legal
Data Processing Agreement
Version 1.0, last updated 25 July 2026
This agreement governs our processing of personal data on your behalf when you use the WhorlID identification service. It applies automatically to every account: by using the service you accept these terms, so there is nothing to sign before you can start. If your procurement process needs a countersigned copy, or your own paper instead of ours, write to [email protected] and we will sign.
This is our template, published so you can read it before you integrate. It is not legal advice, and it does not decide your side of the question: see deploying WhorlID lawfully for what you need to have in place on your own site.
1. Roles
You are the controller. You decide to run device identification on your site, for which purposes, and on what legal basis. We are the processor: we process device data only to provide the service and only on your instructions, which are the settings you choose in your project plus the API calls your integration makes. If we ever process your end users' data for our own purposes we become a controller for that processing, and we do not do so under this agreement.
2. Subject matter, duration, nature and purpose
Subject matter: recognition of returning devices and the risk signals derived from them.
Duration: for as long as your account is active, plus the retention periods in section 6.
Nature and purpose: collecting technical browser and device characteristics, comparing them against the profiles previously seen on your projects, returning an identifier and risk signals to you, and storing the result so you can verify it server-side.
Permitted purposes: fraud prevention, account security, and abuse detection. Using the service for cross-site advertising, ad measurement, audience building, or any tracking unrelated to security is a breach of this agreement and grounds for termination.
3. Categories of data and data subjects
Data subjects: visitors to and users of your websites and applications.
Categories of personal data: technical device and browser characteristics (user agent, platform, screen properties, CPU core count, device memory, touch support, detected fonts, canvas and WebGL rendering output, audio processing output, language, timezone, math rounding behavior), the IP address and user agent observed by our servers, a derived country and datacenter flag, the derived visitor identifier, and the derived match and risk scores. Any identifier of your own that you choose to send us alongside a request.
The service does not collect names, email addresses, page contents, form input, keystrokes, browsing history, or anything the user typed, and it does not read or set advertising cookies. We ask you not to send us special-category data under Article 9 GDPR; the service has no field for it and no need of it.
4. Our obligations
- Process personal data only on your documented instructions.
- Keep the data confidential and limit access to the people who need it to operate the service.
- Implement the technical and organisational measures in section 5.
- Engage sub-processors only under section 7.
- Assist you with data subject requests, data protection impact assessments, and supervisory authority enquiries, as described in section 9.
- Notify you without undue delay, and in any event within 48 hours of becoming aware, of any personal data breach affecting your data, with the information we have at that point.
- Delete or return the data on termination, as described in section 6.
5. Security measures
- All data in transit is encrypted with TLS. The collector will not post over plain HTTP.
- Secret API keys are stored only as cryptographic hashes and compared in constant time. Public keys are origin-restricted per project.
- Visitor identifiers are scoped to a single project. The same device visiting two customers receives two unrelated identifiers, and no API key can read another project's data.
- Retention limits are enforced by a scheduled job in the production database, not by policy alone (section 6).
- Production access is limited to the operator of the service, over authenticated channels, and is used only to run and repair the service.
- Outbound webhook destinations are validated to public hosts to prevent internal network access.
- Databases are backed up; backups inherit the same access controls.
We are a small operation and we would rather tell you that plainly than imply a certification we do not hold. We do not currently hold ISO 27001 or SOC 2. If your risk assessment requires one, tell us before you integrate.
6. Retention and deletion
- Raw device signals attached to an identification event are deleted 30 days after the event.
- Identification events (visitor id, similarity, IP, user agent, timestamp, risk signals) are deleted 90 days after the event.
- Visitor profiles are deleted after 365 days with no new visit.
- Webhook delivery records are deleted after their retention period once delivery has succeeded or permanently failed.
- On your instruction: deleting a project in the dashboard immediately and permanently deletes its visitor profiles, events, keys, and webhook configuration. Closing your account deletes the remainder; see our privacy policy for the request route and turnaround.
Custom retention periods, shorter or longer, are available on Enterprise terms. Deletion from live systems is immediate; backups age out on their own cycle.
7. Sub-processors
You give general authorisation for the sub-processors below. Each is bound by data protection terms no less protective than this agreement.
- Hosting and database (application servers, Postgres) in the European Union.
- Content delivery and DNS for the collector script and website.
- Paddle as merchant of record for payments. Paddle processes your billing data as its own controller, under its own terms, and never receives end-user device data.
- Transactional email for account and billing messages. End-user device data is never sent by email.
We will give you at least 30 days' notice by email before adding or replacing a sub-processor that touches identification data. If you reasonably object on data protection grounds you may terminate the affected service without penalty for the remainder of the term.
8. Location and international transfers
The identification service, its database, and its backups are operated inside the European Union. We do not transfer identification data outside the EEA under this agreement. If that ever changes we will notify you in advance and put an Article 46 transfer mechanism in place first. Payment and email sub-processors may process account data outside the EEA under their own transfer mechanisms.
9. Data subject requests, audits, and assistance
Requests from your end users come to you, since you are the controller. If one reaches us we will forward it and not answer it ourselves. On your request we will locate, export, or delete the data held for a given visitor identifier, and we will help you answer access and erasure requests within 10 working days. You can also do most of this yourself: the visitor and event APIs read out everything we hold for a device, and project deletion erases it.
You may audit our compliance with this agreement once a year, and after any breach notification, by written questionnaire and interview with the operator of the service. On-site audits and penetration testing are available on Enterprise terms. We will answer honestly, including about things we have not built yet.
10. Liability, term, and precedence
This agreement takes effect when you first use the service and ends when your account is closed and the retention periods in section 6 have run. Where this agreement conflicts with our other terms on the processing of personal data, this agreement wins. Liability is governed by the agreement under which you purchase the service. This agreement is governed by Irish law, with the courts of Ireland having jurisdiction, and the Irish Data Protection Commission as our lead supervisory authority.
Contact
Privacy and data protection: [email protected]. For a countersigned copy, an Enterprise addendum, or a security questionnaire, use the same address or the contact form.