Data Processing Agreement
Draft template. A data-protection lawyer must review this before it is final. It is published for transparency and describes the system's real architecture.
Roles
- Controller: the B2B customer (issuer or verifying organization).
- Processor: Glemo. It processes credentials and verifications on the controller's instructions; it does not decide purposes or means.
Subject and duration
Issuing, cryptographic anchoring, verification, and aggregate analytics of verifiable credentials, for as long as the controller's account is active.
Data categories
- Credential holders: email (the credential subject identifier), name in claims, achievements.
- Controller's users: account email.
- Never on-chain: only keyed hashes.
Technical and organizational measures
- Keyed commitments per credential; PII never leaves for attestation backends.
- Right to erasure: key destruction plus off-chain scrub, audited in the erasure log.
- Encryption in transit (TLS); issuer keys in a KMS; hashed API keys.
- Retention: data lives while the credential is active; backups rotate on the stated window.
Subprocessors
| Subprocessor | Function | Data |
|---|---|---|
| Managed Postgres provider | Primary storage | All off-chain data |
| Resend | Credential email delivery | Holder email |
| Stripe | Customer billing | Customer billing data |
| Avalanche (public network) | Anchoring | Keyed hashes only, no PII |
Assistance to the controller
Rights requests (access, erasure): Glemo runs the technical erasure (72 h SLA) on the controller's instruction.
Breach notification
Without undue delay, and no later than 48 h after internal confirmation.