Data Processing Addendum

This Data Processing Addendum (“DPA”) is incorporated into, and is subject to the terms and conditions of, the Subscription Terms and Conditions or other terms (the “Agreement”) between Subscriber and newcase, Inc. (“Newcase”) applicable to the Subscriber’s use of the Newcase Services. This DPA shall be effective for the term of the Agreement and applies only to the extent Newcase Processes Subscriber Personal Data (as defined below) on behalf of Subscriber in the provision of the Newcase Services. “Subscriber Personal Data” as used herein may include Protected Health Information (“PHI”) as defined under the Health Insurance Portability and Accountability Act of 1996, as amended (“HIPAA”), solely to the extent Newcase creates, receives, maintains, or transmits PHI on behalf of Subscriber in the provision of the Newcase Services. Where PHI is involved, the parties agree that the HIPAA Business Associate Agreement attached as Exhibit A (the “BAA”) is incorporated into and forms part of this DPA, and governs Newcase’s Processing of PHI.

  1. Definitions

    1. “Subscriber Personal Data” means Personal Data provided to Newcase by or on behalf of Subscriber and/or generated for Subscriber in connection with the Newcase Services.

    2. “Data Protection Law” means all laws that apply to the Processing of Subscriber Personal Data under the Agreement, including the California Consumer Privacy Act and any binding regulations promulgated thereunder and other laws and regulations of the United States and its states, as amended from time to time.

    3. “Data Subject” means the individual to whom Subscriber Personal Data relates.

    4. “Personal Data” has the meaning given to it in the Data Protection Law, and includes “Personal Data,” “personally identifiable information,” and equivalent terms as such terms may be defined by the Data Protection Law.

    5. “PHI” has the meaning given in HIPAA and its implementing regulations.

    6. “Processing” (including its cognate “Process”) means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

    7. “Security Incident” means a material breach of Newcase’s security leading to the unauthorized or unlawful access by a third party, or confirmed accidental or unlawful destruction, loss or alteration, of Subscriber Personal Data in Newcase’s possession, custody or control. “Security Incidents” will not include unsuccessful attempts or activities that do not compromise the security of Subscriber Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of Newcase Services attacks, and other network attacks on firewalls or networked systems.

Capitalized terms used but not defined herein have the meaning given to them in the Agreement.

  1. Subscriber’s Instructions

    1. Newcase will Process Subscriber Personal Data only in accordance with Subscriber’s instructions as described in Schedule 1 to this DPA. By entering into this DPA, Subscriber instructs Newcase to Process Subscriber Personal Data to provide the Newcase Services and to perform its other obligations and exercise its rights under the Agreement, including, without limitation, to (a) carry out the Newcase Services or the business of which the Newcase Services is a part, (b) carry out any benefits, rights, and obligations relating to the Newcase Services, (c) maintain records relating to the Newcase Services, and (d) comply with any legal or self-regulatory obligations relating to the Newcase Services.

  2. Processing of Subscriber Personal Data

    1. Newcase serves as a Newcase Services provider or processor, meaning that Newcase Processes Subscriber Personal Data at the direction of and on behalf of Subscriber.

    2. Each party will comply with the obligations applicable to it under the Data Protection Law with respect to the Processing of Subscriber Personal Data. Subscriber represents and warrants that it has the necessary rights, consents and permissions to use Subscriber Personal Data and to enable Newcase to Process Subscriber Personal Data as intended by the Parties under the Agreement.

    3. When Newcase Processes Subscriber Personal Data, it will:

  1. Except as permitted by applicable law, the Agreement or this DPA, not (a) “sell” or “share” (each as defined in the Data Protection Law) Subscriber Personal Data, (b) retain, use, or disclose Subscriber Personal Data for any purpose other than for the specific purpose of providing the Newcase Services, (c) retain, use, or disclose Subscriber Personal Data outside of the direct business relationship between Subscriber and Newcase, and (d) combine Subscriber Personal Data with any Personal Data other than Subscriber Personal Data;

  2. Require Newcase’s personnel who access Subscriber Personal Data to commit to protect the confidentiality of Subscriber Personal Data;

  3. Provide reasonable assistance necessary for Subscriber to comply with its obligations under the Data Protection Law;

  4. Promptly notify Subscriber of any request made by a Data Subject in relation to Subscriber Personal Data. Newcase will, at Subscriber’s written request, provide Subscriber with reasonable assistance necessary for the fulfillment of Subscriber’s obligation to respond to requests for the exercise of Data Subjects’ rights under the Data Protection Law. Newcase shall not respond to such requests other than confirming with the Data Subject that the request relates to Subscriber and Subscriber Personal Data. Subscriber shall be solely responsible for responding to such requests;

  5. Unless prohibited by law, inform Subscriber if Newcase receives a request, complaint or other inquiry regarding the Processing of Subscriber Personal Data;

  6. Inform Subscriber if it can no longer comply with its obligations under this DPA. Upon notice to Newcase, Subscriber may take reasonable and appropriate steps to remediate Newcase’s use of Subscriber Personal Data in violation of this DPA; and

  7. Upon termination of the Agreement, as instructed by Subscriber, delete or return Subscriber Personal Data, except where continued retention of Subscriber Personal Data is in accordance with applicable law or Newcase’s policies, in which case Newcase shall retain such Subscriber Personal Data in accordance with this DPA.

  1. Subprocessing

    1. Subscriber agrees that Newcase may use third-party suppliers, including Affiliates, to Process Subscriber Personal Data on its behalf for the provision of the Newcase Services (each a “Subprocessor”). Prior to engaging any new Subprocessor that will process Subscriber Personal Data, Newcase will provide Subscriber notice and an opportunity to object, and Subscriber will have ten (10) business days from such notice to submit any objection in writing.

    2. When engaging any Subprocessor, Newcase will enter into a written contract with such Subprocessor containing data protection obligations consistent with those in this DPA with respect to the protection of Subscriber Personal Data to the extent applicable to the nature of the Newcase Servicess provided by such Subprocessor.

  2. Data Security

    1. Newcase will implement and maintain technical and organizational measures designed to protect Subscriber Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Subscriber Personal Data, as further described in Schedule 2 to this DPA. Newcase may update the security measures from time to time, provided the updated measures do not decrease the overall protection of Subscriber Personal Data.

    2. Subscriber agrees that, without limitation of Newcase’s obligations under Section 5.1 of this DPA, Subscriber is solely responsible for its use of the Newcase Services, including (a) making appropriate use of the Newcase Services to ensure a level of security appropriate to the risk in respect of Subscriber Personal Data; (b) securing the account authentication credentials, systems and devices Subscriber uses to access the Newcase Services; (c) securing Subscriber’s systems and devices that Newcase uses to provide the Newcase Services; and (d) backing up Subscriber Personal Data. Subscriber agrees that the Newcase Services and Newcase’s security commitments under this DPA are adequate to meet Subscriber’s needs, including with respect to any security obligations of Subscriber under the Data Protection Law, and provide a level of security appropriate to the risk in respect of Subscriber Personal Data.

  3. Security Incidents

    1. If Newcase becomes aware of a Security Incident, Newcase will: (a) notify Subscriber of the Security Incident without undue delay and in any event within seventy-two (72) hours after becoming aware of it; and (b) take reasonable steps to identify the cause of such Security Incident, minimize harm and prevent a recurrence.

    2. If an incident involves both Subscriber Personal Data and PHI, Newcase will provide notice in accordance with the earlier of (i) the timelines set forth in this DPA and (ii) the timelines set forth in the BAA.

    3. Subscriber is solely responsible for complying with incident notification requirements applicable to Subscriber. Newcase’s notification of or response to a Security Incident under this Section will not be construed as an acknowledgement by Newcase of any fault or liability with respect to the Security Incident.

  4. Audit

    1. Newcase will make available to Subscriber, at Subscriber’s request, reasonable information as necessary to demonstrate compliance with this DPA.

    2. To the extent Newcase makes available to Subscriber confidential summary reports (each, an “Audit Report”) prepared by third-party security professionals, upon request from Subscriber, Newcase may provide such Audit Report in satisfaction of any audit rights accorded to Subscriber pursuant to the Data Protection Law. The Audit Report shall be considered Newcase’s confidential information.

    3. If Subscriber can demonstrate that it requires additional information, beyond the Audit Report, then Subscriber may request that Newcase provide an audit, at Subscriber’s cost, subject to reasonable confidentiality procedures. Such audit shall: (a) not include access to any information that could compromise confidential information relating to Newcase’s other Subscribers or suppliers, Newcase’s technical and organizational measures, or any trade secrets; and (b) be performed upon not less than thirty (30) days’ notice, during regular business hours, and in such a manner as not to unreasonably interfere with Newcase’s normal business activities.

  5. General

    1. If there is any conflict between this DPA and the Agreement, this DPA will prevail to the extent of that conflict in connection with the Processing of Subscriber Personal Data. IIn the event of a conflict between this DPA and any BAA incorporated into or executed between the Parties, the BAA will control to the extent of that conflict and with respect to the Processing of PHI.

    2. If any provision of this DPA is found by any court or administrative body of competent jurisdiction to be invalid or unenforceable, then the invalidity or unenforceability of such provision does not affect any other provision of this DPA and all provisions not affected by such invalidity or unenforceability will remain in full force and effect.

    3. Notwithstanding anything to the contrary in the Agreement or this DPA, the liability of each party under this DPA is subject to the limitations of liability set out in the Agreement. Subscriber acknowledges that Newcase is reliant on Subscriber for direction as to the extent to which Newcase is entitled to Process Subscriber Personal Data on behalf of Subscriber in the provision of the Newcase Services. Consequently, Newcase will not be liable under the Agreement for any claim brought by individuals to whom Subscriber Personal Data relates arising from (a) any action or omission by Newcase in compliance with Subscriber’s instructions, or (b) Subscriber’s failure to comply with its obligations under the Data Protection Law.

    4. This DPA will be governed by and construed in accordance with governing law and jurisdiction provisions in the Agreement.

Schedule 1

Details of Processing

  1. Categories of Data Subjects. This DPA applies to Newcase’s Processing of Subscriber Personal Data relating to Subscriber’s authorized users, employees, contractors, and clients whose information appears in case records and documents Processed by Newcase in the provision of the Newcase Services.

  2. Types of Personal Data. The extent of Subscriber Personal Data Processed by Newcase is determined and controlled by Subscriber in its sole discretion and includes names, email addresses, and other Personal Data that Subscriber may Process through the Newcase Services.

  3. Types of Sensitive Personal Data. Subscriber Personal Data may include sensitive Personal Data, including health-related information, and may include PHI where the Services are used to process PHI and the BAA applies.

  4. Subject-Matter and Nature of the Processing. Subscriber Personal Data will be subject to the Processing activities that Newcase needs to perform in order to provide the Newcase Services pursuant to the Agreement.

  5. Purpose of the Processing. Newcase will Process Subscriber Personal Data for purposes of providing the Newcase Services as set out in the Agreement.

  6. Duration of the Processing. Subscriber Personal Data will be Processed for the duration of the Agreement in accordance with the terms of this DPA.

Schedule 2

Technical Measures

Newcase will implement and maintain the security practices and procedures set out below:

  1. Organizational management and dedicated staff responsible for the development, implementation and maintenance of Newcase’s information security program.

  2. Periodic review and assessment of risks to Newcase’s organization, monitoring and maintaining compliance with Newcase’s policies and procedures, and reporting the condition of its information security and compliance to internal senior management as appropriate.

  3. Data security controls which include logical segregation of data, restricted (e.g., role-based) access and monitoring, and use of commercially available and industry standard encryption technologies for Subscriber Personal Data as appropriate.

  4. Logical access controls designed to manage electronic access to data and system functionality based on authority levels and job functions.

  5. Password controls designed to manage and control password strength and password management requirements for assigned Newcase credentials as appropriate.

  6. Change management procedures and tracking mechanisms designed to test, approve and monitor changes to Newcase’s technology and information assets.

  7. Incident response procedures designed to allow Newcase to investigate, respond to, mitigate and notify events related to Newcase’s technology and information assets.

  8. Network security controls that provide for the use of enterprise firewalls and intrusion detection systems and other traffic and event correlation procedures designed to protect systems from intrusion and limit the scope of any successful attack, as appropriate.

  9. Business resiliency/continuity and disaster recovery procedures designed to maintain Newcase Services and/or recovery from foreseeable emergency situations or disasters.

Exhibit A

BUSINESS ASSOCIATE AGREEMENT

This HIPAA Business Associate Addendum (“BAA”) is incorporated into and forms part of the Data Processing Addendum (“DPA”) and the Agreement between Subscriber (the “Business Associate”) and newcase, Inc. (the “Subcontracting Business Associate”). This BAA is effective as of the effective date of the Agreement (the “Effective Date”) collectively, “the Parties.”

The following terms used in this BAA shall have the same meaning as those terms in the HIPAA Rules: Breach, Covered Entity, Designated Record Set, Disclosure, Individual, Notice of Privacy Practices, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

Definitions:

  1. Business Associate.  “Business Associate” shall generally have the same meaning as the term “business associate” at 45 C.F.R. § 160.103, and in reference to the party to this BAA, shall mean Subscriber.  “Subcontracting Business Associate” shall also qualify as a “business associate” pursuant to 45 C.F.R. § 160.103, but shall refer to newcase, Inc., for purposes of this BAA.

  2. Electronic Protected Health Information (“E-PHI”).  This term shall have the same meaning as the term “electronic protected health information” in 45 C.F.R. § 160.103, limited to the information created or received by the Subcontracting Business Associate from or on behalf of Subscriber.

  3. HIPAA Rules.  “HIPAA Rules” shall mean the Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Part 160 and Part 164, as amended.

  4. Protected Health Information (“PHI”).  This term shall have the same meaning as the term “protected health information” in 45 C.F.R. § 160.103, limited to the information created or received by the Subcontracting Business Associate from or on behalf of Business Associate.

  1. Obligations and Activities of Subcontracting Business Associate:

The Subcontracting Business Associate agrees to:

  1. Not use or disclose PHI other than as permitted or required by the Agreement or as required by law;

  2. Use appropriate safeguards, and comply with Subpart C of 45 C.F.R. Part 164 with respect to E-PHI, to prevent use or disclosure of protected health information other than as provided for by the Agreement;

  3. Report to Business Associate any use or disclosure of PHI not provided for by the Agreement of which it becomes aware, including breaches of unsecured PHI as required at 45 C.F.R. § 164.410, and any security incident of which it becomes aware, within ten (10) days of becoming aware of such use or disclosure.  Such report shall include, if known, whose unsecured PHI was acquired, accessed, used, or disclosed as a result of the breach, a description of the breach, the date the breach occurred, the date of discovery of the breach, if known, the categories of unsecured PHI involved in the breach, the status of the investigation of the breach, the steps taken to mitigate harm with respect to the affected individuals resulting from the breach, and the steps taken to prevent recurrence of the breach.  Subcontracting Business Associate shall cooperate with Business Associate as reasonably requested in the investigation of any suspected breach, including by sharing the results of any investigation or forensic analysis.  Subcontracting Business Associate shall report to Business Associate in writing any Security Incident involving E-PHI, other than a Security Incident that involves an impermissible use or disclosure of PHI reported pursuant to this paragraph, within 30 days of Subcontracting Business Associate’s discovery thereof.  The parties acknowledge and agree that this section constitutes notice by Subcontracting Business Associate to Business Associate of the ongoing occurrence of events that may constitute Security incidents but that are trivial, routine, do not constitute a material threat to the security of PHI, and do not result in unauthorized access to or use of disclosure of PHI (such as typical pings and port scans), for which no additional notice of Business Associate shall be required.

  4. In accordance with 45 C.F.R. § 164.502(e)(1)(ii) and § 164.308(b)(2), if applicable, ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of the Subcontracting Business Associate agree to the same restrictions, conditions, and requirements that apply to the Subcontracting Business Associate with respect to such information;

  5. Use commercially reasonable steps to mitigate any harmful effect that is actually known to Subcontracting Business Associate of a use or disclosure of PHI by Subcontracting Business Associate or its agents or subcontractors in violation of this BAA;

  6. Make available PHI in a designated record set to the Business Associate as necessary to satisfy Business Associate’s obligations under 45 C.F.R. § 164.524;

  7. Make any amendment(s) to PHI in a designated record set as directed or agreed to by the Business Associate pursuant to 45 C.F.R. § 164.526, or take other measures as necessary to satisfy Business Associate’s obligations under 45 C.F.R. § 164.526;

  8. Maintain and make available the information required to provide an accounting of disclosures to the Business Associate as necessary to satisfy Business Associate’s obligations under 45 C.F.R. § 164.528;

  9. To the extent that the Business Associate notifies the Subcontracting Business Associate that the Business Associate is to carry out one or more of its Covered Entity clients’ obligation(s) under Subpart E of 45 C.F.R. Part 164, comply with the requirements of Subpart E that apply to such Covered Entity (and thus to the Business Associate) in the performance of such obligation(s); 

  10. Make its internal practices, books, and records available to the Secretary for purposes of determining compliance with the HIPAA Rules; and

  11. If Business Associate notifies Subcontracting Business Associate that a Covered Entity client has agreed to be bound by additional restrictions on the uses of disclosures of PHI pursuant to paragraph IV(b), Subcontracting Business Associate shall be bound by such additional restrictions and shall not use or disclose PHI in violation of such additional restrictions.

  1. Permitted Uses and Disclosures by Subcontracting Business Associate:

To the extent that the Subcontracting Business Associate may create or receive information which constitutes PHI or E-PHI, except as otherwise limited in this BAA:

  1. Subcontracting Business Associate may only use and disclose PHI solely to perform the Services and related obligations as set forth in the Agreement/DPA, and only if such use or disclosure would not violate HIPAA if done by Business Associate.

  2. Subcontracting Business Associate may only use or disclose PHI as necessary to evaluate the medical care and treatment of the Business Associate’s client.  

  3. Subcontracting Business Associate may use or disclose PHI as required by law.

  4. Subcontracting Business Associate agrees to request, use, and disclose only the minimum amount of PHI necessary to provide services to Business Associate.

  5. Except as provided in subsection (f) below, Subcontracting Business Associate may not use or disclose PHI in a manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Business Associate. 

  6. Subcontracting Business Associate may disclose PHI for the proper management and administration of Subcontracting Business Associate or to carry out the legal responsibilities of the Subcontracting Business Associate, provided the disclosures are required by law, or Subcontracting Business Associate obtains reasonable assurances from the person to whom the information is disclosed that the information will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and that the person will notify Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.

  1. Obligations of Business Associate:

    1. Permissible Requests.  Business Associate shall not request Subcontracting Business Associate to use or disclose PHI in any manner that would not be permissible under Subpart E of 45 C.F.R. Part 164 if done by Business Associate. 

    2. Notification of Restrictions.  Business Associate shall (i) notify Subcontracting Business Associate of any limitation in a Covered Entity client’s Notice of Privacy Practices to the extent that such limitation may affect Subcontracting Business Associate’s use or disclosure of PHI; (ii) notify Subcontracting Business Associate of any changes in, or revocation of, permission by an Individual to use or disclose PHI from a Covered Entity client, to the extent that such change may affect Subcontracting Business Associate’s use or disclosure of PHI; and (iii) notify Subcontracting Business Associate of any restriction on the use or disclosure of PHI to which a Covered Entity client has agreed, to the extent that such restriction may affect Subcontracting Business Associate’s use or disclosure of PHI.

  2. Term and Termination:

    1. Term. This BAA is effective as of the Effective Date and remains in effect until terminated in accordance with this Section 5 or the Agreement, whichever results in earlier termination with respect to Services involving PHI.

    2. Termination for Cause. Subcontracting Business Associate authorizes termination of this BAA by Business Associate, if Business Associate determines Subcontracting Business Associate has violated a material term of the Agreement and Subcontracting Business Associate has not cured the breach or ended the violation within the time specified by Business Associate.

    3. Termination Due to Change in Law.  Either party may terminate this BAA effective upon ten (10) days advance written notice in the event that the terminating party has sought amendment of the Agreement pursuant to paragraph VI(b) and no amendment has been agreed upon.

    4. Termination without Cause.  Either party may terminate this BAA effective upon ninety (90) days advance written notice given with or without any reason.

    5. Obligations of Subcontracting Business Associate Upon Termination. Upon termination of this BAA for any reason, Subcontracting Business Associate shall return to Business Associate, or, if agreed to by Business Associate, destroy, all PHI received from Business Associate, or created, maintained, or received by Subcontracting Business Associate on behalf of Business Associate, that the Subcontracting Business Associate still maintains in any form and Subcontracting Business Associate shall retain no copies of the PHI, or, if return or destruction is not feasible, Subcontracting Business Associate shall notify Business Associate thereof and extend the protections of this BAA to the PHI and limit its further use or disclosure to those purposes that make the return or destruction of the PHI feasible.  The requirements of this section shall survive termination or expiration of this BAA and shall be in force as long as any PHI remains in the custody or control of Subcontracting Business Associate.

    6. Survival.  The obligations of Subcontracting Business Associate under this Section shall survive the termination of this BAA.

  3. Miscellaneous:

    1. Regulatory References. A reference in this BAA to a section in the HIPAA Rules means the section as in effect or as amended.

    2. Amendment. This BAA may be amended from time to time as is necessary for compliance with the requirements of the HIPAA Rules and any other applicable law.

    3. Governing Law.  This BAA shall be construed to permit compliance with HIPAA. The governing law and venue provisions of the Agreement control (and any conflicting state-law clause in this BAA is superseded). In the event of conflict between this BAA and the DPA/Agreement, this BAA controls with respect to PHI.

    4. Third Party Beneficiaries.  Nothing in this BAA shall be deemed to create any rights or remedies in any third party.

    5. Interpretation. Any ambiguity in this BAA shall be interpreted to permit compliance with the HIPAA Rules.

    6. Indemnification:  Indemnification, if any, is subject to the limitations of liability and exclusions set forth in the Agreement.

Last updated: February 24, 2026