Skip to content

Data processing for law firms

Data processing for law firms: how AdvokatX, as processor, handles client and case data - security measures, sub-processors, breaches and deletion.

This page is a public summary of the terms under which we process the data a law firm enters into the AdvokatX application. The binding personal data processing agreement, with the content required by Article 45 of the Serbian Personal Data Protection Act (Zakon o zaštiti podataka o ličnosti, "Official Gazette of RS" No. 87/2018, "ZZPL"), is signed separately with each law firm, alongside the contract for using the application. Where this page and the signed agreement differ, the agreement prevails. The Serbian version of this page is the governing one.

Roles

  • The law firm is the controller. It decides why and how the data of its clients and cases is processed, and it is responsible for the lawfulness of that processing, including the legal basis and informing its clients.
  • We are the processor. We process the data only on the firm's behalf and on its instructions, solely to provide the application.

For user account data of the firm's lawyers and staff (for sign-in, security and subscription billing) we are the controller. This is described in the Privacy policy.

Subject matter and duration

The subject matter is storing and processing the data the firm enters into the application to manage cases, deadlines, the case journal, documents, activities and invoicing. Processing lasts for as long as the contract for using the application, including the trial period, plus the period after the contract ends that is needed to export and delete the data.

Nature and purpose

Processing covers receiving, storing, organising, searching, displaying, exporting, backing up and deleting the data, and sending notifications to the firm's users (for example about assigned tasks and deadlines). We do not use the data for any purpose of our own: we do not analyse it, use it for advertising, sell it or use it to build other products.

Types of data

The data the firm enters, which typically includes:

  • identification and contact data of clients, opposing parties and other participants in proceedings,
  • data about cases, proceedings, deadlines and hearings,
  • notes, correspondence and documents in a case,
  • data about activities, hours worked, fee calculations, invoices and payments,
  • data about the firm's users to the extent it appears in cases (who entered or changed what).

Documents and notes may also contain special categories of personal data (for example health data) and data relating to criminal proceedings. The firm decides whether to enter them and is responsible for the legal basis of that processing.

Categories of data subjects

The firm's clients and their representatives, opposing parties, witnesses, experts and other participants in proceedings, contact persons at legal entities, and the firm's lawyers, trainees and staff.

The firm's instructions

We process the data only on the firm's documented instructions. The instructions are the contract itself and the actions the firm's authorised users take in the application. If we believe an instruction breaches the ZZPL or another law, we inform the firm immediately. We disclose data to a public authority only where the law requires it, and we inform the firm before disclosure unless the law prohibits it.

Confidentiality

The data in the application is covered by the firm's professional secrecy (Article 20 of the Serbian Advocacy Act). Only people who maintain the application and need access have it, and they are bound to confidentiality by contract or by law. We do not access the content of cases and documents, except when the firm asks us to for support or when it is necessary to fix a fault or a security incident.

Security measures

Technical and organisational measures in line with Article 50 ZZPL, including:

  • Isolation per firm at database level (row-level security in PostgreSQL), not only in the application.
  • Mandatory two-factor sign-in for every user, and access to modules according to the user's role in the firm.
  • Audit log - who created, changed, deleted or restored cases, documents and fee calculations, and when.
  • Encrypted connection (HTTPS) for all traffic.
  • No public links to documents - downloads only through short-lived signed links or an access-rights check.
  • Protection against user error - deleted items move to Deleted, from where the firm's administrator can restore them.
  • Encrypted backups of the database, kept separately from the server the application runs on.

Where documents are stored

The firm chooses one of two options:

  • Hosted storage - S3-compatible object storage, separated per firm. The storage provider and location are named in the contract with the firm.
  • The firm's own NAS device - documents stay in the office and the application reaches them through a local agent. The firm is responsible for storing and backing up those documents.

Sub-processors

We use the following sub-processors to provide the application:

Sub-processor Role Location
Hetzner Online GmbH Servers running the application and the database Germany (EU)
Unlimited (unlimited.rs) Sending email notifications to the firm's users Serbia
Hosted storage provider Storing documents, if the firm chooses hosted storage Named in the contract
Sentry Application error tracking, only if enabled; configured not to send IP addresses, email addresses or cookies Named in the contract

Each sub-processor is bound by a contract to the same data protection obligations. We tell the firm in advance, at least 30 days ahead, before adding or replacing a sub-processor, and the firm has the right to object. We are liable to the firm for a sub-processor's work as for our own.

Transfers out of Serbia

Data is stored in Serbia or in European Union member states, which are on the list of countries with an adequate level of protection (Article 64 ZZPL and the Government Decision on the list of countries, "Official Gazette of RS" No. 55/2019). We do not transfer data to a country outside that list without the firm's prior consent and an appropriate ground under Article 65 ZZPL.

Helping with data subject rights

If a client or another person contacts us with a request about their data, we pass it to the firm and do not answer it ourselves. The application lets the firm find, correct, export and delete data. Where that is not enough, we help the firm answer the request within the statutory deadline.

Data breaches

If we become aware of a breach affecting the firm's data, we inform the firm without undue delay, with what we know about the nature of the breach, the categories and approximate number of people and records affected, the likely consequences and the measures taken. This allows the firm, where needed, to notify the Commissioner within the deadline in Article 52 ZZPL (72 hours) and to inform the people affected under Article 53 ZZPL. We also help the firm with data protection impact assessments and prior consultation with the Commissioner (Articles 54 and 55 ZZPL), to the extent they concern the application.

When the contract ends

  • The firm can export all its data at any time: tables in CSV/XLSX format and, optionally, all documents from storage, in one ZIP archive.
  • After the contract ends, the firm has the period set in the contract to export its data. After that we delete the data from the application and from hosted storage and confirm this in writing.
  • Copies in backups are deleted in the regular cycle, no later than 90 days after deletion from the application.
  • We keep data longer only where the law requires it, and then we do not process it for anything else.

Audits

At the firm's request we provide all information needed to show that we meet our obligations under the agreement and Article 45 ZZPL, and we allow audits by the firm or a person it authorises, with prior notice and a duty of confidentiality. In the application, the firm can itself see the audit log of changes to its data.

Contact

Send questions about data processing, or a request for the data processing agreement, to office@advokatx.rs.

  • Business name: Nikola Arsić PR Grafičko dizajniranje NA DOTCOM Smoljinac
  • Short business name: Nikola Arsić PR NA DOTCOM
  • Legal form: sole proprietorship (preduzetnik) registered in Serbia
  • Registered address: Moravska 7, 12312 Smoljinac, Malo Crniće municipality, Serbia
  • Company registration number (MB): 67173953
  • Tax ID (PIB): 113904435
  • Email: office@advokatx.rs

Last updated: 2026-09-27