Data Processing Addendum
Effective date: April 1, 2026
Last updated: July 18, 2026
This is a draft available for contractual review.
This Data Processing Addendum ("DPA") is a draft made available on request for B2B customers. It is not automatically incorporated into any agreement and takes effect only when executed by both parties as an addendum to the Terms of Service. To request an executable copy, contact hello@verifex.dev.
1. Parties
This DPA is entered into between the customer (the "Controller") and Verifex, operated by Sadat Nazarli (the "Processor" or "Operator"), based in Azerbaijan, and supplements the Terms of Service.
2. Subject matter, duration, nature, and purpose
The Processor processes personal data on behalf of the Controller for the purpose of providing sanctions, PEP, and KYB screening services via Verifex. The nature of processing includes name normalisation, fuzzy and phonetic matching, entity resolution, and returning match results and related evidence. Processing begins on the Controller's first use of the relevant features and continues for the duration of the service agreement, plus any applicable retention period described in this DPA and the Privacy Policy.
3. Categories of personal data
- Names of screened individuals or entities
- Dates of birth, nationalities, or countries of residence, where provided
- Entity types (person, company, vessel)
- Company officers, persons with significant control (PSCs), and ultimate beneficial owners (UBOs), for KYB
- Screening results, confidence scores, and risk assessments
- Request metadata (timestamps, IP addresses, API-key identifiers)
4. Categories of data subjects
- The Controller's customers and prospective customers
- Transaction counterparties
- Officers, PSCs, and beneficial owners of screened entities
- Any individuals or entities the Controller submits for screening
5. Controller instructions
The Processor processes personal data only on the Controller's documented instructions, including as set out in the Terms of Service and this DPA, unless required to do otherwise by applicable law (in which case the Processor will inform the Controller where legally permitted).
6. Confidentiality
The Processor ensures that persons authorised to process the personal data are subject to an appropriate duty of confidentiality.
7. Technical and organisational measures
The Processor maintains measures including:
- HTTPS with TLS 1.3 for data in transit; HSTS with a one-year max-age
- API keys stored as SHA-256 hashes (never in plaintext)
- Passwords hashed with bcrypt (12 rounds)
- HMAC-SHA256 signatures on webhook payloads
- Append-oriented audit logging, with screening events recorded against source-list and algorithm versions
- SSRF and path-traversal protection
- Content-Security-Policy, X-Frame-Options: DENY, and X-Content-Type-Options: nosniff headers
- Zod input validation and CSV-injection prevention
- Per-key and per-IP rate limiting; fail-closed design
- CI secret scanning, dependency checks, and automated regression and security tests
Production access is limited to the founder; formal role-based access control is planned. Full-disk encryption at rest and off-site backup improvements are planned and not yet complete. A full and current description of implemented, contractual, and planned controls is maintained on the Security page.
8. Subprocessors
The Controller authorises the Processor to engage the subprocessors listed at /subprocessors, which is the canonical list. The Processor will give at least 30 days' notice of new subprocessors where contractually required, and the Controller may object on reasonable data-protection grounds.
9. International transfers
Primary processing occurs in the European Union. Where personal data is transferred outside the EU/EEA and a transfer mechanism is required, the parties will execute the European Commission's Standard Contractual Clauses (SCCs, Decision 2021/914) or an equivalent mechanism. Not all SCCs are already executed; where an executed mechanism exists, the Controller may request a copy.
10. Personal-data-breach assistance
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and will provide reasonable assistance and available information to help the Controller meet its own breach-notification obligations.
11. Data-subject-rights assistance
Taking into account the nature of the processing, the Processor will provide reasonable assistance to the Controller in responding to data-subject requests for access, rectification, erasure, restriction, portability, and objection.
12. Deletion or return on termination
On termination of the services, the Processor will, at the Controller's choice, delete or return the personal data, subject to any retention required by applicable law and to the retention arrangements described in the Privacy Policy.
13. Audit information
The Processor will make available to the Controller the information reasonably necessary to demonstrate compliance with this DPA, on reasonable prior notice and during normal business hours, subject to confidentiality.
14. Liability and order of precedence
This DPA forms part of, and is subject to, the Terms of Service, including their limitation-of-liability provisions. In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails to the extent of the conflict. All other terms of the main agreement remain in effect.
15. Contact
For questions about this DPA or to request an executable copy, contact hello@verifex.dev.