Data Processing Agreement (DPA)
Effective date: 03.04.26
Revised: 28.07.26
This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions (“Agreement”) between:
Ckvens AS (“Processor”) and the customer (“Controller”).
This DPA applies where the Processor processes Personal Data on behalf of the Controller.
1. Definitions
For the purposes of this DPA:
- “Personal Data” means any information relating to an identified or identifiable natural person
- “Processing” has the meaning given in GDPR Article 4
- “Controller” means the customer determining the purposes and means of processing
- “Processor” means Ckvens AS
- “GDPR” means Regulation (EU) 2016/679
2. Subject Matter and Duration
2.1 Subject matter — Processing of Personal Data in connection with the provision of the Ckvens platform.
2.2 Duration — This DPA applies for the duration of the Agreement and until all Personal Data is deleted or returned.
3. Nature and Purpose of Processing
The Processor will process Personal Data solely for the purpose of:
- providing access to the Ckvens platform
- enabling case structuring, document handling, and analysis
- supporting AI-assisted features within the platform
The Processor shall not process Personal Data for its own purposes.
AI-assisted features are provided through two model providers, both processing within the EU: Azure OpenAI Service (Microsoft, Sweden Central) and Anthropic Claude models served via Amazon Bedrock (AWS, European Union regions). Both process data in real time without permanently storing prompts or completions and without training on customer data. On Amazon Bedrock, the model provider (Anthropic) has no access to customer content.
4. Categories of Data and Data Subjects
4.1 Categories of Personal Data
May include, depending on customer use:
- names and contact details
- case-related information
- documents and communications
- other information uploaded by users
4.2 Special categories
The platform may process sensitive data, including data related to legal matters. The Controller is responsible for ensuring a lawful basis for processing such data.
4.3 Data subjects
May include:
- clients
- witnesses
- employees
- third parties referenced in case materials
5. Processor Obligations
The Processor shall:
- process Personal Data only on documented instructions from the Controller
- ensure confidentiality of all personnel with access to Personal Data
- implement appropriate technical and organisational measures
- ensure compliance with GDPR Article 28
6. Security Measures
The Processor implements appropriate security measures, including:
- hosting on Microsoft Azure infrastructure within the EU (primary region Sweden Central; document embeddings in Norway East); AI processing of Claude models on AWS infrastructure within the EU
- encryption in transit (TLS 1.2+) and at rest (AES-256)
- role-based access control mechanisms
- short-lived, role-based cloud credentials for AI processing — no static cloud access keys in the application
- audit trail logging of user and system activity
- authentication via secure credential handling with hashed passwords, or single sign-on via the Controller’s Microsoft Entra ID tenant
- rate limiting and input validation on all API endpoints
The Processor shall maintain security appropriate to the risk and shall regularly review and update measures as needed.
7. Sub-processors
7.1 General authorization
The Controller provides general authorization for the Processor to engage sub-processors, subject to the requirements set out in this Section 7.
7.2 Current sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Cloud hosting, storage, database, document search, speech-to-text | EU (Sweden Central; embeddings in Norway East) |
| Azure OpenAI Service | AI-assisted analysis and document processing (GPT models) | EU (Sweden Central) |
| Amazon Web Services (Amazon Bedrock) | AI-assisted analysis (Anthropic Claude models) | EU (AWS European Union regions, primary Frankfurt) |
| Mistral AI | Document text extraction (OCR) during indexing | EU |
| Tavily | Web search queries — only for conversations where the user has enabled web search | USA |
| Chatwoot | In-app support conversations | USA |
| Resend | Transactional email delivery (invitations, notifications) | USA |
| Polar | Subscription billing and payment processing (merchant of record) | USA |
7.3 Requirements
The Processor shall:
- ensure sub-processors are bound by equivalent data protection obligations
- remain responsible for the performance of sub-processors
7.4 Changes to sub-processors
The Processor shall provide the Controller with at least 30 days’ prior notice before engaging a new sub-processor or making material changes to existing arrangements.
The Controller may object on reasonable data protection grounds within 14 days of receiving notice. If the parties are unable to resolve the objection, the Controller may terminate the Agreement.
8. International Transfers
Personal Data — including all case documents and all AI processing of case content — is processed within the European Economic Area (EEA).
Limited transfers outside the EEA occur only for transactional email (Resend), optional web search queries (Tavily), in-app support conversations (Chatwoot), and subscription billing and payment processing (Polar). For any such transfer, the Processor shall ensure:
- appropriate safeguards are in place in accordance with GDPR Chapter V
- Standard Contractual Clauses (SCCs) approved by the European Commission are used where required
- the Controller is informed of any such transfers
9. Assistance to the Controller
The Processor shall assist the Controller, taking into account the nature of processing, with:
- responding to data subject rights requests (access, rectification, erasure, portability, restriction, and objection)
- data protection impact assessments (DPIA)
- compliance with GDPR obligations, including notification to supervisory authorities
The platform provides built-in tools for data export and account deletion to support data subject rights.
10. Data Breach Notification
The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach.
The notification shall include:
- a description of the nature of the breach
- the categories and approximate number of data subjects and records affected
- likely consequences
- measures taken or proposed to mitigate the breach
11. Audit and Compliance
The Processor shall make available to the Controller information necessary to demonstrate compliance with GDPR Article 28.
The Processor shall allow and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
Audits shall be:
- conducted with reasonable prior notice
- limited in scope to the processing activities under this DPA
- subject to confidentiality obligations
12. Deletion or Return of Data
Upon termination of the Agreement, the Processor shall, at the choice of the Controller:
- delete all Personal Data, or
- return all Personal Data in a commonly used, machine-readable format
Deletion or return shall be completed within 30 days of termination, unless retention is required by applicable law.
The Processor shall confirm deletion in writing upon request.
13. Liability
Liability under this DPA shall be governed by the liability provisions of the Agreement.
14. Governing Law
This DPA shall be governed by the laws of Norway, without regard to conflict of law principles.
15. Acceptance
This DPA is accepted:
- by execution of the Agreement, or
- by acceptance of the Terms and Conditions during sign-up
16. Changes to this DPA
The Processor may update this DPA from time to time to reflect changes in processing activities, applicable law, or sub-processor arrangements.
Where changes are material, the Processor shall provide at least 30 days’ prior notice.
The Controller may object to such changes within 14 days of receiving notice. If the parties are unable to resolve the issue, the Controller may terminate the Agreement.
Continued use of the services after the effective date of changes constitutes acceptance of the updated DPA.
ANNEX 1 – Processing Details
| Item | Details |
|---|---|
| Purpose | Provision of legal case management platform with AI-assisted analysis |
| Duration | For the duration of the Agreement |
| Categories of data | Names, contact details, case information, documents, communications |
| Data subjects | Clients, witnesses, employees, third parties in case materials |
| Processing activities | Storage, organisation, retrieval, analysis, OCR, search indexing, AI-assisted processing, speech-to-text |
| Infrastructure | Microsoft Azure (EU — Sweden Central, embeddings Norway East); AWS Amazon Bedrock (EU — primary Frankfurt) |
| AI processing | Azure OpenAI Service (GPT models) and Anthropic Claude models via Amazon Bedrock — no permanent storage of prompts or outputs, no training on customer data, model provider has no access to content on Bedrock |
Last updated: 28 July 2026
Ckvens AS © 2025–2026. All rights reserved.