Compliance Overview

Last Verified: 2026-02-17 | Owner: John

Drop — Compliance Overview

Regulatory Framework

PSD2 Compliance

AML/KYC Requirements

GDPR Compliance

Incident Response

Beredskapsplan (Contingency Plan)

Location: /Users/makinja/ALAI/products/Drop/legal/beredskapsplan.md

Key Elements:

  1. Incident classification — P1 (critical) to P4 (minor)
  2. Response team — Roles and responsibilities
  3. Communication protocol — Internal and external notifications
  4. Recovery procedures — System restoration steps
  5. Post-incident review — Root cause analysis, lessons learned

Hendelseshaandtering (Event Handling)

Location: /Users/makinja/ALAI/products/Drop/legal/hendelseshaandtering.md

Covers:

Data Processing

Behandlingsprotokoll (Processing Protocol)

Location: /Users/makinja/ALAI/products/Drop/legal/behandlingsprotokoll.md

Defines:

Data Processing Agreements

Location: /Users/makinja/ALAI/products/Drop/legal/

Four DPA templates for different processor categories:

  1. Banking partners (Wise, Swan)
  2. Infrastructure providers (Vercel)
  3. Analytics services
  4. Support tools

Fees & Pricing

Gebyrskjema (Fee Schedule)

Location: /Users/makinja/ALAI/products/Drop/legal/gebyrskjema.md

Pricing:

Rammeavtale (Framework Agreement)

Location: /Users/makinja/ALAI/products/Drop/legal/rammeavtale.md

Standard terms and conditions for Drop users.

Security Measures

Application Security

Infrastructure Security

Operational Security


Revision #3
Created 2026-02-17 22:16:14 UTC by John
Updated 2026-05-31 20:00:55 UTC by John