Skip to main content
MYID Self Verify
Platform Manage Protect Learn MYID Autopilot Customer Results Pricing Support
Support Book a Demo
Legal

Data Processing Agreement

Standard terms for personal data that SPS processes on behalf of a MYID customer.

Effective
July 18, 2026
Processor
Software Productivity Strategists, Inc.
Binding status
When incorporated or executed
Contract status. This standard DPA becomes binding only when it is incorporated into a signed customer agreement, accepted through an authorized order process, or separately executed by both parties. A signed agreement controls if it expressly differs.

Contents

  1. Scope and roles
  2. Processing details
  3. Instructions
  4. Customer obligations
  5. Confidentiality
  6. Security measures
  7. Subprocessors
  8. Individual requests
  9. Security incidents
  10. Assessment assistance
  11. Return and deletion
  12. Audit information
  13. International transfers
  14. Regulated data
  15. Liability and order
  16. Processing description

1. Scope and roles

This DPA applies when SPS processes personal data on behalf of Customer through MYID Self Verify and applicable data protection law requires processor terms. Customer is the controller or processor that gives lawful instructions. SPS is the processor or further processor for that processing.

Terms such as controller, processor, personal data, processing, individual, supervisory authority, and security incident have the meaning given by applicable data protection law.

2. Processing details

SPS processes personal data to provide, secure, support, troubleshoot, and maintain the Services according to the agreement, Customer configuration, documented instructions, and applicable law. The subject, duration, purpose, data categories, and individuals are described in Section 16 and the applicable order.

3. Documented instructions

SPS will process personal data only on documented Customer instructions, including the agreement, order, configuration, support request, and authorized use of the Services, unless law requires other processing. If legally permitted, SPS will inform Customer before processing required by law.

SPS will notify Customer if an instruction appears to violate applicable data protection law. SPS may pause the affected processing while the parties clarify a lawful instruction.

4. Customer obligations

Customer is responsible for a lawful basis, transparency, authority, data accuracy, purpose limits, data minimization, individual rights, retention instructions, connected providers, and the legality of its instructions. Customer must not submit regulated or sensitive data that is outside the approved scope.

Customer must configure and test the Services, restrict administrator and provider access, maintain an independent recovery path, and provide complete instructions for deletion, export, region, and retention.

5. Confidentiality

SPS will limit personal data access to personnel and approved providers who need access for the Services and are subject to confidentiality obligations or a legal duty of confidentiality. Access is removed when no longer required.

6. Security measures

Taking account of the processing, available technology, implementation cost, and risk, SPS will maintain appropriate technical and organizational measures for the applicable deployment. Measures can include:

  • Encrypted network transport and protected secret references
  • Authentication, authorization, tenant context, and least privilege
  • Protected mobile storage and operating system biometric services
  • Secret redaction and W7 audit capture metadata
  • Restricted database roles and protected backups
  • Bounded performance telemetry without request bodies or credentials
  • Source review, automated tests, builds, security checks, backup, and rollback
  • Provider readiness tests and capability controls before tenant launch

Exact measures, providers, regions, recovery objectives, retention, monitoring, and customer controls are documented for the deployment. This DPA does not create a universal certification, uptime, or recovery promise.

7. Subprocessors

Customer authorizes SPS to use subprocessors needed for the Services, subject to written data protection obligations appropriate to the processing. The current public categories and common providers are described in the Subprocessor Notice. The customer schedule or order identifies the applicable deployment providers.

SPS will provide notice of a material new subprocessor when required by the signed agreement. Customer may raise a reasonable documented data protection objection within the period stated in that agreement. The parties will work in good faith on a reasonable alternative. If no reasonable alternative is available, either party may terminate only the affected service as the signed agreement permits.

SPS remains responsible for a subprocessor’s performance of delegated processor obligations to the extent required by applicable law and the signed agreement.

8. Individual rights requests

Taking account of the nature of processing, SPS will provide reasonable assistance for Customer to respond to an applicable access, correction, deletion, restriction, objection, portability, or appeal request. If SPS receives a request concerning Customer controlled data, SPS may direct the person to Customer and notify Customer when appropriate.

SPS may require verification and will not disclose Customer Data to a requester without Customer authorization or a legal obligation.

9. Personal data security incidents

SPS will notify Customer without undue delay after confirming a personal data security incident affecting Customer Data when notification is required by applicable law or the signed agreement. Notice will include available information reasonably needed for Customer’s assessment and response.

Notification is not an admission of fault or liability. Unsuccessful attempts, scans, blocked traffic, events affecting only SPS data, and incidents caused solely by Customer or its providers are handled according to the agreement and applicable law.

10. Assessment and consultation assistance

Taking account of the processing and information available, SPS will provide reasonable assistance with Customer security obligations, data protection assessments, and regulator consultation when required by applicable law. Customer is responsible for its assessment, decision, filing, and costs unless a signed agreement states otherwise.

11. Return and deletion

At the end of the Services or on a valid documented instruction, SPS will return or delete Customer personal data according to the signed agreement, applicable law, technical capability, provider behavior, and backup cycle. SPS may retain information required by law, security, dispute, accounting, or proof of deletion, subject to continued protection and purpose limits.

Customer is responsible for exporting required data before access ends and for deletion in Customer controlled connected systems.

12. Audit information

SPS will make available information reasonably necessary to demonstrate the processor obligations in this DPA, subject to confidentiality, security, privilege, customer isolation, and protection of other customers.

The parties should first use current security documentation, architecture, test evidence, subprocessor information, audit samples, and independent reports if any. If that information is insufficient and law requires further review, Customer may request a focused audit no more than once each year unless a confirmed incident or regulator requires more. The audit requires reasonable notice, mutually agreed scope, qualified independent personnel, no production disruption, no access to another customer’s data, and Customer payment of reasonable costs unless law or a signed agreement requires otherwise.

13. International transfers

The parties will identify applicable processing locations and use a lawful transfer mechanism where required. If European standard contractual clauses are required, the applicable controller to processor or processor to processor module is incorporated only when identified in the signed customer agreement, together with completed annex information and any required supplementary measures.

No public page guarantees a specific region or transfer mechanism for every Customer.

14. Regulated and sensitive data

Customer must not introduce electronic protected health information, criminal justice information, payment card data, government classified information, children’s data, or another specially regulated category unless the parties have approved the use in writing and completed all required safeguards, provider reviews, regions, assessments, and contract terms.

Use of a security framework name on the Compliance page does not authorize processing of regulated data.

15. Liability and order of terms

The liability exclusions, limits, disclaimers, indemnities, and dispute terms in the governing customer agreement apply to this DPA. This DPA does not create a separate or additional liability cap.

If this DPA conflicts with the governing customer agreement on personal data processing, this DPA controls only for that conflict unless the signed agreement expressly states otherwise. Mandatory applicable law controls over both.

16. Processing description

SubjectEnterprise identity operations, account recovery, profile and MFA management, directory actions, user guided security response, notifications, training status, audit evidence, performance measurement, administration, and support as configured by Customer.
DurationThe service term and the return, deletion, backup, legal, and security periods stated in the signed agreement.
PurposeProvide, secure, support, test, measure, and maintain the functions Customer selects and instructs.
IndividualsAuthorized employees, contractors, administrators, support contacts, security personnel, and other persons Customer places in scope.
DataCompany and tenant details, business identity attributes, authentication and session events, factor metadata, directory status, approved profile changes, security events and responses, device and training evidence, notification records, audit evidence, performance measurements, and support communication.
Sensitive values excluded from ordinary logsPasswords, proposed passwords, OTP values, recovery codes, authorization values, tokens, cookies, API keys, client secrets, private keys, and comparable authentication material.
FrequencyAs initiated by Users, administrators, scheduled jobs, notifications, provider polling, configured automation, support, and monitoring during the service term.
DeletionAccording to Customer instruction, contract retention, provider behavior, legal need, and backup cycle.

Contact

Privacy and DPA questions: privacy@ext.myidselfverify.com

Legal notices: legal@ext.myidselfverify.com

Software Productivity Strategists, Inc., 2400 Research Blvd, Suite 115, Rockville, Maryland 20850, United States.

Privacy Policy Subprocessor Notice Compliance Status
MYID Self Verify

Help every user manage, protect, and recover their work identity without replacing the systems your organization already trusts.

mail public

Product

  • Platform
  • Manage
  • Protect
  • Autopilot
  • Insights
  • Mobile App
  • Enterprise MFA
  • IBM Verify
  • Pricing

Trust

  • Security
  • Compliance
  • Data Processing
  • Subprocessors
  • Accessibility
  • Legal Center

Support

  • Support Center
  • User Guide
  • Administrator Guide
  • How Data Is Used
  • Privacy Request
  • Account Deletion
  • Contact Us

Company

  • Case Studies
  • SPS, Inc.
  • General Contact
  • Security Contact
  • Privacy Contact
© 2026 Software Productivity Strategists, Inc. MYID Self Verify is an SPS product.
Privacy Terms Cookies Cookie choices
Your analytics choice

We use optional first party analytics to understand when people visit, where they came from, which pages they use, and the general device category. We do not use advertising trackers or sell this information. Read our Cookie Notice.