Data Processing Agreement
GDPR Article 28 · Effective date: 18 June 2026 · Last updated: 18 June 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between [COMPANY LEGAL NAME] ("Processor") and the Customer identified in the AgeVerify EU account ("Controller"). It governs the processing of personal data by the Processor on behalf of the Controller in connection with the AgeVerify EU Services, as required by Article 28 of the EU General Data Protection Regulation (GDPR).
1. Definitions
Terms defined in the GDPR (Regulation (EU) 2016/679) have the same meaning here. In addition:
- "Services" means the AgeVerify EU age verification API, hosted verification UI, developer dashboard, webhooks, sandbox, and related software described in the Terms of Service.
- "Personal Data" means any information relating to an identified or identifiable natural person processed under this DPA.
- "Processing" has the meaning given in GDPR Article 4(2).
- "Sub-Processor" means any third party engaged by the Processor to process Personal Data on the Controller's behalf.
- "End User" means a natural person whose age eligibility is verified through the Services on the Controller's behalf.
- "Verification Session" means a single age verification request initiated via the API.
2. Subject Matter and Duration
The Processor shall process Personal Data on behalf of the Controller for the purpose of providing the Services described in the Terms of Service. Processing commences when the Controller first uses the Services and continues until termination of the Terms of Service, after which the Processor shall delete or return Personal Data as set out in Section 7.6 of this DPA.
3. Nature and Purpose of Processing
The Processor processes Personal Data to:
- Initiate, route, and complete Verification Sessions on behalf of the Controller;
- Return verification outcome data to the Controller via webhook or API polling;
- Maintain audit and compliance records as configured by the Controller's retention mode setting;
- Detect fraud, abuse, and technical errors within the Services;
- Provide support and dispute resolution to the Controller.
The Processor does not use End User Personal Data to train machine learning models, build profiles, or for any purpose other than providing the Services.
4. Categories of Personal Data
The Processor processes the following categories of Personal Data:
- Age eligibility outcome — a boolean indicating whether the End User's age met the configured threshold (e.g.,
age_over_threshold: true); - Session metadata — session ID, timestamp, country code, language, age threshold, verification method, assurance level, provider identifier, and policy version;
- Webhook delivery records — HTTP status, attempt count, and delivery timestamps;
- Audit log entries — when Audit retention mode is enabled.
The Processor does not store names, exact dates of birth, passport or national ID images, biometric data, or any document-level personal data in its production database. Such data may be transiently processed by the integrated identity provider (Sub-Processor) during the verification flow and is not retained by the Processor.
5. Categories of Data Subjects
The data subjects are End Users — natural persons who initiate an age verification flow on the Controller's platform. The Processor does not independently know the identity of data subjects; each End User is represented only by an anonymous session identifier.
6. Controller's Obligations
The Controller shall:
- Ensure it has a lawful basis for processing under GDPR for initiating Verification Sessions;
- Provide End Users with appropriate transparency information (privacy notice) about age verification, including the identity of the Processor and the Sub-Processors listed in Section 8;
- Comply with applicable age verification regulations in all jurisdictions where the Services are used;
- Promptly notify the Processor of any data subject requests, regulatory enquiries, or data breaches that relate to Processor-processed data;
- Configure the appropriate retention mode in the dashboard to reflect their GDPR obligations.
7. Processor's Obligations
7.1 Processing on Instructions
The Processor shall process Personal Data only on documented instructions from the Controller, as set out in this DPA and the Terms of Service, unless required to do so by Union or Member State law. The Processor shall inform the Controller if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.
7.2 Confidentiality
The Processor shall ensure that persons authorised to process Personal Data are bound by appropriate obligations of confidentiality and have received relevant data protection training.
7.3 Security (GDPR Art. 32)
The Processor implements and maintains appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256);
- SHA-256 hashing of API Keys — raw keys are never stored;
- HMAC-SHA256 webhook signatures to verify payload integrity;
- Row-level security and access controls on the database;
- Infrastructure hosted exclusively within the EEA (Frankfurt / Ireland);
- Regular security reviews and dependency audits.
7.4 Sub-Processors (GDPR Art. 28(2))
The Controller provides general written authorisation for the Processor to engage Sub-Processors listed in Section 8. The Processor shall notify the Controller of any intended changes to that list at least 30 days in advance by updating this page and/or emailing registered account holders. The Controller may object to a new Sub-Processor within 14 days; if the parties cannot resolve the objection, either party may terminate the affected Services with 30 days' notice.
The Processor imposes data protection obligations on Sub-Processors that are equivalent to those in this DPA, and remains liable for the acts and omissions of its Sub-Processors.
7.5 Assistance with Data Subject Rights
The Processor shall assist the Controller in fulfilling its obligations under Chapter III of the GDPR (data subject rights). Given the minimal data retained and the anonymous session-based architecture, most data subject requests can be fulfilled by the Controller using the session data available in the developer dashboard or via the compliance export API.
The Processor shall respond to Controller requests to delete, correct, or retrieve specific session records within 30 days. Contact privacy@ageverifyeu.com.
7.6 Deletion and Return
On termination of the Terms of Service, the Processor shall, at the Controller's choice, delete or return all Personal Data and delete existing copies within 90 days, unless Union or Member State law requires retention. The Controller may export session data from the dashboard Compliance page prior to termination.
During the Services, the Controller may configure Strict Privacy Mode to delete session parameters immediately after webhook delivery, retaining only anonymised billing counters.
7.7 Audit and Cooperation
The Processor shall make available all information necessary to demonstrate compliance with GDPR Article 28 and allow for and contribute to audits conducted by the Controller or a mandated auditor, subject to reasonable prior notice (minimum 14 days), confidentiality obligations, and cost-sharing for audits beyond one per year.
The Processor shall also assist the Controller in ensuring compliance with Articles 32–36 (security, breach notification, DPIA, prior consultation).
7.8 Data Breach Notification
The Processor shall notify the Controller without undue delay (and in any event within 72 hours of becoming aware) of a personal data breach involving Controller Personal Data, and shall provide sufficient information to allow the Controller to meet its own regulatory notification obligations.
8. Sub-Processor List
The following Sub-Processors are currently authorised to process Controller Personal Data:
| Sub-Processor | Role | Data location | Transfer mechanism |
|---|---|---|---|
| Railway | Database & compliance file storage | EU (Ireland/Germany) | EEA — no transfer |
| Railway | API & worker hosting | EU (Frankfurt) | EEA — no transfer |
| Cloudflare | CDN & static routing | Global edge | SCCs (EU approved) |
| Stripe | Billing & invoicing | EU (Ireland) | EEA — no transfer |
| EUDI / national wallets | High-assurance age verification (e.g. France Identité) | EU | EEA — no transfer |
Changes to this list are notified via this page and email at least 30 days in advance.
9. International Transfers
The Processor's production infrastructure is hosted within the EEA. Cloudflare's global CDN may route TLS-terminated requests through edge nodes outside the EEA; Cloudflare participates in the EU–US Data Privacy Framework and is covered by Standard Contractual Clauses.
No other international transfers of Personal Data outside the EEA are made without adequate safeguards as required by Chapter V of the GDPR.
10. Liability
Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. The Processor shall be liable to the Controller for damages caused by processing that has not complied with the obligations of this DPA specifically directed to the Processor, or where it has acted outside or contrary to the Controller's lawful instructions.
11. Governing Law
This DPA is governed by the laws of Germany. In the event of a conflict between this DPA and the Terms of Service regarding data protection matters, this DPA prevails.
12. Contact and Signed Copies
By accepting the Terms of Service in the developer dashboard, the Customer agrees to this DPA on behalf of their organization. The timestamp of acceptance is recorded and stored in your organization settings.
For privacy enquiries or to request a countersigned PDF copy:
[COMPANY LEGAL NAME]
[REGISTERED ADDRESS LINE 1]
[CITY, POSTAL CODE, GERMANY]
privacy@ageverifyeu.com