LAPIDAR

Data Processing Addendum

Legal

Data Processing Addendum

Effective 9 October 2026

This Data Processing Addendum ("DPA") forms part of the LAPIDAR Terms of Service between the Customer (an insurance agency) and Alan Balcerowiak, operating LAPIDAR as an unregistered business activity in Poland, ul. Bajeczna 49/2, 32-020 Wieliczka, Poland ("LAPIDAR"). The Customer accepts it together with the Terms, including by completing checkout.

1. Roles

  • The Customer is the controller (or, under US law, the financial institution / business) for personal information contained in commission statements, book exports and other files it uploads ("Customer Personal Data"), such as policyholder names, policy numbers, premiums and commission amounts.
  • LAPIDAR is the processor (service provider) and processes Customer Personal Data only on the Customer's behalf.
  • Payments are sold through Stripe's Managed Payments service, with Link (a Stripe company) as reseller and merchant of record. Link and Stripe are independent controllers of the payment data they collect at checkout. They receive no Customer Personal Data from uploaded files.

2. Scope of processing

3. Instructions

LAPIDAR processes Customer Personal Data only on the Customer's documented instructions, which are these Terms, this DPA and the Customer's use of the service. LAPIDAR will tell the Customer if it believes an instruction breaks the law. LAPIDAR does not sell or share Customer Personal Data, does not use it for its own purposes, and does not combine it with data from other customers. No AI or language models are used to process Customer Personal Data. When the Customer flags a file with "Didn't read right?", LAPIDAR looks at that file to make the service read it; this is part of the Customer's instructions.

4. US financial privacy (GLBA)

The Customer may be subject to the Gramm-Leach-Bliley Act and state insurance privacy and data security laws (for example laws based on the NAIC Insurance Data Security Model Law). LAPIDAR does not claim to be certified or to make the Customer compliant with these laws. LAPIDAR agrees, as a service provider, to:

  • use and disclose nonpublic personal information only to perform the service for the Customer;
  • maintain the safeguards in section 6;
  • notify the Customer of security incidents as set out in section 8;
  • support the Customer's reasonable oversight of service providers by answering written security questions.

5. Confidentiality

Access to Customer Personal Data is limited to Alan Balcerowiak, who is bound by confidentiality. If other persons are given access in the future, LAPIDAR will bind them to confidentiality first and update this DPA.

6. Security measures

LAPIDAR currently applies these measures. We do not hold SOC 2, ISO 27001 or other certifications.

  • Encryption in transit: HTTPS/TLS for all traffic to the site and app.
  • Passwords stored only as argon2 hashes.
  • Per-account storage isolation: each account's files are stored separately and are accessible only to that account.
  • CSRF protection on state-changing requests in the app.
  • Administrative access to the server limited to Alan Balcerowiak.
  • Server located in an OVHcloud data center in the United Kingdom (London).
  • Daily backups on the same server, readable only by its administrator, each kept for up to 15 days.
  • Account deletion feature that removes the account's stored files and data.

Not yet in place, stated so the Customer can assess it: two-factor login for customer accounts, encryption of the server disk at rest, and encrypted off-site backups. Until off-site backups exist, losing the server would mean losing its backups as well.

7. Subprocessors

The Customer authorizes these subprocessors:

Stripe and Link are not subprocessors: they receive no Customer Personal Data and act as independent controllers of the payment data they collect (section 1).

Customer Personal Data must not be sent by email. This mailbox is covered by Google's standard terms, not by a data processing agreement. If the Customer emails a file containing Customer Personal Data anyway, LAPIDAR will ask the Customer to upload it in the app instead and will delete the email and its attachments from the mailbox within 7 days. To report a file the service could not read, use "Didn't read right?" in the app, which keeps the file on our server.

LAPIDAR will give at least 30 days' notice by email before adding or replacing a subprocessor. The Customer may object on reasonable grounds; if we cannot resolve it, the Customer may cancel and receive a refund of prepaid fees for the remaining period. For OVHcloud and Cloudflare, LAPIDAR relies on the provider's standard data processing terms and remains responsible for them.

8. Security incidents

LAPIDAR will notify the Customer without undue delay, and in any case within 72 hours of becoming aware of a breach affecting Customer Personal Data, with the information then available: what happened, data and records affected, likely consequences, and the steps taken. LAPIDAR will help the Customer meet its own notification duties under state law or GDPR.

9. Deletion and return

The Customer can download its results and delete its account at any time; deletion removes Customer Personal Data from the service straight away. When the subscription ends, uploads and new checks stop and Customer Personal Data is kept for 30 days so the Customer can export its results; after that it is deleted, unless the Customer deletes it sooner or asks LAPIDAR for an export within that period. On written request LAPIDAR deletes Customer Personal Data within 30 days, unless the law requires retention. Copies in backups are overwritten within 15 days of deletion. On request LAPIDAR confirms deletion in writing.

10. Assistance and audits

LAPIDAR will reasonably help the Customer respond to data subject requests and with data protection assessments, and will provide information needed to show compliance with this DPA, including written answers to security questionnaires. On-site audits are possible on 30 days' notice, at the Customer's cost, no more than once a year.

11. International transfers

Customer Personal Data is stored in the United Kingdom, which is covered by an adequacy decision of the European Commission. Where Customers are in the US, data is transferred from the US to the United Kingdom, and results are returned to the Customer. To the extent that return transfer requires it, the parties agree that Module 4 (processor to controller) of the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 is incorporated into this DPA by reference. Where a subprocessor processes data outside the EU and outside countries covered by an adequacy decision, transfers rely on the EU–US Data Privacy Framework where the provider is certified under it, or on Standard Contractual Clauses.

12. Liability and order of precedence

Liability under this DPA is subject to the limitation in the Terms. If this DPA conflicts with the Terms on data protection, this DPA prevails.

Questions: contact@getlapidar.com