GDPR & EU Compliance
Last updated: July 2026
Casely is committed to the principles of the EU General Data Protection Regulation (GDPR) and the UK GDPR. This page explains how we handle personal data and the rights available to individuals in the EU, EEA, and UK.
Controller and processor roles
- For personal data of website visitors and prospects (e.g. contact-form submissions), Casely acts as a data controller.
- For client and case data that a law firm stores on the platform, the firm is the controller and Casely acts as a data processor, handling the data only on the firm's documented instructions.
Lawful bases
We process personal data on one or more of the following bases: your consent, the performance of a contract, our legitimate interests in operating and improving the service, and compliance with legal obligations.
Your rights
If you are in the EU, EEA, or UK, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erasure ("right to be forgotten"), subject to legal retention duties;
- Restrict or object to certain processing;
- Data portability — receive your data in a portable format;
- Withdraw consent at any time, without affecting prior lawful processing.
Firms using the platform can export their full data set at any time from within the application. To exercise any of these rights, contact us via the contact page; we respond within the timeframes required by law.
Data Processing Agreement
We make a Data Processing Agreement (DPA) available to firms on request, including the standard sub-processor and security commitments required under Article 28.
International transfers
Where personal data is transferred outside the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses and ensure equivalent protection. Firms can discuss data-residency options with us.
Cookies & tracking consent
Our marketing site uses privacy-respecting analytics. Any non-essential cookies or advertising/measurement tags are consent-gated for visitors in the EEA/UK — they load only after you opt in, and a server-side check enforces the same rule.
Retention
We keep personal data only as long as necessary for the purpose it was collected, or as required by law, after which it is deleted or anonymized.
Supervisory authority
You have the right to lodge a complaint with your local data-protection supervisory authority. We would appreciate the chance to address your concern first via the contact page.