This Data Processing Addendum (“DPA”) is incorporated into and forms part of the Terms of Service or other written agreement (the “Agreement”) between the customer (“Customer”) and Devlpfy LLC (“Verazify”) for the provision of the identity verification and AML compliance services (the “Service”). By accepting the Agreement or using the Service, Customer agrees to this DPA on behalf of itself and, to the extent required, its affiliates. If there is a conflict between this DPA and the Agreement regarding the processing of personal data, this DPA controls.
Clickwrap acceptance
01Parties & roles
The parties acknowledge that, with respect to the processing of personal data of Customer’s end users (“End-User Data”) through the Service:
- Customer is the controller (or, where Customer is itself a processor, the processor acting on behalf of a third-party controller), and equivalent roles under regional law such as “responsable” (Mexico LFPDPPP) and “controlador” (Brazil LGPD); and
- Verazify is the processor (or “encargado” / “operador”), processing End-User Data only on Customer’s documented instructions.
Customer’s documented instructions comprise this DPA, the Agreement, and the configuration choices Customer makes in the Service. Verazify will inform Customer if, in its opinion, an instruction infringes applicable data protection law, unless legally prohibited from doing so.
02Scope & purpose of processing
Verazify processes End-User Data solely to provide, secure, and support the Service — that is, to perform document authentication, biometric face matching and liveness detection, data extraction, sanctions, watchlist and PEP screening, fraud-signal analysis, and related reporting requested by Customer. The subject matter, duration, nature, and purpose of the processing, the types of personal data, and the categories of data subjects are described in Annex A.
Verazify will not process End-User Data for its own purposes, will not sell it, and will not use it to build facial-recognition databases or to train models beyond what is necessary to deliver the checks Customer requests and to maintain the Service’s security and accuracy.
03Processor obligations
Verazify will:
- process End-User Data only on Customer’s documented instructions, including regarding international transfers;
- ensure that personnel authorized to process End-User Data are bound by appropriate confidentiality obligations;
- implement and maintain the technical and organizational measures described in Annex B;
- engage sub-processors only in accordance with Section 5;
- assist Customer, taking into account the nature of the processing, in responding to data-subject requests and in meeting Customer’s security, breach-notification, and data-protection-impact-assessment obligations; and
- make available information reasonably necessary to demonstrate compliance with this DPA.
04Security measures
Verazify implements and maintains technical and organizational measures designed to protect End-User Data against accidental or unlawful destruction, loss, alteration, and unauthorized disclosure or access, appropriate to the risk. These include encryption in transit (TLS) and at rest (AES-256), role-based access controls, network segmentation and rate limiting, logging and monitoring, secure development practices, and business-continuity measures. The current measures are summarized in Annex B and on our Security page. Verazify may update these measures provided the level of protection is not materially reduced.
05Sub-processing
Customer provides general authorization for Verazify to engage sub-processors to support the Service. Verazify maintains a current list of sub-processors at verazify.com/subprocessors, where Customer may subscribe to notifications of changes. Verazify will:
- impose data-protection obligations on each sub-processor that are no less protective than those in this DPA;
- remain liable for the performance of each sub-processor’s obligations; and
- give Customer reasonable prior notice of the addition or replacement of a sub-processor, during which Customer may object on reasonable data-protection grounds.
If Customer reasonably objects and the parties cannot resolve the concern, Customer may terminate the affected part of the Service as its exclusive remedy.
06Data-subject requests
The Service provides features that enable Customer to access, correct, delete, and export End-User Data. Taking into account the nature of the processing, Verazify will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights under applicable law (including GDPR data-subject rights, Mexico LFPDPPP “ARCO” rights, and Brazil LGPD rights). If Verazify receives a request directly from a data subject relating to End-User Data, it will, unless legally required to respond, promptly forward the request to Customer and not otherwise respond except on Customer’s instruction.
07Breach notification
Verazify will notify Customer without undue delay after becoming aware of a personal data breach affecting End-User Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it. Verazify will cooperate with Customer and take reasonable steps to mitigate the breach. Notification of a breach is not an acknowledgment of fault or liability.
08Audits
Verazify will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and, upon reasonable prior written request and no more than once per year (unless required by a supervisory authority or following a breach), allow for and contribute to audits conducted by Customer or an independent auditor bound by confidentiality. To minimize disruption, Verazify may satisfy audit requests by providing third-party audit reports, certifications, and questionnaires where available. Audits will be conducted during business hours, subject to Verazify’s security policies, and must not compromise the confidentiality of other customers’ data.
09International transfers & SCCs
Where Verazify or its sub-processors process End-User Data outside the jurisdiction of origin, including in the United States or the European Union, such transfers are made using a lawful transfer mechanism. For transfers subject to the GDPR, the parties agree that the European Commission’s Standard Contractual Clauses (“SCCs”) are incorporated into this DPA by reference and apply, with Customer (or the relevant controller) as data exporter and Verazify as data importer, completed by the details in Annex A and Annex B. For transfers subject to other frameworks, the parties will rely on the equivalent safeguards recognized by the applicable law (for example, adequacy findings or local standard clauses). Verazify applies supplementary measures, including encryption, to protect data in transit and at rest.
10Deletion & return on termination
Upon termination or expiry of the Agreement, and at Customer’s choice, Verazify will delete or return End-User Data and delete existing copies, except to the extent applicable law requires continued storage or the data is retained in routine backups that are deleted on a defined cycle. Where required by AML or other law, Customer remains responsible for retaining records for the mandated period. Verazify will, on request, confirm in writing that deletion has been completed.
11Annex A — Categories of data & data subjects
Data subjects
The personal data processed concerns the following categories of data subjects: the end users whom Customer verifies through the Service (for example, applicants, account holders, customers, or counterparties of Customer), and, where relevant, their authorized representatives.
Categories of personal data
| Category | Examples |
|---|---|
| Identity & document data | Full name, date and place of birth, nationality, gender, document type and number, issue and expiry dates, and MRZ data extracted from identity documents. |
| Document & facial images | Photographs or scans of identity documents; a selfie image or short video captured for verification. |
| Biometric data (special category) | Facial templates and liveness signals derived from images or video solely to match a face to a document and confirm a live human is present. |
| Contact & address data | Address, email, or phone number, where Customer’s verification flow collects them. |
| Screening data | Results of sanctions, watchlist, and PEP screening associated with the data subject. |
| Technical & fraud-signal data | Device, network, and session metadata and timestamps used to detect manipulation, spoofing, and replay. |
Nature & purpose of processing
Collection, structuring, storage, analysis, comparison, screening, and reporting for the purpose of identity verification and AML compliance requested by Customer.
Duration
For the term of the Agreement and the retention period configured by Customer or required by applicable law, after which data is deleted or de-identified in accordance with Section 10.
12Annex B — Technical & organizational measures
Verazify maintains the following technical and organizational security measures, which may be updated provided the overall level of protection is not materially reduced:
| Area | Measures |
|---|---|
| Encryption | TLS for data in transit; AES-256 for data at rest, including document and biometric data. |
| Access control | Role-based access on a least-privilege, need-to-know basis; unique accounts; multi-factor authentication for administrative access; logging of access to production systems. |
| Network security | Network segmentation, firewalls, rate limiting and abuse protection, and hardened, regularly patched infrastructure. |
| Application security | Secure software-development lifecycle, code review, dependency and vulnerability management, and a responsible-disclosure program. |
| Monitoring & logging | Centralized logging, monitoring, and alerting to detect and respond to anomalous or unauthorized activity. |
| Data minimization & retention | Configurable retention windows, deletion and de-identification workflows, and purpose-limited processing of biometric data. |
| Resilience & continuity | Encrypted backups, redundancy across availability zones, and documented incident-response and business-continuity procedures. |
| Personnel & governance | Confidentiality obligations, security awareness training, and vendor / sub-processor due diligence. |
13Contact
To request a countersigned DPA or to raise data-processing questions, contact our legal team.
Legal contact
- Email:
- legal@verazify.com
- Legal entity:
- Devlpfy LLC (d/b/a Verazify)
- Registered address:
- 1317 Edgewater Drive, Suite #7262, Orlando, FL 32804, USA — operating across Latin America & the Caribbean