Data Processing Agreement
This DPA governs attest’s processing of Personal Data on behalf of a Customer.
Effective date: August 26, 2026
1. Parties and scope
This DPA supplements the Terms between attest as Processor and the accepting Customer as Controller. It applies when attest processes Personal Data on Customer’s behalf. It controls over the Terms for conflicting data-processing matters.
2. Definitions
Personal Data is information relating to an identified or identifiable natural person. Processing includes receiving, organizing, storing, retrieving, using, disclosing, returning, and erasing Personal Data. Data Protection Law means applicable privacy and data-protection law, including GDPR, UK GDPR, and CCPA where applicable. Other defined terms have the meanings in the Terms.
3. Roles and documented instructions
Customer determines purposes and means and what metadata to submit. attest processes Personal Data only on Customer’s documented instructions embodied in the Terms, this DPA, and Customer’s supported use of the Service. attest will promptly inform Customer if an instruction infringes applicable Data Protection Law. Processing required by law will be disclosed beforehand unless the law prohibits notice.
4. Purpose and minimization
attest processes only to operate, secure, support, and meter the Service as specified in Schedule 1. Customer will submit only necessary information and represents that it has a lawful basis, required notices, rights, and instructions. attest is not general-purpose content storage and does not need raw sensitive payloads to function.
5. Subprocessors
Customer generally authorizes these subprocessors:
| Provider | Function | Processing location |
|---|---|---|
| Render | Application hosting and infrastructure | United States |
| Managed PostgreSQL via Render | Account, verification, and usage persistence | United States |
| Stripe, Inc. | Payments, subscriptions, and usage metering | United States |
| Resend | Transactional account and security email | United States processing |
attest will provide at least 30 days’ notice by account email or an updated public list before a new subprocessor processes Customer Personal Data. Customer may object within that period on reasonable data-protection grounds. The parties will work in good faith; if unresolved, Customer may terminate the affected Service without penalty. Each subprocessor must have no less protective applicable obligations, and attest remains responsible for its subprocessor obligations under this DPA.
6. Security measures
attest maintains measures appropriate to the processing: TLS in transit; access limited to authorized personnel with operational need; environment-scoped API authentication; logical Production and Sandbox isolation; operational logging designed to avoid credentials, authentication headers, and raw sensitive payloads; replay and duplicate protection; durable database persistence; and confidentiality obligations for authorized personnel. Measures will be reviewed as risks and technology change and will not be materially reduced during the term without notice. Security is not represented as impenetrable, and no certification is promised.
7. Data-subject assistance
attest will promptly notify Customer of a data-subject request unless prohibited and will not independently respond unless authorized or legally required. Taking account of the processing, attest will provide commercially reasonable assistance with access, rectification, erasure, restriction, portability, objection, and Customer’s response obligations. Assistance may use supported search or export functionality or a request through applicable account or support controls; this does not promise self-service record deletion.
8. Data Breach
If attest becomes aware of accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, attest will notify Customer without undue delay and in any event within 72 hours. To the extent known, notice will describe the nature and approximate scope, likely consequences, mitigation taken or proposed, and a Service contact point. attest will reasonably cooperate with investigation and legally required notifications. Notice is not an admission of fault.
9. International transfers
Current infrastructure processing is United States-based. Transfers from the EEA, UK, or Switzerland will use safeguards required by applicable law. If required, the parties will execute the European Commission Standard Contractual Clauses, Module Two, and/or the UK International Data Transfer Addendum through the support channel made available through the Service. This DPA does not claim those instruments are already executed.
10. Information and audit rights
attest will provide information reasonably necessary to demonstrate compliance and respond to reasonable requests within 30 days. Where information is insufficient, attest will cooperate with a mutually agreed independent auditor at Customer expense, on reasonable notice, subject to scope, security, and confidentiality controls. Audits may not unreasonably disrupt operations and are limited to once per 12 months unless law requires more or a specific Data Breach warrants it.
11. Return, retention, and deletion
Verification Records are retained during active Service. Following termination they remain available under a 90-day export window, then are deleted unless law or a valid legal hold requires retention. On written request, attest will delete or return Personal Data subject to that window and legal obligations and confirm deletion in writing. Billing and usage records may be retained for up to seven years for tax and accounting requirements.
12. Confidentiality
Personnel authorized to process Personal Data are bound by contractual or statutory confidentiality obligations. Access to Customer event metadata is limited to personnel who require it to operate, secure, maintain, or support the Service.
13. Duration and governing law
This DPA lasts while attest processes Customer Personal Data, including the export window, and ends when deletion obligations finish. Virginia law governs as provided in the Terms except where mandatory Data Protection Law supersedes it.
Schedule 1 — Processing details
- Subject matter
- Operation of the attest machine-activity verification Service.
- Duration
- The Customer relationship plus applicable export, deletion, legal-hold, and statutory-retention periods.
- Nature and purpose
- Receiving, normalizing, verifying, persisting, retrieving, reporting, exporting, securing, and metering submitted machine-event metadata as required to provide the Service.
- Categories of data subjects
- Only where Personal Data is actually submitted: Customer account users; Customer personnel; and individuals identifiable from event metadata submitted by Customer.
- Categories of Personal Data
- Only to the extent collected or submitted: account identity/contact data; organization/account information; security/session information; IP/server information where collected; machine-event metadata that may contain Personal Data; and billing/usage identifiers and records.
- Special-category and highly sensitive data
- attest is not designed to require it. Customer should not submit sensitive content unless necessary, lawful, and supported by the Service. The Service does not need medical records, legal documents, credentials, financial account numbers, or raw confidential payloads.