Verazify Legal & Trust

Data Processing Addendum

This Addendum governs Verazify's processing of personal data on behalf of its customers and forms part of the Terms of Service.

Effective date: August 11, 2026

This Data Processing Addendum (“DPA”) is incorporated into and forms part of the Terms of Service or other written agreement (the “Agreement”) between the customer (“Customer”) and Devlpfy LLC (“Verazify”) for the provision of the identity verification and AML compliance services (the “Service”). By accepting the Agreement or using the Service, Customer agrees to this DPA on behalf of itself and, to the extent required, its affiliates. If there is a conflict between this DPA and the Agreement regarding the processing of personal data, this DPA controls.

Clickwrap acceptance

This DPA is presented on a clickwrap basis and takes effect when Customer accepts the Agreement or begins using the Service. A countersigned copy is available on request at legal@verazify.com for Customers that require a signed instrument.

01Parties & roles

The parties acknowledge that, with respect to the processing of personal data of Customer’s end users (“End-User Data”) through the Service:

  • Customer is the controller (or, where Customer is itself a processor, the processor acting on behalf of a third-party controller), and equivalent roles under regional law such as “responsable” (Mexico LFPDPPP) and “controlador” (Brazil LGPD); and
  • Verazify is the processor (or “encargado” / “operador”), processing End-User Data only on Customer’s documented instructions.

Customer’s documented instructions comprise this DPA, the Agreement, and the configuration choices Customer makes in the Service. Verazify will inform Customer if, in its opinion, an instruction infringes applicable data protection law, unless legally prohibited from doing so.

02Scope & purpose of processing

Verazify processes End-User Data solely to provide, secure, and support the Service — that is, to perform document authentication, biometric face matching and liveness detection, data extraction, sanctions, watchlist and PEP screening, fraud-signal analysis, and related reporting requested by Customer. The subject matter, duration, nature, and purpose of the processing, the types of personal data, and the categories of data subjects are described in Annex A.

Verazify will not process End-User Data for its own purposes, will not sell it, and will not use it to build facial-recognition databases or to train models beyond what is necessary to deliver the checks Customer requests and to maintain the Service’s security and accuracy.

03Processor obligations

Verazify will:

  • process End-User Data only on Customer’s documented instructions, including regarding international transfers;
  • ensure that personnel authorized to process End-User Data are bound by appropriate confidentiality obligations;
  • implement and maintain the technical and organizational measures described in Annex B;
  • engage sub-processors only in accordance with Section 5;
  • assist Customer, taking into account the nature of the processing, in responding to data-subject requests and in meeting Customer’s security, breach-notification, and data-protection-impact-assessment obligations; and
  • make available information reasonably necessary to demonstrate compliance with this DPA.

04Security measures

Verazify implements and maintains technical and organizational measures designed to protect End-User Data against accidental or unlawful destruction, loss, alteration, and unauthorized disclosure or access, appropriate to the risk. These include encryption in transit (TLS) and at rest (AES-256), role-based access controls, network segmentation and rate limiting, logging and monitoring, secure development practices, and business-continuity measures. The current measures are summarized in Annex B and on our Security page. Verazify may update these measures provided the level of protection is not materially reduced.

05Sub-processing

Customer provides general authorization for Verazify to engage sub-processors to support the Service. Verazify maintains a current list of sub-processors at verazify.com/subprocessors, where Customer may subscribe to notifications of changes. Verazify will:

  • impose data-protection obligations on each sub-processor that are no less protective than those in this DPA;
  • remain liable for the performance of each sub-processor’s obligations; and
  • give Customer reasonable prior notice of the addition or replacement of a sub-processor, during which Customer may object on reasonable data-protection grounds.

If Customer reasonably objects and the parties cannot resolve the concern, Customer may terminate the affected part of the Service as its exclusive remedy.

06Data-subject requests

The Service provides features that enable Customer to access, correct, delete, and export End-User Data. Taking into account the nature of the processing, Verazify will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights under applicable law (including GDPR data-subject rights, Mexico LFPDPPP “ARCO” rights, and Brazil LGPD rights). If Verazify receives a request directly from a data subject relating to End-User Data, it will, unless legally required to respond, promptly forward the request to Customer and not otherwise respond except on Customer’s instruction.

07Breach notification

Verazify will notify Customer without undue delay after becoming aware of a personal data breach affecting End-User Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it. Verazify will cooperate with Customer and take reasonable steps to mitigate the breach. Notification of a breach is not an acknowledgment of fault or liability.

08Audits

Verazify will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and, upon reasonable prior written request and no more than once per year (unless required by a supervisory authority or following a breach), allow for and contribute to audits conducted by Customer or an independent auditor bound by confidentiality. To minimize disruption, Verazify may satisfy audit requests by providing third-party audit reports, certifications, and questionnaires where available. Audits will be conducted during business hours, subject to Verazify’s security policies, and must not compromise the confidentiality of other customers’ data.

09International transfers & SCCs

Where Verazify or its sub-processors process End-User Data outside the jurisdiction of origin, including in the United States or the European Union, such transfers are made using a lawful transfer mechanism. For transfers subject to the GDPR, the parties agree that the European Commission’s Standard Contractual Clauses (“SCCs”) are incorporated into this DPA by reference and apply, with Customer (or the relevant controller) as data exporter and Verazify as data importer, completed by the details in Annex A and Annex B. For transfers subject to other frameworks, the parties will rely on the equivalent safeguards recognized by the applicable law (for example, adequacy findings or local standard clauses). Verazify applies supplementary measures, including encryption, to protect data in transit and at rest.

10Deletion & return on termination

Upon termination or expiry of the Agreement, and at Customer’s choice, Verazify will delete or return End-User Data and delete existing copies, except to the extent applicable law requires continued storage or the data is retained in routine backups that are deleted on a defined cycle. Where required by AML or other law, Customer remains responsible for retaining records for the mandated period. Verazify will, on request, confirm in writing that deletion has been completed.

11Annex A — Categories of data & data subjects

Data subjects

The personal data processed concerns the following categories of data subjects: the end users whom Customer verifies through the Service (for example, applicants, account holders, customers, or counterparties of Customer), and, where relevant, their authorized representatives.

Categories of personal data

CategoryExamples
Identity & document dataFull name, date and place of birth, nationality, gender, document type and number, issue and expiry dates, and MRZ data extracted from identity documents.
Document & facial imagesPhotographs or scans of identity documents; a selfie image or short video captured for verification.
Biometric data (special category)Facial templates and liveness signals derived from images or video solely to match a face to a document and confirm a live human is present.
Contact & address dataAddress, email, or phone number, where Customer’s verification flow collects them.
Screening dataResults of sanctions, watchlist, and PEP screening associated with the data subject.
Technical & fraud-signal dataDevice, network, and session metadata and timestamps used to detect manipulation, spoofing, and replay.

Nature & purpose of processing

Collection, structuring, storage, analysis, comparison, screening, and reporting for the purpose of identity verification and AML compliance requested by Customer.

Duration

For the term of the Agreement and the retention period configured by Customer or required by applicable law, after which data is deleted or de-identified in accordance with Section 10.

12Annex B — Technical & organizational measures

Verazify maintains the following technical and organizational security measures, which may be updated provided the overall level of protection is not materially reduced:

AreaMeasures
EncryptionTLS for data in transit; AES-256 for data at rest, including document and biometric data.
Access controlRole-based access on a least-privilege, need-to-know basis; unique accounts; multi-factor authentication for administrative access; logging of access to production systems.
Network securityNetwork segmentation, firewalls, rate limiting and abuse protection, and hardened, regularly patched infrastructure.
Application securitySecure software-development lifecycle, code review, dependency and vulnerability management, and a responsible-disclosure program.
Monitoring & loggingCentralized logging, monitoring, and alerting to detect and respond to anomalous or unauthorized activity.
Data minimization & retentionConfigurable retention windows, deletion and de-identification workflows, and purpose-limited processing of biometric data.
Resilience & continuityEncrypted backups, redundancy across availability zones, and documented incident-response and business-continuity procedures.
Personnel & governanceConfidentiality obligations, security awareness training, and vendor / sub-processor due diligence.
These measures reflect Verazify’s current controls. See the Security page for our compliance roadmap; certifications noted as in progress or planned are not yet held.

13Contact

To request a countersigned DPA or to raise data-processing questions, contact our legal team.

Legal contact

For DPA execution requests and data-processing matters.
Legal entity:
Devlpfy LLC (d/b/a Verazify)
Registered address:
1317 Edgewater Drive, Suite #7262, Orlando, FL 32804, USA — operating across Latin America & the Caribbean
    Data Processing Addendum — Verazify · Verazify