Trademark protection for law firms and legal teams

Back to home

Legal information

Data processing agreement

Version 2026-10-06

This Data Processing Addendum ("DPA") is entered into between The organization identified in the acceptance record, the address identified in the acceptance record ("Controller"), and Limetree Legal UG (haftungsbeschränkt), Mühlenkamp 31, 22301 Hamburg, Germany ("Processor"). It forms part of the agreement under which Processor provides Limetree Legal services to Controller (the "Main Agreement").

1. Scope and order of precedence

This DPA applies where Processor processes personal data on behalf of Controller within the meaning of Article 28 GDPR. If this DPA conflicts with the Main Agreement on processing personal data, this DPA prevails. Mandatory data-protection law prevails over both.

Controller remains responsible for determining the purposes and essential means of processing and for the lawfulness, transparency, accuracy, and data-subject communications relating to its processing.

2. Details of processing

The subject matter, duration, nature, purpose, data categories, and data subjects are described in Annex 1. Processing continues for the term of the Main Agreement and any period required to return or delete data, unless law requires further processing.

3. Documented instructions

Processor will process personal data only on Controller's documented instructions, including instructions in the Main Agreement, this DPA, Controller's use and configuration of the service, and authorized support requests. Processor will inform Controller if it believes an instruction infringes applicable data-protection law, unless prohibited by law, and may suspend the affected processing pending clarification.

If Union or Member State law requires processing outside Controller's instructions, Processor will inform Controller before processing unless the law prohibits that information for important public-interest reasons.

4. Confidentiality and personnel

Processor ensures that persons authorized to process personal data are bound by confidentiality or an appropriate statutory duty and receive access only to the extent needed for their duties. Processor maintains proportionate privacy and security awareness measures for relevant personnel.

4a. Professional secrecy and further assisting persons

Limetree Legal undertakes to the customer to maintain confidentiality of all client matter information and other professional secrets learned in providing the service. This duty applies regardless of whether information is personal data and survives termination. Knowledge may be obtained only to the extent necessary to perform the contract. Mandatory disclosures required by law remain reserved; where legally permitted, the customer is informed in advance and disclosure is limited to what is legally required.

The parties expressly record the warning that unauthorized disclosure of a third-party secret learned when assisting a lawyer may be punishable under section 203(4) of the German Criminal Code by imprisonment for up to one year or a fine, and in the cases under section 203(6) by imprisonment for up to two years or a fine. Failure to impose confidentiality obligations on further assisting persons may also be punishable in the circumstances specified there.

Limetree Legal may engage suitable personnel and the providers authorized under section 6. Before possible access to professional secrets, Limetree Legal binds those persons to confidentiality in text form, informs them of the criminal consequences, and limits access to what is necessary. Equivalent obligations must be passed down the service chain. Data protection terms alone do not replace these professional secrecy obligations.

For services performed abroad involving potential access to professional secrets, Limetree Legal provides the information the customer needs to assess comparable protection under section 43e(4) of the German Federal Lawyers Act (BRAO). A lawful data transfer does not replace this assessment. Where a service directly serves an individual client matter, obtaining any client consent required under section 43e(5) BRAO remains the customer's responsibility. This agreement does not purport to grant that consent.

4b. AI-assisted processing

AI processing is limited to the commissioned function and documented instructions. Limetree Legal does not use client matter content to train its own general-purpose models or permit providers to do so. Authorized recipients, purposes and transfer conditions are set out in Annex 3. Additional recipients are subject to section 6. The customer remains responsible for professional review of outputs.

5. Security

Taking into account the state of the art, implementation costs, and the nature, scope, context, purposes, and risks of processing, Processor will implement and maintain appropriate technical and organizational measures under Article 32 GDPR. The applicable measures are described in the Technical and Organizational Measures document incorporated as Annex 2.

Processor may update individual measures where the overall level of protection is not materially reduced. Material reductions require Controller's prior agreement where required by law.

6. Subprocessors

Controller grants Processor general written authorization to engage subprocessors listed in the current Subprocessor List. Processor will impose data-protection obligations on subprocessors that provide substantially equivalent protection for the relevant processing and remains responsible for their performance as required by Article 28 GDPR.

Processor will give notice of an intended addition or replacement at least 30 calendar days before the change. Controller may object on reasonable data-protection grounds within 14 calendar days after receipt of the notice. The parties will attempt in good faith to resolve the objection. If no reasonable solution is available, Controller may terminate the service affected by the change on 30 days' notice to the end of a month; the remainder of the Main Agreement is unaffected.

7. International transfers

Processor will not transfer personal data to a third country or international organization except on documented instructions and with a lawful transfer mechanism. Where Processor or a subprocessor relies on standard contractual clauses, the applicable modules, supplementary measures, and transfer assessments will be made available as legally required. On request, Processor will identify the third countries to which personal data is actually transferred in connection with the service and the transfer mechanism used in each case (for example, an adequacy decision or standard contractual clauses, including the applicable module and supplementary measures).

8. Assistance to Controller

Considering the nature of processing and information available to Processor, Processor will reasonably assist Controller with:

  • responding to requests to exercise data-subject rights;
  • compliance with security obligations under Articles 32 to 34 GDPR;
  • data-protection impact assessments and prior consultations under Articles 35 and 36 GDPR; and
  • information reasonably necessary to demonstrate compliance with Article 28 GDPR.

If a data subject or supervisory authority contacts Processor directly about Controller data, Processor will refer the request to Controller unless legally required to respond and will not respond substantively without authorization.

Assistance required by law is not conditional on additional remuneration. Additional services beyond that scope may be charged by prior agreement. Privacy enquiries and instructions should be sent to support@limetreelegal.de.

9. Personal data breaches

Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Controller data. The notice will include available information required for Controller's assessment and notification duties, including the nature of the breach, likely consequences, affected data and persons, and measures taken or proposed. Information may be provided in phases where it is not available at the same time.

Notices are sent to the contact address recorded for the organization, which Controller must keep up to date. Privacy and security enquiries to Limetree Legal should be sent to support@limetreelegal.de; for confidential content the parties agree a suitable protected transmission channel.

10. Audit and evidence

Processor will provide information necessary to demonstrate compliance with this DPA and allow audits, including inspections, by Controller or an independent auditor mandated by Controller. Audits must respect confidentiality, security, other customers, and operational continuity and should ordinarily rely first on current certifications, independent reports, questionnaires, and remote evidence.

Audits ordinarily require reasonable advance notice and take place during usual business hours. Urgent audits, statutory rights, and supervisory authority powers remain unrestricted. Mandated auditors must be bound by confidentiality.

11. Return and deletion

At Controller's choice and subject to the Main Agreement, Processor will return or delete personal data after the end of services and delete existing copies, unless Union or Member State law requires storage. Data in backups will be isolated from ordinary use and deleted through documented backup-expiration cycles.

Controller communicates its choice of return or deletion in text form. Limetree Legal enables return in a commonly used electronic format and carries out the agreed deletion, including existing copies, without undue delay. For backups that cannot immediately be selectively erased, the specific deletion date is communicated; until then they are restricted to recovery purposes. Following restoration, previously issued deletion instructions must be applied again. Records subject to mandatory retention are kept separately for that purpose and deleted upon expiry. Completed deletion is confirmed in text form on request.

12. Liability and term

This DPA remains in effect for as long as Processor processes personal data on Controller's behalf. Liability is governed by the Main Agreement to the extent permitted by applicable law and without limiting mandatory rights or liabilities under the GDPR.

Annex 1 — Description of processing

Subject matter and purpose

Provision, security, support and maintenance of Limetree Legal for trademark research, filing preparation, portfolio management, deadlines, register and digital monitoring, evidence and document management, and authorized AI-assisted analysis. This includes user and permission management, storage, imports, exports, notifications and support.

Nature of processing

Collection, receipt, access, organization, structuring, storage, adaptation, retrieval, consultation, matching, calculation, transmission to authorized recipients, restriction, export, and deletion as configured or instructed.

Duration

For the Main Agreement term plus agreed return and deletion periods and any mandatory legal retention.

Categories of data subjects

  • Controller's users, employees, contractors, and advisers;
  • Controller's customers, suppliers, and business contacts;
  • clients, trademark owners, representatives, contacts, parties to proceedings, and persons named in register or research data; and
  • other persons whose data Controller lawfully submits to the service.

Categories of personal data

  • identity, account, role, and contact data;
  • organization, contract, billing, and support data;
  • trademark, matter, register, filing, deadline, monitoring, and evidence-of-use data;
  • integration identifiers, authorization metadata, synchronization status, and logs;
  • documents, exports, communications, and uploaded files; and
  • device, IP, audit, diagnostic, and security data.

Special categories of personal data under Article 9 GDPR and data under Article 10 GDPR are not intended for ordinary trademark workflows. Their deliberate processing requires a separate agreement addressing purpose, legal basis and safeguards. This DPA also protects inadvertently submitted data; Controller must be informed and the further handling agreed.

Controller instructions

The Main Agreement, this DPA, settings and actions of authorized users, documented support requests, and any further lawful written instructions agreed by the parties.

Annex 2 — Technical and organizational measures

The version of the Technical and Organizational Measures document identified in the contract or acceptance record forms Annex 2. The stable URL https://www.limetreelegal.de/en/legal/technical-organizational-measures displays the latest approved version; the recorded version and immutable acceptance snapshot determine the version incorporated into this DPA.

Annex 3 — Authorized subprocessors

The version of the Subprocessor List identified in the contract or acceptance record forms Annex 3. The stable URL https://www.limetreelegal.de/en/legal/subprocessors displays the latest approved version. Later changes are governed by Section 6 and do not alter the evidence of which version was accepted.