Data Processing Agreement
Last updated: 12 August 2026 · Version: 1.0Ελληνική έκδοσηDownload PDF (EL/EN)
This Data Processing Agreement (the "DPA") forms part of the Terms of Service between the Customer and Hartwell Legal Systems, a registered trade name of the sole proprietorship registered with the Dutch Chamber of Commerce under number 97254649, with an address at Nevelgaarde 8, 3436 ZZ Nieuwegein, Utrecht, the Netherlands ("Hartwell").
This DPA applies automatically when Customer accepts the Terms and uses CourtSync to process personal data on Customer's behalf. It is entered into electronically and does not require a separately signed PDF.
The Greek and English versions are intended to have the same meaning. If they differ, the English version prevails.
1. Scope, roles, and precedence
For the personal data described in this DPA, Customer acts as controller and Hartwell acts as processor. If Customer lawfully acts as processor for another controller, Hartwell acts as Customer's subprocessor and the same obligations apply as appropriate.
This DPA applies only to personal data that Hartwell processes on Customer's documented instructions through CourtSync ("Customer Personal Data"). Personal data that Hartwell processes for its own purposes, such as account administration, security, billing, support, optional product analytics and session replay, and advertising measurement, is governed by the Privacy Policy.
If this DPA conflicts with the Terms on a matter concerning processing of Customer Personal Data, this DPA prevails.
2. Documented instructions and the CourtSync process
Customer's documented instructions consist of the Terms, this DPA, Customer's CourtSync configuration, the cases and identifiers selected by Customer, actions submitted through the Service, enabled features, and written support instructions.
For the current judicial-portal monitoring feature, processing works as follows:
- Customer provides credentials for a supported judicial portal and selects or identifies the cases to be monitored;
- CourtSync encrypts the credentials before storage and uses them only to authenticate to the supported portal on Customer's behalf;
- at the monitoring frequency available under Customer's plan, or when Customer requests an immediate check, CourtSync authenticates to the portal, retrieves the information required for the selected cases, and records the relevant results;
- CourtSync compares current results with earlier results, detects changes, displays available information and history to authorised users, and sends service notifications where enabled; and
- Hartwell does not use the credentials to access unrelated cases, act independently of Customer, or pursue a purpose unrelated to the enabled feature.
Where a future CourtSync feature supports transmitting, submitting, or filing information through a connected system, the action will occur only when Customer explicitly enables or instructs it. Monitoring a case does not by itself authorise CourtSync to make a filing or procedural submission.
Hartwell processes Customer Personal Data only on documented instructions, unless Union or Member State law requires the processing. Where legally permitted, Hartwell will inform Customer before such mandatory processing. Hartwell will also inform Customer if it reasonably believes an instruction infringes applicable data-protection law.
3. Purpose limitation and analytics boundary
Hartwell processes Customer Personal Data only to:
- provide the CourtSync features selected by Customer;
- authenticate to supported judicial portals on Customer's behalf;
- retrieve, record, organise, compare, monitor, display, transmit, submit where instructed, return, or delete case-related information as required by the enabled feature;
- detect changes and provide notifications;
- secure, maintain, troubleshoot, and support the Service;
- comply with Customer's lawful instructions; and
- comply with applicable law.
Hartwell will not sell Customer Personal Data or use it for advertising, independent profiling, unrelated analytics, or training general-purpose artificial intelligence models. Hartwell may use technical service telemetry that does not reveal portal credentials, case content, files, or other sensitive Customer Personal Data, and data that has been irreversibly anonymised or aggregated, to secure and improve CourtSync.
With a user's consent, Hartwell may separately process product-usage, heatmap, and session-replay data as controller under the Privacy Policy. Those technologies are configured to mask or exclude Customer Personal Data before transmission. If an analytics, support, communications, or other provider is permitted to receive Customer Personal Data in order to provide the Service on Customer's behalf, that provider will be treated as a subprocessor under Section 8.
4. Customer responsibilities
Customer is responsible for:
- determining the purposes and essential means of processing and ensuring that its instructions are lawful;
- having an appropriate legal basis and providing any required notices to data subjects;
- ensuring that processing of personal data relating to criminal convictions, offences, allegations, investigations, or proceedings is authorised under applicable Union or Member State law and subject to appropriate safeguards;
- having the authority and permission to provide portal credentials, case identifiers, instructions, and Customer Personal Data to CourtSync;
- selecting only cases and information that Customer is authorised to access;
- keeping account and portal access rights current and secure;
- responding to data-subject requests and meeting Customer's own legal and professional obligations; and
- not instructing Hartwell to process data unlawfully.
Customer remains responsible for the accuracy, legality, relevance, and minimisation of Customer Personal Data submitted to the Service.
5. Hartwell's processor obligations
Hartwell will:
- ensure that persons authorised to process Customer Personal Data are subject to confidentiality obligations;
- implement appropriate technical and organisational measures as described in Annex 2;
- process Customer Personal Data only on documented instructions;
- make available information reasonably necessary to demonstrate compliance with this DPA;
- assist Customer, taking into account the nature of processing and information available to Hartwell, with data-subject requests and Customer's obligations under Articles 32 to 36 GDPR;
- maintain records required of a processor under applicable data-protection law;
- notify Customer where Hartwell receives a binding disclosure request, unless prohibited by law;
- forward a data-subject request concerning Customer Personal Data to Customer and not respond substantively unless authorised or required by law; and
- limit processing to authorised systems, personnel, and subprocessors.
6. Security and confidentiality
Hartwell maintains technical and organisational measures appropriate to the risk of processing, taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing. The current categories of measures are described in Annex 2.
Hartwell may update the measures to reflect technical development, operational changes, and risk, provided that the overall level of protection is not materially reduced.
Customer acknowledges that no system can be guaranteed completely secure. Any customer-specific security requirement, recovery objective, or service-level commitment must be agreed separately in writing.
7. Personal-data breaches
Hartwell will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data.
The notification will include information reasonably available to Hartwell concerning the nature of the breach, affected data and data subjects, likely consequences, and measures taken or proposed. Where all information is not initially available, it may be provided in phases.
Hartwell will take reasonable steps to contain, investigate, and mitigate the breach and will reasonably assist Customer with legally required notifications. Customer remains responsible for determining whether notice to a supervisory authority or data subjects is required.
8. Subprocessors
Customer gives Hartwell general written authorisation to engage subprocessors to process Customer Personal Data for the purpose of providing CourtSync. The categories of current core subprocessors and their general processing locations are listed in Annex 3; the named list is available to Customer on request.
Hartwell will:
- impose data-protection obligations on each subprocessor that are no less protective than the relevant obligations in this DPA;
- remain responsible for the subprocessor's performance of those obligations to the extent required by applicable law; and
- give Customer reasonable advance notice of a material addition or replacement of a subprocessor where practicable.
Customer may object to a new subprocessor on reasonable, documented data-protection grounds. The parties will try in good faith to resolve the objection. If no reasonable resolution is available, Hartwell may discontinue the affected feature or Customer may terminate the affected Service without penalty.
9. International transfers
Hartwell primarily processes Customer Personal Data within the European Economic Area. Hartwell will not transfer such data outside the EEA unless the transfer is made in accordance with applicable data-protection law, including through an adequacy decision, approved contractual safeguards, or another valid mechanism.
Where transfer-specific standard contractual clauses are required, they apply in addition to this DPA. This DPA is an Article 28 processor agreement and is not itself a set of third-country transfer clauses.
10. Assistance with rights and compliance
Taking into account the nature of processing, Hartwell will assist Customer through appropriate technical and organisational measures, insofar as possible, with requests for access, rectification, erasure, restriction, portability, or objection.
Hartwell will also reasonably assist Customer with risk assessments, data-protection impact assessments, prior consultation with supervisory authorities, and documentation of security measures, taking into account the information available to Hartwell and the nature of the Service.
Where a request requires disproportionate or bespoke work beyond normal CourtSync operation, the parties may agree a reasonable fee before the work begins, unless the assistance is required because of Hartwell's breach.
11. Return and deletion
During the relationship, Customer may delete cases or disconnect judicial portals through available functionality. Disconnecting removes the active credential from CourtSync's operational data store.
After termination of the Service or expiry of the retrieval or export period under the Terms, Hartwell will, at Customer's choice where available and lawful, return or delete Customer Personal Data from active systems, unless retention is required by law.
Limited residual copies may remain temporarily within recovery or backup mechanisms until the normal lifecycle expires. During that period they remain protected, are not restored to the active Service except for legitimate recovery, and are not used for another purpose.
Hartwell may retain limited security, audit, billing, or legal-compliance records where it has an independent legal basis or obligation, in which case it acts as controller for those records.
12. Audits and information
Hartwell will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. Compliance will ordinarily be demonstrated first through this DPA, the public Security Architecture and Judicial-Portal Integration page, responses to reasonable questionnaires, and available documentation.
If that information is insufficient and Customer has a reasonable basis for additional audit, Customer may conduct an audit no more than once in any 12-month period, unless a material incident has occurred or a competent authority requires a more frequent audit. An audit must be conducted on reasonable advance notice, during normal business hours, without compromising security or other customers' rights, and subject to confidentiality.
Customer bears reasonable audit costs unless the audit identifies a material breach of this DPA by Hartwell.
13. Duration, liability, and changes
This DPA remains effective while Hartwell processes Customer Personal Data. Obligations that by their nature should survive termination, including confidentiality, deletion, and incident cooperation, remain effective.
The parties' liability under this DPA is subject to the liability provisions in the Terms, without limiting data-subject rights or liability that cannot legally be limited.
Hartwell may update this DPA to reflect changes in law, the Service, security, or subprocessors. Reasonable advance notice will be provided for material changes. A change that materially reduces protection will not apply retrospectively without a valid legal basis.
14. Contact
Questions or notices concerning this DPA may be sent to support@courtsync.gr.
Annex 1 — Details of processing
Subject matter
Provision of CourtSync as cloud-based software for legal professionals. The current core processing consists of using Customer-provided credentials to access supported judicial portals on Customer's behalf, retrieving and monitoring information for cases selected by Customer, recording relevant results and history, comparing results to detect changes, displaying information, and providing notifications.
Future supported judicial workflows, including transmission, submission, or filing functions, are covered only where Customer explicitly enables or instructs the relevant feature.
Duration
For the duration of Customer's use of the relevant feature and for the limited period thereafter required to return or delete data, complete the normal recovery lifecycle, maintain security records, or comply with law.
Nature of processing
Receipt, encryption, storage, secure runtime use, authentication, access, retrieval, collection, recording, organisation, comparison, monitoring, display, transmission, submission where instructed, notification, support, restriction, return, and deletion.
Purpose
To provide the CourtSync features selected by Customer and no independent purpose of Hartwell.
Frequency
Automated periodic checks according to Customer's plan, checks requested by Customer, and other processing initiated by Customer through supported features.
Categories of data subjects
- Customer's authorised users and legal professionals;
- Customer's clients;
- defendants or accused persons;
- complainants, reporting persons, victims, or injured parties;
- opposing parties;
- witnesses;
- lawyers, representatives, experts, judges, court personnel, and other professionals; and
- other natural persons identified in judicial information returned for a Customer-selected case.
Categories of personal data
- Customer-provided judicial-portal usernames, passwords, tokens, or related authentication information;
- judicial case numbers, identifiers, and references;
- names and other identifiers appearing in judicial information;
- client records entered by Customer to organise its cases (name and optional contact details);
- labels and notes added by Customer to monitored cases;
- procedural status, actions, events, dates, hearings, decisions, and related metadata;
- notification and monitoring configuration;
- history and comparison records generated from portal results;
- files or information submitted for a future supported workflow where Customer explicitly enables that feature; and
- support information supplied by Customer where necessary to troubleshoot the relevant processing.
Sensitive data
Customer Personal Data may include personal data relating to criminal convictions, offences, allegations, investigations, security measures, or criminal proceedings within the meaning of Article 10 GDPR.
The current monitoring feature is not designed to require Article 9 special-category data. If such data appear incidentally in portal information or are supplied by Customer, Hartwell processes them only as part of Customer Personal Data and only on Customer's instructions.
Processing location
Primarily within the European Economic Area, subject to Section 9 and the subprocessor information in Annex 3.
Annex 2 — Technical and organisational measures
Hartwell maintains measures appropriate to the current CourtSync processing, including the following categories.
Access control and authorisation
- Production access is restricted to authorised persons and services with a business or technical need.
- Access permissions are limited by role and service function.
- Customer accounts and workspaces are logically separated.
- Administrative and production access is restricted and reviewed as operationally appropriate.
Judicial-portal credential protection
- Customer-provided credentials are encrypted at the application layer before storage.
- Encryption keys and application secrets are centrally managed and separated from encrypted credential data.
- The capability to use credentials is restricted to an authorised processing context only when needed to authenticate to the supported portal on Customer's behalf.
- Credentials are not used for advertising, independent profiling, unrelated analytics, or general-purpose AI training.
Transmission and storage security
- Network communications use encrypted transport where supported, including TLS for web and service connections.
- Persistent case and monitoring data is stored in a managed database environment configured within the European Union.
- Application secrets are not intentionally stored in public source code or browser-side application code.
- Production compute is designed to avoid durable state outside designated data stores.
Data minimisation and analytics separation
- CourtSync retrieves and stores information reasonably necessary to provide Customer-selected features.
- Optional analytics and session replay are activated only after relevant user consent where required.
- On authenticated pages, tools are configured in strict or equivalent masking mode. Only low-risk, static interface elements may be deliberately unmasked.
- Portal credentials, case identifiers, names, judicial content, procedural text, decisions, documents, uploaded files, free-text fields, support content, and other sensitive data are masked or excluded before transmission.
- Sensitive information is not intentionally included in URLs, parameters, custom events, tags, properties, or replay identifiers.
- Pseudonymous user, workspace, or session identifiers may be used, but names, email addresses, credentials, and case content are not intentionally sent as analytics identifiers or custom values.
- Access to analytics and replay dashboards is restricted to authorised persons.
- If a provider is permitted to process Customer Personal Data on Customer's behalf, it is treated as a subprocessor under Section 8.
Logging and monitoring
- Security and infrastructure events are logged for operational monitoring and investigation.
- Access to logs is restricted.
- Hartwell does not claim that every user action is logged, and logs are not intended to contain readable portal credentials.
Integrity, availability, and recovery
- Managed-infrastructure and database-provider recovery capabilities are used to support continuity and recovery.
- Hartwell maintains procedures intended to restore the Service following an incident, but no specific recovery point, recovery time, or backup-retention commitment is made under this DPA unless separately agreed.
- Security configuration and recovery measures are reviewed and improved based on risk and service maturity.
Incident management
- Suspected security incidents are assessed, contained, investigated, and documented as appropriate.
- Hartwell maintains a process to notify affected customers without undue delay where a personal-data breach affects Customer Personal Data.
Confidentiality and organisational controls
- Persons with authorised access are subject to confidentiality obligations.
- Access is revoked or adjusted when no longer required.
- Subprocessors are engaged under written data-protection obligations.
- Security measures are reviewed when material changes are made to the Service or processing.
Deletion and lifecycle controls
- Customer can remove cases or disconnect judicial portals through available functionality.
- Portal credentials and Customer Personal Data are returned or deleted after termination in accordance with Section 11, subject to limited recovery and legal-retention exceptions.
Annex 3 — Current core subprocessors
Core subprocessors are identified by category. The named list, with each provider's purpose and location, is available to Customer on request at support@courtsync.gr, and Customer receives advance notice of material additions or replacements in accordance with Section 8.
Cloud infrastructure provider
Purpose: application hosting, managed compute, key and secret management, object storage where used, and infrastructure logging and monitoring. Data involved: encrypted portal credentials, service configuration, case and monitoring data where processed by the relevant service, and operational logs. Location: EEA regions (currently Sweden).
Managed database provider
Purpose: hosting of the production database. Data involved: encrypted credentials, case identifiers, retrieved information, monitoring history, Customer-entered client records and labels, and Service configuration. Location: within the European Union (currently Frankfurt, Germany).
Web-application hosting provider
Purpose: hosting and delivery of the application and its server-side API layer, through which requests to the other systems transit. Data involved: request content in transit — including portal credentials at the moment of submission, case information, and client records — together with IP addresses, session cookies, and technical logs. Location: server-side functions execute in an EEA region (Frankfurt); a global content-delivery network serves static assets.
Account and notification system hosting provider
Purpose: hosting of the account and identity system and of the service that prepares and dispatches notifications. Data involved: account details (name, email, hashed password, plan), the mapping between account and data space, and the content of notifications pending dispatch (case identifiers, office, change type, Customer-set labels and, on a verification failure, the portal username — never the password). Location: per the provider's configured hosting region; any restricted transfer is subject to an applicable transfer mechanism.
Email delivery provider
Purpose: delivery of the Service's email messages (change notifications, verification failures, the weekly summary, and operational account messages). Data involved: recipient name and email address and the content of the messages, as described immediately above. Location: European Union.
Optional analytics and advertising providers are not subprocessors under this DPA where Hartwell uses them for its own controller purposes and configures them not to receive Customer Personal Data. If such a provider is permitted to receive Customer Personal Data on Customer's behalf, Hartwell will treat it as a subprocessor and apply the notice and objection process in Section 8.
If a further provider is permitted to receive Customer Personal Data, it will be added to this Annex before that use begins, following the process in Section 8.
Related documentation: Terms of Service · Privacy Policy · Security Architecture