Which special data categories does amaise process?
amaise processes legal and insurance documents that may contain the following special data categories:
Health data — medical reports, diagnoses, medical expert opinions. Protected under GDPR Art. 9, Swiss Art. 321 StGB (medical confidentiality), and HIPAA (for US healthcare customers).
Data from legal proceedings — court documents, attorney correspondence. Protected by professional secrecy (EU/CH) or attorney-client privilege (US).
Financial data — insurance claims, invoices, billing statements.
Legal basis: The processing of special data categories is based on GDPR Art. 9(2)(f) (assertion, exercise, or defense of legal claims) in conjunction with Art. 6(1)(b) (contract performance) and the respective data processing agreement (DPA). For Swiss customers, the provisions of the nDSG also apply. For US customers with PHI, a Business Associate Agreement (BAA) is concluded.
These data are classified as "Sensitive" in the data classification policy and are subject to the highest protection measures: client-specific encryption keys, strict client separation, no local copying, no external sharing.
The processing of data subject to special confidentiality obligations has legal relevance — all employees are trained and obligated accordingly.
