Data Processing Agreement

Version 1.0 — last updated: September 30, 2026

Between IT Brains SASU (a company registered in France), operating under the brand ProofAge, and each business customer using the ProofAge services — privacy@proofage.xyz

At a glance

A plain-language summary for procurement and privacy reviews. The agreement below is what binds; this summary does not change it.

Roles

You are the controller. ProofAge is your processor and acts only on your documented instructions.

Data location

EEA by default. A US region, or a region fixed for your account, is available on request. Providers outside the EEA are listed in Annex III.

Breach notice

Without undue delay, and no later than 48 hours after we become aware of a breach.

New sub-processors

30 days' notice by email for core providers, with a right to object. Backup and optional providers: listed here before use.

Transfers

EU Standard Contractual Clauses (2021/914), with the UK Addendum and Swiss amendments built in.

No secondary use

We never sell your data, use it for advertising, or train machine-learning models on it.

Retention

Images and document data: 30 days. Face embeddings and device hashes: 12 months. Then permanent deletion.

Biometric laws

Covers GDPR Art. 9 and US biometric privacy laws such as BIPA, CUBI and CCPA/CPRA.

Audits

Security documentation on request, and an audit once a year with 30 days' notice.

Do I need to sign anything?

No. This DPA is part of the Terms of Service and takes effect automatically when you create a ProofAge account or start using the services. It is already signed on behalf of IT Brains SASU, and it applies to every workspace in your account.

If your procurement process needs a countersigned copy, email legal@proofage.xyz with your company's legal name, registered address, registration number, and the name and title of your signatory. We will send back a signed PDF of the current version.

To hear about sub-processor changes, you don't need to do anything: account owners receive them by email. To add another address, such as your DPO, email privacy@proofage.xyz with the subject "Subscribe to sub-processor updates".

1. Definitions

This Data Processing Agreement ("DPA") forms part of the agreement between IT Brains SASU, operating under the brand ProofAge ("ProofAge", "we", "us"), and the business that uses the ProofAge services ("Customer", "you"), consisting of the Terms of Service and any order form or written agreement that refers to them (together, the "Agreement").

Capitalised terms not defined here have the meaning given in the Agreement. In this DPA:

  • Data Protection Laws means all laws that apply to the processing of Customer Personal Data under the Agreement, including Regulation (EU) 2016/679 (the "GDPR"), the French Loi Informatique et Libertés, the GDPR as retained in UK law together with the UK Data Protection Act 2018 (the "UK GDPR"), the Swiss Federal Act on Data Protection (the "FADP"), and US State Privacy Laws.
  • Customer Personal Data means personal data that ProofAge processes on the Customer's behalf in providing the services, as described in Annex I.
  • End User means an individual who completes, or starts, a verification that the Customer requested.
  • Biometric Data means facial images and face embeddings processed to estimate age, detect presentation attacks, or match a selfie to an identity document, including "biometric identifiers" and "biometric information" as defined in US biometric privacy laws.
  • Sub-processor means a third party that ProofAge engages to process Customer Personal Data.
  • SCCs means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914.
  • UK Addendum means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
  • US State Privacy Laws means US state laws on consumer privacy and biometric data, including the California Consumer Privacy Act as amended by the CPRA ("CCPA"), the Illinois Biometric Information Privacy Act ("BIPA"), the Texas Capture or Use of Biometric Identifier Act ("CUBI"), and Washington's biometric identifier and My Health My Data laws.

"Controller", "processor", "data subject", "personal data", "personal data breach", "processing" and "supervisory authority" have the meanings given in the GDPR. Where a US State Privacy Law uses "business", "service provider" or "contractor", those terms correspond to controller and processor respectively.

2. Scope and Roles of the Parties

2.1 This DPA applies whenever ProofAge processes Customer Personal Data to provide age verification, age estimation, identity verification (KYC) and the related fraud prevention services under the Agreement.

2.2 For Customer Personal Data, the Customer is the controller and ProofAge is the processor. Where the Customer is itself a processor acting for a third-party controller, ProofAge is the Customer's sub-processor, and the Customer confirms that its controller has authorised ProofAge's appointment and the instructions in this DPA.

2.3 ProofAge acts as an independent controller, and not under this DPA, for the limited data it needs to run its own business: account, billing and contact details of the Customer's staff, service usage and security logs, and data it must keep to meet its own legal obligations. That processing is described in the Privacy Policy.

2.4 The subject matter, duration, nature and purpose of the processing, and the types of personal data and data subjects, are set out in Annex I.

3. Customer Instructions

3.1 ProofAge processes Customer Personal Data only on the Customer's documented instructions, including for transfers to a third country, unless EU or Member State law requires otherwise. In that case ProofAge will tell the Customer about the legal requirement before processing, unless the law prohibits it on important grounds of public interest.

3.2 The Customer's complete instructions at the date of this DPA are to process Customer Personal Data:

  • to run the verification flows the Customer configures and return the result to the Customer;
  • to detect and prevent fraud, including by comparing a new verification against face embeddings and device signals from earlier verifications, as described in Section 14;
  • to have ProofAge staff review individual verifications where needed to resolve a dispute, investigate suspected fraud, or diagnose a technical fault;
  • to maintain, secure and support the services; and
  • as the Customer otherwise directs through the dashboard, the API, workspace settings, or in writing.

3.3 ProofAge will tell the Customer promptly if, in its opinion, an instruction infringes Data Protection Laws. ProofAge may then suspend that processing until the instruction is confirmed or changed.

3.4 ProofAge does not sell or rent Customer Personal Data, does not use it for advertising or marketing, and does not use it to train, fine-tune or otherwise develop machine-learning models, whether its own or anyone else's. Reviewing an individual verification to confirm a decision or investigate fraud or a fault is part of providing the service, not model training.

4. Customer Obligations

4.1 The Customer is responsible for:

  • having a lawful basis for each verification it requests, and a condition under Article 9 GDPR (or the equivalent under other Data Protection Laws) for the processing of Biometric Data;
  • giving End Users the notices that Data Protection Laws require, including identifying ProofAge as its service provider where that is required;
  • the accuracy and lawfulness of any personal data it sends to ProofAge, such as reference identifiers or metadata; and
  • deciding what it does with a verification result, including granting or refusing access to its own services.

4.2 Where the Customer uses the ProofAge-hosted verification flow, ProofAge presents a consent screen and records the End User's explicit consent on the Customer's behalf before any camera capture begins. The Customer may rely on that record, but it remains responsible for choosing consent as its legal basis and for any additional notice or consent its own jurisdiction requires. Where the Customer captures images in its own interface and sends them through the API, the Customer obtains any consent itself.

4.3 The Customer will not send ProofAge special category data beyond what a verification flow needs. Because age checks exist to keep minors out, End Users may include minors; the Customer is responsible for any additional safeguard that Data Protection Laws require for them.

5. ProofAge Obligations

5.1 Confidentiality. ProofAge restricts access to Customer Personal Data to personnel who need it to provide the services, and ensures they are bound by a written duty of confidentiality or a statutory one.

5.2 Purpose limitation. ProofAge does not process Customer Personal Data for its own purposes, and does not combine it with personal data it receives from other sources, except for any shared fraud blocklist the Customer chooses to join, as described in Section 14.

5.3 Disclosure. ProofAge does not disclose Customer Personal Data to third parties other than its Sub-processors, unless the Customer instructs it to or the law requires it. If a public authority demands access to Customer Personal Data, ProofAge will, where legally allowed, notify the Customer, redirect the authority to the Customer, and challenge requests it considers unlawful or excessive. It discloses only the minimum the demand requires.

5.4 Assistance. Taking into account the nature of the processing and the information available to it, ProofAge assists the Customer in meeting its obligations under Articles 32 to 36 GDPR, as described in Sections 6, 9 and 11.

5.5 Records. ProofAge keeps a record of its processing activities as a processor under Article 30(2) GDPR and makes it available to supervisory authorities on request.

6. Security of Processing

6.1 ProofAge implements and maintains appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, as required by Article 32 GDPR. The measures in place are described in Annex II.

6.2 ProofAge may update these measures as technology and threats change, provided that no update materially lowers the overall level of protection.

6.3 The Customer is responsible for the security of its own systems and credentials, including keeping API keys and webhook secrets confidential, verifying webhook signatures, and controlling who in its organisation can access the ProofAge dashboard.

7. Sub-processors

7.1 General authorisation. The Customer gives ProofAge a general authorisation to engage Sub-processors. The Sub-processors in use are listed in Annex III, which the Customer approves by entering into this DPA.

7.2 Flow-down. ProofAge engages each Sub-processor under a written contract that imposes data protection obligations no less protective than those in this DPA, including a prohibition on using Customer Personal Data for the Sub-processor's own purposes or to train its models. ProofAge remains fully liable to the Customer for the performance of each Sub-processor's obligations.

7.3 Notice of changes. For the core Sub-processors in Part A of Annex III, ProofAge will notify the Customer of any intended addition or replacement at least 30 days before the new Sub-processor starts processing Customer Personal Data, by email to the account owner and any address registered under the "Do I need to sign anything?" section above, and by updating Annex III.

7.3A Backup and optional providers. The Sub-processors in Part B of Annex III are backups or optional signals that receive data only in the circumstances described there. ProofAge may switch them on or off at any time, and may add or replace a provider of the same kind (a backup AI model provider, an active liveness provider or a device intelligence provider) by updating Part B of Annex III before the new provider receives any Customer Personal Data. That update is the notice for such a change; it is also sent to any address registered for sub-processor updates. A new provider in Part B receives no more data, and for no other purpose, than the provider it replaces or joins.

7.4 Objection. The Customer may object to a change on reasonable grounds relating to data protection by writing to privacy@proofage.xyz within the notice period, or for a change under Section 7.3A within 30 days of the update. The parties will discuss the objection in good faith. For a Part B provider, ProofAge may resolve the objection by no longer sending the Customer's data to that provider. Otherwise, if ProofAge cannot offer a reasonable alternative, the Customer may terminate the affected part of the services, without penalty, and pay only for services used up to termination.

7.5 Emergency replacement. If a Sub-processor must be replaced urgently to keep the services secure or available, and the reason is outside ProofAge's control, ProofAge may do so with shorter notice. It will notify the Customer as soon as possible, and the objection right in Section 7.4 still applies.

8. International Data Transfers

8.1 Default region. By default, ProofAge stores Customer Personal Data in the European Economic Area, and its primary processing, including AI analysis, runs there. ProofAge's infrastructure providers operate in both the EEA and the United States.

8.2 Data residency on request. The Customer may ask for its Customer Personal Data to be kept in a specific region, currently the EEA or the United States. Where ProofAge agrees in writing, for example in an order form, it stores and processes that Customer's data in the agreed region and sends it to a provider outside that region only as the written agreement allows. Fixing a region may limit which backup or optional features are available to that Customer. Once a Customer's data is stored in a region, ProofAge will not move it to another region without at least 30 days' notice.

8.3 Apart from a region agreed under Section 8.2, ProofAge transfers Customer Personal Data outside the EEA only to the Sub-processors identified in Annex III as located in a third country, only for the purposes and in the circumstances stated there, and only the data that purpose needs.

8.4 Where a transfer is to a country without an adequacy decision, ProofAge relies on the SCCs (Module 3, processor to processor) entered into with the Sub-processor, or on the Sub-processor's certification under the EU-US Data Privacy Framework where it holds one, supplemented by the measures in Annex II. ProofAge has assessed these transfers and will make a summary of that assessment available on request.

8.5 Where the Customer is located outside the EEA and its transfer to ProofAge is not covered by an adequacy decision, the parties agree that the SCCs apply to the Customer's transfers, as follows:

  • Module 2 (controller to processor) applies where the Customer is a controller, and Module 3 (processor to processor) where it is a processor;
  • in Clause 7, the optional docking clause applies;
  • in Clause 9, Option 2 (general written authorisation) applies, with the notice periods in Sections 7.3 and 7.3A;
  • in Clause 11, the optional redress language does not apply;
  • in Clauses 17 and 18, the SCCs are governed by French law and disputes are resolved by the courts of Paris, France;
  • Annexes I, II and III of the SCCs are completed by the corresponding Annexes of this DPA.

8.6 UK. For transfers subject to the UK GDPR, the SCCs apply as amended by the UK Addendum. Tables 1 to 3 of the UK Addendum are completed by the information in this DPA and its Annexes, and in Table 4 either party may end the UK Addendum as allowed by its Section 19.

8.7 Switzerland. For transfers subject to the FADP, the SCCs apply with these changes: references to the GDPR are read as references to the FADP, the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority, and "Member State" includes Switzerland so that data subjects there can bring claims in their place of habitual residence.

8.8 If the SCCs conflict with this DPA or the Agreement, the SCCs prevail.

9. Personal Data Breaches

9.1 ProofAge will notify the Customer of a personal data breach affecting Customer Personal Data without undue delay, and in any event within 48 hours of becoming aware of it, by email to the account owner.

9.2 The notice will, as far as the information is then available, describe:

  • the nature of the breach, including the categories and approximate number of data subjects and records concerned;
  • its likely consequences;
  • the measures taken or proposed to address it and to mitigate its possible adverse effects; and
  • a contact point for more information.

Where not all of this is available at once, ProofAge will provide it in stages as it becomes available.

9.3 ProofAge will take reasonable steps to contain and investigate the breach, and will cooperate with the Customer so that it can meet its own obligations to notify supervisory authorities and data subjects. Unless the law requires otherwise, ProofAge will not notify the Customer's End Users or regulators about a breach of Customer Personal Data without first consulting the Customer.

9.4 Notifying a breach is not an acknowledgement of fault or liability.

10. Data Subject Requests

10.1 Taking into account the nature of the processing, ProofAge assists the Customer, by appropriate technical and organisational measures, in responding to requests from data subjects to exercise their rights under Chapter III GDPR and equivalent Data Protection Laws.

10.2 End Users often contact ProofAge directly, because they met ProofAge during the verification. The Customer instructs ProofAge, as part of the services, to handle a request that an End User sends to ProofAge with a verification session reference for:

  • withdrawal of consent, or erasure of their data, which ProofAge carries out, informing the Customer that the verification's data was deleted; and
  • access to, or a copy of, the data ProofAge holds about that verification.

ProofAge will forward any other request, including a request for human review of a decision, to the Customer without undue delay and will not respond to it beyond acknowledging receipt, unless the Customer asks it to.

10.3 Where the Customer cannot fulfil a request using the dashboard or the API, ProofAge will help it do so on request.

11. Impact Assessments and Regulators

11.1 Processing Biometric Data at scale is likely to require a data protection impact assessment. ProofAge will give the Customer the information about the services that it reasonably needs to carry out a data protection impact assessment and any prior consultation with a supervisory authority under Articles 35 and 36 GDPR, including a description of the processing, its safeguards, and the accuracy and fairness testing of the models it uses.

11.2 ProofAge will cooperate with any supervisory authority that has jurisdiction over the processing, and will tell the Customer about any inquiry that concerns Customer Personal Data, unless the law prohibits it.

12. Audits and Information

12.1 ProofAge will make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR and this DPA. The Customer agrees to first seek that information through written requests: ProofAge will answer a reasonable security questionnaire and provide its security documentation, once a year or after a personal data breach.

12.2 If that information is not enough to demonstrate compliance, or a supervisory authority requires it, the Customer may carry out an audit, including an inspection, itself or through an independent auditor bound by confidentiality who is not a competitor of ProofAge. The Customer will give at least 30 days' written notice, agree the scope in advance, conduct the audit during business hours without unreasonably disrupting ProofAge's operations, and bear its own costs. Audits are limited to once in any 12-month period, except after a personal data breach or at a supervisory authority's request.

12.3 An audit may not give access to other customers' data, or to Sub-processors' facilities beyond the audit reports and certifications those Sub-processors make available. The Customer will share its audit report with ProofAge and keep it confidential.

13. Retention, Deletion and Return

13.1 During the Agreement, ProofAge keeps Customer Personal Data for the periods set out in Annex I and then permanently and irreversibly deletes it. The Customer can export a verification's results through the API or the dashboard at any time within those periods, and can ask ProofAge to delete a verification's data sooner.

13.2 When the Agreement ends, ProofAge will delete all Customer Personal Data within 30 days, unless the Customer asks, before the Agreement ends, for an export of the data that the services still hold. Copies in database backups are removed as those backups expire, which currently takes no more than 7 days, and are not restored for any other purpose in the meantime.

13.3 ProofAge may keep Customer Personal Data after these periods only where EU or Member State law requires it, such as a consent record kept as evidence of compliance. It will continue to protect that data under this DPA and process it only for the purpose that requires its retention.

13.4 On request, ProofAge will confirm in writing that deletion has been completed.

14. Biometric Data and Automated Decisions

14.1 Why Biometric Data is processed. ProofAge processes Biometric Data only to estimate an End User's age, to confirm that a live person is present (liveness and anti-spoofing), to match a selfie to the photograph on an identity document, and to prevent fraud as described below.

14.2 Fraud prevention. The Customer instructs ProofAge to keep face embeddings and device fingerprint hashes for 12 months and to compare new verifications against them, in order to detect the same person attempting verifications under different identities and to block profiles previously identified as fraudulent. The face blocklist is optional. By default it is limited to the Customer's own account; it covers other customers' accounts only if the Customer joins a shared blocklist group. Face embeddings are mathematical vectors that cannot be used to reconstruct a photograph. They are never disclosed to any customer or third party, and only the outcome of a comparison (a fraud signal) is used in a verification decision.

14.3 No commercial use. ProofAge will not sell, lease, trade or otherwise profit from Biometric Data, or disclose it except as this DPA allows. It stores and protects Biometric Data using at least the same standard of care it applies to other confidential information.

14.4 Public retention schedule. ProofAge's retention periods and destruction rules for Biometric Data are published in the Privacy Policy and in Annex I. Biometric Data is permanently destroyed at the end of those periods, or earlier when the End User withdraws consent, and in no case later than when the purpose for collecting it has been satisfied.

14.5 US biometric laws. Where BIPA, CUBI or a similar law applies, the Customer is responsible for informing End Users in writing, before collection, that Biometric Data is being collected, the purpose and length of time it will be used, and for obtaining their written release. ProofAge's hosted consent screen is designed to support this, and ProofAge will adjust its wording on reasonable request.

14.6 Automated decisions. Verification results are produced by automated processing. ProofAge returns a result and supporting signals; the Customer decides whether to grant access to its services, and is responsible for offering End Users human review, the ability to express their point of view, and to contest a decision where Article 22 GDPR requires it. ProofAge will help the Customer review a contested verification on request.

15. US State Privacy Laws

15.1 Where the CCPA or another US State Privacy Law applies, ProofAge acts as the Customer's service provider or processor, and receives Customer Personal Data only for the limited and specified business purposes in Annex I. ProofAge will not:

  • sell or share Customer Personal Data, as those terms are defined in the CCPA;
  • retain, use or disclose it for any purpose other than the business purposes in the Agreement, including any commercial purpose, or outside the direct business relationship with the Customer; or
  • combine it with personal information it receives from or on behalf of anyone else, or collects from its own interactions with a consumer, except as the CCPA permits for service providers, including to detect security incidents and protect against fraudulent or illegal activity.

15.2 ProofAge will comply with the US State Privacy Laws that apply to it, provide the same level of privacy protection they require, and notify the Customer if it determines it can no longer meet its obligations under them. The Customer may take reasonable and appropriate steps to stop and remediate unauthorised use of Customer Personal Data.

15.3 ProofAge certifies that it understands and will comply with the restrictions in this Section 15.

16. Liability

16.1 Each party's liability arising out of or relating to this DPA, whether in contract, tort or otherwise, is subject to the limitations and exclusions of liability in the Agreement, and any reference in the Agreement to a party's liability means its aggregate liability under the Agreement and this DPA together.

16.2 Nothing in this DPA limits either party's liability to data subjects under Article 82 GDPR or under the third-party beneficiary rights in the SCCs, to the extent that liability cannot be limited by law.

17. Term, Precedence and Governing Law

17.1 Term. This DPA stays in force for as long as ProofAge processes Customer Personal Data, including after the Agreement ends until deletion is complete under Section 13.

17.2 Order of precedence. If there is a conflict, the following order applies: first the SCCs (where they apply), then this DPA, then the rest of the Agreement. On data protection matters, this DPA prevails over any other term of the Agreement.

17.3 Changes. ProofAge may update this DPA to reflect changes in Data Protection Laws, in guidance from a supervisory authority, or in the services, provided that the update does not materially reduce the protection of Customer Personal Data. ProofAge will notify the Customer of any material update by email at least 30 days before it takes effect. Previous versions are available on request.

17.4 Governing law. Except where the SCCs or a Data Protection Law require otherwise, this DPA is governed by the law that governs the Agreement, and disputes are resolved as the Agreement provides.

17.5 Severability. If any provision of this DPA is found invalid or unenforceable, the rest of it remains in effect, and the provision is amended to the minimum extent needed to make it valid while keeping the parties' intent.

Annex I — Description of the Processing

A. List of parties

Data exporter (controller)

The Customer, as identified in its ProofAge account. Contact: the account owner's email address and any data protection contact the Customer registers. Signature and date: by accepting the Terms of Service.

Data importer (processor)

IT Brains SASU, operating as ProofAge, France. Contact: privacy@proofage.xyz. Activities: providing the age and identity verification services under the Agreement.

B. Description of the processing

Data subjects End Users who start or complete a verification that the Customer requested. They may include minors attempting to pass an age check.
Personal data Selfie images and short capture frames; identity document images (front and back); data read from the document (full name, date of birth, nationality, sex, document type, number, issuing country, issue and expiry dates, MRZ); estimated age and the age-threshold result; document validation and fraud signals; IP address and approximate location (country, city); User-Agent and device fingerprint hash; session timestamps; the consent record; and any reference identifier the Customer attaches to the verification.
Special categories Biometric data: facial images and face embeddings derived from the selfie and the document photograph, and face match results. Safeguards: explicit consent recorded before capture, encryption at rest, strict access control with logging, fixed retention periods, and no disclosure of embeddings to any customer or third party (see Annex II and Section 14).
Nature of processing Collection through the web and mobile capture flow or the API, storage, OCR and document analysis, face detection, age estimation, liveness and anti-spoofing analysis, face matching, comparison against fraud lists, human review of individual cases, transmission of results to the Customer, and deletion.
Purposes To verify that an End User meets the age threshold the Customer configures, or to verify their identity; to detect and prevent fraud; and to maintain, secure and support the services.
Frequency Continuous, each time the Customer creates a verification.
Duration The term of the Agreement, then until deletion under Section 13, subject to the retention periods below.
Sub-processor transfers As set out in Annex III, for the subject matter, nature and duration described there.

C. Retention periods

Data Retention
Selfie and document images 30 days
Data read from the document, face match result, verification result 30 days
IP address and approximate location 30 days
Face embeddings (selfie and document photo) 12 months
Device fingerprint hash 12 months
Consent record As long as the law requires it as evidence of consent

Periods run from the verification. The Customer may request shorter retention for its workspaces; ProofAge will confirm in writing what it can support.

D. Competent supervisory authority

The Commission Nationale de l'Informatique et des Libertés (CNIL), 3 Place de Fontenoy, 75007 Paris, France, unless Clause 13 of the SCCs designates another authority for the Customer.

Annex II — Technical and Organisational Measures

ProofAge maintains at least the following measures. Sub-processors are bound to measures that give an equivalent level of protection for the data they receive.

Encryption

  • TLS 1.2 or higher for all traffic to and from the services
  • AES-256 encryption at rest for databases, object storage and backups
  • Verification media reachable only through authenticated requests or short-lived signed URLs

Access control

  • Least-privilege, role-based access for personnel
  • Access to production data limited to named staff and logged
  • Two-factor authentication and passkeys available for dashboard accounts

Customer isolation

  • Every record scoped to the Customer's tenant and workspace
  • API requests signed with HMAC and per-workspace keys
  • Webhooks signed so the Customer can verify their origin

Data minimisation and retention

  • Only the data a flow needs is collected
  • Automatic, scheduled deletion at the end of each retention period
  • Only IP addresses, never images, sent for geolocation

Infrastructure and availability

  • Hosting in Google Cloud EU regions by default (US regions on request), whose data centres hold ISO 27001 and SOC 2 certifications
  • Daily encrypted database backups, kept for 7 days
  • Health checks and alerting on the services

Monitoring and logging

  • Audit trail of changes to verifications and settings
  • Error monitoring configured not to collect personal data by default
  • Rate limiting and bot protection on public endpoints

Secure development

  • Code review and automated tests before every release
  • Secrets kept out of source code and rotated when exposed
  • Dependencies kept up to date against known vulnerabilities

People and incidents

  • Confidentiality obligations for everyone with data access
  • Incident response process with 48-hour customer notice
  • Vendor review before engaging any Sub-processor

Annex III — Sub-processors

ProofAge uses the Sub-processors below to process Customer Personal Data. They fall into two groups: core Sub-processors that take part in every verification, and Sub-processors that may be used, because they are backups or serve optional features. Changes to either list are announced as described in Section 7.

A. Core Sub-processors

Sub-processor Purpose Data processed Location Transfer safeguard
Google Cloud EMEA Limited Hosting, databases, storage and backups; face and document analysis; document OCR and AI analysis (Document AI, Vertex AI Gemini) All Customer Personal Data EU regions by default; US regions on request (Section 8.2) Stays in the EEA unless a US region is agreed; SCCs
Functional Software, Inc. (Sentry) Error and performance monitoring Technical error data; personal data not collected by default EU (Germany) Stored in the EEA; SCCs for support access
Ably Real-time Ltd Tells the open verification page that its status changed, so the page can reload it Verification identifier and status codes; no images, names or document data United Kingdom UK adequacy decision; SCCs for onward transfers
Kloudend, Inc. (ipapi.co) IP geolocation for fraud prevention IP address only United States SCCs
IPinfo, Inc. IP geolocation (fallback when the first provider does not answer) IP address only United States SCCs

B. Sub-processors that may be used

These Sub-processors do not take part in every verification. The AI model providers are backups: ProofAge sends them data only when the primary, EU-hosted models on Google Cloud are unavailable or cannot complete an analysis, or when an individual verification needs a second model's review. Active liveness is an optional check that asks the End User to follow on-screen prompts, used for the flows where it is enabled; the images it captures are processed in the Customer's region and are not used to improve the provider's own services. Device intelligence is an optional, temporary fraud signal: it is used only for a limited number of verifications, may be switched off entirely, and no device data is collected once it is off. Only the attributes needed to recognise a device are sent, not everything a browser exposes. ProofAge may switch these providers on or off, or replace one with another of the same kind, as described in Section 7.3A.

Sub-processor When it is used Data processed Location Transfer safeguard
Anthropic, PBC Backup AI model for anti-spoofing checks and fraud review of individual verifications Selfie and document images, verification signals United States SCCs; API terms prohibit training on the data
OpenAI, L.L.C. Backup AI model for anti-spoofing checks and fraud review of individual verifications Selfie and document images, verification signals United States SCCs; API terms prohibit training on the data
Amazon Web Services EMEA SARL (Amazon Rekognition Face Liveness) Optional active liveness check, for the flows where it is enabled Short selfie video frames, liveness result EU region by default; US region on request (Section 8.2) Stays in the EEA unless a US region is agreed; SCCs; opted out of use for service improvement
FingerprintJS, Inc. (Fingerprint) Optional device intelligence for fraud prevention, for a limited number of verifications where enabled Browser and device attributes, IP address United States SCCs

Providers that ProofAge uses only for its own account, billing and communication data, such as Stripe for payments and Brevo for email, are not Sub-processors of Customer Personal Data and are described in the Privacy Policy.

Questions about this DPA

Privacy and data protection: privacy@proofage.xyz

Contracts and countersigned copies: legal@proofage.xyz

IT Brains SASU, operating under the brand ProofAge, France.