CaseCaddySign in
Last updated: June 2026

Data Processing Agreement

This Data Processing Agreement ("DPA") sets out how CaseCaddy processes personal data on behalf of Subscribers. It is incorporated into and forms part of our Terms of Service and is accepted when you create a CaseCaddy account.

This DPA is intended to satisfy the requirements of Article 28 of UK GDPR. If you require a separately countersigned DPA for your own records, contact hello@casecaddy.app.

1. Parties

Data ControllerThe Subscriber — the mortgage broker or brokerage that has created a CaseCaddy account and entered Client Data into the Service
Data ProcessorCaseCaddy Ltd, the operator of CaseCaddy (registered in England and Wales, Company No. [in progress])

2. Subject matter and duration

Subject matter

This DPA governs the processing of personal data by CaseCaddy (as Processor) on behalf of the Subscriber (as Controller) in connection with the provision of the CaseCaddy Service, being a mortgage broker document chasing and case management platform.

Duration

This DPA remains in force for as long as CaseCaddy processes personal data on behalf of the Subscriber, and terminates automatically on expiry or termination of the Subscriber's Terms of Service, subject to the data retention and deletion obligations in Section 13.

3. Nature and purpose of processing

CaseCaddy processes Client Data on behalf of the Subscriber for the following purposes:

  • +Storing contact information for clients, solicitors, estate agents, lenders, and other parties associated with mortgage cases
  • +Managing case records, outstanding document lists, and case status on the Subscriber's behalf
  • +Generating and sending automated reminder and completion emails to case parties on the Subscriber's instructions
  • +Recording and storing reminder logs, delivery status, and email audit trails
  • +Generating AI-assisted email drafts where the Subscriber uses that feature (limited case context only)

CaseCaddy does not process Client Data for any purpose other than providing the Service to the Subscriber.

4. Types of personal data processed

CategoryData items
Identity dataFull name
Contact dataEmail address, phone number (if provided)
Address dataResidential or correspondence address; property address
Case reference dataCase reference numbers, property details, relevant dates
Communication dataReminder emails sent, delivery status, upload event timestamps
Document reference dataNames/labels of outstanding documents only (not the documents themselves)

CaseCaddy does not knowingly process special category personal data (as defined in Article 9 UK GDPR), financial documents, identity documents, or mortgage documents. The Subscriber should not enter special category data or sensitive financial data into the Service.

5. Categories of data subjects

The personal data relates to the following categories of data subjects:

  • Mortgage applicants and co-applicants (the Subscriber's clients)
  • Solicitors and conveyancers acting on mortgage cases
  • Estate agents involved in related property transactions
  • Lenders and their representatives
  • Other third parties involved in mortgage cases as entered by the Subscriber

6. Controller obligations

The Subscriber, as Data Controller, agrees that it will:

  • +Process personal data only on a valid lawful basis under UK GDPR
  • +Provide appropriate privacy information to data subjects, including as regards the sending of automated reminder emails through CaseCaddy
  • +Only instruct CaseCaddy to process personal data in accordance with applicable law
  • +Ensure that personal data entered into the Service is accurate, adequate, relevant, and not excessive
  • +Not enter special category personal data into the Service
  • +Respond to data subject rights requests in accordance with UK GDPR, using information provided by CaseCaddy where relevant
  • +Notify CaseCaddy promptly of any instruction that CaseCaddy believes would cause CaseCaddy to breach applicable law

7. Processor obligations

CaseCaddy, as Data Processor, agrees that it will:

  • +Process Client Data only on the Subscriber's documented instructions, and not for any other purpose
  • +Immediately inform the Subscriber if, in CaseCaddy's opinion, an instruction infringes applicable UK data protection law
  • +Ensure that persons authorised to process Client Data are subject to appropriate written confidentiality obligations
  • +Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk
  • +Engage sub-processors only in accordance with Section 10 of this DPA
  • +Assist the Subscriber with data subject rights requests as set out in Section 11
  • +Assist the Subscriber in ensuring compliance with obligations under Articles 32–36 UK GDPR (security, breach notification, DPIAs, consultation), taking into account the nature of the processing and the information available to CaseCaddy
  • +At the Subscriber's election, delete or return all Client Data on termination of the Service
  • +Make available to the Subscriber information reasonably necessary to demonstrate compliance with this DPA

CaseCaddy will not:

  • Use Client Data to train AI models or for any purpose beyond providing the Service
  • Sell, license, or otherwise commercially exploit Client Data
  • Disclose Client Data to any third party other than authorised sub-processors
  • Transfer Client Data outside the UK without appropriate safeguards in place

8. Confidentiality

CaseCaddy will ensure that only those employees, contractors, and agents who need access to Client Data in order to deliver the Service are authorised to access it, and that all such persons are bound by written confidentiality obligations no less protective than those in this DPA.

9. Security measures

CaseCaddy implements appropriate technical and organisational measures to protect Client Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include, where implemented:

Encryption in transitTLS encryption on all connections between users and the platform
Encryption at restEncryption of client PII fields (names, email addresses, postal addresses) in the database
Access controlsRole-based access controls and the principle of least privilege for staff and systems
AuthenticationAuthentication managed by Clerk, which supports multi-factor authentication
Audit loggingLogging of data access and modification events with timestamps within the application
Incident responseA documented process for responding to security incidents, including personal data breaches

Security measures are reviewed and updated on an ongoing basis. CaseCaddy does not claim any formal certification (such as ISO 27001, SOC 2, or Cyber Essentials) unless separately confirmed in writing.

10. Sub-processors and international transfers

The Subscriber authorises CaseCaddy to engage the following sub-processors to deliver the Service. Each is subject to data processing terms providing protections equivalent to or greater than those in this DPA. Where a sub-processor is based outside the UK, appropriate transfer safeguards are in place as noted:

ProviderPurposeLocationSafeguard
ClerkAuthentication and user session managementUnited StatesUK IDTA / SCCs
SupabaseDatabase storage and hostingEuropean UnionEU adequacy decision
ResendTransactional email deliveryUnited StatesUK IDTA / SCCs
VercelApplication hosting and CDNUnited StatesUK IDTA / SCCs
AnthropicAI email drafting (where feature is used)United StatesUK IDTA / SCCs · No training on customer data

CaseCaddy will notify the Subscriber by email at least 14 days before engaging any new sub-processor or materially changing the role of an existing sub-processor. If the Subscriber objects to a new sub-processor on reasonable data protection grounds, the Subscriber may terminate the Service without penalty by providing written notice within 14 days of the notification.

11. Data subject rights

The Subscriber, as Data Controller, is responsible for responding to rights requests from data subjects (for example, requests to access, correct, or delete their personal data).

CaseCaddy will assist the Subscriber in meeting these obligations. Where CaseCaddy receives a rights request directly from a data subject, it will forward this to the Subscriber promptly. CaseCaddy will, within 5 working days of receiving a Subscriber's instruction, provide the Subscriber with the relevant data, delete the relevant data, or confirm that the data does not exist on the platform, as instructed and to the extent technically possible.

12. Personal data breach

If CaseCaddy becomes aware of any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Client Data, it will notify the Subscriber without undue delay and in any event within 48 hours of becoming aware of the breach.

Notification will include, to the extent known at the time:

  • A description of the nature of the personal data breach
  • The categories and approximate number of data subjects affected
  • The categories and approximate number of personal data records affected
  • The likely consequences of the breach
  • The measures taken or proposed to address the breach and mitigate its effects

The Subscriber remains responsible for determining whether a breach must be notified to the ICO or to affected data subjects, and for making any such notifications.

13. Audit and compliance assistance

CaseCaddy will provide the Subscriber with all information reasonably necessary to demonstrate compliance with the obligations in this DPA, including responses to reasonable written questions about CaseCaddy's data processing practices.

Where an audit of CaseCaddy's processing facilities is required by applicable law or an order of a supervisory authority, CaseCaddy will cooperate with reasonable audit requests, subject to at least 30 days' prior written notice, agreement on reasonable scope and timing, and the Subscriber bearing the reasonable cost of any audit. The Subscriber may not conduct audits in a way that disrupts CaseCaddy's services or compromises the security or confidentiality of other customers' data.

14. Return and deletion of data

On termination or expiry of the Service for any reason, CaseCaddy will, at the Subscriber's election, either delete all Client Data or return it to the Subscriber in a portable format, within 30 days.

The Subscriber should export their data before cancelling their account. CaseCaddy will retain Client Data for 30 days after account cancellation to allow export; after that it will be permanently deleted.

On completion of deletion, CaseCaddy will provide written confirmation to the Subscriber on request. Billing and financial records may be retained for the period required by applicable law.

15. Governing law

This DPA is governed by the laws of England and Wales. Any disputes arising from it are subject to the exclusive jurisdiction of the courts of England and Wales.