ideevy
Product Solutions Developers Pricing Company
Try for free Book a demo

Data Processing Addendum

Effective date: June 19, 2026

This Addendum applies where IDEEVY processes personal data on behalf of a Business Customer in connection with the IDEEVY service.

Company: INTEGRITYTECH HK LIMITED
Website: ideevy.com
Company Registration No.: 3339122
Business Registration No.: 75921776
Registered Address: Room 905, Block 2, Cyberport, 100 Cyberport Road, Hong Kong

1. Parties and scope

This Data Processing Addendum forms part of the agreement between IDEEVY and the Business Customer where IDEEVY processes personal data on behalf of the Business Customer. It applies to personal data processed through IDEEVY verification services, workflow orchestration, APIs, dashboard, and related support.

Unless otherwise agreed, the Business Customer is the controller and IDEEVY is the processor for End User verification data.

2. Subject matter, duration, nature, and purpose

The subject matter is the processing of personal data for document verification, verification case management, workflow routing, provider orchestration, fallback and second-opinion checks, unified result delivery, support, security, and service administration.

Processing continues for the term of the agreement and any retention period required or permitted under the agreement, this Addendum, the Privacy Policy, or applicable law.

3. Customer instructions

IDEEVY will process personal data according to documented instructions from the Business Customer, including the agreement, API requests, dashboard configuration, workflow rules, provider settings, order forms, and support instructions.

Customer instructions may include routing personal data to External Providers, including Customer-selected External Providers, when configured by the Business Customer. IDEEVY may decline or suspend instructions that appear unlawful, insecure, unsupported, or inconsistent with the agreement.

4. Categories of data subjects and personal data

Data subjects

  • End Users whose documents are submitted for verification;
  • Business Customer personnel and dashboard users;
  • support, billing, technical, and administrative contacts.

Personal data categories

  • identity document images and files;
  • extracted document data and document metadata;
  • document authenticity, quality, and consistency signals;
  • verification status, workflow metadata, routing logs, provider-level details, and webhook events;
  • API request metadata, IP address, device data, and security logs;
  • Business Customer account, contact, billing, support, and dashboard user data; and
  • provider identifiers, configuration data, and credentials where supplied by the Business Customer.

Identity documents may contain sensitive or special category information depending on the document and jurisdiction. The Business Customer is responsible for ensuring that any such processing is lawful for its use case.

5. IDEEVY personnel

IDEEVY will ensure that personnel authorized to process personal data are subject to appropriate confidentiality obligations and receive access only where needed for service delivery, support, security, or legal compliance.

6. Subprocessors and customer-selected providers

The Business Customer authorizes IDEEVY to use subprocessors for hosting, storage, security, monitoring, communications, analytics, support, and service operations, and for verification-related services where IDEEVY engages those providers as subprocessors.

Customer-selected External Providers are different. Where the Business Customer chooses, contracts with, configures, or provides credentials for an External Provider, that provider may process personal data under the Business Customer’s own relationship and may not be an IDEEVY subprocessor.

The Business Customer is responsible for assessing, authorizing, and maintaining the legal basis and contractual terms for Customer-selected External Providers, including any international transfer requirements. See also Subprocessors & Infrastructure.

7. Security measures

IDEEVY will implement appropriate technical and organizational measures designed to protect personal data, including encryption in transit, access controls, authentication, logging, monitoring, customer separation, credential protection, and incident response procedures appropriate to the service.

The Business Customer is responsible for securing its own systems, API keys, webhook endpoints, provider credentials, users, and configurations.

8. Personal data breach

IDEEVY will notify the Business Customer without undue delay after becoming aware of a personal data breach affecting personal data processed by IDEEVY as processor. The notice will include information reasonably available to IDEEVY to help the Business Customer meet its legal obligations.

The Business Customer is responsible for notifying regulators or individuals where required by law, except where IDEEVY is directly required to do so.

9. Assistance

Taking into account the nature of processing, IDEEVY will provide reasonable assistance to the Business Customer with data subject requests, security obligations, data protection impact assessments, and regulatory inquiries where required by applicable data protection law and where the information is available to IDEEVY.

The Business Customer is responsible for responding to End Users unless otherwise agreed.

10. International transfers

IDEEVY may process personal data in countries where IDEEVY, its subprocessors, or configured providers operate. Where required, the parties will use appropriate safeguards for international transfers, such as standard contractual clauses or other lawful transfer mechanisms.

For Customer-selected External Providers, the Business Customer is responsible for authorizing the transfer and ensuring the provider relationship includes any required safeguards.

11. Return and deletion

Upon termination or expiration of the agreement, IDEEVY will delete or return personal data according to the agreement, applicable law, and technical feasibility. Backup, security, audit, billing, and legal records may be retained for limited periods where required or permitted.

Unless otherwise agreed or configured, verification records may be retained for up to one year.

12. Audits and information

IDEEVY will provide reasonable information to demonstrate compliance with this Addendum, such as security summaries, policies, certifications, or written responses. Onsite audits or detailed infrastructure reviews require prior written agreement, reasonable notice, confidentiality protections, and security restrictions.

13. Conflict

If this Addendum conflicts with the main agreement, this Addendum controls for processing of personal data as processor, unless the parties expressly agree otherwise in writing.

← Back to home