Data Processing Agreement (DPA)

Effective date: 03.04.26
Revised: 28.07.26

This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions (“Agreement”) between:

Ckvens AS (“Processor”) and the customer (“Controller”).

This DPA applies where the Processor processes Personal Data on behalf of the Controller.

1. Definitions

For the purposes of this DPA:

  • “Personal Data” means any information relating to an identified or identifiable natural person
  • “Processing” has the meaning given in GDPR Article 4
  • “Controller” means the customer determining the purposes and means of processing
  • “Processor” means Ckvens AS
  • “GDPR” means Regulation (EU) 2016/679

2. Subject Matter and Duration

2.1 Subject matter — Processing of Personal Data in connection with the provision of the Ckvens platform.

2.2 Duration — This DPA applies for the duration of the Agreement and until all Personal Data is deleted or returned.

3. Nature and Purpose of Processing

The Processor will process Personal Data solely for the purpose of:

  • providing access to the Ckvens platform
  • enabling case structuring, document handling, and analysis
  • supporting AI-assisted features within the platform

The Processor shall not process Personal Data for its own purposes.

AI-assisted features are provided through two model providers, both processing within the EU: Azure OpenAI Service (Microsoft, Sweden Central) and Anthropic Claude models served via Amazon Bedrock (AWS, European Union regions). Both process data in real time without permanently storing prompts or completions and without training on customer data. On Amazon Bedrock, the model provider (Anthropic) has no access to customer content.

4. Categories of Data and Data Subjects

4.1 Categories of Personal Data

May include, depending on customer use:

  • names and contact details
  • case-related information
  • documents and communications
  • other information uploaded by users

4.2 Special categories

The platform may process sensitive data, including data related to legal matters. The Controller is responsible for ensuring a lawful basis for processing such data.

4.3 Data subjects

May include:

  • clients
  • witnesses
  • employees
  • third parties referenced in case materials

5. Processor Obligations

The Processor shall:

  • process Personal Data only on documented instructions from the Controller
  • ensure confidentiality of all personnel with access to Personal Data
  • implement appropriate technical and organisational measures
  • ensure compliance with GDPR Article 28

6. Security Measures

The Processor implements appropriate security measures, including:

  • hosting on Microsoft Azure infrastructure within the EU (primary region Sweden Central; document embeddings in Norway East); AI processing of Claude models on AWS infrastructure within the EU
  • encryption in transit (TLS 1.2+) and at rest (AES-256)
  • role-based access control mechanisms
  • short-lived, role-based cloud credentials for AI processing — no static cloud access keys in the application
  • audit trail logging of user and system activity
  • authentication via secure credential handling with hashed passwords, or single sign-on via the Controller’s Microsoft Entra ID tenant
  • rate limiting and input validation on all API endpoints

The Processor shall maintain security appropriate to the risk and shall regularly review and update measures as needed.

7. Sub-processors

7.1 General authorization

The Controller provides general authorization for the Processor to engage sub-processors, subject to the requirements set out in this Section 7.

7.2 Current sub-processors

Sub-processorPurposeLocation
Microsoft AzureCloud hosting, storage, database, document search, speech-to-textEU (Sweden Central; embeddings in Norway East)
Azure OpenAI ServiceAI-assisted analysis and document processing (GPT models)EU (Sweden Central)
Amazon Web Services (Amazon Bedrock)AI-assisted analysis (Anthropic Claude models)EU (AWS European Union regions, primary Frankfurt)
Mistral AIDocument text extraction (OCR) during indexingEU
TavilyWeb search queries — only for conversations where the user has enabled web searchUSA
ChatwootIn-app support conversationsUSA
ResendTransactional email delivery (invitations, notifications)USA
PolarSubscription billing and payment processing (merchant of record)USA

7.3 Requirements

The Processor shall:

  • ensure sub-processors are bound by equivalent data protection obligations
  • remain responsible for the performance of sub-processors

7.4 Changes to sub-processors

The Processor shall provide the Controller with at least 30 days’ prior notice before engaging a new sub-processor or making material changes to existing arrangements.

The Controller may object on reasonable data protection grounds within 14 days of receiving notice. If the parties are unable to resolve the objection, the Controller may terminate the Agreement.

8. International Transfers

Personal Data — including all case documents and all AI processing of case content — is processed within the European Economic Area (EEA).

Limited transfers outside the EEA occur only for transactional email (Resend), optional web search queries (Tavily), in-app support conversations (Chatwoot), and subscription billing and payment processing (Polar). For any such transfer, the Processor shall ensure:

  • appropriate safeguards are in place in accordance with GDPR Chapter V
  • Standard Contractual Clauses (SCCs) approved by the European Commission are used where required
  • the Controller is informed of any such transfers

9. Assistance to the Controller

The Processor shall assist the Controller, taking into account the nature of processing, with:

  • responding to data subject rights requests (access, rectification, erasure, portability, restriction, and objection)
  • data protection impact assessments (DPIA)
  • compliance with GDPR obligations, including notification to supervisory authorities

The platform provides built-in tools for data export and account deletion to support data subject rights.

10. Data Breach Notification

The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach.

The notification shall include:

  • a description of the nature of the breach
  • the categories and approximate number of data subjects and records affected
  • likely consequences
  • measures taken or proposed to mitigate the breach

11. Audit and Compliance

The Processor shall make available to the Controller information necessary to demonstrate compliance with GDPR Article 28.

The Processor shall allow and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.

Audits shall be:

  • conducted with reasonable prior notice
  • limited in scope to the processing activities under this DPA
  • subject to confidentiality obligations

12. Deletion or Return of Data

Upon termination of the Agreement, the Processor shall, at the choice of the Controller:

  • delete all Personal Data, or
  • return all Personal Data in a commonly used, machine-readable format

Deletion or return shall be completed within 30 days of termination, unless retention is required by applicable law.

The Processor shall confirm deletion in writing upon request.

13. Liability

Liability under this DPA shall be governed by the liability provisions of the Agreement.

14. Governing Law

This DPA shall be governed by the laws of Norway, without regard to conflict of law principles.

15. Acceptance

This DPA is accepted:

  • by execution of the Agreement, or
  • by acceptance of the Terms and Conditions during sign-up

16. Changes to this DPA

The Processor may update this DPA from time to time to reflect changes in processing activities, applicable law, or sub-processor arrangements.

Where changes are material, the Processor shall provide at least 30 days’ prior notice.

The Controller may object to such changes within 14 days of receiving notice. If the parties are unable to resolve the issue, the Controller may terminate the Agreement.

Continued use of the services after the effective date of changes constitutes acceptance of the updated DPA.

ANNEX 1 – Processing Details

ItemDetails
PurposeProvision of legal case management platform with AI-assisted analysis
DurationFor the duration of the Agreement
Categories of dataNames, contact details, case information, documents, communications
Data subjectsClients, witnesses, employees, third parties in case materials
Processing activitiesStorage, organisation, retrieval, analysis, OCR, search indexing, AI-assisted processing, speech-to-text
InfrastructureMicrosoft Azure (EU — Sweden Central, embeddings Norway East); AWS Amazon Bedrock (EU — primary Frankfurt)
AI processingAzure OpenAI Service (GPT models) and Anthropic Claude models via Amazon Bedrock — no permanent storage of prompts or outputs, no training on customer data, model provider has no access to content on Bedrock

Last updated: 28 July 2026

Ckvens AS © 2025–2026. All rights reserved.

Ready to see your matters — clearly?

Submit the form to join our pilot. You can also email us at contact@ckvens.com.

Join and turn case chaos into a crisp, intelligent case.

Get access