Effective Date: December 10, 2025
Last Updated: December 10, 2025
This Data Processing Agreement ("DPA") forms part of the Terms of Service ("Agreement") between CaseMark AI, Inc. ("case.dev," "Processor," "we," "us," or "our") and the entity agreeing to these terms ("Customer," "Controller," "you," or "your").
This DPA reflects the parties' agreement regarding the processing of Personal Data in connection with Customer's use of the case.dev platform and services.
By using our Services, you agree to this DPA. If you are accepting on behalf of an organization, you represent that you have authority to bind that organization.
"Applicable Data Protection Law" means all laws and regulations applicable to the processing of Personal Data, including but not limited to:
"Controller" means the entity that determines the purposes and means of processing Personal Data. Under this DPA, Customer is the Controller.
"Data Subject" means an identified or identifiable natural person whose Personal Data is processed.
"Personal Data" means any information relating to an identified or identifiable natural person, including information defined as "personal data," "personal information," or similar terms under Applicable Data Protection Law.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
"Processing" means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure, or destruction.
"Processor" means an entity that processes Personal Data on behalf of a Controller. Under this DPA, case.dev is the Processor.
"Services" means the case.dev platform and all related services, including the API Platform, Console, Thurgood, Orbit Compute, and Payments Platform.
"Sub-processor" means any third party engaged by case.dev to process Personal Data on behalf of Customer.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission.
"Supervisory Authority" means an independent public authority responsible for monitoring the application of data protection law.
This DPA applies to the processing of Personal Data by case.dev on behalf of Customer in connection with the Services.
Customer represents and warrants that:
case.dev processes Personal Data to provide the Services as described in the Agreement, including:
| Service | Processing Purpose |
|---|---|
| Vault API | Storage, encryption, indexing, and semantic search of documents |
| OCR/Vision API | Text extraction from documents and images |
| Voice API | Transcription of audio/video recordings, speaker identification, PII redaction |
| LLM API | AI-powered analysis, summarization, and generation |
| Workflows API | Automated document processing pipelines |
| Email API | Sending transactional emails on Customer's behalf |
| Thurgood | AI-assisted code generation and execution |
| Orbit Compute | Application hosting and deployment |
| Payments Platform | Trust accounting and payment processing |
Processing continues for the duration of Customer's use of the Services, plus any retention period required by law or specified in the Agreement.
Personal Data processed may relate to the following categories of Data Subjects:
Depending on Customer's use of the Services, Personal Data processed may include:
Identity Data:
Contact Data:
Financial Data:
Legal Matter Data:
Health Data:
Employment Data:
Audio/Visual Data:
Technical Data:
Customer acknowledges that documents uploaded to the Services may contain special categories of Personal Data (sensitive data) as defined under GDPR Article 9, including data revealing racial or ethnic origin, political opinions, religious beliefs, health data, or data concerning sex life or sexual orientation.
Customer is responsible for ensuring a valid legal basis exists for processing such data and for implementing appropriate safeguards.
case.dev will:
Documented Instructions: Customer's instructions are documented in:
case.dev will:
case.dev implements appropriate technical and organizational measures to protect Personal Data, including:
Encryption:
Access Controls:
Infrastructure Security:
Operational Security:
Monitoring and Logging:
Physical Security:
A detailed description of security measures is available in Annex II.
case.dev may engage Sub-processors to assist in providing the Services, subject to the requirements in Section 6.
case.dev will assist Customer in responding to Data Subject requests to exercise their rights under Applicable Data Protection Law, including rights of:
case.dev will:
case.dev will provide reasonable assistance to Customer with:
In the event of a Personal Data Breach affecting Customer's data, case.dev will:
Notification will be sent to the email address associated with Customer's account and/or security contact on file.
Upon termination of the Agreement or upon Customer's written request:
Customer is responsible for:
Customer will provide clear, lawful instructions regarding the processing of Personal Data. Customer acknowledges that case.dev is not required to evaluate the legality of Customer's instructions but may refuse to follow instructions that appear to violate Applicable Data Protection Law.
Customer is responsible for:
Customer provides general authorization for case.dev to engage Sub-processors to process Personal Data, subject to the requirements of this Section 6.
case.dev currently uses the following Sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, storage, compute | United States |
| Stripe, Inc. | Payment processing | United States |
| Clerk, Inc. | Authentication and user management | United States |
| OpenAI, Inc. | AI language model processing | United States |
| Anthropic, PBC | AI language model processing | United States |
| Google LLC | AI language model processing | United States |
| Modal Labs, Inc. | Sandbox execution (Thurgood) | United States |
| GitHub, Inc. | Repository integration | United States |
| Vercel, Inc. | Application hosting | United States |
| AssemblyAI, Inc. | Audio transcription | United States |
| ElevenLabs, Inc. | Text-to-speech | United States |
An up-to-date list of Sub-processors is available at https://case.dev/legal/sub-processors.
case.dev will:
case.dev will:
If Customer has a reasonable, documented objection to a new Sub-processor based on data protection concerns:
Personal Data may be transferred to and processed in the United States and other countries where case.dev or its Sub-processors operate.
For transfers of Personal Data from the European Economic Area (EEA), United Kingdom, or Switzerland to countries without an adequate level of data protection, case.dev relies on:
The parties agree that the Standard Contractual Clauses set forth in Annex I are incorporated into this DPA by reference.
For transfers subject to GDPR:
case.dev implements supplementary measures to protect transferred data, including:
case.dev will:
Customer may audit case.dev's compliance with this DPA, subject to the following:
In lieu of an audit, Customer may review:
case.dev will cooperate with audits by Supervisory Authorities to the extent required by Applicable Data Protection Law.
Each party's liability under this DPA is subject to the limitations of liability set forth in the Agreement.
Each party is liable for damages caused by its violation of Applicable Data Protection Law or this DPA. Where both parties are responsible for damage:
This DPA takes effect on the date Customer accepts the Agreement and continues until the Agreement terminates.
Sections 4.8 (Deletion and Return), 8 (Audits), 9 (Liability), and any provisions that by their nature should survive, will survive termination of this DPA.
In the event of a conflict between this DPA and the Agreement, this DPA will prevail with respect to the processing of Personal Data.
This DPA may be amended by case.dev to reflect changes in Applicable Data Protection Law or our processing activities. Material changes will be notified to Customer with at least 30 days' notice.
If any provision of this DPA is found unenforceable, the remaining provisions will continue in effect.
This DPA is governed by the laws specified in the Agreement, except that the Standard Contractual Clauses are governed as specified therein.
For questions about this DPA or to exercise rights under this DPA:
Email: hello@casemark.com
Mail:
CaseMark AI, Inc.
Attn: Data Protection
500 SW 116th Ave Suite 107
Portland, OR 97225
Data Protection Inquiries: hello@casemark.com
For transfers of Personal Data from the EEA to case.dev in the United States, the parties agree to the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914, which are incorporated by reference.
Module Two: Controller to Processor
Clause 7 (Docking Clause): Not used.
Clause 9 (Use of Sub-processors): Option 2 (General Written Authorization) applies. The time period for notice is 30 days.
Clause 11 (Redress): The optional language is not used.
Clause 17 (Governing Law): The laws of Ireland govern the SCCs.
Clause 18 (Choice of Forum): The courts of Ireland have jurisdiction.
Annex I.A (List of Parties):
Data Exporter:
Data Importer:
Annex I.B (Description of Transfer): As described in Section 3 of this DPA.
Annex I.C (Competent Supervisory Authority): The supervisory authority of the EEA member state where the data exporter is established, or where the data exporter is not established in the EEA, the supervisory authority of the member state where the data exporter's EU representative is established.
Annex II (Technical and Organizational Measures): As described in Section 4.3 and Annex II of this DPA.
Annex III (Sub-processors): As described in Section 6.2 of this DPA.
case.dev implements the following technical and organizational measures to protect Personal Data:
| Measure | Implementation |
|---|---|
| Encryption at rest | AES-256 encryption via AWS KMS for all stored data |
| Encryption in transit | TLS 1.3 for all API communications |
| Key management | AWS Key Management Service with automatic rotation |
| Database encryption | Encrypted database connections and storage |
| Backup encryption | All backups encrypted at rest |
| Measure | Implementation |
|---|---|
| Authentication | API key authentication with secure hashing |
| Multi-factor authentication | Required for internal systems and Console access |
| Role-based access | Organization-level RBAC with Owner, Admin, Member, Viewer roles |
| Least privilege | Access limited to necessary personnel and systems |
| Session management | Secure session tokens with expiration |
| API key rotation | Support for key rotation and revocation |
(Additional security measures for Network Security, Data Isolation, Monitoring and Logging, Incident Response, Business Continuity, Vendor Management, Personnel Security, and Physical Security are described in similar detail in the full DPA documentation.)
Current as of December 10, 2025
| Sub-processor | Processing Activity | Data Processed | Location |
|---|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure, storage, compute | All Customer data | United States |
| Stripe, Inc. | Payment processing | Payment and billing data | United States |
| Clerk, Inc. | Authentication | Account credentials, session data | United States |
| OpenAI, Inc. | AI language model processing | Prompts and content submitted to LLM API | United States |
| Anthropic, PBC | AI language model processing | Prompts and content submitted to LLM API | United States |
| Google LLC | AI language model processing | Prompts and content submitted to LLM API | United States |
| xAI Corp. | AI language model processing | Prompts and content submitted to LLM API | United States |
| DeepSeek | AI language model processing | Prompts and content submitted to LLM API | China |
| Modal Labs, Inc. | Sandbox execution | Code and execution data (Thurgood) | United States |
| GitHub, Inc. | Repository integration | Repository data, OAuth tokens | United States |
| Vercel, Inc. | Application hosting | Deployment artifacts (Orbit) | United States |
| AssemblyAI, Inc. | Audio transcription | Audio files submitted to Voice API | United States |
| ElevenLabs, Inc. | Text-to-speech | Text submitted to TTS API | United States |
| Voyage AI, Inc. | Embedding generation | Text submitted for embeddings | United States |
Updates: This list is updated at https://case.dev/legal/sub-processors. Subscribe to notifications by emailing hello@casemark.com.
By using case.dev Services, Customer acknowledges and agrees to this Data Processing Agreement.
Effective Date: December 10, 2025