Data Processing Addendum

Data Processing Addendum

Last updated: August 2026

For customers who need a formal DPA covering CertiLayer's processing of behavioral data on their behalf, under GDPR Article 28 or equivalent.

1. Purpose

This Data Processing Addendum ("DPA") describes how CertiLayer processes personal data on behalf of customers who use the Service to process behavioral data belonging to their own end users, and forms part of our Terms of Service where GDPR, UK GDPR, or equivalent data protection law applies to that processing.

2. Roles

You (the customer) are the Data Controller for any personal data associated with your end users. CertiLayer is the Data Processor, acting only on your documented instructions as expressed through your use of the API, SDK configuration, and dashboard settings.

3. Scope of processing

Nature of processing: computing behavioral trust scores from timing/movement/rhythm signals submitted via the SDK or API.

Categories of data: behavioral feature vectors (not, by CertiLayer's design, linked to an identified individual), session identifiers, and — only if you choose to include them in optional fields — any additional identifiers you submit alongside a session.

Duration: for the length of your active subscription, plus the data retention window specified by your plan tier.

4. Sub-processors

CertiLayer uses a limited set of infrastructure and billing sub-processors necessary to operate the Service (see /privacy §5). We'll provide advance notice of any new sub-processor with material access to customer data via email to your account's registered contact, and you may object on reasonable data-protection grounds.

5. Security measures

API keys and passwords are stored as BLAKE3 hashes, never in plaintext. Data in transit is encrypted via TLS. Access to production systems is limited and logged. See /security for the full technical breakdown.

6. Assistance with data subject requests

Where a data subject contacts CertiLayer directly about data processed on your behalf, we'll redirect them to you as Controller and, where technically feasible, assist you in fulfilling access, deletion, or portability requests within a reasonable timeframe.

7. Breach notification

We'll notify you without undue delay, and in any case within 72 hours of becoming aware, of any confirmed personal data breach affecting data processed on your behalf, with the information reasonably available to us at the time.

8. International transfers

Where processing involves a transfer of personal data outside the EEA/UK, Standard Contractual Clauses (SCCs) are incorporated by reference into this DPA.

9. Executing a signed copy

This page is CertiLayer's standard DPA. If your organization requires a countersigned copy for procurement or audit purposes, email [email protected] and we'll send one over — available on Starter plans and above.