This is a draft available for contractual review.
This Data Processing Addendum ("DPA") is a draft made available on request for B2B customers. It is not automatically incorporated into any agreement and takes effect only when executed by both parties as an addendum to the Terms of Service. To request an executable copy, contact [email protected].
1. Parties
This DPA is entered into between the customer (the "Controller") and Verifex (the "Processor"), and supplements the Terms of Service.
2. Subject matter, duration, nature, and purpose
The Processor processes personal data on behalf of the Controller for the purpose of providing sanctions, PEP, and KYB screening services via Verifex. The nature of processing includes name normalisation, fuzzy and phonetic matching, entity resolution, and returning match results and related evidence; ongoing monitoring and alerts; adverse-media news retrieval and classification; company registry lookups for KYB; and, where the Controller uses Verifex Shield, transaction and fraud risk scoring. Processing begins on the Controller's first use of the relevant features and continues for the duration of the service agreement, plus any applicable retention period described in this DPA and the Privacy Policy.
3. Categories of personal data
- Names of screened individuals or entities
- Dates of birth, nationalities, or countries of residence, where provided
- Entity types (person, company, vessel)
- Company officers, persons with significant control (PSCs), and ultimate beneficial owners (UBOs), for KYB
- Screening results, confidence scores, and risk assessments
- Request metadata (timestamps, IP addresses, API-key identifiers)
- Identity document numbers and aliases, where provided
- Names placed under ongoing monitoring, and the alerts sent about them
- News headlines, website names and dates found about a screened name (adverse media)
- For Verifex Shield: names and dates of birth of the Controller's customers, account balances, payment amounts and events, device information, and hashed or masked bank account numbers, card numbers and IP addresses
4. Categories of data subjects
- The Controller's customers and prospective customers
- Transaction counterparties
- Officers, PSCs, and beneficial owners of screened entities
- Any individuals or entities the Controller submits for screening
- For Verifex Shield: the Controller's account holders and cardholders, and the senders and recipients of their payments
5. Controller instructions
The Processor processes personal data only on the Controller's documented instructions, including as set out in the Terms of Service and this DPA, unless required to do otherwise by applicable law (in which case the Processor will inform the Controller where legally permitted). The Processor will immediately inform the Controller if, in its opinion, an instruction infringes applicable data-protection law.
6. Confidentiality
The Processor ensures that persons authorised to process the personal data are subject to an appropriate duty of confidentiality.
7. Technical and organisational measures
The Processor maintains measures including:
- HTTPS with TLS 1.2 or 1.3 for data in transit; HSTS with a one-year max-age
- API keys stored as SHA-256 hashes (never in plaintext)
- Passwords hashed with bcrypt (12 rounds)
- HMAC-SHA256 signatures on webhook payloads
- Append-oriented audit logging, with screening events recorded against source-list and algorithm versions
- SSRF and path-traversal protection
- Content-Security-Policy, X-Frame-Options: DENY, and X-Content-Type-Options: nosniff headers
- Zod input validation and CSV-injection prevention
- Per-key and per-IP rate limiting
- CI secret scanning, dependency checks, and automated regression and security tests
Application-level privileged administration uses scoped permissions, expiring ALLOW/DENY grants, step-up, maker-checker controls, audit events and durable mutation receipts. These controls govern the application control plane; they do not describe root, cloud-provider or other infrastructure access. This public DPA does not characterize those separate infrastructure-access arrangements. Database backups are encrypted and stored off-site. Full-disk encryption at rest is planned and not yet complete. A full and current description of implemented, contractual and planned controls is maintained on the Security page.
8. Subprocessors
The Controller authorises the Processor to engage the subprocessors listed at /subprocessors, which is the canonical list. The Processor will inform the Controller of any intended addition or replacement of a subprocessor at least 30 days in advance, and the Controller may object on reasonable data-protection grounds. The Processor imposes on each subprocessor data-protection obligations equivalent to those in this DPA, and remains responsible to the Controller for its subprocessors' performance of them.
9. International transfers
Primary processing occurs in the European Union. Where personal data is transferred outside the EU/EEA or the UK and a transfer mechanism is required, the parties will execute the European Commission's Standard Contractual Clauses (SCCs, Decision 2021/914), with the UK Addendum for UK data, or an equivalent mechanism. Not all SCCs are already executed; where an executed mechanism exists, the Controller may request a copy.
10. Personal-data-breach assistance
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and will provide reasonable assistance and available information to help the Controller meet its own breach-notification obligations.
11. Data-subject-rights assistance
Taking into account the nature of the processing, the Processor will provide reasonable assistance to the Controller in responding to data-subject requests for access, rectification, erasure, restriction, portability, and objection. Taking into account the information available to it, the Processor will also provide reasonable assistance with the Controller's obligations on security of processing, personal-data breaches, data-protection impact assessments and prior consultation with a supervisory authority (Articles 32 to 36 GDPR).
12. Deletion or return on termination
On termination of the services, the Processor will, at the Controller's choice, delete or return the personal data, subject to any retention required by applicable law and to the retention arrangements described in the Privacy Policy.
13. Audit information
The Processor will make available to the Controller the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, by the Controller or an independent auditor it mandates. Audits take place on reasonable prior notice, during normal business hours, subject to confidentiality, and no more than once a year unless a supervisory authority requires it or a personal-data breach has occurred.
14. Liability and order of precedence
This DPA forms part of, and is subject to, the Terms of Service, including their limitation-of-liability provisions. In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails to the extent of the conflict. All other terms of the main agreement remain in effect.
15. Contact
For questions about this DPA or to request an executable copy, contact [email protected].