Data Processing Agreement
Last updated October 7, 2026
For business users integrating the GenID API (API keys) — where you submit content on behalf of your own end users, this DPA supplements our Terms of Service and applies automatically to that use. If you're using GenID only for your own content under your own account, you don't need this document — our Privacy Policy covers that relationship.
1. Roles
Where you (the “Customer”) submit personal data belonging to your own end users through the GenID API — for example, a user-submitted image containing identifiable people — Customer is the controller and GenID (operated by DealDily) is the processor, processing that data solely to provide the certification pipeline (hashing, optional blockchain anchoring, manifest embedding, certificate generation) as instructed by Customer's use of the API.
2. Scope of processing
Subject matter: images and associated metadata submitted via the GenID API. Duration: for as long as Customer's account is active, plus the retention described in our Privacy Policy. Nature: storage, hashing, cryptographic signing, optional blockchain anchoring, and certificate generation. Categories of data subjects: Customer's end users whose content is submitted for certification.
3. Subprocessors
GenID uses the subprocessors listed at /subprocessors, which states what each one is for and what data it receives. We'll update that page if our subprocessors change.
4. Security measures
Identity verification is handled directly by Stripe Identity — we never receive the raw ID document or selfie. API keys are stored as cryptographic hashes, never in plaintext. Session content is hash-chained and signed so any tampering is independently detectable. Storage access runs only through server-side, service-role-authenticated routes, never direct client access.
5. Sub-processing and international transfer
Our subprocessors are primarily US-based (see /subprocessors for each one's location). Where Customer or its end users are located outside the US, data is transferred to and processed in the US.
6. Assistance with data subject rights
Where Customer needs to respond to one of its end users' data subject requests (access, deletion, etc.) concerning data processed through GenID, contact us at the address below and we'll provide reasonable assistance — including, for deletion, the same scope described in our Privacy Policy (a finalized, certified session's hash-chain records and stored image are retained to preserve third-party verifiability, and nothing can be removed from a Polygon anchor once confirmed).
7. Breach notification
We'll notify Customer without undue delay after becoming aware of a security breach affecting Customer's data processed under this DPA.
8. Term
This DPA is effective for as long as Customer uses the GenID API to process personal data on behalf of its own end users, and terminates automatically when the underlying Terms of Service terminate.
9. Contact
Questions about this DPA, or to request a countersigned copy for your own records: legal@genid.app