Under GDPR Art. 28, a written Data Processing Agreement (DPA) must be in place with every processor that processes personal data on behalf of claimio tenants.
This document tracks the status of required DPAs and provides the standard template used with sub-processors.
| Processor | Role | Personal Data Processed | DPA Status | Due | |-----------|------|------------------------|------------|-----| | TransIP B.V. | VPS hosting, Object Storage (backups) | All claimio personal data at rest (encrypted) | ❌ Pending | Q2 2026 | | auditPic (GloryLabs internal service) | Photo upload, hash signing, deepfake detection | Claim photos (potentially biometric-adjacent); photo metadata | ❌ Pending | Q2 2026 |
| Property | Value | |----------|-------| | Company | TransIP B.V. | | Address | Schipholweg 9H, 2316 XA Leiden, Netherlands | | KVK | 52443526 | | Privacy contact | privacy@transip.nl | | Standard DPA | Available via TransIP customer portal | | Nature of processing | Infrastructure hosting; VPS operates all claimio services; Object Store holds encrypted pg_dump backups | | Data location | Netherlands (EU) | | Sub-processors | TransIP may use sub-processors; to be verified in their DPA |
Action: Accept TransIP's standard DPA via their customer portal and retain a copy. Review their sub-processor list annually.
| Property | Value | |----------|-------| | Company | GloryLabs (internal microservice) | | Nature | auditPic is operated by the same legal entity (GloryLabs); a controller-to-controller or intra-group agreement may apply instead of a standard DPA | | Data processed | Claim photos uploaded by claimants; SHA-256 + HMAC-SHA256 signatures | | Data location | Same TransIP VPS infrastructure | | API authentication | API key (X-Api-Key header); no direct DB access |
Action: Legal review required to determine whether intra-group agreement or standard Art. 28 DPA is needed. If auditPic is operated under a separate legal entity, a full DPA is required.
The following template is used when negotiating a custom DPA with processors who do not offer their own standard agreement.
Between:
Controller: [Tenant name] / GloryLabs, [address], hereinafter "Controller"
Processor: [Processor name], [address], hereinafter "Processor"
Together referred to as "Parties."
| Attribute | Details | |-----------|---------| | Nature | Infrastructure hosting / [other] | | Purpose | Operation of claimio SaaS platform | | Type of personal data | Name, email, IBAN, vehicle details, incident description, claim photos | | Categories of data subjects | Insurance claimants, tenant users | | Duration | For the term of the service agreement + data deletion within 30 days of termination |
The Processor shall:
a) Process Personal Data only on documented instructions from the Controller; b) Ensure that persons authorised to process Personal Data have committed to confidentiality; c) Take all measures required pursuant to Art. 32 (security of processing); d) Not engage sub-processors without prior written authorisation of the Controller; e) Assist the Controller in responding to data subject rights requests (Arts. 15–22); f) Assist the Controller in ensuring compliance with Arts. 32–36; g) Delete or return all Personal Data upon termination of services, and delete existing copies unless EU/Member State law requires storage; h) Make available to the Controller all information necessary to demonstrate compliance with Art. 28, and allow and contribute to audits.
The Processor implements at minimum:
Detailed measures are set out in Annex B (Technical and Organisational Measures).
The Processor shall notify the Controller of any personal data breach without undue delay and within 24 hours of becoming aware, to enable the Controller to meet its 72-hour GDPR Art. 33 notification obligation.
Personal Data shall be processed within the European Economic Area (EEA). Any transfer outside the EEA requires prior written approval of the Controller and appropriate safeguards per GDPR Chapter V.
The Parties' liability is governed by the underlying service agreement and GDPR Art. 82.
This Agreement is governed by the laws of the Netherlands.
Signed:
| Controller | Processor | |-----------|-----------| | GloryLabs | [Processor name] | | Date: | Date: | | Name: | Name: | | Title: | Title: |
| Sub-processor | Location | Purpose | |--------------|----------|---------| | [To be completed per processor] | | |
| Category | Measure | |----------|---------| | Encryption in transit | TLS 1.2+ on all external interfaces | | Encryption at rest | AES-256 or equivalent | | Access control | Role-based access; MFA for administrative access | | Availability | Redundant infrastructure; backup and restore procedures | | Incident response | Written incident response procedure; 24h breach notification to Controller | | Audit | Logging of access to personal data; annual security review |
| # | Action | Owner | Due | |---|--------|-------|-----| | 1 | Accept TransIP standard DPA via customer portal; download and archive signed copy | Tech Lead / DPO | Q2 2026 | | 2 | Legal review: determine auditPic DPA requirement (intra-group vs Art. 28 DPA) | DPO / Legal | Q2 2026 | | 3 | If required: sign DPA with auditPic entity | DPO | Q2 2026 | | 4 | Add DPA copies to secure document store (1Password / SharePoint) | DPO | Q2 2026 | | 5 | Annual review of sub-processor lists for all active DPAs | DPO | Annually |
| Version | Date | Author | Changes | |---------|------|--------|---------| | 1.0 | 2026-03-30 | GloryLabs | Initial version |
Reacties