DATA PROCESSING AGREEMENT
This Data Processing Agreement (the “DPA”) forms an integral part of the Agreement between ClaimLane and the Customer and governs ClaimLane’s processing of Personal Data on behalf of the Customer in connection with the provision of the Services.
For the purposes of this DPA, ClaimLane shall be referred to as the “Supplier”. ClaimLane and the Customer shall each be referred to as a “Party” and collectively as the “Parties”.
This DPA shall apply from the date on which the Supplier first processes Personal Data on behalf of the Customer and shall remain in force for as long as such processing continues
Capitalised terms not defined in this DPA shall have the meanings given to them in the Agreement. In the event of any conflict between this DPA and the Agreement concerning the processing of Personal Data, this DPA shall prevail.
1. DATA COVERED BY THE DPA
- 1.1 The scope of the services to be provided to the Customer (the “Services”) is set out in the Work Order. The Supplier will not process Personal Data covered by this DPA for its own purposes. Any processing carried out by ClaimLane as an independent data controller shall be limited to processing for which ClaimLane independently determines the purposes and means, such as the processing of business contact details, billing information and other information required for ClaimLane’s own legal and administrative purposes. Such processing is described in ClaimLane’s Privacy Policy and falls outside the scope of this DPA. For the avoidance of doubt, Personal Data contained in claims, documents, correspondence or other content submitted to the System by or on behalf of the Customer shall not be processed by ClaimLane for its own purposes unless separately agreed and based on an applicable legal basis.
- 1.2 “Personal Data” means any information relating to an identified or identifiable natural person (the “Data Subject”). The personal data to be processed by the Supplier through the performance of the Services concerns the categories of data, the categories of Data Subjects and the purposes of the processing set out in the Work Order.
- 1.3 The Supplier and the Customer may at any time agree to change the scope of the DPA by replacing the Work Order with a new version or by issuing supplemental appendices to the Work Order.
- 1.4 In the Work Order, the Supplier has stated the processing locations used to provide the Services. The Supplier shall keep the information regarding processing locations up to date and shall provide the Customer with at least thirty (30) calendar days’ prior written notice of any material change to such locations. Such notice does not require a formal amendment of the Work Order and may be provided by mail or email. Any change involving the engagement of a new Sub-Processor or a transfer of Personal Data outside the EU/EEA shall additionally be subject to Clauses 5.8 and 5.10 .
- 1.5 Any reference to “Personal Data” under this DPA applies to other information, which has been made confidential by law or agreement to the extent such information is processed.
2. DURATION OF DPA AND TERMINATION
- 2.1 This DPA shall remain in force for as long as the Supplier processes Personal Data on behalf of the Customer.
- 2.2 Upon termination or expiry of the Agreement or the Services involving the processing of Personal Data, the Supplier shall, at the Customer’s choice, delete or return all Personal Data processed on behalf of the Customer and delete any existing copies, unless Union or Member State law requires continued storage of the Personal Data.
- 2.2.1 The Supplier shall complete the deletion or return without undue delay and no later than ninety (90) days after termination or expiry, unless otherwise agreed in writing. At the Customer’s request, the Supplier shall confirm in writing that the deletion has been completed.
- 2.2.2 Where the Supplier is required by applicable law to retain Personal Data, the Supplier shall inform the Customer of the applicable legal requirement, restrict the processing of such Personal Data to the purpose of complying with that requirement and delete the Personal Data when continued retention is no longer required.
- 2.3 This DPA may not be terminated separately from the Agreement for as long as the Supplier processes Personal Data on behalf of the Customer. Termination or expiry of the Agreement shall not affect the provisions of this DPA which, by their nature, are intended to apply until all Personal Data has been deleted or returned
- 2.4 Any processing of Personal Data covered by this DPA must comply with the requirements set out in relevant legislation, and none of the Parties can rely on the contents of this DPA to the extent that this would mean non-compliance with relevant legislation.
- 2.5 The Supplier must cooperate in good faith with the Customer in order to transfer the performance of the Services to another supplier or to the Customer. The Supplier shall, taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in responding to requests from Data Subjects. The Supplier shall not respond directly to a Data Subject’s request concerning Personal Data processed on behalf of the Customer unless instructed by the Customer or required to do so by applicable law. The Supplier shall without undue delay forward any such request to the Customer.
3. INTELLECTUAL PROPERTY RIGHTS
- 3.1 As between the Parties, the Customer retains all rights and interests in the data and other information made available to the Supplier by or on behalf of the Customer. Nothing in this DPA grants the Supplier any ownership rights in Personal Data processed on behalf of the Customer.
4. PROCESSING OF PERSONAL DATA
- 4.1 The Supplier shall process the Customer’s Personal Data solely for the purpose of providing the Services, only on documented instructions from the Customer, including as set out in the Agreement, this DPA, the Work Order and any subsequent documented instructions issued by the Customer, and in accordance with applicable data protection legislation, including Regulation (EU) 2016/679 (the “GDPR”), the Danish Data Protection Act (databeskyttelsesloven) and any other data protection legislation applicable to the Supplier. The Supplier shall immediately inform the Customer if, in the
Supplier’s opinion, an instruction infringes the GDPR or other applicable Union or Member State data protection legislation. - 4.2 The Supplier shall not process Personal Data for any other purpose unless required to do so by Union or Member State law to which the Supplier is subject. In such case, the Supplier shall inform the Customer of that legal requirement before carrying out the processing, unless the applicable law prohibits such information on important grounds of public interest.
- 4.3 The Supplier will comply with the requirements of a data processor and the Customer will comply with the requirements of a data controller, each under the applicable data protection legislation.
- 4.4 Each Party shall obtain and maintain, throughout the term of this DPA, all necessary registrations or notifications which such Party is obliged to obtain and maintain pursuant to applicable data protection legislation or regulation.
- 4.5 The Customer is responsible for ensuring that the processing of Personal Data which it instructs the Supplier to perform has a valid legal basis and otherwise complies with applicable data protection legislation.
5. DATA SECURITY
- 5.1 The Supplier shall implement and maintain the appropriate technical and organisational security measures against:
- (i) accidental or unlawful destruction, loss or alteration;
- (ii) unauthorised disclosure or abuse; or
- (iii) other unlawful processing.
- 5.2 The Supplier shall comply with the data security requirements directly applicable to the Supplier in its capacity as data processor under applicable data protection legislation. Any additional Customer-specific security requirements shall apply only to the extent expressly agreed in writing between the Parties.
- 5.3 The appropriate technical and organisational security measures must be determined with due regard to
- (i) state of the art measures;
- (ii) the cost of their implementation; and
- (iii) ensuring a level of security appropriate for the risks represented by the processing and the nature of the Personal Data to be protected.
- 5.4 The Work Order sets out the minimum technical and organisational security measures applicable to the processing operations, which at all times must be implemented and maintained. The Supplier must, however, also ensure compliance with Clause 5.1 and implement and maintain the necessary technical and organisational security measures; even if such measures are not set out in Work Order.
- 5.5 The Supplier shall on request provide the Customer with sufficient information to enable the Customer to ensure that the appropriate technical and organisational security measures have been implemented.
- 5.6 The Supplier shall make available to the Customer all information reasonably necessary to demonstrate compliance with the Supplier’s obligations under this DPA and Article 28 GDPR.
- 5.6.1 The Supplier shall allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer. Any audit shall, except where reasonably required due to a Personal Data Breach (as defined in Clause 5.7(ii)), an instruction from a supervisory authority or a reasonable suspicion of material non-compliance:
- (i) be subject to reasonable prior written notice;
- (ii) be conducted during normal business hours;
- (iii) not unreasonably interfere with the Supplier’s business operations; and
- (iv) normally be limited to once in any twelve-month period.
- 5.6.2 The Supplier may satisfy the Customer’s audit request by providing relevant and current third-party audit reports, certifications or similar documentation, provided that such documentation reasonably demonstrates the Supplier’s compliance. Where such documentation is insufficient for the Customer to meet its obligations under applicable data protection legislation, the Customer shall remain entitled to conduct an audit or inspection.
- 5.6.3 The Customer shall bear its own costs relating to an audit or inspection. The Supplier may charge reasonable costs for assistance that materially exceeds the Supplier’s ordinary obligations under this DPA, except where the audit identifies material non-compliance by the Supplier.
- 5.6.4 Subject to Clauses 5.6.1 – 5.6.3 and appropriate confidentiality obligations, the Supplier shall provide the Customer’s external advisers with information reasonably necessary for the performance of an audit under this Clause 5.6 . The Supplier shall further provide competent supervisory authorities, and representatives acting on their behalf, with such information and access to the Supplier’s physical facilities as they are entitled to receive under applicable law, upon presentation of appropriate identification.
- 5.6.1 The Supplier shall allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer. Any audit shall, except where reasonably required due to a Personal Data Breach (as defined in Clause 5.7(ii)), an instruction from a supervisory authority or a reasonable suspicion of material non-compliance:
- 5.7 The Supplier must notify the Customer without undue delay and, where feasible, no later than forty-eight (48) hours after becoming aware thereof about:
- (i) any request for disclosure of Personal Data processed under the DPA by authorities, unless expressly prohibited under law e.g., to preserve the confidentiality of a law enforcement investigation;
- (ii) any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed under the DPA (a “Personal Data Breach”), including any reasonable suspicion of a Personal Data Breach; and
- (iii) any request for information received directly from the Data Subjects or from third-parties without responding to that request, unless it has been otherwise authorised to do so.
- 5.7.1 The notification of a Personal Data Breach shall, to the extent the relevant information is available to the Supplier, include:
- (i) a description of the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects and personal data records concerned;
- (ii) a description of the likely consequences of the Personal Data Breach;
- (iii) a description of the measures taken or proposed to be taken to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects; and
- (iv) the name and contact details of a contact point from whom further information may be obtained.
- 5.7.2 Where it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- (i) any request for disclosure of Personal Data processed under the DPA by authorities, unless expressly prohibited under law e.g., to preserve the confidentiality of a law enforcement investigation;
- 5.8 The Supplier may subcontract its processing operations performed on behalf of the Customer (a “Sub-Processor”) under the DPA without the prior written consent of the Customer, provided that the Supplier notifies the Customer in writing about the identity of a potential Sub-Processor (and its sub-processors, if any), with at least thirty (30) calendar days’ prior written notice, before the relevant Sub-Processor processes any of the Personal Data, thereby giving the Customer the opportunity to object to the intended addition or replacement of the Sub-Processor before its engagement.
- 5.8.1 Any objection must be based on reasonable grounds relating to the protection of Personal Data and must be submitted within the notice period. The Parties shall cooperate in good faith to resolve the objection, including by considering a commercially reasonable alternative. If no reasonable solution can be agreed, the Customer may terminate the affected Services by written notice without liability for future fees relating to those affected Services.
- 5.9 The Customer authorises the Supplier’s use of the Sub-Processors listed in the Work Order for the purpose of providing the Services. Where the Supplier engages a Sub- Processor, the Supplier shall, by way of a written agreement or other legal act, impose on the Sub-Processor data protection obligations no less protective than those set out in this DPA, to the extent applicable to the processing performed by the Sub-Processor. In particular, the Supplier shall require the Sub-Processor to implement appropriate technical and organisational measures in such a manner that the processing complies with applicable data protection legislation and this DPA. The Supplier shall remain fully liable to the Customer for the performance of the Sub-Processor’s data protection obligations. The Supplier shall notify the Customer if a Sub-Processor ceases to process Personal Data covered by this DPA.
- 5.10 The Supplier shall not transfer Personal Data to, or permit Personal Data to be accessed or otherwise processed from, a country outside the EU/EEA except on the basis of documented instructions from the Customer, including an authorisation set out in the Work Order, and in compliance with Chapter V GDPR.
- 5.10.1 Where a transfer is based on standard contractual clauses adopted by the European Commission, the Supplier shall ensure that the applicable version and module of such clauses are entered into and shall implement any supplementary technical, organisational or contractual measures reasonably required to ensure an essentially equivalent level of protection.
- 5.10.2 Where a transfer is required by Union or Member State law to which the Supplier is subject, the Supplier shall inform the Customer of that legal requirement before the transfer, unless the applicable law prohibits such information on important grounds of public interest.
- 5.11 The Supplier will assist the Customer with meeting obligations that may be incumbent on the Customer according to relevant laws or regulations where the assistance of the Supplier is implied or necessary for the Customer to comply with these obligations. Such assistance includes assistance to the Customer in connection with accommodating data subjects exercising their rights under Chapter III GDPR and, taking into account the nature of the processing and the information available to the Supplier, assistance in ensuring compliance with Articles 32-36 GDPR, including obligations relating to security of processing, notification and communication of Personal Data Breaches, data protection impact assessments and prior consultation with supervisory authorities.
- 5.11.1 The Supplier may charge the Customer reasonable remuneration for such assistance to the extent the assistance exceeds the Supplier’s obligations under this DPA or applicable data protection legislation.
6. CONFIDENTIALITY
- 6.1 The Supplier shall keep Personal Data confidential and shall process and use Personal Data solely for the purpose of performing its obligations under this DPA.
- 6.2 The terms of this Clause 6 apply to any of the Supplier's employees, consultants and other persons acting under the Supplier’s authority. The Supplier shall ensure that any person authorised to process Personal Data has committed themselves to confidentiality or is subject to an appropriate statutory obligation of confidentiality. Access to Personal Data shall be limited to persons for whom access is necessary for the performance of the Services and shall be subject to periodic review.
7. AMENDMENTS
- 7.1 The Parties may at any time agree to amend this DPA. Amendments must be in writing and executed by duly authorised representatives.
8. GENERAL PROVISIONS
- 8.1 The provisions of the Agreement concerning liability, indemnification, governing law and jurisdiction shall also apply to this DPA, subject to mandatory applicable data protection legislation.
ANNEX 5.1 - WORK ORDER
This Work Order forms an integral part of the DPA. Capitalised terms not defined in this Work Order shall have the meanings given to them in the DPA or, where applicable, the Agreement.
1. THE PROCESSING OPERATIONS
- 8.2 Processing operations
The Supplier provides Services for and on behalf of the Customer by providing the Customer with access to ClaimLane’s cloud-based claims handling platform, designed to assist the Customer in receiving, processing and resolving claims (including returns, complaints and warranty-related cases) from the Customer’s end-customers, including through a customer-facing claims portal. The Customer has instructed the Supplier to collect, structure, store, use and analyse the Customer’s data as a prerequisite for the Supplier’s delivery of the Services, including for the purpose of handling and assisting with claims received from the Customer’s end-customers, and to transmit data and conclusions to the Customer.
The Supplier’s processing and storage of the Customer’s Personal Data as described above shall continue for the duration of the Services. Subject to Clause 2.2 , the Customer instructs the Supplier to apply the following retention periods:
(A) Personal Data collected for the purpose of handling a claim is stored for a period of three and a half (3.5) years after the claim has been closed; and
(B) to the extent the Supplier is independently required by the Danish Bookkeeping Act (bogføringsloven) to retain specific Personal Data, such Personal Data may be retained for the applicable statutory retention period and shall during such period only be processed for the purpose of complying with the relevant legal requirement.
Upon termination or expiry of the Services, the Supplier shall delete or return Personal Data in accordance with Clause 2.2 , irrespective of whether the above retention period has expired, unless the Customer instructs otherwise or applicable law requires continued storage.
- 8.3 Sub-Processors and processing location(s)
- 8.3.1 The Customer authorises the Supplier’s use of the following Sub-Processors: Category Purpose Sub-processors (or a similar and identifiable service)

8.3.2 New Sub-Processors may be engaged in accordance with Clause 5.8 , including theCustomer’s right to object within the applicable notice period.
- 8.4 Data Subjects
The Data Subjects are:
(A) Users of the System, i.e. the Customer’s employees, consultants and other internal representatives authorised to access and use the System through individual login credentials;
(B) the Customer’s end-customers who submit or follow up on claims through the System (including via the customer-facing claims portal); and
(C) other persons whose data is contained in claims-related data, documents, images and correspondence uploaded to, or made available to the Supplier in, the System.
- 8.5 Categories of data
For each Data Subject the following Personal Data can be identified:
(A) Name, workplace, e-mail address and other contact details, login credentials and user activity data (for the Users of the System under (A) above); and
(B) Name, address and registration data (including company information where relevant), contact details (including e-mail address and phone number), purchase information (including order numbers, receipts and other information relevant to the handling of a claim), correspondence and any other information provided by the end- customer in the claims process (for the Data Subjects under (B) and (C) above). This list is not exhaustive as claims and uploaded documents can contain other data unknown to the Supplier.
The processing is not intended to include personal data subject to GDPR art. 9 (special categories of personal data) or civil registration numbers (CPR numbers), and the Customer shall not knowingly upload such data to the System unless separately agreed in writing between the Parties and the Customer has established a valid legal basis for the processing. If such data is incidentally included in claims, documents or correspondence, the Supplier shall process such data solely on documented instructions from the Customer and shall apply technical and organisational measures appropriate to the increased risk.
- 8.6 Technical and organisational security measures
The Supplier shall, as a minimum, implement and maintain the following technical and
organisational security measures, to the extent applicable to the Services and the
relevant processing. The Supplier may replace a listed measure with an alternative
measure providing an equivalent or higher level of security, provided that the overall
level of protection is not reduced.
(A) management and organisation of IT security, including a security concept, a
designated person responsible for data protection and documented processes for
identifying and handling data breaches, security incidents and data subject requests;
(B) pseudonymisation of personal data (including e-mail addresses, names and home
addresses) where possible when data is shared;
(C) physical access controls, including key management, locked facilities, alarm systems
and adequate protection of server rooms;
(D) system access controls, including unique personal user IDs, person-related access
logging, separate IDs for privileged access, removal of IDs upon job changes, secure
password procedures, multi-factor authentication for critical applications, automated
locking, regular software updates and patching, regular vulnerability scans, network
segmentation and firewalls;
(E) data access controls, including role-based limitation of access to data, read-only
rights where necessary and regular reviews of granted access rights;
(F) transmission and input controls, including measures ensuring that personal data
cannot be read, copied, modified or deleted during transmission (e.g. VPN and
SSL/TLS encryption), encryption of mobile devices and storage media, secure
destruction of storage media and logging of entries, modifications and deletions of
personal data;
(G) job control, including binding security guidelines, regular training of staff with access
to personal data, regular internal data protection audits, controlled software
development, IT change management, separation of development and production
systems and controlled Sub-Processor procurement;
(H) availability controls, including business continuity strategy and management, regular
and tested backups, secure and redundant backup storage, redundant internet and
power supply and emergency and recovery plans;
(I) data separation, ensuring that personal data belonging to one customer is separated
from personal data of other customers;
(J) logging and monitoring of data access; and
(K) remote work controls, including a prohibition against working from countries outside
the EU (except countries offering an adequate level of data protection pursuant to
GDPR art. 45), mobile working guidelines, no storage of personal data on terminal
equipment and multi-factor authentication.