Data Protection Impact Assessment (DPIA)

Last updated: 2026-04-19

1. Purpose of this document

This document is the Data Protection Impact Assessment (DPIA) for the NISMap platform operated by Inger s.r.o. The DPIA is prepared under Article 35 GDPR because NISMap systematically and on a large scale processes data related to organizations' cybersecurity and compliance posture (Art. 35(3)(b) GDPR — large-scale processing of special categories of data and data on the trustworthiness / security posture of subjects). Its purpose is to identify risks to the rights and freedoms of data subjects and to demonstrate that appropriate measures have been put in place to mitigate them.

2. Description of processing

2.1 What data we process

  • Domain and company ID submitted for the scan — publicly available data
  • Technical scan results (TLS, headers, DNS, CMS fingerprint, open ports)
  • Responses to the NIS2 compliance questionnaire
  • Email address, name and company name of the registered user
  • Billing data (processed by Stripe as an independent controller for payment purposes)
  • Application audit log (who, when, which action was performed)
  • Vendor ICOs and IBANs entered for supply-chain audit (NIS2 Art. 21(2)(d)), relationship graphs (RPO, RPVS) and IBAN validation against the FS register — all public data via entyrix.com

2.2 Purposes of processing

  • Providing automated NIS2 / cybersecurity assessment
  • Generating reports and recommendations (including AI-generated content via the Claude API; identifiers are removed from the input before sending)
  • Managing user accounts and access rights
  • Invoicing, accounting and meeting statutory obligations
  • Security monitoring and abuse prevention

2.3 Retention periods

  • Scan results — 90 days, then automatically anonymized
  • Audit log — 12 months
  • Accounting and billing records — 10 years (statutory obligation)
  • Account data — for the duration of the account + 30 days after termination

3. Necessity and proportionality assessment

Processing is necessary to provide the service itself — without the domain, company ID and questionnaire answers, no NIS2 assessment can be performed. The scope of data is minimized to what is technically and legally needed:

  • Data minimization — we do not collect any personal data of the client organization's end employees, only the contact details of the primary account user
  • Purpose limitation — data is used solely for the NIS2 compliance assessment and report
  • Pseudonymization / anonymization — before sending to the Claude API we remove company IDs, company names, contact details, birth numbers and recognised personal names and addresses; names and addresses are recognised heuristically
  • No tracking — NISMap does not use tracking cookies or advertising identifiers
  • Legal basis — performance of a contract (Art. 6(1)(b) GDPR), legitimate interest in providing the service (Art. 6(1)(f) GDPR) and legal obligation for accounting (Art. 6(1)(c) GDPR)

4. Identified risks

The following table summarizes the main risks to the rights and freedoms of data subjects identified for processing within NISMap, including likelihood, impact and the measures put in place to mitigate them.

RiskLikelihoodImpactMitigation
Data breach as a result of an attackLowHighEncryption at rest and in transit, RLS at the database layer, regular security audits, EU hosting (Supabase Frankfurt), incident response plan with 72-hour notification.
Unauthorized access to another tenant's dataLowHighRow-Level Security (RLS) in Supabase, data isolation by org_id, mandatory authorization checks in API routes, test coverage.
Sensitive data leakage via AI prompt (Claude API)MediumMediumAutomatic removal of company IDs, company names, emails, phone numbers, IP addresses and recognised names and addresses before every Claude API call, notice in the chat, DPA with Anthropic, EU SCCs, no-training clause under Anthropic Commercial Terms.
Security incident at a sub-processorLowHighSelection of reputable sub-processors, DPAs with sub-processors, monitoring of status pages, contact plan for vendor breach notifications.
Account takeoverMediumMediumOptional MFA via Supabase Auth, rate limiting on login endpoints, email notification on new sign-in, magic-link and OAuth as preferred methods, forced password rotation on suspected leak.
Loss of service availability (DoS, outage)MediumLowDeployment from versioned Docker images with automatic rollback to the previous version on a failed deploy, status page, no critical personal data is stored exclusively in NISMap.
User misinterpretation of AI-generated recommendationsMediumLowExplicit disclaimer with every AI output ("indicative assessment, contact NBÚ / NÚKIB for binding determination"), references to specific provisions of SK Act 69/2018, NBÚ Decree 227/2025 and the NÚKIB decree.

5. Mitigation measures

Risks are actively managed through both organizational and technical controls. Below is a summary of the key controls implemented in the platform.

  • Row-Level Security (RLS) — in PostgreSQL for tenant isolation
  • Encryption in transit — (TLS 1.2+) for all communication with the application and sub-processors
  • Encryption at rest — for the entire database and Supabase Storage
  • MFA — available for all user accounts via Supabase Auth
  • Anonymization — of input before sending to the Claude API (removal of company ID, company name, contact details and recognised names and addresses)
  • Audit log — of sensitive actions with 12-month retention
  • Principle of least privilege — for service role keys and internal access
  • Regular dependency audits — and CSP headers for the frontend
  • DPAs — with sub-processors — list and links to their DPAs at /sub-processors
  • Backup & recovery — the application is restored from versioned Docker images; database backups are handled by Supabase
  • Opendata data boundary — only public company identifiers (ICO, domain) are sent to entyrix.com — never user names, emails or any PII

6. Consultation with data subjects

Because NISMap is a self-service SaaS product and the population of data subjects is broad and open, the consultation takes the form of publishing this DPIA document together with the privacy policy. Any user or data subject can submit comments, questions or requests at any time to privacy@nismap.com. Comments will be taken into account in the next review of this document.

7. Conclusion and re-assessment

Considering the identified risks, the measures put in place and the nature of the processing, we deem the residual risk to the rights and freedoms of data subjects to be acceptable. The processing does not result in a high risk that would require prior consultation with the supervisory authority under Article 36 GDPR. This is a living document and will be re-assessed:

  • At least once a year
  • When a new sub-processor is added or the jurisdiction of processing changes
  • When the scope of processed data or a new product module changes
  • After every material security incident

8. Contact

Questions, comments or requests related to this DPIA document or the processing of personal data in NISMap can be sent to privacy@nismap.com.