Important: This version takes effect on November 30, 2026. It applies to new Subscriptions from that date, and to existing Subscriptions from their next renewal on or after that date, unless a signed agreement or counter-signed Order Form provides otherwise. Until it applies to a Subscription, the previous version continues to govern that Subscription — view the previous version.

Data Processing Addendum

Version 2.0 • Nov 30, 2026     View Previous Versions


This Data Processing Addendum (this “Addendum”) forms part of the Master Service Agreement between ID123 Inc. (the “Service Provider”) and the party subscribing to the Services (“Client”), or of any other agreement between the Parties that incorporates this Addendum by reference (together with the MSA, the “Agreement”), and governs the Service Provider’s Processing of Personal Data in its capacity as Processor in connection with the Services. Where the Parties have entered into a separate data processing agreement, that agreement governs the matters it addresses, and this Addendum applies to any matter it does not address.

Capitalized terms not defined in this Addendum have the meanings given in the MSA. In the event of conflict, the order of precedence in Section 1.3 of the MSA applies.

1. Roles, Scope and Interpretation

1.1 Roles. Client is the Controller and the Service Provider is the Processor in respect of the Personal Data Processed under the Agreement, save where Section 1.3 applies. Where Client is itself a Processor acting on behalf of a third-party Controller, Client warrants that it is authorized to appoint the Service Provider as a sub-processor and to give the instructions set out in this Addendum, and references in this Addendum to Client as Controller are to be read accordingly.

1.2 Identity of the Controller. The Controller is the Customer of Record as defined in the MSA. Where a dispute arises as to the identity of the Controller, the Service Provider will continue to Process Personal Data in accordance with this Addendum and the last instructions received from an authorized administrator, and will apply Section 7.1.4 of the MSA.

1.3 Business Contact Information. Business contact details of Client’s representatives, agents, partners and referrals are Processed in one of two capacities, determined by the purpose of the Processing.

1.3.1 Provided by Client, Processed as Processor. Where Client provides the Service Provider with the business contact details of its representatives, agents, partners or referrals, including name, business email address and business telephone number, the Service Provider Processes those details on Client’s behalf in order to authenticate those individuals, administer Client’s Account, and communicate with them in connection with the provision and support of the Services. That Processing is described in Appendix 1 and is subject to this Addendum in full. The Service Provider will not use business contact details provided by Client under this Section for its own selling, promotional or marketing purposes. Where an individual separately provides their details to the Service Provider directly, Section 1.3.2(a) applies to those details.

1.3.2 Processed as independent Controller. The Service Provider Processes business contact details as an independent Controller, and not on Client’s behalf, where: (a) an individual provides their business contact details to the Service Provider directly, for example by registering for an Account, requesting a demonstration, or submitting a form on the Service Provider’s website; or (b) the Service Provider Processes business contact details obtained otherwise than under Section 1.3.1, including details obtained from a public source, an event, or a referral, for its own purposes of selling, invoicing, promoting or administering its relationship with Client. That Processing is carried out for account administration, service communications and marketing, is described in the Service Provider’s privacy notice, and is governed by that notice and by applicable Data Protection Law rather than by Sections 2 to 13 of this Addendum. An individual may opt out of marketing communications at any time.

1.3.3 The Service Provider does not Process Sensitive Data in either capacity described in this Section.

1.4 Terminology. The terms “personal data”, “data subject”, “processing”, “controller”, “processor” and “supervisory authority” bear the meanings given to them under applicable Data Protection Law. Where a management system standard addressing privacy information management is applied to the Services, the terms “PII”, “PII Controller”, “PII Processor” and “PII Principal” have the same meanings as “Personal Data”, “Controller”, “Processor” and “data subject” respectively in this Addendum, and the obligations of the Service Provider set out in this Addendum constitute its obligations as a PII Processor.

1.5 Jurisdiction-Specific Terms. Appendix 4 sets out terms that apply only where Personal Data is subject to the Data Protection Law of a particular jurisdiction. Those terms apply automatically, without further action by either Party, to the extent that law applies to the Processing, and prevail over the body of this Addendum in respect of that Processing. Client is not required to elect which Part of Appendix 4 applies.

2. Processing of Personal Data

2.1 Documented Instructions. The Service Provider will Process Personal Data only on Client’s documented instructions, including in relation to transfers of Personal Data to a third country, unless required to Process it by a law to which the Service Provider is subject. Where the Service Provider is so required, it will inform Client of that legal requirement before Processing, unless the law prohibits it from doing so on important grounds of public interest.

2.2 Form of Instructions. Client’s documented instructions comprise: (a) the terms of the Agreement, including this Addendum, the applicable Product Addendum and any Order Form; (b) Client’s configuration of the Services through the administrative interfaces made available to it, including its selection of Data Region, retention settings, data fields, and administrator permissions; and (c) written instructions submitted by an authorized administrator of Client to the privacy contact address published by the Service Provider or through the support channels provided under the Agreement.

2.3 Record of Instructions. Written instructions submitted under Section 2.2(c) are retained by the Service Provider for the duration of the Agreement. Administrative activity within the Services, including configuration changes made by Client, is logged and made visible to Client in accordance with the applicable Product Addendum and the published retention schedule.

2.4 Unlawful Instructions. If the Service Provider reasonably believes that an instruction from Client infringes applicable Data Protection Law, it will promptly notify Client and may suspend the affected Processing until Client confirms, amends or withdraws the instruction. Any suspension under this Section is limited to the Processing affected by the instruction in question, and the Service Provider will not suspend any other part of the Services on that basis.

2.5 Scope in the Absence of Instructions. In the absence of specific written instructions, the Service Provider will Process Personal Data solely in accordance with the Agreement, this Addendum, and Client’s configuration of the Services.

2.6 Purpose Limitation. The Service Provider will not Process Personal Data for any purpose other than performing the Services and its obligations under the Agreement. Without limiting the foregoing, the Service Provider will not, and will ensure that its personnel and Sub-processors do not, use, access, analyse or derive from Personal Data for: (a) profiling, advertising or marketing; (b) benchmarking, or the creation of comparative or aggregate datasets spanning the Service Provider’s customers; or (c) product development. The Service Provider will not disclose Personal Data to any third party for any such purpose. The Service Provider will not use Personal Data for the training, fine-tuning, evaluation or development of artificial intelligence or machine learning models except with Client’s prior written consent, and where such consent is given, only using that Client’s Personal Data and only for the purpose of providing the Services to that Client. The Service Provider will not transmit Personal Data to any third-party artificial intelligence or machine learning service unless that service is listed as a Sub-processor and is contractually prohibited from using the Personal Data to train or improve its models. Any retention of Personal Data by such a service is limited to what is necessary to perform the function requested and to meet that service’s own security, abuse-monitoring and legal obligations. Information on the retention period applicable to each such service is available on request and may also be published in the Sub-processor list.

2.7 Preserved Processing. Nothing in Section 2.6 restricts the Service Provider’s use of System Data, or of De-identified Data created and used as permitted by Section 7.4.3 of the MSA, or the Service Provider’s Processing of Personal Data to detect security incidents, prevent fraud, provide support to Client, or maintain the security, integrity and operation of the Services.

2.8 Sale and Retention Restrictions. The Service Provider will not sell, rent, release, disclose, disseminate, make available, transfer or otherwise communicate Personal Data to a third party for monetary or other valuable consideration, and will not share Personal Data for cross-context behavioral advertising. The Service Provider will not retain, use or disclose Personal Data outside the direct business relationship between the Parties or for any commercial purpose other than performing the Services. The Service Provider certifies that it understands and will comply with these restrictions.

2.9 Automated Processing. Automated Processing performed within the Services is described in the applicable Product Addendum. Such Processing does not constitute a decision based solely on automated Processing producing legal effects concerning a data subject or similarly significantly affecting them. Client retains the ability to review and override the outcome of such Processing and is responsible for making a route to human review available to data subjects.

2.10 Sensitive Data. Client will inform the Service Provider where Personal Data submitted to the Services constitutes Sensitive Data, and will obtain any consent or establish any other condition for Processing required under applicable Data Protection Law before submitting it. The categories of Sensitive Data the Services are designed to Process, and the purposes for which they are Processed, are set out in Appendix 1.

3. Confidentiality of Personnel

3.1 The Service Provider will restrict access to Personal Data to those of its personnel who require it in order to provide the Services, on a least-privilege basis, and will ensure that access is scoped by role and, where applicable, by geography.

3.2 The Service Provider will ensure that persons authorized to Process Personal Data are bound by an appropriate obligation of confidentiality, whether contractual or statutory, that survives the termination of their engagement. The Service Provider will not publish, disclose or divulge Personal Data to any third party except as permitted by this Addendum or on Client’s instruction.

3.3 The Service Provider will conduct background verification checks on personnel who will have access to Personal Data, to the extent permitted by applicable law, and will provide information security and data protection training to such personnel periodically.

4. Security of Processing

4.1 Technical and Organizational Measures. The Service Provider will implement and maintain the technical and organizational measures described in Appendix 2, designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, as well as the risk to data subjects. Those measures will be at least as protective as the security requirements set out in the Agreement.

4.2 Changes to Measures. The Service Provider may update the measures described in Appendix 2 from time to time, provided that no update materially diminishes the overall level of security afforded to Personal Data.

4.3 Client Responsibilities. Client is responsible for its own configuration of the Services, for the provisioning and de-provisioning of its administrator and User accounts, for the authentication policy applied where Client uses its own identity provider, and for assessing whether the measures in Appendix 2 are appropriate to the risks presented by its own Processing.

5. Sub-processors

5.1 General Authorization. Client grants the Service Provider general authorization to engage sub-processors to assist in providing the Services (each a “Sub-processor”). A current list of Sub-processors, including the identity of each Sub-processor, the purpose for which it is engaged, and the country in which it Processes Personal Data, is published at https://www.id123.io/terms/dpa/subprocessors/, or any successor address the Service Provider notifies to Client, and incorporated into this Addendum as Appendix 3.

5.2 Notification and Objection. The Service Provider will notify Client in writing, by email to the notice address on Client’s account, of any intended addition to or replacement of a Sub-processor at least fourteen (14) days before that Sub-processor begins Processing Personal Data. The Service Provider will also make an email subscription available at the address at which the Sub-processor list is published. Client may object to an intended change on reasonable grounds relating to data protection by written notice given within that fourteen-day period. The Service Provider will not appoint the objected-to Sub-processor in respect of Client’s Personal Data while the Parties are working in good faith to resolve the objection. Where the objection is not resolved within a reasonable period, Section 5.3 applies.

5.3 Consequence of Unresolved Objection. If the Parties cannot resolve an objection in good faith, either Party may terminate the affected Subscription by written notice. Termination on this basis is without penalty or early termination charge, and the Service Provider will refund to Client any Fees prepaid, prorated for the unused portion of the Subscription.

5.4 Flow-Down. The Service Provider will impose on each Sub-processor, by written contract, data protection obligations no less protective than those set out in this Addendum, including obligations relating to confidentiality, security measures, Personal Data Breach notification, assistance with data subject rights, limitations on the purposes of Processing, restrictions on onward transfer, and deletion or return of Personal Data.

5.5 Liability. The Service Provider remains fully liable to Client for the performance of each Sub-processor’s obligations, and for any act or omission of a Sub-processor, to the same extent as if the Service Provider had performed the relevant Processing itself.

5.6 Information. On written request, the Service Provider will provide Client with information regarding the data protection obligations imposed on a Sub-processor and the safeguards applied to any transfer of Personal Data to it.

6. Data Subject Rights

6.1 Self-Service. The Services include functionality enabling Client to access, correct, restrict, export and delete Personal Data relating to an individual data subject directly, without the involvement of the Service Provider. The Service Provider will maintain that functionality throughout the term of the Agreement.

6.2 Assistance. Taking into account the nature of the Processing, the Service Provider will assist Client by appropriate technical and organizational measures, insofar as this is possible, in fulfilling Client’s obligation to respond to requests from data subjects exercising their rights under applicable Data Protection Law. The Service Provider will provide such assistance without undue delay, taking into account the nature of the Processing and the information available to it.

6.3 Requests Received Directly. Client is responsible for responding to data subject requests. If the Service Provider receives a request directly from a data subject in relation to Personal Data Processed on Client’s behalf, the Service Provider will promptly inform Client, will not respond to the request substantively except on Client’s instruction or as required by law, and will direct the data subject to Client.

6.4 Charges. The Service Provider may charge Client for its reasonable time in providing assistance under this Section, and for costs incurred in any special arrangement requested by Client. The Service Provider will not charge Client for assistance with a data subject request that can be fulfilled through the standard functionality of the Services, nor for cooperation in connection with a Personal Data Breach attributable to the Service Provider.

7. Assistance with Assessments and Consultation

7.1 Taking into account the nature of the Processing and the information available to it, the Service Provider will provide Client with reasonable assistance in relation to: (a) Client’s obligation to ensure the security of Processing; (b) notification of a Personal Data Breach to a supervisory authority and to affected data subjects; (c) the conduct of a data protection impact assessment or equivalent assessment where required by applicable Data Protection Law; and (d) any prior consultation with a supervisory authority arising from such an assessment.

7.2 Such assistance may be provided by means of the documentation the Service Provider publishes or makes available, including its security documentation, sub-processor list, retention schedule, and the description of Processing in Appendix 1, where that documentation reasonably addresses the matter.

8. Personal Data Breach

8.1 Notification. After becoming aware of a Personal Data Breach, the Service Provider will notify Client promptly, and in any event no later than twenty-four hours after verifying the Personal Data Breach or seventy-two hours after discovering it, whichever is earlier. Notification will be given to Client’s account owner.

8.2 Content. The notification will describe, to the extent then available: (a) the nature of the Personal Data Breach, including where possible the categories and approximate number of data subjects and Personal Data records concerned; (b) the likely consequences of the Personal Data Breach; (c) the measures taken or proposed to be taken by the Service Provider to address it, including measures to mitigate its possible adverse effects; and (d) the name and contact details of the Service Provider’s responsible contact point. Where the full particulars are not available within the period in Section 8.1, the Service Provider will provide initial notification within that period and supply the remaining particulars in phases as they become available, without further undue delay.

8.3 Breach Report. The Service Provider will provide Client with a written report on the Personal Data Breach once its investigation has progressed sufficiently to do so, including the root cause where determined and the remediation completed and planned.

8.4 Investigation and Remediation. The Service Provider will immediately investigate the Personal Data Breach, take all reasonable steps to identify, contain, prevent and mitigate its effects, and carry out any recovery or other action necessary to remedy it. The Service Provider will provide Client with regular updates during the investigation.

8.5 Cooperation. At Client’s request, the Service Provider will promptly provide all reasonable assistance necessary to enable Client to notify competent authorities and affected data subjects where Client is required to do so under applicable Data Protection Law. The notification periods in this Section are set so as to enable Client to meet its own notification obligations.

8.6 No Admission. The Service Provider’s obligation to report or respond to a Personal Data Breach under this Section is not an acknowledgement by the Service Provider of fault or liability in respect of it.

9. Data Location and International Transfers

9.1 Data Region. The Service Provider will store Client’s Personal Data at rest only in the Cloud Provider Region selected by Client (the “Data Region”), save that replicas and backup copies may be held, and the Services operated from them, in another Cloud Provider Region in the same country as the Data Region or, where the Data Region is in the European Economic Area, in another country in the European Economic Area. Relocation of Personal Data at rest to a different Cloud Provider Region is governed by Section 3.3.2 of the MSA. That Section sets out when Client’s consent is required.

9.2 Permitted Processing Outside the Data Region. Processing of Personal Data outside the Data Region, other than as permitted by Section 9.1, is limited to the following, and the Service Provider will implement an applicable International Data Transfer Mechanism for each: (a) remote access by the Service Provider’s authorized support and engineering personnel, including personnel of its affiliates located outside the Data Region, on a least-privilege basis, limited to what is necessary to resolve a support request, investigate an incident, or maintain the Services, and subject to the access control and logging measures described in Appendix 2; (b) transfer necessary to comply with applicable law, subject to Section 7.9 of the MSA; (c) temporary Processing necessary to restore the Services following an outage affecting the Data Region, which does not include relocating Personal Data at rest to another Cloud Provider Region, and of which the Service Provider will notify Client without undue delay; and (d) any other transfer expressly authorized by Client in writing.

9.3 Sub-processor Location. Sub-processors engaged to store or Process the substantive Personal Data records held in Client’s account will do so within the Data Region, or in another Cloud Provider Region as permitted by Section 9.1. Sub-processors engaged for ancillary functions that do not involve storage of those records, including payment processing, customer relationship management, application performance monitoring, message delivery, and support ticketing and AI-assisted drafting and triage of support responses (limited to the content of support requests and any Personal Data that Client or its Users include in them), may Process limited Personal Data outside the Data Region, in each case subject to an applicable International Data Transfer Mechanism and as identified, with the country of Processing, in Appendix 3. Client should include in a support request only the Personal Data needed to resolve it.

9.4 Transparency. The Service Provider will maintain and publish current information identifying the Data Regions available, the country in which each is located, whether each is a physically or logically separated partition, and the countries from which Personal Data may be accessed under Section 9.2, and will make that information available to Client on request.

9.5 Transfer Mechanisms. Where a transfer of Personal Data requires an International Data Transfer Mechanism under applicable Data Protection Law, the mechanism specified in the relevant Part of Appendix 4 applies and is incorporated into this Addendum. Before Client transfers Personal Data to the Service Provider, or permits the Service Provider to access Personal Data located in a jurisdiction requiring such a mechanism, Client will verify that the relevant requirements are met. If they are not, the Parties will work together in good faith to fulfill them.

10. Government, Law Enforcement and Third Party Requests

10.1 Requests for access to or disclosure of Personal Data by any governmental, regulatory, judicial or law enforcement authority, or by any other third party, are governed by Sections 6.3 and 7.9 of the MSA.

11. Records of Processing

11.1 The Service Provider will maintain accurate and current records of the Processing activities it carries out on Client’s behalf, including the categories of Personal Data Processed, the purposes of Processing, the categories of recipients, the countries in which Personal Data is Processed, and a general description of the technical and organizational security measures applied.

11.2 The Service Provider will make those records available to a supervisory authority on request in accordance with applicable Data Protection Law. The information Client requires in order to maintain its own records of Processing activities is set out in Appendix 1, in Appendix 2, and in the published Sub-processor list.

12. Audits and Certifications

12.1 Right of Audit. The Service Provider will make available to Client all information reasonably necessary to demonstrate compliance with this Addendum and will allow for and contribute to audits, including inspections, conducted by Client or by an auditor mandated by Client. Audits are limited to the Service Provider’s Processing of Personal Data for Client and do not extend to any other aspect of the Service Provider’s business or information systems.

12.2 Notice and Frequency. Client will give the Service Provider not less than thirty days’ prior written notice of an audit, including a proposed audit plan and the identity of any third-party auditor. Any third-party auditor must be bound by written confidentiality obligations no less protective than those in the Agreement and must not be a competitor of the Service Provider. Audits will be conducted no more than once per calendar year, except that an additional audit may be conducted (a) following a confirmed Personal Data Breach attributable to the Service Provider, or (b) where required by a competent supervisory authority.

12.3 Conduct. Audits will be conducted during normal business hours, in a manner that minimizes disruption to the Service Provider’s operations, and subject to controls protecting the confidentiality and security of other customers’ data. Client will not use its audit rights to obtain access to the Service Provider’s source code, to the systems or data of other customers, or to information unrelated to the Processing of Client’s Personal Data. All findings are Confidential Information of the Service Provider.

12.4 Scope. Audit rights under this Section extend to the Service Provider’s privacy controls and its Processing of Personal Data, including: (a) compliance with this Addendum; (b) purpose limitation controls, being verification that Personal Data is Processed only for documented purposes; (c) retention and deletion practices, being verification that the published retention schedule is applied and that deletion is performed as committed; (d) Sub-processor oversight, being verification that Sub-processors are bound as required by Section 5.4 and that the published Sub-processor list is current; (e) fulfillment of data subject rights within committed timeframes; and (f) the records maintained under Section 7.9.4 of the MSA.

12.5 Report-Based Fulfillment. The Service Provider may satisfy its obligations under this Section by providing Client with one or more of the following, provided the materials reasonably demonstrate compliance with this Addendum: its current information security management system certificate and statement of applicability; any privacy information management system certificate or cloud privacy certificate then held by the Service Provider, together with the corresponding summary audit report; its cloud security program certification status; a summary of its most recent independent third-party penetration test; a completed standard industry security assessment questionnaire; and any other third-party audit report or certification then held. Where those materials do not address the matters Client reasonably needs to verify, Client retains the audit right set out in Section 12.1. Completion of Client’s own security questionnaires is addressed in Section 7.5.8 of the MSA.

12.6 Costs. Client bears the costs of an audit conducted under this Section, including the Service Provider’s reasonable staff time at an agreed hourly rate, except where the audit arises from a Personal Data Breach or other breach by the Service Provider of its obligations under this Addendum, in which case the Service Provider bears its own costs.

13. Deletion and Return

13.1 Election. On termination or expiry of the Services, and at Client’s election, the Service Provider will return Personal Data to Client in accordance with Section 10.3.2 of the MSA or delete it, and will delete existing copies, unless applicable law requires continued storage. Client may make its election at any time before termination and may specify a reasonable secure method and format for return, in which case Client is responsible for any additional cost arising from the method specified.

13.2 Production Systems. Personal Data is deleted from the Service Provider’s production systems on Client’s instruction and, following termination or expiry, within the periods set out in Section 10.3.3 of the MSA. The Service Provider publishes a retention schedule describing the periods it applies to each category of data. That schedule is provided for information, is updated from time to time to reflect current practice, and does not form part of this Addendum.

13.3 Backups. Personal Data contained in encrypted backup, disaster recovery and archival copies is not separately extractable. Such copies are deleted or overwritten in the ordinary course and in any event no later than twelve (12) months from the date of the original deletion instruction, return, or termination, whichever occurs first. During that period, backup copies remain encrypted, are not used for any Processing, are not accessed or used for any purpose other than restoration of the Services, and remain subject to the confidentiality and security obligations of this Addendum.

13.4 Method and Certification. Deletion is performed using methods aligned with recognized standards for media sanitization. The Service Provider will certify deletion in writing to Client on request.

13.5 Sub-processors. The Service Provider will relay Client’s deletion or return instruction to all Sub-processors.

13.6 No Retention for Own Purposes. The Service Provider will not retain Personal Data for its own purposes following termination or expiry of the Services. Where Personal Data cannot be deleted or returned because applicable law requires its retention, it will remain subject to the confidentiality, privacy and security obligations of this Addendum, will be isolated from active Processing and used for no purpose other than the retention required, and the Service Provider will notify Client of the requirement and the period for which it applies.

13.7 Anonymized Data. The Service Provider may retain De-identified Data created as permitted by Section 7.4.3 of the MSA. The Service Provider will not attempt to re-identify such data and will not permit any third party to do so.

14. Contact Points and Representatives

14.0 Representatives. Where required by applicable Data Protection Law, the Service Provider has designated representatives in the following territories. Enquiries relating to the Processing of Personal Data may be addressed to the relevant representative or to the Service Provider directly. The designation of a representative is without prejudice to any legal action that may be initiated against the Service Provider itself.

Territory Representative Address Email
European Union Engage Data Consulting B.V., trading as Engage Compliance Cruquiuskade 251, 1018 AM Amsterdam, Netherlands id123inc@engagecompliance.co
United Kingdom Engage Compliance UK Ltd, trading as Engage Compliance 124 City Road, London, EC1V 2NX, United Kingdom id123inc@engagecompliance.co

14.1 The Service Provider has designated a data protection officer, who may be contacted at the address published by the Service Provider for that purpose. The Service Provider will provide the name and role of the individual holding that position to Client on written request.

15. General

15.1 Compliance. Each Party will comply with its respective obligations under applicable Data Protection Law and with its own privacy notice.

15.2 Liability. The Service Provider’s liability under or in connection with this Addendum is subject to the exclusions and limitations on liability set out in the MSA, save to the extent applicable Data Protection Law does not permit those limitations to apply.

15.3 Conflicts. In the event of conflict between this Addendum and any other component of the Agreement, this Addendum prevails in respect of the Processing of Personal Data, save that a Part of Appendix 4 applicable to the Processing prevails over the body of this Addendum. Where individual provisions of this Addendum are invalid or unenforceable, the validity and enforceability of the remaining provisions is unaffected.

15.4 Changes. The Service Provider may update this Addendum where necessary to comply with applicable Data Protection Law or to reflect a change in the Services, provided no update materially diminishes the protection afforded to Personal Data. An updated Addendum takes effect on the renewal date of Client’s next Subscription period, or earlier by written agreement. Where this Addendum is incorporated by reference to a web address, the updated version will be posted at the same address and Client will be notified in writing. If Client does not agree to a material change, Client will notify the Service Provider in writing and the Parties will work together in good faith to agree a mutually acceptable position.

15.5 Term. This Addendum takes effect on the Effective Date of the Agreement and remains in force for as long as the Service Provider Processes Personal Data on Client’s behalf. The Service Provider’s obligations in relation to returning or deleting Personal Data survive termination until all Personal Data has been returned or deleted in accordance with Section 13.

Appendix 1 — Details of Processing

A. Parties

Data exporter: Client, acting as Controller, with the name, address and contact details provided to the Service Provider through the provision or support of the Services. Data importer: ID123 Inc., 100 Summer Street, Suite 1600, Boston, Massachusetts 02110, United States, acting as Processor.

B. Subject matter, nature and purpose

The Service Provider’s provision and support of the Services under the Agreement and the applicable Product Addendum, for the purpose of enabling Client to create, issue, manage, display and verify the credentials and records described in that Product Addendum.

C. Duration

The term of the Agreement, plus the period from expiry until the return, deletion or anonymization of Personal Data in accordance with Section 13. The periods applied to each category of Personal Data, and the criteria used to determine them, are described in the retention schedule published by the Service Provider at https://www.id123.io/terms/data-retention-deletion-schedule/, which is provided for information and updated from time to time to reflect current practice. The contractual limits are those set out in Section 13 of this Addendum and Section 7.2.4 of the MSA.

D. Frequency of transfer

Continuous.

E. Categories of data subjects

Individuals having a business, personal, membership, employment or institutional relationship with Client or with Client’s customers, including their end users, members, employees, contractors, students, volunteers, guests, patients, constituents, representatives and, where applicable, the parents or guardians of any of them.

F. Categories of Personal Data

Category Description and purpose
Contact information — data subjects Email address, telephone number and postal address of the individuals to whom Client issues credentials, Processed in order to authenticate and communicate with them.
Contact information — Client representatives Business contact details of Client’s representatives, agents, partners and referrals which Client provides to the Service Provider, including name, business email address and business telephone number, Processed in order to authenticate those individuals, administer the Account, and communicate with them in connection with the provision and support of the Services. Business contact details Processed by the Service Provider as an independent Controller under Section 1.3.2 are not within the scope of this Appendix.
Identity information Name, gender, date of birth, photograph, signature, and issuer-assigned identification numbers, Processed in order to create and maintain the credential and to enable the data subject to display, transfer, prove or share it.
Attribute information Education, membership, employment, entitlement, certification, licence and status attributes supplied by Client for inclusion on or association with a credential.
Usage information Device and network information, and records of actions and events within the Services, Processed in order to support and secure Client’s and the data subject’s use of the Services.

G. Sensitive Data

The Services are designed to Process the following categories of Sensitive Data where Client’s credential requires it, and only for the purposes stated. Client is responsible for establishing the condition for Processing required under applicable Data Protection Law.

Category Purpose
Racial or ethnic origin Issuing membership credentials on behalf of organizations advocating for the rights of particular groups.
Political opinions Issuing membership credentials for political or advocacy organizations.
Religious or philosophical beliefs Issuing membership credentials on behalf of religious organizations.
Trade union membership Issuing membership credentials on behalf of trade unions.
Biometric data Validation of photograph quality against the issuer’s guidelines, and one-to-one comparison for the prevention of identity fraud. Derived biometric data is Processed transiently and is not retained.
Gender identity or sexual orientation Issuing membership credentials on behalf of advocacy organizations, or at the request of the data subject in order to display their identity or pronouns.
Health data Issuing credentials identifying a disability, patient, caregiver or health professional status, or credentials required in the course of employment or travel.

Where pseudonymization cannot be applied, the Service Provider Processes Sensitive Data only where Client has established a valid condition for Processing under applicable Data Protection Law. The Service Provider does not Process Sensitive Data in the independent Controller capacity described in Section 1.3.

Appendix 2 — Technical and Organizational Measures

1. Governance

• A documented information security program, comprising administrative, technical and physical safeguards, maintained under an independently certified information security management system.

• Assigned responsibility for information security management, with adequate personnel resources.

• Documented policies covering access control, cryptography, communications security, operations security, supplier relationships, secure development, incident management and business continuity.

• Verification checks on personnel with access to Personal Data, written confidentiality undertakings, and information security training provided periodically.

2. Access control

• Role-based access control with least privilege and segregation of duties, reviewed regularly.

• Access scoped by role and by geography; unique individual user identifiers; prohibition on shared credentials.

• Enforced multi-factor authentication for all remote connections to systems Processing Personal Data, and for all administrative accounts within the Services.

• Logging of administrative access and of changes to settings or data; audit trails of user sessions.

• Documented joiner, mover and leaver process for the timely creation and removal of accounts.

3. Cryptography

• Encryption of Personal Data at rest using AES-256 or an equivalent or stronger algorithm, with encryption keys managed by the Service Provider or its Cloud Provider.

• Encryption of Personal Data in transit using Transport Layer Security version 1.2 as a minimum, with version 1.3 supported and preferred, and cipher suites consistent with current industry guidance.

• Strict transport security enforced for web traffic; cookies set with the secure flag.

4. Operations and network security

• Segregated development, staging and production environments, with production access restricted to authorized engineering personnel.

• Network and web application firewalls; intrusion detection; open port monitoring; brute force protection; anomaly detection.

• Vulnerability scanning conducted regularly at a frequency determined by risk assessment; patch management with remediation timeframes determined by risk assessment.

• Automated static security analysis of code; manual code review of sensitive areas; security validation as a condition of release.

5. Security testing

• Manual penetration testing of new features by the Service Provider’s internal security team before each significant release, conducted in a separate environment containing no customer data.

• An annual penetration test of the platform performed by an independent third party.

• Backup restoration testing and pre-production failover testing.

• Post-incident review of actual incidents, with findings used to update controls and recovery plans.

6. Resilience

• Resilience measures appropriate to the Data Region, including replication across availability zones and automated failover where available.

• Encrypted backups with a documented retention period, monitored and tested for integrity and recoverability.

• A business continuity plan tested and reviewed periodically.

• A recovery time objective of one hour and a recovery point objective of one minute. These are design objectives for restoring the Services and Client Data, not a guarantee that recovery will be achieved within those times in every circumstance.

7. Data lifecycle

• Logical separation of each customer’s data by tenant identifier, enforced at the application and interface layer.

• Documented retention schedule published by the Service Provider and applied by automated lifecycle policy.

• Secure deletion using methods aligned with recognized media sanitization standards.

• Sub-processor supervision to ensure Personal Data is Processed strictly in accordance with Client’s instructions.

The Service Provider may update these measures in accordance with Section 4.2.

Appendix 3 — Sub-processors

The current list of Sub-processors, including for each the identity of the Sub-processor, the purpose for which it is engaged, and the country in which it Processes Personal Data, is published at https://www.id123.io/terms/dpa/subprocessors/, or any successor address the Service Provider notifies to Client, and is incorporated into this Addendum. That list is updated in accordance with Section 5.2.

Appendix 4 — Jurisdiction-Specific Terms

Each Part of this Appendix applies automatically, and only, to the extent the Data Protection Law of the relevant jurisdiction applies to the Processing. Client is not required to elect which Part applies. Where a Part determines its own scope of application by reference to a contractual fact, that provision governs.

Part A — European Economic Area, United Kingdom and Switzerland

A.1 Transfer mechanism. Where the Service Provider Processes Personal Data subject to the General Data Protection Regulation (Regulation (EU) 2016/679), the UK GDPR, or the Swiss Federal Act on Data Protection, and that Processing involves a transfer to a third country not benefiting from an adequacy decision, the Standard Contractual Clauses approved by the European Commission are incorporated into this Addendum, with Client as data exporter and the Service Provider as data importer, and completed as set out in the Data Transfer Addendum. The modules that apply, and the options selected, are set out in the Data Transfer Addendum.

A.2 United Kingdom. For transfers subject to the UK GDPR, the International Data Transfer Addendum issued by the Information Commissioner applies to the Standard Contractual Clauses.

A.3 Switzerland. For transfers subject to the Swiss Federal Act on Data Protection, references in the Standard Contractual Clauses to the GDPR are to be read as references to that Act, references to member state law as references to Swiss law, and the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority.

A.4 Competent supervisory authority. The competent supervisory authority is that of the member state in which Client is established or, where Client is not established in the European Economic Area, that of the member state in which Client’s representative appointed under Article 27 of the GDPR is established, or in which the data subjects whose Personal Data is transferred are located.

A.5 Article 28 terms. Sections 2 to 13 of this Addendum are intended to satisfy the requirements of Article 28(3) of the GDPR and the corresponding provision of the UK GDPR, and are to be construed accordingly.

A.6 Sub-processor objection. The notification period in Section 5.2 satisfies the requirement in Article 28(2) that the Processor inform the Controller of intended changes concerning the addition or replacement of sub-processors.

Part B — United States

B.1 Application. This Part applies where the Service Provider Processes Personal Data subject to the California Consumer Privacy Act as amended by the California Privacy Rights Act, or to any other comprehensive state consumer privacy statute.

B.2 Role. The Service Provider acts as a “service provider” or “processor” as those terms are defined under the applicable statute, and Client acts as the “business” or “controller”. Personal Data is disclosed to the Service Provider solely for the limited and specified business purpose of performing the Services.

B.3 Restrictions. The restrictions in Section 2.8 apply. The Service Provider will not sell or share Personal Data, will not retain, use or disclose Personal Data for any purpose other than the business purposes specified in the Agreement, will not retain, use or disclose Personal Data outside the direct business relationship between the Parties, and will not combine Personal Data received from Client with personal information received from or on behalf of any other person, except as permitted by the applicable statute.

B.4 Sensitive personal information. The Service Provider uses sensitive personal information only for the purposes permitted under the applicable statute, namely to perform the Services, to verify or maintain the quality of the Services, and to prevent, detect and investigate security incidents and identity fraud. The Service Provider does not use sensitive personal information to infer characteristics about a consumer.

B.5 Compliance and notification. The Service Provider will comply with its obligations under the applicable statute and will provide the same level of privacy protection as required of Client. The Service Provider will notify Client if it determines that it can no longer meet those obligations, and Client may on such notice take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Data.

B.6 Deidentified data. Where the Service Provider retains deidentified data under Section 13.7, it will take reasonable measures to ensure the data cannot be associated with an individual, will publicly commit to maintaining it in deidentified form, and will contractually obligate any recipient to do the same.

Part C — Brazil

C.1 Where the Service Provider Processes Personal Data subject to the Lei Geral de Proteção de Dados Pessoais, Client acts as controlador and the Service Provider as operador. Client authorizes the Processing of such Personal Data outside Brazil, and warrants that the transfer complies with that law. The Service Provider will assist Client in responding to requests from the Autoridade Nacional de Proteção de Dados on the same terms as apply to a supervisory authority elsewhere in this Addendum.

Part D — India

D.1 Application. This Part applies where the Service Provider Processes Personal Data subject to the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, together with any rules, directions or notifications issued under them, as in force from time to time (together, the “DPDPA”).

D.2 Terminology. For the purposes of this Part, “Data Fiduciary”, “Data Processor” and “Data Principal” have the same meanings as “Controller”, “Processor” and “data subject” respectively in this Addendum. Client is the Data Fiduciary and the Service Provider is the Data Processor. The Parties acknowledge that under the DPDPA responsibility for compliance rests with the Data Fiduciary notwithstanding that Processing is carried out by a Data Processor.

D.3 Contract requirement. This Addendum is intended to constitute the valid contract required in order for a Data Fiduciary to engage a Data Processor under the DPDPA, and to contain the security safeguards required to be included in an agreement between a Data Fiduciary and a Data Processor.

D.4 Determination of application. The extent to which this Part applies is determined by reference to the place of establishment of the Customer of Record, being the registered address recorded for it in the Account or, where one is stated, in an applicable Order Form:

(a) Where the Customer of Record is established in India, this Part applies in full.

(b) Where the Customer of Record is not established in India but Personal Data Processed under the Agreement relates to Data Principals located in India, only Sections D.5(b), D.6(b), D.7 and D.8 apply, and each applies as an obligation of reasonable assistance rather than as a primary compliance obligation of the Service Provider. Client is responsible for determining whether and to what extent the DPDPA applies to its Processing.

Where no address is recorded, or the recorded address is inaccurate, the actual place of establishment of the Customer of Record governs. This Section resolves by reference to a recorded fact what would otherwise be an open question where Client has establishments in more than one country. The Data Region in which Personal Data is hosted is not relevant to the application of this Part.

D.5 Cross-border transfer.

(a) Where Section D.4(a) applies, the Service Provider will Process Personal Data outside India only in a manner consistent with Client’s obligations under the DPDPA, including any restriction on transfer to a country or territory notified by the Central Government of India from time to time. The Service Provider will notify Client on becoming aware that such a restriction affects a transfer under this Addendum.

(b) Where Section D.4(b) applies, Client authorises the Service Provider to Process such Personal Data outside India, subject to the same notified restrictions.

(c) Where a notified restriction affects a transfer under this Addendum, the Parties will cooperate in good faith to bring the affected transfer into compliance, including by relocating Processing to a permitted Cloud Provider Region, relying on an available derogation, or ceasing the restricted transfer. Where compliance cannot be achieved on a commercially reasonable basis, the procedure and remedies in Section 7.6.4 of the MSA apply, including Client’s right to a prorated refund of prepaid Fees on termination.

D.6 Personal Data Breach.

(a) Where Section D.4(a) applies, the Service Provider will provide Client with the information reasonably necessary to enable Client to give the initial intimation of a Personal Data Breach to the Data Protection Board of India and to each affected Data Principal without delay, and to furnish the detailed report required to be given to the Board within seventy-two (72) hours of Client becoming aware of the breach. The Service Provider’s notification obligation under Section 8.1 of this Addendum is designed to leave Client sufficient time to meet those requirements.

(b) Where Section D.4(b) applies, the Service Provider will, at Client’s request, provide reasonable assistance to enable Client to comply with any notification obligation it may have under the DPDPA.

D.7 Children’s Personal Data. The DPDPA requires verifiable consent of a parent or lawful guardian before the Personal Data of a child is Processed, and treats every individual under eighteen years of age as a child. Client is responsible for obtaining and verifying that consent, and for retaining evidence of it, before submitting the Personal Data of a child to the Services. The Service Provider does not undertake tracking or behavioural monitoring of children and does not direct targeted advertising at children.

D.8 Erasure. The Service Provider will erase Personal Data on Client’s instruction in accordance with Section 13 of this Addendum, and the Services provide the functionality described in Section 6.1 to enable Client to erase Personal Data relating to an individual Data Principal directly, including where a Data Principal withdraws consent or the purpose of Processing is no longer served.

D.9 Statutory retention. Where the DPDPA requires the retention of logs or other records for a minimum period, that requirement prevails over any shorter deletion period otherwise applicable under Section 13 to the extent of the records concerned. The Service Provider will notify Client where this applies and will limit the retained records to those the requirement covers.

D.10 Contact. The contact details published under Section 14 serve as the means by which a Data Principal may raise a question or grievance with the Service Provider. Grievance redressal in respect of Client’s Processing remains Client’s responsibility as Data Fiduciary.

Part E — Other Jurisdictions

E.1 Where Personal Data is subject to the Data Protection Law of a jurisdiction not addressed in Parts A to D, the body of this Addendum applies and the Parties will, at either Party’s reasonable request, enter into such additional terms or transfer mechanisms as that law requires. Neither Party is obliged to agree to terms that materially alter the allocation of risk under the Agreement.