Legal · Authvio

Data Processing Agreement

Processor terms for approved developers and businesses when Authvio handles customer-controlled personal data.

Last updated: July 18, 2026 · A brand of Bolrach Technologies Limited

On this page

1. Scope and parties

This Data Processing Agreement forms part of an agreement between Bolrach Technologies Limited, operating Authvio, and the approved developer or business identified in the related account, order, or agreement. It applies only when and to the extent Authvio processes personal data on the customer's documented instructions as a processor or service provider.

2. Roles

The customer is controller of personal data it submits to Authvio or asks Authvio to process for the customer's verification, decision, event, or integration purpose. Authvio is processor for that customer-controlled processing.

Authvio acts as an independent controller for Authvio account administration, direct user authentication and consent, fraud and abuse prevention, service security, billing, legal compliance, and Authvio's own audit records. The Privacy Policy covers that processing. The parties may also act as separate controllers when an end user chooses to disclose Authvio account claims to the customer.

3. Processing details

Subject matter and duration: providing the contracted authentication, verification, decision, webhook, support, and related services for the agreement term and the deletion or retention period that follows.

People: the customer's end users, applicants, account holders, representatives, developers, administrators, and other people whose data the customer lawfully submits.

Data: identifiers, contact and profile fields, country and residence, document fields and images, selfie and liveness material, face-match results, verification status and decisions, customer references, authentication and session data, device and network logs, webhook data, support records, and other data enabled by the approved scopes and verification level.

Operations: collect, receive, validate, extract, compare, host, encrypt, route, review, disclose to the customer, log, retain, delete, and otherwise process data only as needed for the service and lawful instructions.

4. Customer instructions and duties

  • The agreement, approved console settings, documented API requests, and written support directions are the customer's instructions.
  • The customer must have a lawful basis, give required notices, collect required consent, choose only necessary fields and levels, and respect country, age, sanctions, and sector rules.
  • The customer must not send unsupported special-category data, raw secrets, or unrelated personal data in metadata, references, webhook URLs, or support messages.
  • The customer must protect returned personal fields, verification results, API credentials, webhook secrets, and its own user access.

5. Authvio processor duties

  • Process customer-controlled personal data only on documented instructions unless law requires otherwise.
  • Ensure authorized personnel have confidentiality duties and access only what their role needs.
  • Apply the technical and organizational measures described below.
  • Assist with data-subject requests, impact assessments, regulator consultations, and incident duties where reasonably required and relevant to the service.
  • Tell the customer if an instruction appears to violate applicable data-protection law, unless law prevents that notice.

6. Technical and organizational measures

  • Encryption in transit and encryption of stored verification evidence.
  • Role-based staff access, tenant ownership checks, separate Test and Live resources, and restricted evidence views.
  • Signed webhooks, scoped credentials, secret hashing, session controls, audit records, rate controls, and idempotency protections.
  • Regional evidence routing that fails closed when a required evidence store is unavailable.
  • Retention jobs, deletion workflows, backup controls, service monitoring, and documented recovery procedures.

7. Subprocessors

The customer gives general authorization for Authvio to use subprocessors for infrastructure, storage, identity orchestration, communications, monitoring, support, and enabled verification services. Authvio remains responsible for requiring data-protection duties appropriate to each subprocessor's role.

Request the current subprocessor list through the Legal support topic before production onboarding. We will give reasonable notice of a new subprocessor that materially affects customer-controlled data and provide a process for a good-faith data-protection objection.

8. Data regions and transfers

Global coverage and evidence storage are separate controls. Verification evidence follows the enabled regional route assigned for the request, while control-plane, account, fraud, support, audit, or provider data may be processed elsewhere. The parties will use required transfer safeguards, which may include adequacy decisions, approved contractual clauses, or another lawful mechanism. No unavailable regional-residency path is promised by this DPA.

9. Data-subject and authority requests

Authvio will forward a request that clearly concerns customer-controlled data unless law prevents it, and will not answer for the customer without authorization. The customer remains responsible for deciding the response. Authvio may answer requests concerning data for which Authvio is an independent controller.

10. Personal-data incidents

After confirming a personal-data incident affecting customer-controlled data, Authvio will notify the customer without undue delay and provide available information needed for the customer's legal assessment. Notice does not admit fault. The customer is responsible for its regulator and individual notifications unless law assigns that duty to Authvio.

11. Return, deletion, and retention

On termination or a valid deletion instruction, Authvio will delete or return customer-controlled personal data unless law requires retention. Finished-session evidence follows the active retention policy, currently a 30-day default unless an enabled regional policy sets another period. Backups and legal or audit records may age out under separate controlled schedules. Raw evidence deletion is not reported complete while an object remains queued for deletion.

12. Information and audits

Authvio will provide information reasonably needed to show compliance with this DPA. The parties should first use documentation, questionnaires, certifications that actually apply, and remote evidence. If those are insufficient, an audit may be arranged under reasonable confidentiality, scope, timing, safety, and cost controls, without exposing another customer's data or weakening the service.

13. Order of terms and contact

If this DPA conflicts with the Terms on processor obligations, this DPA controls for that issue. A signed order may add lawful details for a specific service. Other liability, governing-law, and dispute terms remain in the main agreement. Use the Legal support topic for a signed DPA, subprocessor list, transfer terms, or privacy contact.

Questions about this document?

Authvio is a brand of Bolrach Technologies Limited. Send a legal or privacy request through the encrypted support form.