Data Processing Agreement
Data Processing Agreement
Last Updated: August 25, 2026
This Data Processing Agreement ("DPA") forms part of the Agreement between Dynamanic LLC ("Processor", "we", "us") and the entity agreeing to these terms ("Controller", "Customer", "you") for the use of the CaseLens service (the "Service").
1. Definitions
- "Applicable Data Protection Law" means all applicable laws relating to data protection, privacy, and the processing of personal data, including GDPR, CCPA, and other relevant regulations.
- "Customer Data" means any personal data processed by Processor on behalf of Customer through the Service.
- "Personal Data" has the meaning given in GDPR Article 4(1).
- "Processing" has the meaning given in GDPR Article 4(2).
- "Sub-processor" means any third party engaged by Processor to process Customer Data.
2. Scope and Roles
2.1 Roles
- Customer is the Controller of Customer Data
- Dynamanic LLC is the Processor acting on Customer's behalf
2.2 Scope of Processing
This DPA applies to all processing of Customer Data by Processor in connection with the Service.
3. Customer Obligations
Customer shall:
- Ensure lawful basis for processing personal data
- Provide clear instructions for processing
- Notify Processor of any changes to processing requirements
- Ensure accuracy of Customer Data
- Respond to data subject requests
4. Processor Obligations
4.1 Processing Instructions
Processor shall:
- Process Customer Data only on documented instructions from Customer
- Inform Customer if legally required to process otherwise
- Not process data beyond what is necessary for the Service
4.2 Confidentiality
Processor shall ensure that personnel:
- Are bound by confidentiality obligations
- Only process data as instructed
- Receive appropriate training
4.3 Security Measures
Processor implements:
Technical Measures:
- Encryption at rest (AES-256-GCM)
- Encryption in transit (TLS 1.3)
- Access control and authentication (RBAC, MFA)
- Intrusion detection and prevention
- Regular vulnerability scanning
- Secure development practices
Organizational Measures:
- Security awareness training
- Background checks for personnel
- Incident response procedures
- Business continuity planning
- Regular security audits
4.4 Sub-processors
Processor shall:
- Maintain a list of authorized sub-processors
- Notify Customer of changes to sub-processors
- Ensure sub-processors are bound by equivalent obligations
- Remain liable for sub-processor compliance
Current Sub-processors:
| Sub-processor | Purpose | Location |
|---------------|---------|----------|
| AWS | Cloud Infrastructure (compute, storage) | US (with EU options) |
| AWS SES | Transactional Email Delivery | US |
| Stripe | Payment Processing | US |
| SendGrid | Email Delivery | US |
| OpenAI | AI Document Analysis, Translation, Review (when OpenAI provider enabled) | US |
| Anthropic | AI Document Analysis, Translation, Review (when Anthropic provider enabled) | US |
4.5 Data Subject Rights
Processor shall assist Customer in responding to requests from data subjects exercising their rights under Applicable Data Protection Law.
4.6 Data Breach Notification
Processor shall:
- Notify Customer of personal data breaches without undue delay (within 72 hours)
- Provide information necessary for Customer to meet notification obligations
- Take appropriate remedial measures
4.7 Data Protection Impact Assessments
Upon request, Processor shall provide reasonable assistance with DPIAs and prior consultations with supervisory authorities.
4.8 Audits
- Customer may audit Processor's compliance, subject to reasonable notice
- Processor shall provide relevant security documentation and, once available, independent audit reports (e.g., SOC 2 Type II)
- Customer may request third-party audits at Customer's expense
5. International Transfers
5.1 Transfer Mechanisms
For transfers of Customer Data outside the EEA, Processor uses:
- Standard Contractual Clauses (SCCs) - Module 2 (Controller to Processor)
- Supplementary measures as appropriate
5.2 Data Localization
Upon request, Processor can ensure data remains in specified regions (EU, US, etc.) subject to additional terms.
6. Data Retention and Deletion
6.1 Retention
- Processor retains Customer Data for the duration of the Agreement
- Customer controls retention within the Service
6.2 Deletion
Upon termination:
- Customer has 30 days to export data
- Processor deletes Customer Data within 90 days
- Processor provides deletion certification upon request
- Deletion may be delayed where legally required
7. Liability
7.1 Allocation
- Each party is liable for its own non-compliance
- Processor liability is subject to Agreement limitations
7.2 Indemnification
Processor shall indemnify Customer for direct damages resulting from Processor's breach of this DPA.
8. Term and Termination
- This DPA is effective for the term of the Agreement
- DPA survives termination until all Customer Data is deleted
- Either party may terminate for material breach
9. Amendments
This DPA may be amended:
- To comply with regulatory requirements
- With 30 days notice to Customer
- By mutual written agreement
10. Contact
Data Protection Officer:
Dynamanic LLC
Email: privacy@dynamanic.io
ANNEX I: Details of Processing
| Category | Details |
|---|---|
| Subject Matter | CaseLens document processing and review |
| Duration | Duration of Agreement |
| Nature and Purpose | Document storage, search, review, production |
| Data Subjects | Employees, clients, third parties in documents |
| Personal Data Types | Names, email addresses, document content, metadata |
ANNEX II: Security Measures
See Section 4.3 above for detailed security measures.
ANNEX III: Standard Contractual Clauses
The Standard Contractual Clauses (Module 2: Controller to Processor) adopted by European Commission Decision 2021/914 are incorporated by reference.
By using the Service, Customer agrees to this Data Processing Agreement.