Data Processing Agreement
Standard terms for personal data that SPS processes on behalf of a MYID customer.
Contents
1. Scope and roles
This DPA applies when SPS processes personal data on behalf of Customer through MYID Self Verify and applicable data protection law requires processor terms. Customer is the controller or processor that gives lawful instructions. SPS is the processor or further processor for that processing.
Terms such as controller, processor, personal data, processing, individual, supervisory authority, and security incident have the meaning given by applicable data protection law.
2. Processing details
SPS processes personal data to provide, secure, support, troubleshoot, and maintain the Services according to the agreement, Customer configuration, documented instructions, and applicable law. The subject, duration, purpose, data categories, and individuals are described in Section 16 and the applicable order.
3. Documented instructions
SPS will process personal data only on documented Customer instructions, including the agreement, order, configuration, support request, and authorized use of the Services, unless law requires other processing. If legally permitted, SPS will inform Customer before processing required by law.
SPS will notify Customer if an instruction appears to violate applicable data protection law. SPS may pause the affected processing while the parties clarify a lawful instruction.
4. Customer obligations
Customer is responsible for a lawful basis, transparency, authority, data accuracy, purpose limits, data minimization, individual rights, retention instructions, connected providers, and the legality of its instructions. Customer must not submit regulated or sensitive data that is outside the approved scope.
Customer must configure and test the Services, restrict administrator and provider access, maintain an independent recovery path, and provide complete instructions for deletion, export, region, and retention.
5. Confidentiality
SPS will limit personal data access to personnel and approved providers who need access for the Services and are subject to confidentiality obligations or a legal duty of confidentiality. Access is removed when no longer required.
6. Security measures
Taking account of the processing, available technology, implementation cost, and risk, SPS will maintain appropriate technical and organizational measures for the applicable deployment. Measures can include:
- Encrypted network transport and protected secret references
- Authentication, authorization, tenant context, and least privilege
- Protected mobile storage and operating system biometric services
- Secret redaction and W7 audit capture metadata
- Restricted database roles and protected backups
- Bounded performance telemetry without request bodies or credentials
- Source review, automated tests, builds, security checks, backup, and rollback
- Provider readiness tests and capability controls before tenant launch
Exact measures, providers, regions, recovery objectives, retention, monitoring, and customer controls are documented for the deployment. This DPA does not create a universal certification, uptime, or recovery promise.
7. Subprocessors
Customer authorizes SPS to use subprocessors needed for the Services, subject to written data protection obligations appropriate to the processing. The current public categories and common providers are described in the Subprocessor Notice. The customer schedule or order identifies the applicable deployment providers.
SPS will provide notice of a material new subprocessor when required by the signed agreement. Customer may raise a reasonable documented data protection objection within the period stated in that agreement. The parties will work in good faith on a reasonable alternative. If no reasonable alternative is available, either party may terminate only the affected service as the signed agreement permits.
SPS remains responsible for a subprocessor’s performance of delegated processor obligations to the extent required by applicable law and the signed agreement.
8. Individual rights requests
Taking account of the nature of processing, SPS will provide reasonable assistance for Customer to respond to an applicable access, correction, deletion, restriction, objection, portability, or appeal request. If SPS receives a request concerning Customer controlled data, SPS may direct the person to Customer and notify Customer when appropriate.
SPS may require verification and will not disclose Customer Data to a requester without Customer authorization or a legal obligation.
9. Personal data security incidents
SPS will notify Customer without undue delay after confirming a personal data security incident affecting Customer Data when notification is required by applicable law or the signed agreement. Notice will include available information reasonably needed for Customer’s assessment and response.
Notification is not an admission of fault or liability. Unsuccessful attempts, scans, blocked traffic, events affecting only SPS data, and incidents caused solely by Customer or its providers are handled according to the agreement and applicable law.
10. Assessment and consultation assistance
Taking account of the processing and information available, SPS will provide reasonable assistance with Customer security obligations, data protection assessments, and regulator consultation when required by applicable law. Customer is responsible for its assessment, decision, filing, and costs unless a signed agreement states otherwise.
11. Return and deletion
At the end of the Services or on a valid documented instruction, SPS will return or delete Customer personal data according to the signed agreement, applicable law, technical capability, provider behavior, and backup cycle. SPS may retain information required by law, security, dispute, accounting, or proof of deletion, subject to continued protection and purpose limits.
Customer is responsible for exporting required data before access ends and for deletion in Customer controlled connected systems.
12. Audit information
SPS will make available information reasonably necessary to demonstrate the processor obligations in this DPA, subject to confidentiality, security, privilege, customer isolation, and protection of other customers.
The parties should first use current security documentation, architecture, test evidence, subprocessor information, audit samples, and independent reports if any. If that information is insufficient and law requires further review, Customer may request a focused audit no more than once each year unless a confirmed incident or regulator requires more. The audit requires reasonable notice, mutually agreed scope, qualified independent personnel, no production disruption, no access to another customer’s data, and Customer payment of reasonable costs unless law or a signed agreement requires otherwise.
13. International transfers
The parties will identify applicable processing locations and use a lawful transfer mechanism where required. If European standard contractual clauses are required, the applicable controller to processor or processor to processor module is incorporated only when identified in the signed customer agreement, together with completed annex information and any required supplementary measures.
No public page guarantees a specific region or transfer mechanism for every Customer.
14. Regulated and sensitive data
Customer must not introduce electronic protected health information, criminal justice information, payment card data, government classified information, children’s data, or another specially regulated category unless the parties have approved the use in writing and completed all required safeguards, provider reviews, regions, assessments, and contract terms.
Use of a security framework name on the Compliance page does not authorize processing of regulated data.
15. Liability and order of terms
The liability exclusions, limits, disclaimers, indemnities, and dispute terms in the governing customer agreement apply to this DPA. This DPA does not create a separate or additional liability cap.
If this DPA conflicts with the governing customer agreement on personal data processing, this DPA controls only for that conflict unless the signed agreement expressly states otherwise. Mandatory applicable law controls over both.
16. Processing description
| Subject | Enterprise identity operations, account recovery, profile and MFA management, directory actions, user guided security response, notifications, training status, audit evidence, performance measurement, administration, and support as configured by Customer. |
|---|---|
| Duration | The service term and the return, deletion, backup, legal, and security periods stated in the signed agreement. |
| Purpose | Provide, secure, support, test, measure, and maintain the functions Customer selects and instructs. |
| Individuals | Authorized employees, contractors, administrators, support contacts, security personnel, and other persons Customer places in scope. |
| Data | Company and tenant details, business identity attributes, authentication and session events, factor metadata, directory status, approved profile changes, security events and responses, device and training evidence, notification records, audit evidence, performance measurements, and support communication. |
| Sensitive values excluded from ordinary logs | Passwords, proposed passwords, OTP values, recovery codes, authorization values, tokens, cookies, API keys, client secrets, private keys, and comparable authentication material. |
| Frequency | As initiated by Users, administrators, scheduled jobs, notifications, provider polling, configured automation, support, and monitoring during the service term. |
| Deletion | According to Customer instruction, contract retention, provider behavior, legal need, and backup cycle. |
Contact
Privacy and DPA questions: privacy@ext.myidselfverify.com
Legal notices: legal@ext.myidselfverify.com
Software Productivity Strategists, Inc., 2400 Research Blvd, Suite 115, Rockville, Maryland 20850, United States.