GDPR and DPA Overview
FortisEU provides GDPR documentation and a Data Processing Agreement ("DPA") as part of procurement and contracting. This page is an informational overview. The definitive DPA is provided for review and signature during your procurement process.
1. Roles
- Customer: typically acts as Controller for Customer Content processed in the service.
- FortisEU: typically acts as Processor for Customer Content, processing it only to provide the contracted service.
2. Subprocessors
FortisEU may use subprocessors to operate the service (for example: email delivery, infrastructure, and monitoring). An up-to-date subprocessor list is provided through the Trust Center request process.
3. Security Measures
FortisEU implements administrative, technical, and organizational measures appropriate to the nature of the service and data processed. For security review artifacts (overview, policies, and available evidence), request a security package via the Trust Center.
4. Audit and Due Diligence
Procurement teams often require a security overview, DPA, and subprocessor list. FortisEU supports this via a structured Trust Center process to reduce back-and-forth.
5. Contact
Privacy inquiries: privacy@fortis.eu
Security inquiries: security@fortis.eu