Confidentiality and Personnel
How Caelex binds staff and service providers to secrecy
Effective: 28 July 2026 · Caelex, Julian Polleschner, Berlin · Version 1.1
This page describes Caelex's contractual and organisational measures to protect confidential information, including attorney–client mandate data. It is not legal advice and does not replace a firm's internal assessment under Section 203 of the German Criminal Code (StGB) or the BRAO.
Section 203 StGB attaches to natural persons and specified assisting relationships. Cloud providers are not “automatically” within the offence; Caelex governs secrecy and processing through employment, service and data-processing contracts and TOMs.
The German version at /legal/mitwirkende is the legally binding text. This English version is a convenience translation. In the event of conflict, the German text prevails.
1. Caelex staff and appointees
- Persons with access to production infrastructure or client data are bound in writing to confidentiality
- The obligation covers mandate contents, parties, file numbers, vault files, chat histories and comparable data
- Confidentiality survives the end of the engagement, where contractually agreed
- Breaches may have employment-law, civil and — where the statute applies — criminal consequences
2. Sub-processors
Caelex engages sub-processors under Art. 28 GDPR contracts (DPAs) and the transfer mechanisms named in the sub-processor register. Typical clauses cover purpose limitation, confidentiality, TOMs and — where agreed — zero data retention / no training.
- Neon (database): DPA; EU region Frankfurt
- Vercel (hosting): DPA; EU primary where configured
- Anthropic (AI): DPA/enterprise posture including zero data retention, where contractually active
- Cloudflare R2 (vault): DPA; EU jurisdiction
- Others: see /legal/sub-processors-en
3. Content of the obligation (internal)
- No disclosure of client data to unauthorised persons
- No use for own purposes outside performance of assigned duties
- Processing only within the assigned task and purpose limitation
- Compliance with TOMs and internal access rules
- Immediate reporting of incidents to internal security channels
- Return or deletion of access credentials and media upon departure
4. Role vis-à-vis the firm
Vis-à-vis the firm, Caelex is a processor or service provider within the meaning of the respective contract and the GDPR. The firm remains the controller for the professional-law permissibility of use and for the decision which content is entered into the system.
5. Documentation and audit
Caelex keeps records of authorised persons and sub-processors to the extent reasonably practicable. Firms with a valid contract may request information under the agreed audit clauses (legal@caelex.eu).
6. Reporting incidents
Suspicion of unauthorised access or a breach of confidentiality: security@caelex.eu. The 72-hour notification to supervisory authorities remains, where applicable, the controller's (the firm's) duty.
Contact
Caelex, Julian Polleschner, Berlinlegal@caelex.eusecurity@caelex.euVersion 1.1 · 28 July 2026