We're choosing our first design partners Join them

Data Processing Agreement

Draft template. A data-protection lawyer must review this before it is final. It is published for transparency and describes the system's real architecture.

Roles

  • Controller: the B2B customer (issuer or verifying organization).
  • Processor: Glemo. It processes credentials and verifications on the controller's instructions; it does not decide purposes or means.

Subject and duration

Issuing, cryptographic anchoring, verification, and aggregate analytics of verifiable credentials, for as long as the controller's account is active.

Data categories

  • Credential holders: email (the credential subject identifier), name in claims, achievements.
  • Controller's users: account email.
  • Never on-chain: only keyed hashes.

Technical and organizational measures

  • Keyed commitments per credential; PII never leaves for attestation backends.
  • Right to erasure: key destruction plus off-chain scrub, audited in the erasure log.
  • Encryption in transit (TLS); issuer keys in a KMS; hashed API keys.
  • Retention: data lives while the credential is active; backups rotate on the stated window.

Subprocessors

SubprocessorFunctionData
Managed Postgres providerPrimary storageAll off-chain data
ResendCredential email deliveryHolder email
StripeCustomer billingCustomer billing data
Avalanche (public network)AnchoringKeyed hashes only, no PII

Assistance to the controller

Rights requests (access, erasure): Glemo runs the technical erasure (72 h SLA) on the controller's instruction.

Breach notification

Without undue delay, and no later than 48 h after internal confirmation.

Data Processing Agreement · Glemo