Legal information
Data processing agreement
The terms under which IRON ID Group processes personal data on behalf of a customer organization.
Last updated [DATE]
DraftThese documents are drafted and complete, but the contracting entity is being incorporated and counsel has not signed them off yet. Three points remain explicitly open and are marked in the text: the entity and the governing law, the liability cap in the terms of service, and the identity of the data protection officer.
1.Roles and subject matter
When you use the services to process personal data, you are the controller and IRON ID Group, [LEGAL ENTITY NAME], is the processor.
This agreement supplements the terms of service. Where the two conflict on the processing of personal data, this agreement prevails.
2.Duration of processing
Processing lasts as long as the main contract, plus the thirty-day export period provided on termination.
Confidentiality and security obligations survive the end of the contract for as long as IRON ID holds data on your behalf.
3.Documented instructions
IRON ID processes data only on the controller's documented instructions. Using the services constitutes the initial instruction; any further instruction is given in writing.
If an instruction appears to us contrary to the applicable law, we inform you without delay and may suspend its execution until the point is clarified.
4.Categories of data and of data subjects
Processing covers the following categories, determined by the use you make of the services:
- Data subjects: members of your organization, invited external collaborators, correspondents, and — for the KYC SDK — the people whose verification you request.
- Identification data: name, email address, job title, team membership.
- Authentication data: hashed passwords, multi-factor factors, sessions, devices.
- Deposited content: documents and their metadata, as you upload them.
- Verification data (KYC SDK): identity documents, extracted data, check results, reviewer decisions.
- Log data: actions taken, timestamps, technical context.
5.Confidentiality of personnel
People authorised to process the data are bound by a contractual confidentiality obligation, and access only the data their task requires.
Technical access to production environments is limited, named, and recorded in the audit log.
6.Technical and organisational measures
The following measures are in place and described in detail on the security page:
- Encryption at rest with AES-256-GCM, with a distinct data key per version, wrapped by a key management service that never sees the content.
- Encryption of communications in transit.
- Isolation between organizations enforced by row level security in the database, in addition to the application filter.
- An append only audit log, protected by SQL permissions and a database trigger, Merkle chained with sealed checkpoints.
- Multi-factor authentication, session and device management, scoped and revocable API keys.
- Separation of key purposes: six purposes, six distinct non-exportable keys, with the certificate authority root kept offline.
- Web application firewall, DDoS mitigation and rate limiting at the edge.
7.Sub-processors
You authorise IRON ID to use the sub-processors listed in the privacy policy: Scaleway for hosting, storage and key management; Cloudflare at the edge; Resend for transactional email.
Any addition or replacement is notified to you thirty days before it takes effect. You may object on reasonable data protection grounds; failing a solution, you may terminate without penalty.
IRON ID imposes on each sub-processor protection obligations at least equivalent to those of this agreement and remains responsible for their performance.
8.Assistance to the controller
IRON ID assists you, so far as technically possible, in answering data subject requests. The platform offers access, rectification, export and erasure directly.
We also assist with your impact assessments and prior consultations, by providing the information we hold on the architecture and the security measures.
9.Breach notification
IRON ID notifies you of any personal data breach without undue delay after becoming aware of it, and in any event within a period that lets you meet the deadline your own applicable law imposes, according to the deployment model in place.
The notification describes the nature of the breach, the categories and approximate volume of data and of people concerned, the likely consequences, and the measures taken or proposed.
10.Transfers
Data is hosted in France, in region fr-par, outside the reach of the Cloud Act. No transfer takes place to another country beyond the listed sub-processors and the contractual safeguards that govern them.
Where a sovereign deployment is agreed, the data region and the applicable sub-processors are set by the corresponding quotation.
11.Deletion or return
At the end of the contract you have thirty days to export all data in an open, documented format. After that period, IRON ID deletes the data according to the retention periods in the privacy policy.
Proof data — fingerprints, timestamps, audit entries — remains on the terms described in clause 5 of the privacy policy, because otherwise the proofs already issued would stop being verifiable.
12.Audit
IRON ID makes available the information needed to demonstrate compliance with this agreement, and submits to audits, including inspections, carried out by you or by a mandated auditor bound by confidentiality.
Save for an incident or an authority's requirement, audits take place at most once a year, on thirty days' notice, during business hours, and without compromising the security of other customers' data.
13.Governing law
The contracting entity and the law governing this agreement will be stated here together with those of the terms of service, before the services become commercially available. [TO BE COMPLETED BY LEGAL COUNSEL]
Get started
See IRON ID for your organization.
Request a demo of the Platform, join early access to be onboarded in the first cohorts, or request a quote for a KYC or Sign SDK integration.
Reply within two business days · contact@iron-id.io