Acciparte

Security and data

Regulated data deserves an architecture that starts with permission

A claim mixes personal data, health data, contract data and data from third parties who are nobody's customer. Acciparte is designed so that every piece of data has an owner, every access has a permission, and every permission leaves a trace.

Principles

Four rules that hold by design

These are data model decisions, not statements of intent. The detail is in the client documentation.

Nobody sees anything by default
Every access is an explicit, logged grant. Recipients are configured by the client; third parties enter with authorisation and for a limited time.
Every piece of data has an owner
Each driver's data belongs to them; photographs belong to whoever contributed them; the quote belongs to the workshop. Access is granted by parts, never to the whole claim file.
Health data is kept separate
A special category under Article 9 of the GDPR: isolated from the rest of the claim file and shared only with the data subject's consent or with the legal basis that applies to the insurer.
Everything is logged
Consents, accesses, deliveries and denials, with date, requester and authoriser, in an audit log that is not edited or deleted.

Infrastructure

Where and how it is hosted

European Union

Platform hosted in the European Union. The main providers, too.

Encryption and access control

Encryption in transit, role-based access control and data isolation per client.

Data processor

A data processing agreement signed with every client before the service is activated. In deployments carrying the client's brand, the client is the controller and Acciparte the processor.

For your security committee

Technical documentation on request

Permissions model specification, architecture, sub-processors, data processing agreement and answers to the vendor security questionnaire. Shared with a work email through the client documentation or by writing to admin@acciparte.com.

ISO 27001 certification is planned. In the meantime, the architecture follows its controls: role-based access, encryption, isolation per client and an audit log.

Frequently asked questions

Questions about security and data

Where is the data hosted?

In the European Union, with a first-tier cloud provider. Region and sub-processor detail is in the client documentation.

Who is the data controller?

The client that contracts the deployment is the data controller, and Acciparte is the processor, with a contract signed before the service is activated. Onboarded participants (workshop, loss adjuster, clinic) accept purpose and confidentiality terms at registration.

How is data on injured parties handled?

As a special category under Article 9 of the GDPR: isolated from the rest of the claim file, outside any policy-based permission, and shared only with the explicit, case-by-case consent of the data subject, or with the specific legal basis that applies to the insurer. A deployment can be limited to material damage and leave health data out of the circuit entirely.

Can a workshop see the driver's data?

No. An onboarded participant sees exclusively what they themselves have contributed, plus the claim file's reference. They enter through a temporary link, with prior registration and one party's authorisation.

What happens to the data when the contract ends?

The reference and the claim file are portable. The client receives its claim files, and the data is retained or deleted according to legal retention periods, configurable by contract.

Next step

Need the technical detail for your security committee?

We share the permissions model specification, the architecture and the data processing agreement in a meeting with your team.