Data Processing Addendum
· Last updated 2026-09-20Data Processing Addendum
This DPA applies where Webbmi AB processes personal data on behalf of a business customer (group claim sponsor, advisor, etc.) acting as the controller. For individual consumers, our Privacy Policy applies.
1. Roles
You (Customer) are the controller. Webbmi AB is the processor. Each party complies with the GDPR and applicable data protection laws.
2. Subject matter & duration
Processing of personal data necessary to provide the Claimance service for as long as your subscription is active, plus retention periods set out in our Privacy Policy.
3. Nature & purpose
Hosting, storing, displaying, transmitting, analyzing and otherwise processing Customer Data to provide the service, including AI-assisted drafting, classification and packaging of insurance correspondence.
4. Categories of data subjects & data
- Data subjects: Customer's end users (claimants).
- Data categories: Identity, contact, claim details, insurer correspondence, payment metadata.
- Special categories: Health/medical data may be processed where strictly necessary for the claim. Customer is responsible for obtaining any explicit consent required under Art. 9 GDPR.
5. Sub-processors
Customer authorizes the sub-processors listed in our Privacy Policy and on this page. We give 30 days' notice of additions and offer Customer the right to object on reasonable data-protection grounds.
| Provider | Purpose | Location |
|---|---|---|
| Supabase (managed Postgres, Auth, Storage) | Application database & file storage | EU (Frankfurt) |
| Cloudflare | CDN, DDoS protection, edge runtime | Global edge; EU origin |
| Lovable AI Gateway | Routing prompts to AI providers (OpenAI, Google) — no training on your data | EU/US |
| Postmark (ActiveCampaign) | Transactional email delivery & inbound parsing | US (DPF-certified) |
| Stripe / Paddle | Payment processing (only if you subscribe) | EU/US |
6. Security
We maintain technical and organizational measures including: encryption in transit (TLS 1.2+) and at rest (AES-256 / authenticated encryption for identity vault), least-privilege IAM, audited admin access, automated dependency scanning, signed webhook handlers, and a documented incident response process. A current summary of measures is available on request.
7. International transfers
For any transfer outside the EU/EEA, we rely on the EU Standard Contractual Clauses (2021) and, where applicable, the EU-US Data Privacy Framework.
8. Breach notification
We notify Customer of a confirmed personal-data breach affecting Customer Data without undue delay and in any event within 48 hours of becoming aware.
9. Assistance
We assist Customer in responding to data-subject requests, performing DPIAs and consulting supervisory authorities, to the extent reasonably necessary and proportionate.
10. Audits
Customer may audit our compliance once per year on 30 days' notice, or more frequently if required by a supervisory authority or following a personal-data breach. We may satisfy audit obligations by providing third-party certifications and reports.
11. Return / deletion
On termination, we will, at Customer's choice, delete or return all Customer Data within 30 days, unless we are legally required to retain it.
12. Liability & SCCs
Liability under this DPA is governed by the limits in the Terms of Service. Where SCCs apply, their liability provisions prevail over this clause to the extent of any conflict.
13. Contact
DPO / Privacy contact: info@claimance.ai