Legal
Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Customer Subscription Agreement between FamilyCase.AI Inc. (“Processor”) and the customer law firm (“Controller”) and describes how FamilyCase processes personal information on the Controller's behalf when providing the service.
1. Roles & documented instructions
The firm is the controller for matter/client personal data. FamilyCase processes that data only to provide the service and per documented instructions (including this DPA, the product configuration the firm sets, and lawful written instructions). FamilyCase will not process Controller personal data for its own purposes unrelated to the service, and will not use customer content to train public foundation models. Authorized firm users accept product terms; portal users receive privacy disclosures where the portal processes personal information.
2. Categories of data subjects & data
Data subjects may include firm personnel, clients, opposing parties, children referenced in family-law matters, witnesses, and other individuals appearing in matter content. Categories include account data, billing data, usage/security logs, and matter content the firm stores (which may include special-category or sensitive personal information).
3. Confidentiality & security (TOMs)
FamilyCase maintains confidentiality and restricts access on a need-to-know basis. Technical and organizational measures include encryption in transit and at rest, per-tenant isolation (including database row-level security in database mode), access controls, logging/monitoring, and a hash-chained audit trail of sensitive actions. FamilyCase ensures personnel processing personal data are bound by confidentiality obligations.
4. Subprocessors
Controller authorizes FamilyCase to engage the subprocessors listed on the public Subprocessor List (currently including AWS, Stripe, Resend, and Google OAuth as applicable). FamilyCase will impose data-protection obligations on subprocessors no less protective than this DPA. FamilyCase will provide notice of intended new subprocessors via an update to the Subprocessor List and/or account-owner email at least 14 days before the new subprocessor processes Controller personal data (or sooner if required for security). Controller may object on reasonable data-protection grounds; if the parties cannot resolve the objection, Controller may terminate the affected service as its sole remedy.
5. Personal data breaches
FamilyCase will notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller personal data, and in any event within 72 hours where feasible, providing information reasonably available to help the Controller meet its own notification duties. Notification does not admit fault or liability.
6. Data subject rights & assistance
Taking into account the nature of processing, FamilyCase will assist the Controller by appropriate technical and organizational measures, insofar as possible, to respond to requests to exercise data subject rights under applicable law. Where a data subject contacts FamilyCase directly about firm-controlled matter data, FamilyCase may refer the request to the Controller.
7. Deletion or return on termination
Upon termination or expiry of the service, FamilyCase will, at Controller's choice communicated within 30 days, return available Controller personal data in a reasonable export format or delete it (and certify deletion on request), except for copies retained as required by law, professional-responsibility holds the Controller configured, billing/tax records, or secure backups that are deleted on the backup cycle. Ordinary deletion completes within 30 days after the applicable wind-down period unless a longer period is required by law or Controller instructions.
8. International transfers
FamilyCase processes personal data primarily in the United States (AWS us-west-2). Where the GDPR, UK GDPR, or Swiss law requires a transfer mechanism for transfers to FamilyCase in the United States, the parties incorporate the European Commission Standard Contractual Clauses (Module Two: controller-to-processor) and the UK International Data Transfer Addendum as applicable. The SCCs prevail over conflicting terms for the transferred data. Supplementary measures include encryption in transit and at rest and tenant isolation.
9. Audits & compliance information
Upon reasonable written request no more than once per 12 months (unless required by a supervisory authority or following a personal data breach), FamilyCase will make available information necessary to demonstrate compliance with this DPA, which may include security summaries, questionnaire responses, and relevant third-party audit reports under NDA. On-site audits are available only where required by law or a supervisory authority and after the parties agree scope, timing, and cost allocation.
10. Version log
Version 1.1.1 (2026-09-29): Wording clarification; no change to obligations.