Data Processing Agreement (DPA)

Last updated: June 17, 2026

This Data Processing Agreement ("DPA") forms a legally binding part of the SaaS Subscription Agreement or Terms of Service between KYCProtect ("Processor") and the entity registering for an account ("Client" or "Data Controller"). This DPA governs the processing of personal data in connection with providing mobile-first anti-money laundering (AML), customer due diligence (CDD), and identity verification technology infrastructure.

1. Definitions and Interpretation

  • "Applicable Law" means the General Data Protection Regulation (EU) 2016/679 ("GDPR") and any supplementary data protection laws applicable within the European Economic Area (EEA).
  • "Client Personal Data" means any personal data relating to the customers, buyers, or ultimate beneficial owners (UBOs) of the Client that is uploaded, transmitted, or processed via the KYCProtect platform.
  • "Biometric Data" means personal data resulting from specific technical processing relating to the physical, physiological or behavioral characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images processed through facial-matching technology under Article 9.
  • "Sub-processor" means any third-party data processor engaged by KYCProtect to perform specific processing activities on behalf of the Client.

2. Scope, Roles, and Responsibilities

The parties acknowledge that for all Client Personal Data handled during the execution of the services, the Client acts as the Data Controller and KYCProtect acts as the Data Processor operating under strict Article 28 parameters.

KYCProtect shall process Client Personal Data exclusively upon the documented, written instructions of the Client, including instructions regarding data transfers, unless required to do otherwise by European Union or Member State law to which the Processor is subject.

3. Controller Warranties and Liability Shift

The Client expressly represents, warrants, and covenants to KYCProtect that:

  • All personal data provided to the platform has been collected, stored, and transferred in strict compliance with Applicable Law.
  • The Client has established a valid, verifiable lawful basis (such as legal obligation under local AML directives or explicit consent under Article 6) for all verification requests triggered through the platform.
  • The Client shall ensure that appropriate fair processing information and layered notices are visible to end-collectors in accordance with our Privacy Policy, including the provision of a clear, non-biometric alternative verification route if requested by an individual.

KYCProtect maintains no administrative obligation to monitor or audit the lawfulness or validity of a verification request initiated by the Client. The Client shall fully indemnify and hold harmless KYCProtect against any administrative fines, regulatory penalties, or third-party civil judgments arising directly or indirectly from the Client's failure to establish a valid lawful processing baseline.

4. Details of Processing Activities

Purpose / Core ActivityCategories of Personal DataLawful Basis (Controller Reliance)
AML Identity Verification (Manual Route)Full name, date of birth, document numbers, scanned copies of government-issued IDs, passports, utility bills.Legal Obligation under applicable national Anti-Money Laundering Regulations pursuant to Article 6.
Automated Biometric Identity MatchingFacial mapping vectors, video selfies, metadata confirmations returned via verification webhooks.Explicit, voluntary, unbundled consent gathered at point of capture pursuant to Article 9 without prejudice to restrictions on automated decision-making under Article 22.
Sanctions & PEP Screening PipelinesClient names cross-referenced against global political, financial, criminal, and institutional watchlists.Legal Obligation under transnational compliance mandates pursuant to Article 6.
Immutable Compliance AuditingRecipient email records, timestamp logs, status flags, event histories shown in user dashboards.Legitimate corporate interest in maintaining an unalterable audit trail under Article 6.

5. Authorized Sub-processors

The Client grants a general written authorization to KYCProtect to engage sub-processors to execute specific infrastructure operations. The primary authorized sub-processors currently utilized by the platform include:

  • Didit: Identity Verification, Biometric Facial Scanning, and Cryptographic Security Webhooks. (Data hosted within the European Union).
  • Primary Cloud Infrastructure: High-availability secure server environments hosted natively and exclusively inside the European Economic Area (EEA).

KYCProtect shall maintain an up-to-date repository of all sub-processors on its public website. KYCProtect warrants that any sub-processor engaged shall be bound by written contractual obligations providing materially equivalent technical and organizational safeguards as established in this DPA.

6. Data Residency and International Transfers

KYCProtect explicitly guarantees that all primary client databases, active system nodes, transaction logs, and fallback backup infrastructure are located exclusively within the European Union (EEA). No client personal data processed on behalf of the Client shall be transferred, stored, or accessed outside the EEA without the prior express written instruction of the Client and the implementation of approved suitable safeguards as referred to in Article 46, Article 47, or the specific derogations of Article 49.

7. Technical and Organizational Security Measures

KYCProtect shall implement and maintain enterprise-grade security protections in accordance with Article 32 GDPR, including but not limited to:

  • Full cryptographic encryption of data in transit via HTTPS/TLS-encrypted APIs.
  • Advanced AES-256 encryption applied to all records sitting at rest within production environments.
  • Strict policy of least privilege governing access controls, backed by mandatory multi-factor user authentication.
  • Immutable, unalterable frontend and backend user event log auditing to track system operations transparently.

8. Data Retention, Deletion, and Breaches

  • Statutory Retention: KYCProtect shall securely archive verification histories and identity compliance files for the mandatory statutory duration required under applicable AML regulations (typically five to seven years following the conclusion of a transactional relationship), after which data will be automatically purged or anonymized via automated system scripts.
  • Breach Notification: In the event of a verified Personal Data Breach affecting system infrastructure, KYCProtect shall notify the Client without undue delay and cooperate fully to provide necessary details to assist the Client with mandatory regulatory reporting to local Supervisory Authorities.

9. Governing Law and Jurisdiction

This DPA and any dispute arising from its execution shall be governed by, and construed in accordance with, the laws of the European Union Member State where the primary corporate entity of KYCProtect is registered, subject to the exclusive jurisdiction of its local courts.

End of Data Processing Agreement