legal

Data Processing Agreement

Version 1.0, last updated 25 July 2026

This agreement governs our processing of personal data on your behalf when you use the WhorlID identification service. It applies automatically to every account: by using the service you accept these terms, so there is nothing to sign before you can start. If your procurement process needs a countersigned copy, or your own paper instead of ours, write to [email protected] and we will sign.

This is our template, published so you can read it before you integrate. It is not legal advice, and it does not decide your side of the question: see deploying WhorlID lawfully for what you need to have in place on your own site.

1. Roles

You are the controller. You decide to run device identification on your site, for which purposes, and on what legal basis. We are the processor: we process device data only to provide the service and only on your instructions, which are the settings you choose in your project plus the API calls your integration makes. If we ever process your end users' data for our own purposes we become a controller for that processing, and we do not do so under this agreement.

2. Subject matter, duration, nature and purpose

Subject matter: recognition of returning devices and the risk signals derived from them.

Duration: for as long as your account is active, plus the retention periods in section 6.

Nature and purpose: collecting technical browser and device characteristics, comparing them against the profiles previously seen on your projects, returning an identifier and risk signals to you, and storing the result so you can verify it server-side.

Permitted purposes: fraud prevention, account security, and abuse detection. Using the service for cross-site advertising, ad measurement, audience building, or any tracking unrelated to security is a breach of this agreement and grounds for termination.

3. Categories of data and data subjects

Data subjects: visitors to and users of your websites and applications.

Categories of personal data: technical device and browser characteristics (user agent, platform, screen properties, CPU core count, device memory, touch support, detected fonts, canvas and WebGL rendering output, audio processing output, language, timezone, math rounding behavior), the IP address and user agent observed by our servers, a derived country and datacenter flag, the derived visitor identifier, and the derived match and risk scores. Any identifier of your own that you choose to send us alongside a request.

The service does not collect names, email addresses, page contents, form input, keystrokes, browsing history, or anything the user typed, and it does not read or set advertising cookies. We ask you not to send us special-category data under Article 9 GDPR; the service has no field for it and no need of it.

4. Our obligations

5. Security measures

We are a small operation and we would rather tell you that plainly than imply a certification we do not hold. We do not currently hold ISO 27001 or SOC 2. If your risk assessment requires one, tell us before you integrate.

6. Retention and deletion

Custom retention periods, shorter or longer, are available on Enterprise terms. Deletion from live systems is immediate; backups age out on their own cycle.

7. Sub-processors

You give general authorisation for the sub-processors below. Each is bound by data protection terms no less protective than this agreement.

We will give you at least 30 days' notice by email before adding or replacing a sub-processor that touches identification data. If you reasonably object on data protection grounds you may terminate the affected service without penalty for the remainder of the term.

8. Location and international transfers

The identification service, its database, and its backups are operated inside the European Union. We do not transfer identification data outside the EEA under this agreement. If that ever changes we will notify you in advance and put an Article 46 transfer mechanism in place first. Payment and email sub-processors may process account data outside the EEA under their own transfer mechanisms.

9. Data subject requests, audits, and assistance

Requests from your end users come to you, since you are the controller. If one reaches us we will forward it and not answer it ourselves. On your request we will locate, export, or delete the data held for a given visitor identifier, and we will help you answer access and erasure requests within 10 working days. You can also do most of this yourself: the visitor and event APIs read out everything we hold for a device, and project deletion erases it.

You may audit our compliance with this agreement once a year, and after any breach notification, by written questionnaire and interview with the operator of the service. On-site audits and penetration testing are available on Enterprise terms. We will answer honestly, including about things we have not built yet.

10. Liability, term, and precedence

This agreement takes effect when you first use the service and ends when your account is closed and the retention periods in section 6 have run. Where this agreement conflicts with our other terms on the processing of personal data, this agreement wins. Liability is governed by the agreement under which you purchase the service. This agreement is governed by Irish law, with the courts of Ireland having jurisdiction, and the Irish Data Protection Commission as our lead supervisory authority.

Contact

Privacy and data protection: [email protected]. For a countersigned copy, an Enterprise addendum, or a security questionnaire, use the same address or the contact form.

Privacy policy | Deploying WhorlID lawfully | Back to home

Data Processing Agreement | WhorlID