verifa
Documents
Documents
Terms of Service Privacy Policy DPA Acceptable Use Biometric Policy Cookie Policy Law Enforcement

Data Processing Agreement

Last updated: March 30, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Verifa ("Processor," "we," "us") and the organization using Verifa's services ("Controller," "Customer," "you") for the provision of identity verification services (the "Services"), as described in the Terms of Service.

This DPA is entered into to ensure compliance with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, the Swiss Federal Act on Data Protection ("FADP"), and other applicable data protection legislation.

1. Definitions

Capitalized terms not defined in this DPA have the meaning given to them in the Terms of Service. The following terms have the meanings set out below:

  • "Applicable Data Protection Law" means all laws and regulations relating to the processing of personal data applicable to the processing described in this DPA, including GDPR, UK GDPR, the Swiss FADP, CCPA/CPRA, and any successor legislation.
  • "Controller" means the Customer, the entity that determines the purposes and means of processing personal data.
  • "Data Subject" means the identified or identifiable natural person to whom personal data relates, including verification applicants.
  • "Personal Data" means any information relating to a Data Subject that is processed by the Processor on behalf of the Controller in connection with the Services.
  • "Processing" means any operation performed on personal data, including collection, recording, storage, retrieval, use, disclosure, erasure, or destruction.
  • "Processor" means Verifa, the entity that processes personal data on behalf of the Controller.
  • "Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
  • "Standard Contractual Clauses" ("SCCs") means the contractual clauses approved by the European Commission for the transfer of personal data to third countries, as set out in Commission Implementing Decision (EU) 2021/914.
  • "UK International Data Transfer Addendum" ("UK IDTA") means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner's Office under Section 119A of the UK Data Protection Act 2018.
  • "Subprocessor" means any third party engaged by the Processor to process personal data on behalf of the Controller.

2. Scope and Roles

The Customer acts as the Controller and Verifa acts as the Processor with respect to personal data processed in connection with the Services. The details of the processing are described in Annex 1 of this DPA.

This DPA applies to all personal data processed by Verifa on behalf of the Customer, regardless of the country from which the personal data originates.

3. Obligations of the Processor

Verifa shall:

  1. Process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country, unless required to do so by applicable law — in which case Verifa shall inform the Controller of that legal requirement before processing, unless prohibited by law.
  2. Ensure that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  3. Implement and maintain appropriate technical and organizational security measures as described in Annex 2, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.
  4. Not engage any Subprocessor without prior written authorization from the Controller, subject to Section 6 of this DPA.
  5. Assist the Controller, taking into account the nature of processing, by appropriate technical and organizational measures, insofar as possible, in fulfilling the Controller's obligation to respond to Data Subject rights requests.
  6. Assist the Controller in ensuring compliance with obligations related to security of processing, notification of Security Incidents, data protection impact assessments, and prior consultation with supervisory authorities.
  7. At the Controller's choice, delete or return all personal data to the Controller after the end of the provision of Services, and delete existing copies unless applicable law requires storage of the personal data.
  8. Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
  9. Immediately inform the Controller if, in the Processor's opinion, an instruction from the Controller infringes applicable data protection law.

4. Obligations of the Controller

The Controller shall:

  1. Ensure that it has a lawful basis for processing personal data and for instructing the Processor to process personal data on its behalf.
  2. Provide all necessary notices to, and obtain all necessary consents from, Data Subjects as required by applicable data protection law — including biometric data consent where required by BIPA or similar legislation.
  3. Ensure that its instructions to the Processor comply with applicable data protection law.
  4. Be responsible for the accuracy, quality, and legality of personal data provided to the Processor.

5. Security Incidents

Verifa shall notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a Security Incident affecting the Controller's personal data. The notification shall include:

  • A description of the nature of the Security Incident, including the categories and approximate number of Data Subjects and records concerned
  • The name and contact details of the point of contact from whom more information can be obtained
  • A description of the likely consequences of the Security Incident
  • A description of the measures taken or proposed to address the Security Incident, including measures to mitigate its possible adverse effects

Verifa shall cooperate with the Controller and take commercially reasonable steps to assist in the investigation, mitigation, and remediation of any Security Incident.

6. Subprocessors

The Controller provides general written authorization for Verifa to engage Subprocessors to assist in providing the Services. The current list of Subprocessors is set out in Annex 3 and is also available at /subprocessors.

When engaging a new Subprocessor, Verifa shall:

  1. Update the Subprocessor list at least 30 days before the new Subprocessor begins processing personal data.
  2. Notify the Controller of the intended change by email (to the address associated with the Customer's account).
  3. Impose data protection obligations on the Subprocessor that are no less protective than those set out in this DPA, by way of a written contract.
  4. Remain fully liable to the Controller for the performance of the Subprocessor's obligations.

If the Controller objects to a new Subprocessor on reasonable data protection grounds, the parties shall discuss the concern in good faith. If the concern cannot be resolved within 30 days, the Controller may terminate the affected Services without penalty.

7. International Data Transfers

Verifa shall not transfer personal data outside of the country in which the Controller is established unless:

  1. The transfer is to a country recognized as providing an adequate level of data protection by the European Commission, the UK Secretary of State, or the Swiss Federal Data Protection and Information Commissioner (as applicable); or
  2. Appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, the UK International Data Transfer Addendum (UK IDTA), or other transfer mechanisms recognized under the Swiss FADP, and the Data Subject has enforceable rights and effective legal remedies.

Where SCCs are required, the parties agree that the SCCs set out in Commission Implementing Decision (EU) 2021/914 (Module Two: Controller to Processor) are incorporated into this DPA by reference. For transfers subject to UK data protection law, the UK International Data Transfer Addendum (IDTA) to the EU SCCs, as issued by the UK Information Commissioner's Office, shall apply. For transfers subject to the Swiss FADP, the SCCs shall apply with the modifications necessary to comply with Swiss data protection requirements.

Transfer Impact Assessments

In accordance with the guidance of the European Data Protection Board and the requirements established by the Court of Justice of the European Union (Schrems II, Case C-311/18), Verifa conducts Transfer Impact Assessments (TIAs) for international data transfers to evaluate whether the laws and practices of the destination country provide an adequate level of protection for personal data. Verifa shall make the results of relevant TIAs available to the Controller upon request and shall implement supplementary measures where necessary to ensure the continued protection of transferred personal data.

8. Data Subject Rights

Verifa shall promptly notify the Controller if it receives a request from a Data Subject to exercise their rights under applicable data protection law (access, rectification, erasure, restriction, portability, or objection). Verifa shall not respond to such requests directly unless instructed to do so by the Controller or required by applicable law.

Verifa shall assist the Controller by appropriate technical and organizational measures in fulfilling Data Subject rights requests, including providing the Controller with the ability to delete verification data via the API (DELETE /api/v1/sessions/{id}/data).

9. Data Protection Impact Assessments

Verifa shall provide reasonable assistance to the Controller with any data protection impact assessment and any prior consultation with a supervisory authority that is required under Article 35 or 36 of the GDPR, taking into account the nature of processing and the information available to Verifa.

10. Audit Rights

Verifa shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits conducted by the Controller or an independent auditor mandated by the Controller. Audits shall be subject to the following conditions:

  1. The Controller shall provide at least 30 days' written notice of any audit request.
  2. Audits shall be conducted during normal business hours and shall not unreasonably disrupt Verifa's operations.
  3. The Controller shall bear the costs of any audit, unless the audit reveals a material breach of this DPA by Verifa.
  4. Audit findings shall be treated as confidential information of Verifa.
  5. Where Verifa holds SOC 2 Type II or equivalent certifications, these may be provided in lieu of an on-site audit at Verifa's discretion. Verifa is currently pursuing SOC 2 Type II certification and will make the report available to Customers upon completion.

11. Data Retention and Deletion

Upon termination or expiration of the Services, Verifa shall, at the Controller's election:

  1. Return all personal data to the Controller in a commonly used, machine-readable format; or
  2. Delete all personal data (including all copies) within 30 days, and certify such deletion in writing upon request.

If the Controller does not make an election within 30 days of termination, Verifa shall delete all personal data. Verifa may retain personal data to the extent required by applicable law, in which case Verifa shall isolate and protect such data from further processing except to the extent required by law.

12. Liability

Each party's liability arising out of or related to this DPA shall be subject to the limitations of liability set out in the Terms of Service. This DPA does not limit either party's liability with respect to any breach of applicable data protection law.

13. Term

This DPA shall remain in effect for the duration of the Controller's use of the Services, and shall automatically terminate upon termination or expiration of the Services agreement, subject to the data retention and deletion obligations in Section 11.

14. Governing Law

This DPA shall be governed by and construed in accordance with the laws that govern the Terms of Service, except where applicable data protection law requires otherwise.

15. Contact

Verifa — Data Protection

Email: privacy@withverifa.com

Annex 1 — Details of Processing

Subject Matter and Duration

Verifa processes personal data on behalf of the Controller for the purpose of providing automated identity verification services. Processing continues for the duration of the Services agreement plus the applicable data retention period.

Nature and Purpose of Processing

Processing includes: collection, storage, retrieval, analysis, comparison, and deletion of personal data for the purpose of verifying the identity of Data Subjects (verification applicants) as instructed by the Controller.

Categories of Data Subjects

  • Individuals undergoing identity verification ("Applicants") as directed by the Controller
  • Controller's authorized users of the Verifa dashboard (name, email, role)

Types of Personal Data

  • Identity document data: photographs of government-issued ID (front and back), extracted data (name, date of birth, address, document number, expiration date)
  • Biometric data: facial geometry derived from selfie photographs (used solely for face matching against ID photo)
  • Selfie photograph: photograph of the Applicant's face
  • Contact information: email address and/or phone number (when collected during verification)
  • Device and network data: IP address, browser type, device type
  • Consent records: timestamp, IP address, and content of consent given
  • Verification results: pass/fail determination, confidence scores, risk signals

Sensitive Data

Processing includes biometric data (facial geometry) classified as special category data under GDPR Article 9 and sensitive personal information under CCPA/CPRA. Processing is performed with the Data Subject's explicit consent and solely for identity verification purposes.

Retention

Personal data is retained for the retention period configured by the Controller (default: 90 days). After expiry, all personal data — including document images, selfie photographs, biometric data, and encrypted PII — is permanently and irreversibly destroyed. Non-identifying session metadata (status, timestamps) may be retained for audit purposes.

Annex 2 — Technical and Organizational Security Measures

Encryption

  • In transit: all data transmitted over HTTPS/TLS 1.2+
  • At rest: all personal data encrypted using AES-256-GCM before storage; encryption keys managed via dedicated secrets management (HashiCorp Vault or equivalent)
  • Key management: unique encryption contexts per record; key rotation supported

Access Controls

  • Role-based access control (RBAC) for all dashboard and admin panel users
  • API authentication via scoped API keys with per-key permission sets
  • No human operator access to raw biometric data or decrypted PII during normal operations
  • Multi-factor authentication support for administrative access

Data Isolation

  • Logical data isolation per Customer organization
  • Separate sandbox and live environments with independent data stores
  • Biometric data stored separately from other personal information

Infrastructure Security

  • Application hosted on hardened infrastructure with network segmentation
  • Regular security patching and vulnerability scanning
  • Encrypted backups with access logging
  • DDoS protection and rate limiting

Monitoring and Audit Logging

  • Comprehensive audit logging of all data access and administrative actions
  • Audit logs retained for 7 years
  • Immutable audit trail — logs cannot be modified or deleted

Certifications and Compliance

  • Verifa is actively pursuing SOC 2 Type II certification. Upon completion, the SOC 2 Type II report will be made available to Customers under NDA upon request.
  • Security controls are designed and implemented in alignment with SOC 2 Trust Services Criteria (Security, Availability, Confidentiality) and industry best practices

No Third-Party Processing for Verification

  • All face matching, document OCR, and AI/ML analysis performed in-house — no third-party AI services receive personal data
  • Subprocessors are limited to infrastructure, communications, screening, and billing (see Annex 3)

Incident Response

  • Documented incident response procedure with defined escalation paths
  • Security incident notification within 72 hours as per Section 5

Annex 3 — Subprocessors

The following Subprocessors are authorized to process personal data on behalf of the Controller as part of the Services. This list is also maintained at /subprocessors.

Subprocessor Purpose Data Processed Location
Amazon Web Services (AWS) Cloud infrastructure, data storage, and processing All personal data (encrypted at rest and in transit) United States
Twilio SMS delivery (OTP verification codes) and phone carrier lookup Phone number United States
SendGrid (Twilio) Transactional email delivery (OTP codes, notifications) Email address United States
Stripe Payment processing and subscription billing Customer billing information (not applicant data) United States
ComplyAdvantage AML/PEP screening and monitoring Name, date of birth (of screened individuals) United States / United Kingdom

Important: With the exception of AWS (which hosts the encrypted infrastructure), no Subprocessor receives identity document images, selfie photographs, biometric data, or verification results. All identity verification processing (face matching, document OCR, risk analysis) is performed entirely within Verifa's own infrastructure.