Data Processing Agreement
Under legal review. This document describes the system's real architecture and is published for transparency while counsel finalizes the wording. Questions: privacy@glemo.io.
Roles
- Controller: the B2B customer (issuer or verifying organization).
- Processor: Glemo. It processes credentials and verifications on the controller's instructions; it does not decide purposes or means.
Subject and duration
Issuing, cryptographic anchoring, verification, and aggregate analytics of verifiable credentials, for as long as the controller's account is active.
Data categories
- Credential holders: email (the credential subject identifier), name in claims, achievements.
- Controller's users: account email.
- Never on-chain: only keyed hashes.
Technical and organizational measures
- Keyed commitments per credential; PII never leaves for attestation backends.
- Right to erasure: key destruction plus off-chain scrub, audited in the erasure log.
- Encryption in transit (TLS); issuer keys in a KMS; hashed API keys.
- Retention: data lives while the credential is active; backups rotate on the stated window.
Subprocessors
| Subprocessor | Function | Data |
|---|---|---|
| Managed Postgres provider | Primary storage | All off-chain data |
| Resend | Credential email delivery | Holder email |
| Paddle | Customer billing (merchant of record) | Customer billing data |
Assistance to the controller
Rights requests (access, erasure): Glemo runs the technical erasure (72 h SLA) on the controller's instruction.
Breach notification
Without undue delay, and no later than 48 h after internal confirmation.