Data processing agreement
Draft last updated
Draft: not yet in force. This page is a draft and not yet in force. It describes how the KYCVerify service at kycverify.me processes data; the bracketed fields are still to be completed and reviewed with counsel. Questions: hello@kycverify.me.
1. Roles and scope
This agreement applies where [Organisation legal name] (the "processor") processes personal data on behalf of a customer (the "controller"; in India, the Data Fiduciary) to provide identity-verification services. It forms part of the terms of service.
2. Instructions
The processor processes personal data only on the controller's documented instructions. The workflows, retention period and other settings the controller configures in the console, and its API calls, are its instructions. The processor informs the controller if it believes an instruction infringes the law.
3. Confidentiality
The processor ensures that people authorised to process the personal data are bound by confidentiality and have access only as their role requires.
4. Security
The processor implements the technical and organisational measures in Annex 2 and keeps them appropriate to the risk, which includes biometric and national-identity data.
5. Sub-processors
The controller authorises the sub-processors in Annex 3. The processor gives [30] days' notice of any new sub-processor, during which the controller may object on reasonable grounds; it imposes equivalent obligations on each sub-processor and remains liable for them. No third-party identity-verification provider is used.
6. Data-subject requests
The processor assists the controller with requests from individuals, including by purging a session on request (DELETE /v1/sessions/{id} or the console), and forwards requests it receives directly to the controller without responding to them itself, unless instructed.
7. Personal data breaches
The processor notifies the controller without undue delay, and within [hours] hours, after becoming aware of a personal data breach affecting the controller's data, with the information the controller needs to meet its own notification duties, and updates it as more is known.
8. Assessments and audits
The processor assists with data protection impact assessments and prior consultations, and makes available the information necessary to demonstrate compliance. It allows audits by the controller or an auditor it mandates, on [notice period] notice, no more than [once a year] unless required by a regulator or after a breach.
9. Return and deletion
At the end of the services the processor, at the controller's choice, returns the controller's personal data in [format] or deletes it within [period], and deletes existing copies unless the law requires retention. Automatic deletion under the controller's retention setting continues during the term.
10. International transfers
Personal data is processed in [location]. It is transferred elsewhere only with [the controller's approval and an appropriate safeguard, such as standard contractual clauses], and never to a country restricted under applicable law.
Annex 1: Processing details
- Subject matter
- Identity verification of individuals invited by the controller
- Nature and purpose
- Collecting identity artefacts and images, extracting and checking data, matching faces, screening names against sanctions lists, detecting duplicates, supporting human review, delivering results
- Data subjects
- The controller's applicants, users, customers, employees or contractors
- Categories of data
- Identity, document, images, biometric data (face embeddings), Aadhaar (last four digits and UIDAI-signed demographics and photo; for a photographed Aadhaar card, the encrypted card image and a masked number), PAN, contact, technical data and results
- Special categories
- Biometric data processed to uniquely identify a person
- Frequency
- Continuous, for each session the controller creates
- Duration
- For the term, and for each session until the controller's retention period (default 90 days) or an earlier purge
Annex 2: Technical and organisational measures
- Uploaded files encrypted at rest with AES-256-GCM, a random 96-bit nonce per file and the file id bound as associated data, under a key held only by the operator.
- Full document and Aadhaar numbers never stored in clear fields; document numbers masked and kept with a keyed hash; Aadhaar fields limited to the last four digits. Document images (including a photographed Aadhaar card, which shows the full number) are stored encrypted until purge.
- Passwords hashed with Argon2id; API keys, console sessions, hosted-flow tokens and one-time codes stored as SHA-256 hashes.
- Role-based access (owner, admin, reviewer, viewer); every console query scoped to the controller's organisation and every API query to one app.
- Audit log of sign-ins, key changes, workflow changes, webhook changes, review decisions, purges, team changes and list refreshes, with actor, target and IP.
- Rate limits on sign-in and on the hosted flow; uploads limited to 10 MB and identified by content.
- Webhooks signed with HMAC-SHA256; deliveries refused to private and loopback addresses.
- Automatic purge of files, embeddings, fingerprints and identity data after the controller's retention period, checked every 10 minutes.
- [Organisational measures: TLS configuration, network restrictions, backups and restore tests, access reviews, staff training, incident response, vulnerability management.]
Annex 3: Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| [Hosting provider] | Servers and storage for the Service | [Country, region] |
| None: our own mail server | Delivering one-time email codes from no-reply@kycverify.me | The same servers as the Service |
| [Backup storage, if separate] | Encrypted backups | [Country, region] |