Data Processing Addendum
The terms under which Certivo processes personal data on behalf of customers. This DPA forms part of the agreement between Certivo and the customer. This is a template for evaluation and must be reviewed by counsel before production use.
1. Roles of the parties
For personal data relating to a customer's end users, the customer is the controller and Certivo is the processor. Each party complies with applicable data-protection law in respect of its role.
2. Scope & instructions
Certivo processes personal data only on the customer's documented instructions, including as set out in this DPA and the Order Form, unless required otherwise by law (in which case Certivo notifies the customer where legally permitted). The subject matter, duration, nature and purpose of processing, and the categories of data and data subjects, are described in Annex A.
3. Confidentiality of personnel
Certivo ensures that personnel authorised to process personal data are bound by appropriate confidentiality obligations and are trained on their data-protection responsibilities.
4. Security measures
Certivo implements the technical and organisational measures described in Annex B and on our Security page, appropriate to the risk of the processing.
5. Sub-processing
The customer grants a general authorisation for Certivo to engage sub-processors to deliver the Services. Certivo maintains a current list of sub-processors on our Sub-processors page, imposes data-protection terms on them consistent with this DPA, remains responsible for their performance, and provides advance notice of changes with an opportunity to object.
6. Data-subject requests
Taking into account the nature of the processing, Certivo assists the customer with appropriate technical and organisational measures to respond to data-subject requests to exercise their rights.
7. Personal-data-breach notification
Certivo notifies the customer without undue delay after becoming aware of a personal-data breach affecting the customer's data, and provides reasonable information to assist the customer in meeting its own notification obligations.
8. Deletion & return
On termination or expiry of the Services, Certivo deletes or returns the customer's personal data at the customer's choice, and deletes existing copies unless retention is required by law.
9. Audits & information
Certivo makes available information reasonably necessary to demonstrate compliance with this DPA and, subject to confidentiality and reasonable notice, allows for and contributes to audits conducted by the customer or an appointed auditor.
10. International transfers
Where processing involves a transfer of personal data across borders, the parties rely on an appropriate transfer mechanism such as the Standard Contractual Clauses or an applicable adequacy decision.
Annex A — Details of processing
| Subject matter | Provision of the Certivo compliance platform to the customer. |
| Duration | For the term of the Services and any wind-down period. |
| Nature & purpose | Identity verification, AML/sanctions screening, KYB, monitoring and case management. |
| Categories of data | Identifiers, contact details, identity-document and biometric/liveness data, screening and KYB results. |
| Categories of data subjects | The customer's end users, applicants and business counterparties. |
Annex B — Technical & organisational measures
Measures include encryption in transit and at rest, role-based access control with least-privilege, tenant isolation, append-only audit logging, secure development practices, vulnerability management, and business-continuity backups. These are described further on our Security page.
Company details
| Registered entity name | [Registered entity name] |
| Company number | [Company number] |
| Registered office | [Registered office] |
| Group | OnyxOne Group |
| General enquiries | hello@certivo.example |
Bracketed values are placeholders to be completed by the operating entity before this document is published or executed.
Last updated: 20 July 2026. Version 1.0 (evaluation template).
This document is a template maintained by Certivo and should be reviewed by qualified counsel before execution in a specific jurisdiction. It does not constitute legal advice.