Data Processing Agreement (DPA)

Version 2026-10-03Effective from 2026-10-03

The operator details (name, registration number, address, contact) will be added to this document once approved. The terms apply as set out in this version.

Version of 3 October 2026. Forms part of the verkyc Customer Terms of Service.

1. Roles of the parties

1.1. The Customer is the controller (operator) of applicants' personal data: it determines the purposes and means of the verification. [to be confirmed] (the "Processor") processes applicants' personal data on behalf of the Customer.

1.2. This agreement is an instruction to process personal data within the meaning of the law of the Customer's country (including Article 6(3) of Federal Law No. 152-FZ of 27 July 2006 "On Personal Data" for Customers from the Russian Federation) and a processor contract within the meaning of Article 28 of Regulation (EU) 2016/679 (GDPR) where it applies.

1.3. For its own purposes (security of the Service, abuse prevention, audit log, billing of the Customer and its own legal obligations) the Processor acts as an independent controller; such data is described in the Privacy Policy.

2. Subject matter, purposes and duration

2.1. Subject matter: identity verification of applicants and verification of organisations at the Customer's request in the Service.

2.2. Purposes: the purposes stated by the Customer in the organisation's legal profile and in the case (customer onboarding, business customer onboarding, periodic review, ongoing monitoring).

2.3. Duration: the term of the Customer Terms and the retention period of case data under the Customer's retention profile (section 9).

3. Categories of data subjects and data

3.1. Data subjects: applicants who are natural persons; representatives, directors, shareholders and beneficial owners of verified organisations; Customer employees as console users.

3.2. Data:

  • identity document data: surname, given names, patronymic, date and place of birth, sex, nationality, document number and expiry, issuing authority, machine readable zone;
  • document images and capture video frames;
  • document chip data: data groups, signatures and certificates;
  • biometric data: face image, its biometric template and the comparison result, only if the Customer enabled face comparison and it is permitted for the country and scenario;
  • data about the organisation, its directors, shareholders and beneficial owners;
  • results of screening against sanctions lists, lists of politically exposed persons and adverse media;
  • technical session data: IP address, device and browser data, capture events.

4. Customer instructions

4.1. The Processor processes data only on documented instructions of the Customer. Instructions are the Customer Terms and this agreement, the organisation's legal profile, the verification policy, the retention profile and the Customer's API and console requests.

4.2. If, in the Processor's opinion, an instruction infringes applicable data protection law, the Processor informs the Customer and may suspend it until it is confirmed or amended.

4.3. The Processor does not use applicants' data to train or improve models. Such use is permitted only on a separate written instruction of the Customer, where the Customer has a legal basis for that purpose and, where required, a separate consent of the applicant; it is switched off by default.

5. Confidentiality and personnel

5.1. Only Processor staff who need access to perform this agreement and who are bound by confidentiality obligations get access to data. Support access to case data is granted at the Customer's request, for a limited time and with a log entry.

6. Security measures

6.1. The Processor applies the measures described in the "Security measures" annex, including:

  • encryption of personal data at rest with keys dedicated to the organisation and the applicant, key management in an external key store, and encryption in transit (TLS);
  • separation of organisations' data at database level;
  • a mandatory second factor for Customer employees and Processor staff;
  • parsing of untrusted files in an isolated executor and malware scanning of uploads;
  • a log of access to materials with the reason for disclosure;
  • daily encrypted backups made on the node, weekly restore tests, monitoring and alerting;
  • vulnerability management: dependency scanning and static analysis on every release.

7. Sub-processors

7.1. The Customer gives a general authorisation to engage the sub-processors listed below. The Processor notifies the Customer in the console at least 30 days before adding or replacing a sub-processor. Within that period the Customer may object on reasonable grounds; if the parties do not agree, the Customer may terminate the Customer Terms without penalty.

Sub-processorPurposeLocation
Hetzner Online GmbHservers, object storage, backup storageGermany
Climailsdelivery of service e-mails (links to applicants and employees)Germany

7.2. The payment provider NerezPay processes only data about the Customer's invoice payments; applicants' data is not passed to it and it is not a sub-processor under this agreement.

7.3. Verification sources (state registers, lists, the provider of data on politically exposed persons) receive a request only to the extent needed for the check and only when the Customer has enabled that check. The list of sources, their countries and the data passed is shown in the console for each country under "Legal applicability". Open organisation registers (for example GLEIF) receive only the identifier or name of the organisation.

7.4. The Processor concludes contracts with sub-processors with data protection obligations no less protective than this agreement and is liable to the Customer for their performance.

8. Location and cross-border transfer

8.1. Data is stored and processed in the eu-de-1 region (Germany), including backups, logs and metrics. Germany is a member state of the European Union and a party to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108).

8.2. For a Customer from another country, processing of data in Germany is a cross-border transfer made by the Customer. The Customer complies with the requirements of its law for such a transfer: it checks the ground for the transfer, notifies the supervisory authority where required and keeps the primary records about citizens of its country in that country where its law requires it. The Service gives the Customer an export of case data for such storage.

8.3. Remote access to data is possible from the countries the Customer states for its employees in the legal profile and, for Processor support staff, from Germany.

9. Retention, return and deletion

9.1. Retention periods of materials, results and logs are set by the Customer's retention profile within the bounds the Service sets for the country. When a period ends, data is deleted; materials encrypted with the applicant's key become unreadable when the key is destroyed.

9.2. Deleted data disappears from backups no later than 35 days after deletion.

9.3. On termination of the Customer Terms the Processor, at the Customer's choice, returns case data in a machine-readable format within 30 days and deletes it no later than 30 days after the return or after the Customer declines the return. The Processor keeps longer only data it must retain by law and informs the Customer of it.

10. Assistance to the Customer

10.1. The Processor assists the Customer:

  • in answering applicants' requests: a request submitted through the verification page is passed to the Customer's console within 1 working day; the Service provides export, correction and deletion of case data;
  • in data protection impact assessments and consultations with the supervisory authority, by providing information on the Service and its security measures;
  • in meeting security and incident notification obligations.

11. Incidents

11.1. The Processor notifies the Customer of a security incident affecting the Customer's personal data without undue delay and no later than 12 hours after becoming aware of it. The notice states the nature of the incident, categories and approximate number of data subjects and records concerned, likely consequences, measures taken and proposed, and a contact point. Information not available at the time of notice is provided as it becomes available.

11.2. The 12-hour period allows the Customer to meet its own deadlines for notifying the supervisory authority, including 24 hours under Article 21(3.1) of Federal Law No. 152-FZ and 72 hours under Article 33 GDPR.

12. Audits

12.1. The Processor makes available to the Customer the information needed to demonstrate compliance with this agreement: a description of security measures, security test reports and the log of access to the Customer's data. Once a year the Customer may carry out an audit itself or through an independent auditor bound by confidentiality, with 30 days' notice; an extraordinary audit is possible after an incident.

13. Liability and term

13.1. Liability of the parties is governed by the Customer Terms. The limitation of liability does not apply to a breach of this agreement to the extent applicable law does not allow such a limitation.

13.2. This agreement remains in force for as long as the Processor processes the Customer's personal data.