Skip to content

Data processing agreement

Draft last updated

Draft: not yet in force. This page is a draft and not yet in force. It describes how the KYCVerify service at kycverify.me processes data; the bracketed fields are still to be completed and reviewed with counsel. Questions: hello@kycverify.me.

1. Roles and scope

This agreement applies where [Organisation legal name] (the "processor") processes personal data on behalf of a customer (the "controller"; in India, the Data Fiduciary) to provide identity-verification services. It forms part of the terms of service.

2. Instructions

The processor processes personal data only on the controller's documented instructions. The workflows, retention period and other settings the controller configures in the console, and its API calls, are its instructions. The processor informs the controller if it believes an instruction infringes the law.

3. Confidentiality

The processor ensures that people authorised to process the personal data are bound by confidentiality and have access only as their role requires.

4. Security

The processor implements the technical and organisational measures in Annex 2 and keeps them appropriate to the risk, which includes biometric and national-identity data.

5. Sub-processors

The controller authorises the sub-processors in Annex 3. The processor gives [30] days' notice of any new sub-processor, during which the controller may object on reasonable grounds; it imposes equivalent obligations on each sub-processor and remains liable for them. No third-party identity-verification provider is used.

6. Data-subject requests

The processor assists the controller with requests from individuals, including by purging a session on request (DELETE /v1/sessions/{id} or the console), and forwards requests it receives directly to the controller without responding to them itself, unless instructed.

7. Personal data breaches

The processor notifies the controller without undue delay, and within [hours] hours, after becoming aware of a personal data breach affecting the controller's data, with the information the controller needs to meet its own notification duties, and updates it as more is known.

8. Assessments and audits

The processor assists with data protection impact assessments and prior consultations, and makes available the information necessary to demonstrate compliance. It allows audits by the controller or an auditor it mandates, on [notice period] notice, no more than [once a year] unless required by a regulator or after a breach.

9. Return and deletion

At the end of the services the processor, at the controller's choice, returns the controller's personal data in [format] or deletes it within [period], and deletes existing copies unless the law requires retention. Automatic deletion under the controller's retention setting continues during the term.

10. International transfers

Personal data is processed in [location]. It is transferred elsewhere only with [the controller's approval and an appropriate safeguard, such as standard contractual clauses], and never to a country restricted under applicable law.

Annex 1: Processing details

Subject matter
Identity verification of individuals invited by the controller
Nature and purpose
Collecting identity artefacts and images, extracting and checking data, matching faces, screening names against sanctions lists, detecting duplicates, supporting human review, delivering results
Data subjects
The controller's applicants, users, customers, employees or contractors
Categories of data
Identity, document, images, biometric data (face embeddings), Aadhaar (last four digits and UIDAI-signed demographics and photo; for a photographed Aadhaar card, the encrypted card image and a masked number), PAN, contact, technical data and results
Special categories
Biometric data processed to uniquely identify a person
Frequency
Continuous, for each session the controller creates
Duration
For the term, and for each session until the controller's retention period (default 90 days) or an earlier purge

Annex 2: Technical and organisational measures

  • Uploaded files encrypted at rest with AES-256-GCM, a random 96-bit nonce per file and the file id bound as associated data, under a key held only by the operator.
  • Full document and Aadhaar numbers never stored in clear fields; document numbers masked and kept with a keyed hash; Aadhaar fields limited to the last four digits. Document images (including a photographed Aadhaar card, which shows the full number) are stored encrypted until purge.
  • Passwords hashed with Argon2id; API keys, console sessions, hosted-flow tokens and one-time codes stored as SHA-256 hashes.
  • Role-based access (owner, admin, reviewer, viewer); every console query scoped to the controller's organisation and every API query to one app.
  • Audit log of sign-ins, key changes, workflow changes, webhook changes, review decisions, purges, team changes and list refreshes, with actor, target and IP.
  • Rate limits on sign-in and on the hosted flow; uploads limited to 10 MB and identified by content.
  • Webhooks signed with HMAC-SHA256; deliveries refused to private and loopback addresses.
  • Automatic purge of files, embeddings, fingerprints and identity data after the controller's retention period, checked every 10 minutes.
  • [Organisational measures: TLS configuration, network restrictions, backups and restore tests, access reviews, staff training, incident response, vulnerability management.]

Annex 3: Sub-processors

Sub-processorPurposeLocation
[Hosting provider]Servers and storage for the Service[Country, region]
None: our own mail serverDelivering one-time email codes from no-reply@kycverify.meThe same servers as the Service
[Backup storage, if separate]Encrypted backups[Country, region]