The signing of a confidentiality obligation is not required if this supervisory authority is subject to a professional or legal duty of secrecy where a breach is punishable under criminal law.
7. Sub-processors and Subcontracting Relationships
7.1. The Processor is generally entitled to engage sub-processors (further processors) in compliance with the following regulations. The engagement of sub-processors as further processors is only permissible if the Processor notifies the Client of the name and address as well as the intended activity of the sub-processor.
7.2. A sub-processor relationship requiring consent exists if the Processor commissions further processors with the entire service or a partial service of the service agreed in the Main Agreement. The Processor will enter into agreements with these third parties to the extent necessary to ensure appropriate data protection and information security measures. The Processor ensures that the sub-processor fulfils the obligations to which the Processor is subject in accordance with these clauses and the GDPR.
7.3. The contractually agreed services or partial services are carried out with the involvement of the sub-processors listed in Annex 3. The Client consents to the engagement of these sub-processors. Sub-processors that process case, contract or debtor data of the Client do so in data centres within the European Union; where a sub-processor is established outside the EEA, the processing is secured by standard contractual clauses under Art. 46(2)(c) GDPR and, where applicable, the EU-U.S. Data Privacy Framework. The current version of Annex 3 is available at www.incaseof.law/en/privacy-policy (section 11).
7.4. Before engaging additional sub-processors or replacing listed ones, the Processor shall obtain the Client's consent, which may not be withheld without a material data protection reason. The Client has the right to object to the engagement of additional sub-processors, announced in writing in advance. Consent by the Client shall be deemed given if the Client does not object to the intended change of sub-processors within two weeks of notification.
7.5. If the Processor places orders with sub-processors, it is the Processor's responsibility to transfer its data protection obligations from this DPA to the sub-processor.
7.6. In case of an objection, the Processor may, at its own discretion, either provide the service without the intended change, or, if providing the service without the intended change is unreasonable for the Processor, discontinue the service affected by the change within a reasonable period and after prior notification of the Client. The Processor will inform the Client immediately of the intended discontinuation and deadline (text form suffices). Both parties will in this case be granted the separate right of termination within 2 weeks after notification of the discontinuation.
8. Information Obligations, Text Form, Choice of Law
8.1. Should the data at the Processor be endangered by seizure or confiscation, by insolvency or composition proceedings, or by other events or measures of third parties, the Processor must inform the Client thereof without undue delay. The Processor shall immediately inform all persons responsible in this context that the sovereignty and ownership of the data lie exclusively with the Client as "Controller" within the meaning of the GDPR.
8.2. Amendments and supplements to this DPA and all its components – including any assurances given by the Processor – require an agreement, which may also be in an electronic format (text form), and an express indication that it is an amendment or supplement to this DPA. This also applies to the waiver of this formal requirement.
8.3. In case of any contradictions, the provisions of this DPA regarding data protection shall prevail over the provisions of the Main Agreement. Should individual parts of this DPA be ineffective, this shall not affect the validity of the DPA as a whole.
8.4. Austrian law shall apply.
9. Liability and Damages
The Processor shall be liable in accordance with the liability provisions set forth in the Main Agreement.
Annex 1 – Nature and Purpose of Processing
Categories of Data Subjects: The transmitted personal data concern the following categories of data subjects: Clients of the Client and, if applicable, employees of these clients.
Categories of Data: The transmitted personal data belong to the following data categories: see Section 6 of the Privacy Policy.
Categories of Sensitive Data (if applicable): The transmitted personal data include the following sensitive data: see Section 6 of the Privacy Policy.
Subject Matter of Processing and Processing Operations: The transmitted personal data are subjected to the following fundamental processing operations: Technical processing and acquisition of client names and addresses for correspondence / reminders or payment orders within the scope of the debt management process and legal enforcement.
Purposes of Processing: The transmitted personal data are processed for the following purposes of the Controller: Sending reminders, general out-of-court and judicial debt management measures.
Location of Data Processing: Data processing performed by the Processor takes place at the following locations: Processor's business premises: incaseof.law GmbH, Rathausstraße 21/13, 1010 Vienna. Data processing also takes place at the processing locations of the sub-processors.
Annex 2 – Technical and Organizational Measures according to Art. 32 GDPR (cf. Section 3.2. of the Data Processing Agreement)
Preventive Security Measures – Measures to prevent a successful attack
Technical Measures
- Logical Access Control: The assignment of access permissions follows the "Need-to-Know" principle.
- Authentication: Any access to personal data occurs exclusively after successful authentication.
- Password Security: Where passwords are used for authentication, they should be at least 8 characters long and consist of lowercase and uppercase letters, numbers, and special characters. Passwords are stored exclusively in encrypted form.
- Encryption during Transmission: Personal data is encrypted during transmission over the internet, at least insofar as it concerns sensitive data.
- Mobile Device Encryption: Mobile end devices and mobile data carriers are encrypted, at least insofar as sensitive data is stored on these devices.
- Network Security: A firewall is used to separate the internal network from the internet and – as far as possible – blocks incoming network traffic.
- Measures against Malware: Anti-virus software is used on all systems where possible. All incoming emails are automatically scanned for malware.
- Vulnerability Management: Where possible, automatic installation of security updates is enabled on all devices. Otherwise, critical security updates are installed within 3 working days, medium criticality security updates within 25 working days, and low criticality security updates within 40 working days.
Organizational Measures
- Clear Responsibilities: Internal responsibilities for data security issues are defined.
- Confidentiality Obligation of Processor's Employees: Employees are obligated to maintain confidentiality beyond the duration of their employment. In particular, they are obliged to transmit personal data to third parties only on the express instruction of a superior.
- Training and Information Measures: Employees are trained (internally or externally) on data security issues and adequately informed about data security issues (e.g., password security).
- Orderly Termination of Employment: Upon termination of employment, all accounts of the departing employee are immediately blocked, and all keys of the departing employee are collected.
- Management of Computer Hardware: Records are kept of which end devices (e.g., PC, laptop, mobile phone) have been assigned to which employee.
- Input Control: Procedures exist for controlling the accuracy of the personal data entered.
- No Duplicate Use of User Accounts: Each person should have their own user account – sharing user accounts is only permitted in particularly justified cases.
- No Unnecessary Use of Administrative Accounts: User accounts with administrative rights are only used in exceptional cases – regular use of IT systems occurs without administrative rights.
- Selection of Service Providers: When selecting service providers, the data security level offered by the service provider is taken into account. A service provider, who is to be classified as a processor, is only engaged after a data processing agreement has been concluded.
- Secure Data Disposal: Paper containing personal data is generally shredded or handed over to an external service provider for secure destruction. Data carriers are completely overwritten or physically destroyed before disposal so that the data stored on them cannot be recovered.
Physical Measures
- Physical Access Control: Entry to the business premises by external persons is only permitted when accompanied by an employee.
- Burglary Protection: Access points to the business premises have adequate burglary protection (e.g., a security door of a higher resistance class).
- Special Protection of Computer Hardware: Access to premises where computer servers are located is secured by special measures (e.g., an additional lock).
- Key Management: Keys enabling access to the business premises or parts thereof are only handed out to particularly trustworthy persons and only to the extent and for as long as these persons actually require their own key.
Detective Security Measures – Measures to detect an attack
Technical Measures
- Malware Scans: Regular scans for malware (anti-virus scans) are performed to identify malware that has already compromised an IT system.
- Automatic Logfile Monitoring: Insofar as the security logfiles of multiple systems are centrally collected on one system, an automated evaluation of the logfiles is carried out to detect possible security breaches.
- Security Mailing Lists: It is ensured that an employee of the company or an external service provider subscribes to relevant mailing lists for the announcement of new IT security threats (e.g., mailing lists of the manufacturers of the software used) to be aware of the current threat situation.
Organizational Measures
- Detection of Security Breaches by Processor's Employees: All employees are instructed on how to recognize security breaches (e.g., missing computer hardware, messages from anti-virus software).
- External Persons: All employees are instructed to address external persons if they are encountered on the business premises.
- Audits: Regular audits are conducted (e.g., checking whether all critical security updates have been installed). In particular, a regular review of granted access and entry authorizations is carried out (which employee is assigned which user account with which access rights; which persons have which keys).
- Manual Logfile Review: Insofar as logfiles are maintained (e.g., on unsuccessful authentication attempts), these are reviewed at regular intervals.
Physical Measures
- Fire Detector: If appropriate due to the size and nature of the business premises, a fire detector that is automatically triggered by smoke will be installed.
Reactive Security Measures – Measures to react to an attack
Technical Measures
- Data Backup: Data backups are created regularly and stored securely.
- Data Recovery Concept: A concept for the rapid restoration of data backups is developed to enable the timely restoration of regular operations after a security breach.
- Automatic Malware Removal: The anti-virus software used has the function to automatically remove malware.
Organizational Measures
- Reporting Obligation for Employees: All employees are instructed to report security breaches immediately to a predefined internal department or person.
- Reporting Obligation for External Service Providers: All service providers have been provided with contact details for reporting security breaches.
- Process for Responding to Security Breaches: An appropriate process ensures that security breaches can be reported to the data protection authority within 72 hours of becoming aware of the breach. In particular, all employees must be informed of the emergency telephone numbers of the persons to be involved (e.g., emergency telephone number for IT support).
Physical Measures
- Fire Extinguishers: An adequate number of fire extinguishers are available on the business premises. All employees know where the fire extinguishers are located.
- Fire Alarm: Insofar as there is no fire detector with an automatic connection to the fire brigade, an appropriate process ensures that the fire brigade can be notified manually.
Deterrent Security Measures – Measures to reduce attacker motivation
Technical Measures
- Automatic Warning Messages: Users receive automatic warning messages for risky IT usage (e.g., via the web browser when an encrypted website does not use a correct SSL/TLS certificate).
Organizational Measures
- Sanctions for Attacks by Own Employees: All employees are informed that attacks on company-owned IT systems will not be tolerated and can lead to serious employment law consequences, such as dismissal.
Annex 3 – Sub-processors (cf. clause 7.3 of the Data Processing Agreement), as of 4 October 2026
The Processor engages the following sub-processors. Case, contract and debtor data are processed in data centres within the European Union. Services that do not process personal data (e.g. public documentation) are not listed.
| Sub-processor (company, seat) | Service / purpose | Processing location | Transfer basis |
|---|---|---|---|
| Supabase Inc., San Francisco (USA) | Database, authentication, file storage of the platform | AWS eu-west-1, Ireland (test: eu-north-1, Stockholm) | EU region; Data Privacy Framework, SCC |
| Railway Corp., San Francisco (USA) | Application servers (API, ERV gateway, PDF rendering, database) | Google Cloud europe-west4, Netherlands | EU region; SCC |
| Vercel Inc., San Francisco (USA) | Web applications (customer portal, debtor portal, website, API docs) | fra1, Frankfurt (DE) | EU region; Data Privacy Framework, SCC |
| Google Cloud EMEA Ltd., Dublin (IE) | AI-based document extraction (Vertex AI); sign-in via Google account (optional) | europe-west3, Frankfurt (DE); no use for training | EU processing; Google Cloud DPA |
| Twilio Ireland Ltd., Dublin (IE) | SMS, one-time codes, portal chat | Region IE1, Ireland | EU region; Twilio DPA |
| Twilio SendGrid (Twilio Ireland Ltd.), Dublin (IE) | Transactional e-mail delivery | EU data residency | EU region; Twilio DPA |
| Functional Software Inc. (Sentry), San Francisco (USA) | Error and performance monitoring | EU region, Frankfurt (DE) | EU region; Data Privacy Framework, SCC |
| Cloudflare Inc., San Francisco (USA) | Network proxy, attack protection, bot check (transit) | Processing at EU locations; no storage of content data | Data Privacy Framework, SCC |
| DIMOCO Payments GmbH, Vienna (AT) | Payment processing in the debtor portal | Austria | EU |
| Österreichische Post AG (Einfach-Brief), Vienna (AT) | Printing and postal dispatch of letters | Austria | EU |
| MANZ Solutions GmbH, Vienna (AT) | Electronic legal communication Austria (webERV) | Austria | EU |
| procilon GmbH, Taucha (DE) | Electronic legal communication Germany (EGVP/EDA), from go-live | Germany | EU |
| maesn GmbH, Berlin (DE) | Connection of accounting systems (sevDesk, Business Central, Odoo, Xero), only where used by the Client | EU | EU |
| Pipedrive OÜ, Tallinn (EE) | Customer relationship management (Client master data, no debtor data) | EU | EU |
| Slack Technologies Ltd., Dublin (IE) | Internal system notifications without personal case data | EU/USA | Data Privacy Framework, SCC |
Changes to Annex 3 are notified to the Client in advance in accordance with clause 7.4.
incaseof.law GmbH – Version 2.2/2026