Trademark protection for law firms and legal teams

Back to home

Legal information

Technical and organizational measures

Version 2026-10-06

This annex describes the safeguards required for the commissioned processing. Limetree Legal reviews and develops these measures according to risk. Additional safeguards individually agreed with the customer remain binding.

Access and tenant separation

Access to organization and client matter data requires authentication and checks of organization membership and the required permission. Owners and administrators manage memberships; roles and additional matter permissions limit available functions and data. Access checks also run on the server. Authentication supports passkeys; SSO and SCIM are available subject to the contracted service scope.

Confidentiality and permission management

Internal and external persons with potential access are bound to confidentiality and informed of applicable secrecy duties before access. Operations and support access is limited to necessary tasks. Permissions are changed or revoked when responsibilities change or persons leave. Datacenter physical security is provided by the commissioned infrastructure operators; administration interfaces require separate protection.

Transmission and storage

The public application is served over HTTPS. Private files are kept in non-public storage and delivered through authorized access. Credentials and technical secrets are managed separately from public source code. Appropriate provider-side encryption and protected administrative access must be maintained and regularly reviewed for databases, object storage and backups.

Integrity and accountability

Inputs are validated server-side. Permissions are checked before relevant reads and writes. Evidence and agreement acceptances use stored versions and content digests. Security and operations logs are access-restricted and purpose-limited; unnecessary client matter content must not be included in diagnostic logs.

Availability and recovery

Limetree Legal maintains procedures for backups, recovery and outages. Backups are protected against unauthorized access. Recoverability and deletion are reviewed regularly. Specific recovery times or availability commitments apply only when expressly agreed in the Main Agreement or SLA.

Instructions, deletion and incidents

Requests for access, rectification, return, deletion and data incidents are documented and assigned to responsible persons. Retention and deletion requirements cover production data, exports and backups. Incident procedures cover containment, assessment, remediation, documentation and notification of Controller without undue delay under the DPA.

Changes and providers

Software changes are versioned and subjected to suitable checks before release. Security-relevant dependencies and vulnerabilities are addressed. Before engaging a provider, its duties, contractual basis, access and any international transfers are reviewed. Agreed safeguards also apply to support and AI-assisted processing.