Data Processing Addendum
Last updated: 2026-09-07
Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the agreement governing an organization's use of auth.my (the "Agreement").
This DPA is between the organization accepting it ("Customer") and USSV LLC ("Provider").
1. Scope
This DPA applies only to Personal Data that Provider processes on behalf of Customer as a processor or service provider in connection with the Service ("Customer Personal Data").
This DPA does not apply to processing for which Provider independently determines the purposes and essential means.
Provider generally acts as an independent controller for processing necessary to:
- maintain the core auth.my identity network;
- administer Provider's relationship with Customer;
- secure and protect the Service;
- prevent fraud and abuse;
- maintain platform-level security records;
- calculate Provider's own billing;
- comply with law; or
- establish or defend legal claims.
The parties acknowledge that their privacy roles depend on the particular processing activity and are determined by applicable law rather than solely by the labels used in this DPA.
2. Definitions
"Applicable Data Protection Law" means data-protection and privacy law applicable to the processing of Customer Personal Data, including where applicable the GDPR and UK GDPR.
"Controller", "Processor", "Personal Data", "Processing", and "Data Subject" have the meanings given by Applicable Data Protection Law.
"Subprocessor" means a third party engaged by Provider to process Customer Personal Data on Customer's behalf.
3. Customer instructions
Customer instructs Provider to process Customer Personal Data:
- to provide the Service described in the Agreement;
- according to Customer's configuration and use of the Service;
- to maintain security, availability, recovery, and support functions necessary to provide that Service; and
- according to additional documented instructions agreed by the parties.
Provider will process Customer Personal Data only on documented instructions from Customer unless processing is required by applicable law.
If Provider is legally required to process Customer Personal Data outside Customer's instructions, Provider will inform Customer before doing so unless the law prohibits that notice.
Provider will inform Customer if, in Provider's reasonable opinion, an instruction infringes Applicable Data Protection Law.
4. Customer responsibilities
Customer is responsible for:
- having a lawful basis for Customer Personal Data provided to Provider;
- providing required notices to Data Subjects;
- configuring the Service consistently with applicable law;
- issuing lawful instructions;
- limiting access to authorized personnel; and
- responding to Data Subjects for processing for which Customer is Controller.
Customer will not instruct Provider to process Personal Data in violation of Applicable Data Protection Law.
5. Confidentiality
Provider will ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.
Access will be limited to persons who require it for their duties.
6. Security
Provider will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
The current measures are summarized in Annex II.
Customer acknowledges that security measures may evolve as technology, threats, and the Service change, provided the overall level of protection is not materially reduced.
7. Subprocessors
Customer grants Provider general authorization to use Subprocessors.
Provider will maintain a current Subprocessor List identifying Subprocessors that materially process Customer Personal Data.
Provider will provide reasonable notice before adding or replacing a Subprocessor that materially changes the processing of Customer Personal Data.
Customer may object on reasonable data-protection grounds.
The parties will work in good faith to resolve the objection.
If no reasonable alternative is available, Customer may discontinue the affected feature or terminate the affected Service according to the Agreement.
Provider will impose data-protection obligations on each Subprocessor that are appropriate to the processing and no less protective in material respects than Provider's relevant obligations under this DPA.
Provider remains responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Law.
8. Data Subject requests
Taking into account the nature of the processing, Provider will provide reasonable assistance to Customer in responding to verified Data Subject requests relating to Customer Personal Data.
If Provider receives a request that clearly concerns processing for which Customer is Controller, Provider may direct the requester to Customer unless Provider is legally required to respond directly.
Customer remains responsible for determining how to respond to a request.
9. Compliance assistance
Taking into account the nature of the processing and information available to Provider, Provider will provide reasonable assistance with:
- security-of-processing obligations;
- personal-data-breach obligations;
- data-protection impact assessments; and
- consultations with supervisory authorities,
where required by Applicable Data Protection Law and relevant to Provider's processing.
10. Personal Data Breaches
Provider will notify Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data.
Where reasonably practicable, initial notice will be provided within 48 hours after confirmation.
The notice will include information reasonably available to Provider concerning:
- the nature of the incident;
- affected data and Data Subjects;
- likely consequences;
- containment or remediation measures; and
- a contact for follow-up.
Provider may provide information in phases as the investigation develops.
Notification is not an admission of fault or liability.
11. Deletion and return
During the Agreement, Customer may use available Service functions to delete Customer Personal Data where supported.
Following termination of the affected Service, Provider will delete or return Customer Personal Data within a reasonable period unless retention is required by law or the data is processed by Provider as an independent Controller.
Customer Personal Data may remain temporarily in disaster-recovery backups until the applicable backup expires.
Backup copies are isolated from ordinary use and will not be restored except for disaster recovery or other legitimate continuity purposes.
If a backup containing previously deleted Customer Personal Data is restored, the applicable deletion requirement will be reapplied.
12. Audit information
Provider will make available information reasonably necessary to demonstrate compliance with this DPA.
Provider may satisfy routine audit requests through security documentation, technical descriptions, questionnaires, third-party reports or certifications if available, and other reasonable evidence.
If that information is insufficient and Applicable Data Protection Law requires additional verification, Customer may request an audit on reasonable prior notice.
Audits must:
- occur no more than once annually unless required following a material incident or by a supervisory authority;
- avoid unnecessary access to other customers' data;
- be conducted during normal business hours;
- comply with reasonable confidentiality and security requirements; and
- not unreasonably disrupt the Service.
Customer bears its own audit costs unless applicable law requires otherwise or the audit identifies a material breach by Provider.
13. International transfers — EEA
Where Customer transfers Customer Personal Data subject to the GDPR to Provider in a country that does not benefit from an applicable adequacy decision, the parties will use an applicable lawful transfer mechanism.
Unless another lawful mechanism is agreed, the parties will enter into the then-current European Commission Standard Contractual Clauses for international transfers.
Where Customer is a Controller and Provider is a Processor, Module Two (controller-to-processor) will ordinarily apply.
The information in the Annexes to this DPA may be used to complete the applicable appendices to those clauses.
The parties will cooperate in completing any transfer assessment and implementing supplementary measures reasonably required by applicable law.
14. International transfers — United Kingdom
For a restricted transfer subject to the UK GDPR, the parties will use an appropriate UK transfer mechanism.
Where the parties rely on the European Commission Standard Contractual Clauses, they will also enter into or incorporate the then-current UK International Data Transfer Addendum where applicable.
Alternatively, the parties may use the UK International Data Transfer Agreement or another lawful mechanism.
15. Government requests
Provider will:
- review government requests for Customer Personal Data for facial validity and scope;
- disclose only data reasonably required by a valid request;
- notify Customer where legally permitted; and
- challenge requests where Provider reasonably considers a challenge appropriate and legally available.
16. Order of precedence
If this DPA conflicts with the Agreement regarding processing of Customer Personal Data, this DPA controls.
Mandatory transfer clauses control over conflicting terms of this DPA to the extent required for their validity.
17. Duration
This DPA remains effective for as long as Provider processes Customer Personal Data on behalf of Customer.
Annex I — Details of Processing
Subject matter
Provision of identity, authentication, organization administration, application access, security, and related auth.my services configured by Customer.
Duration
For the duration of Customer's use of the applicable Service plus applicable retention and deletion periods.
Nature and purpose
Processing may include collection, storage, organization, encryption, authentication, access control, retrieval, disclosure according to Customer configuration, logging, transmission, support, backup and recovery, security monitoring, and deletion.
Data Subjects
Depending on Customer's use:
- Customer employees;
- contractors;
- organization members;
- invited users;
- administrators;
- developers;
- users of Customer-controlled applications; and
- other persons whose Personal Data Customer instructs Provider to process.
Categories of Personal Data
Depending on Customer configuration:
- name;
- email address;
- phone number;
- organization membership and role;
- identifiers;
- authentication metadata;
- public passkey information;
- device and browser information;
- IP address;
- approximate country, region or city;
- session information;
- Connected Application records;
- consent and authorization records;
- usage information;
- security and audit events;
- communication-delivery metadata; and
- other information Customer lawfully submits through supported Service functionality.
Special Categories
The core Service is not intended for Customer to submit special-category data as defined by GDPR Article 9.
Customer must not intentionally submit special-category data unless the parties have expressly agreed that the relevant Service supports that processing and appropriate safeguards have been implemented.
Annex II — Technical and Organizational Measures
Provider's current measures include, as applicable:
Identity security
- passwordless authentication;
- passkeys/WebAuthn support;
- multi-factor authentication;
- session revocation;
- token revocation;
- refresh-token rotation and reuse detection;
- step-up authentication for sensitive actions; and
- backup recovery methods.
Cryptographic protection
- TLS for data in transit;
- application-layer encryption for sensitive stored fields;
- authenticated encryption for protected Personal Data;
- protected key-management practices;
- hashing of one-time authentication codes;
- hashing of backup codes; and
- key-rotation procedures.
Access control
- least-privilege administrative access;
- separate administrative functions;
- audit logging of administrator actions;
- logging of access to sensitive user records;
- protected Service credentials; and
- restricted infrastructure access.
Network protection
- Cloudflare edge protection;
- no ordinary public exposure of internal service ports;
- rate limiting;
- protocol-level request limits;
- email and SMS abuse controls; and
- automated fraud safeguards for messaging channels.
Availability and recovery
- automated database backups;
- off-host/object-storage backup copies;
- database replication where configured;
- regular restoration testing;
- health monitoring;
- incident detection;
- automated deployment health checks; and
- documented failover and recovery procedures.
Data minimization
- private passkey material never stored by Provider;
- one-time and backup codes stored as hashes;
- limited communication logs;
- no advertising tracking;
- no email-open tracking; and
- deletion/de-identification workflows.
Secure development and operations
- automated tests;
- CI-controlled builds;
- dependency review and update processes;
- controlled production deployment;
- audit trails;
- secrets management; and
- incident-response procedures.
Annex III — Subprocessors
The current Subprocessor List published by Provider forms part of this Annex.
The list may be updated in accordance with Section 7 of this DPA.