Data Processing Agreement

Last updated: 15 March 2026

This Data Processing Agreement ("DPA") forms part of the agreement between FiorLab Limited, a company registered in Ireland (CRO 813471) ("Processor"), and the customer organisation ("Controller") for the provision of the FiorLab supplier risk intelligence platform (the "Service"), pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").

To execute this DPA for your organisation, please contact legal@fiorlab.com with your company details.

1. Definitions

"Personal Data" means any information relating to an identified or identifiable natural person processed through the Service. "Processing" has the meaning given in Article 4(2) GDPR. "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller. "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.

2. Scope and Purpose of Processing

ElementDetail
Subject MatterProvision of supplier risk intelligence and assessment services
DurationFor the term of the service agreement plus data retention period
Nature and PurposeStorage, analysis, scoring, and reporting of supplier assessment data to support procurement risk management
Types of Personal DataNames, email addresses, job titles, company affiliation, supplier financial and compliance metrics, and (where applicable) GxP pharmaceutical supplier qualification and compliance data
Categories of Data SubjectsBuyer employees, supplier employees, supplier company representatives

3. Obligations of the Processor

The Processor shall:

4. Sub-processors

The Controller provides general authorisation for the Processor to engage the following sub-processors:

Sub-processorLegal entityPurposeCountry of processingTransfer basis
Google Cloud FirestoreGoogle Ireland Limited, part of Google LLC (US)Database: supplier records, assessments, scores, contracts, RFPs, reportsEU multi-region (eur3): Belgium and the NetherlandsProcessed in the EU
Google Cloud StorageGoogle Ireland Limited, part of Google LLC (US)Uploaded supplier documentsBelgium (europe-west1)Processed in the EU
Firebase AuthenticationGoogle LLC (US)User authentication: email addresses and credentialsUnited StatesSCCs and EU-U.S. Data Privacy Framework
Vercel (application)Vercel, Inc. (US)Application hosting and API compute (app.fiorlab.com)Frankfurt (fra1). Vercel replicates platform backups globally.SCCs and EU-U.S. Data Privacy Framework
Vercel (marketing site)Vercel, Inc. (US)Marketing website hosting and contact form (fiorlab.com)Frankfurt (fra1). Vercel replicates platform backups globally.SCCs and EU-U.S. Data Privacy Framework
SentryFunctional Software, Inc. trading as Sentry (US)Application error monitoringFrankfurt for error events. Account, configuration and audit data remain in the United States.SCCs and EU-U.S. Data Privacy Framework
ResendPlus Five Five, Inc. (US)Transactional email deliveryUnited StatesSCCs and EU-U.S. Data Privacy Framework
StripeStripe Payments Europe, Limited (Ireland), with Stripe, LLC (US) as an additional processing partyPayments and billingEU and United StatesSCCs and EU-U.S. Data Privacy Framework
AnthropicAnthropic PBC (US)AI-assisted contract and document analysis via api.anthropic.com; document text is redacted before sendingUnited StatesSCCs
Sentry (control plane)Functional Software, Inc. trading as Sentry (US)Issue queries made by the FiorLab admin dashboard against sentry.io/api/0/United StatesSCCs and EU-U.S. Data Privacy Framework
CloudflareCloudflare, Inc. (US)DNS resolution, CDN and DDoS protection (network transit; no application data at rest)Global edge network, including the United StatesSCCs and EU-U.S. Data Privacy Framework

Transfers to the United States listed above are covered by Standard Contractual Clauses and, where the sub-processor is certified, the EU-U.S. Data Privacy Framework. Firebase Authentication is a US-only Google service with no data-residency configuration available on any plan.

This table is maintained at the level of detail required for a DORA Article 28 register of contractual arrangements, so that regulated customers can transcribe it directly into their own register without a separate information request.

The Processor shall notify the Controller at least 30 days in advance of any intended addition or replacement of sub-processors, giving the Controller the opportunity to object.

5. Data Breach Notification

The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Data Breach. The notification shall include: the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.

6. International Transfers

The Processor shall not transfer Personal Data outside the EEA unless appropriate safeguards are in place in accordance with Chapter V GDPR. Transfers to the United States occur for authentication (Firebase Authentication), transactional email (Resend), AI-assisted document analysis (Anthropic), DNS and edge delivery (Cloudflare), payment processing by Stripe, LLC, Sentry account and audit data, and Vercel platform operations and backups. Standard Contractual Clauses as approved by the European Commission (Decision 2021/914) shall apply to each, together with the EU-U.S. Data Privacy Framework where the sub-processor is certified.

7. Technical and Organisational Measures

The Processor implements the following measures:

8. Audits

The Controller may audit the Processor's compliance with this DPA once per year, with 30 days' written notice. The Processor shall cooperate with audits and make relevant records available. Where the Controller appoints a third-party auditor, the auditor must execute a confidentiality agreement acceptable to the Processor.

9. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. Nothing in this DPA limits either party's liability for breaches of data protection law to the extent such limitation is not permitted under applicable law.

10. Term and Termination

This DPA shall remain in effect for the duration of the service agreement. The obligations regarding confidentiality and data return/deletion survive termination. Upon termination, the Processor shall, at the Controller's election, return or securely delete all Personal Data within 90 days.

11. Contact

For questions about this DPA or to execute a signed copy:

FiorLab Limited — Data Protection
CRO Number: 813471
Email: legal@fiorlab.com
Dublin, Ireland