Legal

Data Processing Agreement

Last updated: February 1, 2026

1. Scope and Purpose

This Data Processing Agreement ("DPA") forms part of the agreement between AuthProof, Inc. ("Processor") and the customer ("Controller") and governs the processing of personal data by the Processor on behalf of the Controller.

The Processor processes personal data solely for the purpose of providing content verification services as described in the Terms of Service. No personal data is used for any purpose other than fulfilling the Controller's verification requests.

2. Types of Personal Data Processed

The personal data processed may include: account holder names, email addresses, organizational information, IP addresses, and any personal data contained within documents submitted for verification. Document content is processed in-memory only and is not retained after analysis.

3. Processing Instructions

The Processor shall process personal data only in accordance with the Controller's documented instructions, unless required by applicable law. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes applicable data protection law.

4. Security Measures

The Processor implements appropriate technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction. Such measures may include encryption of personal data at rest using industry-standard encryption technologies, including AES-256 where applicable, access controls, secure system configurations, monitoring of systems and services, personnel access restrictions, and other safeguards appropriate to the nature of the personal data processed and the risks involved.

The Processor regularly reviews and updates its security practices to maintain the confidentiality, integrity, and availability of personal data processed on behalf of the Controller.

5. Sub-processors

The Processor may engage sub-processors to assist in providing the services. The current list of sub-processors is available upon request. The Processor shall notify the Controller of any intended changes to sub-processors, giving the Controller the opportunity to object. All sub-processors are bound by data processing obligations no less protective than those in this DPA.

6. Data Subject Rights

The Processor shall assist the Controller in responding to requests from data subjects exercising their rights under applicable data protection law, including rights of access, rectification, erasure, restriction, portability, and objection. The Processor shall promptly notify the Controller of any data subject request received directly.

7. Data Breach Notification

The Processor shall notify the Controller without undue delay, and in any event within 48 hours, upon becoming aware of a personal data breach. The notification shall include the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken to address the breach.

8. Data Transfers

Where personal data is transferred or processed across jurisdictions, the Processor shall take reasonable steps to ensure that appropriate safeguards are in place and that such transfers are conducted in accordance with applicable data protection laws.

9. Audit Rights

The Controller may request information reasonably necessary to verify the Processor's compliance with this DPA. The Processor shall make available relevant information regarding its data processing practices, subject to reasonable confidentiality, security, and operational requirements.

10. Term and Termination

This DPA shall remain in effect for the duration of the service agreement. Upon termination, the Processor shall, at the Controller's choice, return or delete all personal data processed on behalf of the Controller, unless retention is required by applicable law.

11. Contact

For questions regarding this DPA or to request execution of this agreement, contact dpa@authproof.ai.

Need a signed DPA?

Enterprise customers can request a pre-signed DPA or submit their own for review.

Request DPA