inperio://live

Legal · DPA

Data Processing Addendum

Last updated · 3 July 2026

When inperio.tech processes personal data on behalf of an insurer, MGA or broker, we do so as a processor under a Data Processing Addendum (DPA) that forms part of our customer agreement. This page summarises it; the executed DPA governs.

01

Roles

For platform data, our customer is the controller and INPERIO (TECHNOLOGIES) LIMITED is the processor. We process personal data only on the customer’s documented instructions and for the purpose of providing the platform.

02

Our commitments as processor

  • process personal data only on documented instructions from the controller;
  • ensure personnel are bound by confidentiality;
  • implement appropriate technical and organisational security measures;
  • assist the controller with data-subject requests and with security, breach and impact-assessment obligations;
  • delete or return personal data at the end of the services, subject to legal retention;
  • make available the information needed to demonstrate compliance, and allow audits.
03

Sub-processors

We engage vetted sub-processors (for example, hosting and infrastructure providers) under written terms no less protective than the DPA. We maintain a current sub-processor list and give notice of intended changes so the controller can object.

04

International transfers

Where personal data is transferred outside the UK, EEA or Jersey, we rely on an adequacy decision or Standard Contractual Clauses (with the UK Addendum where relevant), together with any additional safeguards required.

05

Security & breach notification

We apply encryption, tenant isolation, access controls and audit logging, and we notify the controller without undue delay after becoming aware of a personal-data breach affecting their data.

06

Requesting the DPA

To request our current DPA, sub-processor list or security documentation, contact privacy@inperio.tech.