Data Processing Agreement (DPA)
Template · Last updated: June 2026
This is a template for customers who require a DPA under the GDPR/UK GDPR (Article 28). For a countersigned copy or to use your own paper, email contact@chainanchor.io. This template is not legal advice.
This DPA forms part of the agreement between the customer (“Controller”) and ChainAnchor (“Processor”) for use of the Service. Where ChainAnchor processes personal data on the Controller’s behalf, the following terms apply.
1. Roles & scope
The Controller determines the purposes and means of processing; the Processor processes personal data only on the Controller’s documented instructions, including as set out in the agreement and this DPA. For its own account data, ChainAnchor acts as an independent controller.
2. Details of processing
- Subject matter / duration: provision of the Service for the term of the agreement.
- Nature & purpose: storing and displaying proofs, anchoring fingerprints on-chain, monitoring, and related features.
- Types of personal data: account identifiers (email, username), and any personal data contained in content the Controller chooses to anchor or capture.
- Categories of data subjects: the Controller’s users and any individuals appearing in captured content.
3. Processor obligations
- Process personal data only on documented instructions, including for international transfers, unless required by law (in which case it will inform the Controller where permitted).
- Ensure persons authorized to process are bound by confidentiality.
- Implement appropriate technical and organizational security measures (see the Security & Trust page).
- Assist the Controller, taking into account the nature of processing, in responding to data-subject requests and in meeting its obligations on security, breach notification, and DPIAs.
- Notify the Controller without undue delay after becoming aware of a personal-data breach.
- At the Controller’s choice, delete or return personal data at the end of the agreement, subject to legal retention requirements. Note: data already written to the public blockchain (hashes + timestamps) is permanent and cannot be deleted.
- Make available information necessary to demonstrate compliance and allow for reasonable audits.
4. Sub-processors
The Controller provides general authorization for the Processor to engage the sub-processors listed on the Security & Trust page. The Processor will give notice of intended changes and remain responsible for its sub-processors’ performance.
5. International transfers
Where personal data is transferred outside the EEA/UK, the Processor relies on an appropriate transfer mechanism (such as the Standard Contractual Clauses), which are incorporated by reference where applicable.
6. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the agreement.