Data governance

Claims data handled to Swiss standards

Policyholder claim data is among the most sensitive personal information a company can hold. Insurteam processes it under Swiss FADP and EU GDPR frameworks, with data residency in Switzerland.

Regulatory framework

FADP and GDPR compliance

Insurteam operates as a data processor under Swiss FADP and EU GDPR. Your insurer organisation remains the data controller; Insurteam acts only on your documented instructions.

Swiss FADP

Revised Federal Act on Data Protection

All policyholder data processed under the revised Swiss FADP. Data processing agreements available for review. Swiss data residency maintained throughout the processing pipeline.

EU GDPR

General Data Protection Regulation

Insurteam's processing is compatible with EU GDPR data processor requirements. Standard contractual clauses available for EU-domiciled insurer clients. Data subject rights procedures documented and accessible.

Data processor

Processor, not controller

Insurteam processes claim data only on the documented instructions of the insurer client. We do not use claim data for model training, profiling, or any purpose beyond the contracted processing agreement.

Retention

Defined retention periods

Claim data is retained for the duration specified in the processing agreement, typically 90 days post-settlement for audit purposes. Data destruction certificates available on request.

Infrastructure

Encryption, access control, audit log

Encryption at rest and in transit

All claim data encrypted at rest using AES-256. Transport encrypted with TLS 1.3. API keys rotatable on demand.

Role-based access control

Principle of least privilege applied throughout. Separate API credentials per integration. Human operator access logged and reviewed quarterly.

Full audit trail

Every claim processing step logged with timestamp, operator ID, and data-access record. Audit log accessible via API and retained for the agreed period.

Swiss data residency

Processing infrastructure hosted in Switzerland. No data leaves Switzerland without explicit insurer instruction and contractual basis. Enterprise clients may request private cloud deployment.

Vulnerability management

Dependency scanning automated in the build pipeline. Security patches applied within 48 hours for critical advisories. Penetration testing conducted before major releases.

Incident response

Documented incident response plan with defined notification timelines. Data breach notification to affected insurer clients within 72 hours of confirmed incident.

Certification roadmap

Planned compliance milestones

In place

FADP and GDPR DPA templates

Data processing agreements available for all insurer clients

In place

AES-256 at rest, TLS 1.3 in transit

Encryption standard applied across all data stores and API endpoints

In progress

ISO 27001 certification

Information security management system audit initiated

Planned

Penetration test (third-party)

Annual third-party penetration testing programme

Planned

SOC 2 Type I readiness assessment

Controls audit aligned with SOC 2 trust service criteria

Talk to our team about your security requirements

Enterprise clients can request full data processing agreements, security questionnaire responses, and a dedicated review with our team before signing.