Proxy
Menu

Data processing terms

How Proxy processes personal data on your instruction.

These terms form part of the agreement and govern the personal data inside the documents your organisation sends to Proxy. You are the controller. We are your processor, and we act on your instructions.

Version
1.0
Effective
Not yet in force
Operator
Case Ledger Tech Ltd

Draft

These documents are not in force.

35 facts have still to be supplied, and they are highlighted in the text where they belong. Nothing here binds anybody until those are filled in and a solicitor has reviewed the result. The outstanding list is on the legal index.

In short.

This summary is not the agreement and has no legal effect. It is here so that somebody deciding whether to read the rest can decide.

  • You are the controller. We process only on your documented instructions.
  • Subprocessors are named in advance, and you can object before one is engaged.
  • We tell you about a breach without undue delay, and help you meet your own deadline.
  • At the end we give you an export window, then delete. Deletion is not reversible after it.

1 Roles and scope

1.1 (link to this clause)

These Data Processing Terms are incorporated into the agreement between Case Ledger Tech Ltd, trading as Proxy ("Case Ledger Tech", "we", the "Processor"), and the organisation named on the Order Form (the "Customer", "you", the "Controller"). Words defined in the terms of service carry the same meaning here.

1.2 (link to this clause)

"Data protection law" means the UK GDPR and the Data Protection Act 2018, and where it applies to a party, Regulation (EU) 2016/679 and the national law implementing it. "Personal data", "controller", "processor", "data subject", "processing" and "personal data breach" carry the meanings that law gives them.

1.3 (link to this clause)

You are the controller of the personal data contained in Customer Data. We process it as your processor, and only as set out in these terms.

1.4 (link to this clause)

We are a controller, not a processor, for the personal data described in our privacy notice: Users' account and audit records, billing contacts, security records, and correspondence. Those are governed by the privacy notice rather than by these terms.

1.5 (link to this clause)

Each party complies with data protection law in its own right. You warrant that you have a lawful basis for the processing you instruct, that you have given data subjects the information they are owed, and that you are entitled to disclose the Customer Data to us.

2 Our instructions

2.1 (link to this clause)

We process personal data only on your documented instructions, including as to international transfers, unless we are required to process by law. Where the law requires it, we will tell you first unless that law forbids us on grounds of public interest.

2.2 (link to this clause)

Your documented instructions are: the agreement, these terms, your configuration of the Service, and the API and interface calls you make. Calling the Service is instructing it, which is why a scope narrows what an integration can be instructed to do.

2.3 (link to this clause)

You may give additional written instructions. If one falls outside what the Service does, we will tell you, and we may charge for the work or decline it.

2.4 (link to this clause)

We will tell you if, in our opinion, an instruction infringes data protection law, and we may suspend that instruction until it is resolved. Telling you is an obligation, not a legal opinion, and it does not transfer your responsibility as controller to us.

2.5 (link to this clause)

We do not use Customer Data to train models for anybody else, and we do not sell it, share it for anybody's marketing, or use it to build any product other than the Service we provide to you.

3 Personnel

3.1 (link to this clause)

We make sure that anybody authorised to process personal data under these terms is under a duty of confidence, contractual or statutory, that survives the end of their engagement.

3.2 (link to this clause)

Access inside Case Ledger Tech is limited to those whose role requires it, and is removed when the role changes.

4 Security

4.1 (link to this clause)

We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking account of the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing as well as the risk to data subjects.

4.2 (link to this clause)

The measures in force are set out in Annex B. We may change them, and we will not change them in a way that materially reduces their protection during your term.

4.3 (link to this clause)

You are responsible for the security decisions the Service puts in your hands: which scopes an integration holds, which origins are on its allowlist, which Users you provision, the retention and storage class you set per object, and the security of your own systems and credentials.

4.4 (link to this clause)

We hold no security certification, and we do not claim one. If and when we do, it will be named and dated on /security and available to read before it appears here.

5 Subprocessors

5.1 (link to this clause)

You give us general authorisation to engage subprocessors. The subprocessors engaged when your Order Form is signed are listed at subprocessor list location, with what each one processes and where.

5.2 (link to this clause)

Before a new subprocessor starts processing your personal data, we will give you at least subprocessor change notice period notice by subprocessor notification method. You may object on reasonable data protection grounds within that period.

5.3 (link to this clause)

If you object, we will work with you to find a solution. If we cannot within a reasonable time, you may terminate the affected Services on written notice, and we will refund the unused portion of prepaid Credits for them on a pro rata basis. That is your remedy for an objection.

5.4 (link to this clause)

We impose on every subprocessor, by written contract, obligations that protect personal data to the standard these terms require. We remain fully liable to you for a subprocessor's performance.

6 Data subject requests

6.1 (link to this clause)

The Service is built so that you can answer most requests yourself: records are retrievable through the API, the audit trail says who did what and when, retention and deletion are set per object, and deletion stays reversible for a defined window and then does not.

6.2 (link to this clause)

If a data subject contacts us directly about Customer Data, we will not respond substantively. We will tell them to contact you, and where we can identify you we will forward the request without undue delay.

6.3 (link to this clause)

Where you cannot answer a request through the Service, we will give you reasonable assistance, at your cost where the work is more than trivial, and we will tell you before incurring a charge.

7 Assistance

7.1 (link to this clause)

Taking account of the nature of the processing and the information available to us, we will assist you in meeting your obligations under Articles 32 to 36 of the UK GDPR: security, breach notification, data protection impact assessments, and prior consultation with the Commissioner.

7.2 (link to this clause)

For a data protection impact assessment, that assistance is the information in these terms, on /security, and in the API reference, plus answers to reasonable written questions about the processing.

8 Personal data breach

8.1 (link to this clause)

We will tell you without undue delay, and in any event within breach notification window of becoming aware, of a personal data breach affecting your personal data.

8.2 (link to this clause)

The notification will describe, so far as we know it at the time:

  1. the nature of the breach, including the categories and approximate number of data subjects and records affected;
  2. the likely consequences;
  3. the measures taken or proposed to address it and to mitigate its effects;
  4. a contact point for more information.

8.3 (link to this clause)

Where we cannot provide all of that at once, we will provide it in phases without undue further delay. An initial notification is not delayed to make it complete.

8.4 (link to this clause)

We will not notify the Commissioner or data subjects on your behalf unless you ask us to in writing, or unless the law requires us to. Deciding whether to notify is yours, because the obligation is yours.

8.5 (link to this clause)

Notifying you is not an admission of fault by either party.

9 Return and deletion

9.1 (link to this clause)

Throughout the term you can export Customer Data through the Service at any time, without asking us.

9.2 (link to this clause)

On termination or expiry, Customer Data remains available for export for post-termination export window. After that window we delete it, and existing copies are deleted unless the law requires us to keep them, in which case we keep only what is required, for only as long as it is required, and we go on protecting it under these terms.

9.3 (link to this clause)

Deletion from backups follows the backup cycle and completes within backup deletion period. Backups are not restored selectively to remove a single record; they age out.

9.4 (link to this clause)

We will confirm deletion in writing if you ask.

10 Audit and information

10.1 (link to this clause)

We will make available the information needed to demonstrate compliance with Article 28, and we will answer a security questionnaire. We would rather answer a long list of specific questions than publish a short list of comfortable ones.

10.2 (link to this clause)

You may audit, or appoint an auditor who is not a competitor of ours and who is bound by confidentiality, no more than once in any twelve months unless data protection law or a regulator requires more, or a personal data breach has occurred.

10.3 (link to this clause)

An audit is on at least 30 days' written notice, during business hours, for no longer than is reasonable, and must not disrupt the Service or expose another customer's data or another customer's configuration.

10.4 (link to this clause)

You bear your own costs and our reasonable costs of supporting an audit beyond the answers in clause 10.1.

11 International transfers

11.1 (link to this clause)

Your data region is fixed for your organisation rather than chosen per request, is agreed before anything is stored, and is recorded on your Order Form. Changing it is a migration, and it is treated as one.

11.2 (link to this clause)

We will not transfer your personal data out of the United Kingdom, or out of the region on your Order Form, except as needed to provide the Service through a subprocessor listed under clause 5, and then only with a lawful transfer mechanism in place.

11.3 (link to this clause)

That mechanism is UK adequacy regulations where they cover the country, and otherwise the International Data Transfer Agreement or the international data transfer addendum to the EU standard contractual clauses, with a transfer risk assessment. Where EU GDPR applies to you, the EU standard contractual clauses apply, with these terms supplying the Annexes.

11.4 (link to this clause)

If a transfer mechanism we rely on is invalidated, we will work with you in good faith on an alternative, and if there is none you may terminate the affected Services with a pro rata refund of prepaid Credits.

12 General

12.1 (link to this clause)

These terms take precedence over the rest of the agreement for anything concerning personal data.

12.2 (link to this clause)

Each party's liability under these terms is subject to the limits and exclusions in the terms of service, except where applying them would be contrary to data protection law. Nothing here limits a data subject's rights or a regulator's powers.

12.3 (link to this clause)

These terms end when the agreement ends, except that our obligations continue for as long as we hold any of your personal data.

12.4 (link to this clause)

These terms are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction, without prejudice to the jurisdiction clauses of any standard contractual clauses that apply.

Annex A Details of the processing

A.1 (link to this clause)

Required by Article 28(3).

Subject matter
the provision of the Proxy Services enabled on the Order Form: capture, processing, storage, coordination, signature and proof of the Customer's business documents and records.
Duration
the term of the agreement, plus the export window and the deletion periods in clause 9.
Nature and purpose
receiving, storing, transforming, extracting from, classifying, routing, transmitting, signing and recording documents and related records, on the Customer's instruction, so that the Customer can carry out its own business and evidence that it did.
Types of personal data
whatever the Customer chooses to send. Typically: names, contact details, addresses, employment and account identifiers, signature records and signer references, and the contents of documents that may contain any personal data. Specified for this Customer at categories of personal data for this customer.
Categories of data subject
the Customer's own customers, employees, contractors, applicants, counterparties and signers. Specified for this Customer at categories of data subject for this customer.
Special category data
not required by the Service. If the Customer sends it, the Customer is responsible for the Article 9 condition and must tell us before doing so, because it may change the measures that are appropriate.
Frequency
continuous, for as long as the Customer uses the Service.

Annex B Technical and organisational measures

B.1 (link to this clause)

Isolation is structural. Every record belongs to one organisation, and a request carrying another organisation's identifier is refused while the route is still being resolved, before application code runs. The answer is 404 rather than 403, because a 403 would confirm the record exists.

B.2 (link to this clause)

A scope narrows and never grants. An integration's effective permission is the intersection of its scopes with what its owner can already do, and entitlement is checked separately from the scope on every request. A credential cannot be configured into an authority nobody has.

B.3 (link to this clause)

Credentials are separated by job. A publishable key identifies an integration in a browser and reads nothing; a secret key works server to server; a client session is minted by the customer's backend for one capability, one resource and a few minutes. Credentials never appear in logs, exception messages or webhook payloads.

B.4 (link to this clause)

Every mutation records a named actor, on the audit trail and on the record itself, so that who did this and when has an answer that does not depend on log retention.

B.5 (link to this clause)

Encryption in transit is TLS with no plaintext fallback. Objects are encrypted at rest by the storage provider. Signing traffic runs on its own host, and cross-origin access is an allowlist per integration rather than a wildcard.

B.6 (link to this clause)

Retention is explicit per object across six storage classes. Deletion stays reversible for a defined window and then does not, and every size and lifecycle change is recorded as a ledger event rather than a recalculated total.

B.7 (link to this clause)

Every metered operation writes a usage record carrying the operation key, the quantity, the billing unit and the cost, readable by the customer without charge, so that what was done to the data can be reconciled against what was billed.

B.8 (link to this clause)

Webhook delivery carries a status through pending, processed, failed or ignored, retries are recorded, signatures are validated server-side and the verdict is kept with the signature, and a replayed request is answered as a replay rather than performed twice.

B.9 (link to this clause)

Organisational measures: access limited to the roles that need it, confidentiality obligations on all personnel, background check policy, security training cadence, and business continuity and backup arrangements.

Annex C Subprocessors

C.1 (link to this clause)

Proxy runs on third-party infrastructure and uses providers for object storage, payments, message delivery and identity checks.

C.2 (link to this clause)

The current list, naming each subprocessor, what it processes, the purpose and the country, is maintained at subprocessor list location and is provided with these terms. It is updated when it changes, on the notice in clause 5.2.

C.3 (link to this clause)

This annex is deliberately a pointer rather than a list. A list written into a versioned document goes stale the first time a provider changes, and a stale subprocessor list is a compliance failure rather than an inaccuracy.

The other documents.

All four form one agreement. This one does not stand on its own, and neither do the others.

Terms of service
What Proxy provides, what your organisation is responsible for, how it is paid for, how it can be suspended, and how the agreement ends. Your order form incorporates these terms at the version stated on it.
Privacy notice
This notice covers the people Case Ledger Tech deals with directly: visitors to this site, people who ask for access, people who sign in to Proxy, and billing contacts. Personal data inside a customer's documents is covered by the data processing terms instead.
Acceptable use
This policy forms part of the agreement and applies to everybody who uses Proxy through your organisation. It matters more here than on most platforms, because Sign and Communications act in your name towards people who are not your customers.