Processor terms
Under legal review. This document describes the system's real architecture and is published for transparency while counsel finalizes the wording. Questions: privacy@glemo.io.
Clauses that fix Glemo's role as a processor (not a controller) in the B2B terms of service:
- Documented instructions. Glemo processes personal data only to issue, anchor, and verify credentials on the customer's instruction (the API calls are the documented instruction).
- No own purposes. Glemo does not use holder data for its own purposes; analytics and reputation run on aggregates without claims.
- Confidentiality. Staff with access are under a confidentiality duty; production access is restricted and audited.
- Subprocessors. A public list (see the DPA); changes are notified 30 days ahead for objection.
- Holder rights. Glemo runs the technical erasure (CNIL pattern) on the customer's instruction within the SLA; the customer answers to the holder.
- Return or deletion at contract end. Export of the customer's credentials plus deletion of personal data; on-chain anchors become unlinkable through key destruction.
- Audit. Reasonable information to demonstrate compliance (erasure log, CI security gates, compliance docs).