Caseworth
PricingContact
LoginGet started free →
Core Platform
  • LexstimateAI-powered case valuation report
  • The PointMass tort early warning intelligence
Free Tools
  • SoL CheckerStatute of limitations by state
  • Injury Code ScannerICD and injury code lookup
  • Legal Opinion ReaderDecode court opinions fast
Platform
  • FeaturesEverything Caseworth does
Free to start
Get My Lexstimate
Plain-English case valuation with cited outcomes. No credit card required.
Try free→
For Attorneys
  • Caseworth ProLitigation intelligence for law firms
  • Attorney BridgeConsumer referral connections
  • IntegrationsCRM + case management sync
For Consumers
  • Consumer PlatformKnow your rights and your range
  • Get a LexstimateStart your free case estimate
For Funders
  • Funder PlatformPortfolio intelligence and analytics
Caseworth Labs
  • Caseworth LabsThe studio and our ventures
For Law Firms
Caseworth Pro
Settlement benchmarks, mass tort intelligence, and Attorney Bridge connections.
See Pro→
Learn
  • BlogLegal intelligence insights
  • Coverage MapActive states and practice areas
  • Case StudiesReal-world outcome analysis
Support
  • Help CenterGuides, FAQs, and documentation
Network
  • Attorney DirectoryFind a Caseworth-connected attorney
  • Why CaseworthOur data and methodology
Find Counsel
Attorney Directory
Connect with verified attorneys who know how to read what Caseworth finds.
Browse attorneys→

Legal

Data Processing Agreement

Last updated: July 14, 2026

This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the agreement between Caseworth, CO. ("Caseworth," "we," "us," "Processor") and the law-firm or business customer that has subscribed to the Services (the "Customer," "you," "Controller") (that agreement, the Terms of Service or any superseding master services agreement, the "Agreement"). This DPA governs Caseworth's Processing of Personal Data that Customer submits to, or Processes through, the Services in connection with Customer's own clients, matters, and business ("Firm Customer Data").

This DPA applies where, and to the extent that, Caseworth Processes Firm Customer Data on Customer's behalf as a processor (or "service provider" under U.S. state privacy law) and Customer acts as the controller (or "business"). It does not govern Personal Data for which Caseworth is itself the controller — for example, consumer account data or information individual consumers submit directly through Lexstimate — which is governed by our Privacy Policy. For the controller/processor split, see Section 8A of the Privacy Policy and Section 5A of the Terms of Service.

In the event of a conflict between this DPA and the Agreement with respect to the Processing of Firm Customer Data, this DPA controls. A separate, negotiated or signed DPA executed by both parties, where one exists, supersedes this online DPA to the extent of any conflict.

1. Definitions

Capitalized terms not defined here have the meaning given in the Agreement or in applicable data protection law.

  • "Applicable Data Protection Law" means all privacy and data protection laws applicable to the Processing of Firm Customer Data, including, as applicable, the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended (CCPA/CPRA), the Colorado Privacy Act (CPA), the Virginia Consumer Data Protection Act (VCDPA), the Washington My Health My Data Act (MHMDA), and comparable U.S. state laws.
  • "Controller" (or "business") means the entity that determines the purposes and means of the Processing of Personal Data. For Firm Customer Data, this is the Customer.
  • "Processor" (or "service provider") means the entity that Processes Personal Data on behalf of the Controller. For Firm Customer Data, this is Caseworth.
  • "Personal Data" means any information relating to an identified or identifiable natural person that is contained in Firm Customer Data and Processed under this DPA.
  • "Data Subject" means the identified or identifiable individual to whom Personal Data relates (for Firm Customer Data, typically Customer's clients, prospective clients, or claimants).
  • "Processing" means any operation performed on Personal Data, whether or not by automated means (e.g., collection, storage, use, disclosure, or deletion).
  • "Subprocessor" means a third party engaged by Caseworth to Process Firm Customer Data.
  • "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Firm Customer Data Processed by Caseworth.

2. Roles and Scope of Processing

As between the parties, Customer is the Controller and Caseworth is the Processor of Firm Customer Data. Customer is responsible for the accuracy, quality, and legality of Firm Customer Data, for the means by which Customer acquired it, and for having a lawful basis and any consents or authorizations required (including from Customer's own clients) for Caseworth to Process it as contemplated by the Agreement. Caseworth will Process Firm Customer Data only as a Processor acting on Customer's behalf.

Subject Matter and Duration

The subject matter of the Processing is the provision of the Services described in the Agreement (case-intelligence, intake, analytics, and related tooling). The Processing continues for the term of the Agreement and until Firm Customer Data is deleted or returned in accordance with Section 8, plus any period during which residual copies persist in routine backups pending deletion on Caseworth's standard backup cycle.

Nature and Purpose of Processing

Caseworth Processes Firm Customer Data to provide, maintain, secure, and support the Services and to perform its obligations under the Agreement — including hosting and storage, intake and case analysis, generating estimates and analytics, routing and notifications, and technical support. Caseworth does not sell Firm Customer Data, does not "share" it for cross-context behavioral advertising, and does not use it for its own independent purposes or to build, train, or enrich its models or knowledge graph, except as separately and expressly instructed or authorized in writing by Customer.

Categories of Data Subjects

  • Customer's clients and prospective clients (claimants).
  • Individuals who are the subject of a matter (e.g., injured parties, including minors submitted by an authorized adult).
  • Customer's personnel and authorized users of the Services.
  • Third parties referenced within case or intake materials.

Categories of Personal Data

  • Identifiers and contact data: name, email, phone, mailing address, and account/user identifiers.
  • Case and intake data: matter details, narratives, documents, and files submitted through the Services.
  • Sensitive / consumer health data: where included by Customer, medical records, injury and treatment facts, diagnosis and procedure codes (e.g., ICD/CPT), and other health-related case details.
  • Financial and billing data to the extent submitted within a matter.
  • Usage and technical data generated by authorized users' interaction with the Services.

The specific data Customer chooses to submit is determined and controlled by Customer.

3. Processor Obligations

Caseworth will:

  • Process only on documented instructions. Process Firm Customer Data only on Customer's documented instructions — including as set out in the Agreement, this DPA, and Customer's configuration and use of the Services — except where required to do so by law, in which case Caseworth will, unless legally prohibited, inform Customer of that legal requirement before Processing. If Caseworth believes an instruction violates Applicable Data Protection Law, it will inform Customer.
  • Confidentiality. Ensure that persons authorized to Process Firm Customer Data are bound by an appropriate obligation of confidentiality and Process the data only as needed to perform their role.
  • Security. Implement and maintain appropriate technical and organizational measures designed to protect Firm Customer Data against a Security Incident, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing. These measures include encryption of data in transit and at rest, access controls and least-privilege administration, logging and monitoring, and regular security assessments. See Section 4.
  • Subprocessors. Engage Subprocessors only as permitted in Section 5, and impose data protection obligations on each Subprocessor that are, in substance, no less protective than those in this DPA (flow-down).
  • Assistance with Data-Subject requests. Taking into account the nature of the Processing, provide reasonable assistance through appropriate technical and organizational measures — insofar as possible — to enable Customer to respond to requests from Data Subjects to exercise their rights (access, correction, deletion, portability, objection, restriction, and opt-out) under Applicable Data Protection Law. If Caseworth receives such a request directly, it will, unless legally prohibited, promptly notify Customer and will not respond to the request itself except on Customer's documented instructions.
  • Assistance with compliance obligations. Provide Customer with reasonable assistance with data protection impact assessments, prior consultations with supervisory authorities, and Security Incident obligations, in each case taking into account the nature of Processing and the information available to Caseworth.
  • Breach notification to Controller. Notify Customer without undue delay after becoming aware of a Security Incident affecting Firm Customer Data, and provide information reasonably available to Caseworth to assist Customer in meeting its own notification obligations. See Section 6.
  • Deletion or return on termination. On termination or expiration of the Agreement, delete or return Firm Customer Data as described in Section 8.
  • Records and audits. Make available to Customer information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, as described in Section 7.

4. Security Measures

Caseworth maintains a security program that includes, at a minimum: encryption of Firm Customer Data in transit (TLS) and at rest; role-based access controls and least-privilege access to production systems; authentication and session management; network and application-level protections; audit logging and monitoring; secure software-development and change-management practices; personnel confidentiality obligations; and periodic review and testing of these controls. Caseworth may update its security measures from time to time provided that the updates do not materially reduce the overall level of protection. Additional detail regarding hosting and infrastructure subprocessors is set out in Section 5 and in our Privacy Policy (Section 4A).

[PLACEHOLDER — counsel: confirm and list any formal certifications or attestations (e.g., SOC 2, HIPAA posture / Business Associate Agreement availability) before representing them here.]

5. Subprocessors

Customer authorizes Caseworth to engage Subprocessors to Process Firm Customer Data in connection with providing the Services. Caseworth will: (a) enter into a written agreement with each Subprocessor imposing data protection obligations that are, in substance, no less protective than those in this DPA (flow-down of the relevant obligations, including security and confidentiality); and (b) remain responsible for each Subprocessor's performance of those obligations to the same extent Caseworth would be responsible if performing the services directly.

Current Subprocessors. Caseworth's current infrastructure and service Subprocessors (for example, hosting, authentication and database, payment processing, email delivery, and error monitoring) are identified, together with their purpose and the categories of data they receive, in the "Essential Service Providers and Subprocessors" section of our Privacy Policy (Section 4A). That list is maintained as our authoritative subprocessor register for the Services.

Changes and objection. Caseworth will provide a mechanism for Customer to be informed of intended additions or replacements of Subprocessors so that Customer has the opportunity to object on reasonable data protection grounds. Where Customer reasonably objects and the parties cannot resolve the objection, Customer's remedy is as set out in the Agreement.

[PLACEHOLDER — counsel: specify the subprocessor-change notice mechanism and notice period (e.g., email to a designated contact or a subscribable change page) and the agreed objection window.]

6. Security Incident Notification

Caseworth will notify Customer without undue delay after becoming aware of a Security Incident affecting Firm Customer Data. The notification will describe, to the extent then known and as information becomes available, the nature of the incident, the categories and approximate volume of Firm Customer Data and Data Subjects affected, the likely consequences, and the measures taken or proposed to address the incident and mitigate harm. Caseworth will cooperate with Customer and take reasonable steps that Customer directs to assist in the investigation, mitigation, and remediation of the incident.

As between the parties, Customer, as Controller, is responsible for determining whether the incident triggers notification obligations to Data Subjects, regulators, or others under Applicable Data Protection Law and for making any such notifications; Caseworth will provide the reasonable assistance described above. Caseworth's notification of, or response to, a Security Incident is not an acknowledgement of fault or liability. Caseworth's internal incident-response and breach-assessment procedures are documented separately and are not part of this DPA.

7. Audits and Records

Caseworth will make available to Customer information reasonably necessary to demonstrate compliance with this DPA. Where Applicable Data Protection Law entitles Customer to audit, Caseworth will allow for and contribute to audits conducted by Customer or an independent auditor mandated by Customer, subject to reasonable and appropriate confidentiality, scope, notice, frequency, and security requirements, and conducted in a manner that does not disrupt Caseworth's operations or compromise the security or confidentiality of other customers' data. Caseworth may satisfy audit requests by providing then-current third-party audit reports, certifications, or security documentation where available.

[PLACEHOLDER — counsel: set audit frequency, notice period, and cost-allocation terms, and confirm whether third-party report delivery is the default satisfaction method.]

8. Deletion or Return on Termination

On termination or expiration of the Agreement, and at Customer's election, Caseworth will delete or return Firm Customer Data to Customer, and delete existing copies, except to the extent Applicable Data Protection Law requires Caseworth to retain some or all of it. Ordinarily, deletion or return will be completed within 30 days of termination, except that copies residing in routine backups will be deleted on Caseworth's standard backup cycle and remain subject to this DPA's confidentiality and security obligations until deleted. This Section is consistent with Section 7 of our Privacy Policy (Firm-customer data retention) and Section 5B of the Terms of Service.

9. International Data Transfers

Caseworth is headquartered in the United States, and Firm Customer Data may be Processed there. Where Firm Customer Data is subject to laws requiring a transfer mechanism (for example, the EU/UK GDPR), the parties will implement an appropriate lawful transfer mechanism, such as the applicable Standard Contractual Clauses, which are incorporated by reference where required.

[PLACEHOLDER — counsel: confirm whether the EU/UK Standard Contractual Clauses (and the UK Addendum) should be attached as an appendix and with which module/role selections.]

10. Legal Process and Third-Party Requests

If Caseworth receives a subpoena, court order, warrant, or other legal, governmental, or regulatory request seeking disclosure of Firm Customer Data, Caseworth will, unless legally prohibited, notify Customer before responding so that Customer, as Controller, may seek a protective order or other appropriate remedy, and will provide reasonable cooperation in doing so. Caseworth will disclose only the minimum Firm Customer Data legally required. Where notice is legally prohibited, Caseworth will use reasonable efforts to obtain a waiver of the prohibition and to challenge overbroad demands.

11. General

This DPA is governed by the same law and subject to the same limits of liability, exclusions, and dispute-resolution terms as the Agreement. If any provision of this DPA is held invalid or unenforceable, the remainder remains in effect. Except as modified by this DPA, the Agreement remains in full force and effect.

12. How to Contact Us

For questions about this DPA, to request a signed copy, or to submit data protection correspondence, contact:

Caseworth, CO. (a Delaware corporation)
131 Continental Drive, Suite 305
Newark, Delaware 19713
Email: privacy@caseworth.io
Support: support@caseworth.io

This DPA should be read together with our Terms of Service and Privacy Policy.

Caseworth

AI-powered legal intelligence. Built for the people who needed it most. Rolling out nationally.

Follow Caseworth on LinkedInFollow Caseworth on Facebook

Product

  • Lexstimate Report
  • The Point
  • Features
  • Pricing

Solutions

  • For Attorneys
  • For Consumers
  • For Funders
  • Caseworth Labs
  • Statute of Limitations Checker
  • Injury Code Scanner
  • Legal Opinion Reader

Resources

  • Coverage map
  • Blog
  • Case Studies
  • Help Center
  • Changelog
  • Attorney Directory
  • Why Caseworth

Company

  • Contact
  • Careers
  • Press

Legal

  • Privacy
  • Consumer Health Data (WA)
  • Terms
  • Security
  • Compliance
  • Cookies
  • Data Processing Agreement

© 2026 Caseworth. All rights reserved.

This platform provides informational analysis only and does not constitute legal advice.

Data Processing Agreement | Caseworth | Caseworth