Data Processing Agreement

Last updated October 7, 2026

For business users integrating the GenID API (API keys) — where you submit content on behalf of your own end users, this DPA supplements our Terms of Service and applies automatically to that use. If you're using GenID only for your own content under your own account, you don't need this document — our Privacy Policy covers that relationship.

1. Roles

Where you (the “Customer”) submit personal data belonging to your own end users through the GenID API — for example, a user-submitted image containing identifiable people — Customer is the controller and GenID (operated by DealDily) is the processor, processing that data solely to provide the certification pipeline (hashing, optional blockchain anchoring, manifest embedding, certificate generation) as instructed by Customer's use of the API.

2. Scope of processing

Subject matter: images and associated metadata submitted via the GenID API. Duration: for as long as Customer's account is active, plus the retention described in our Privacy Policy. Nature: storage, hashing, cryptographic signing, optional blockchain anchoring, and certificate generation. Categories of data subjects: Customer's end users whose content is submitted for certification.

3. Subprocessors

GenID uses the subprocessors listed at /subprocessors, which states what each one is for and what data it receives. We'll update that page if our subprocessors change.

4. Security measures

Identity verification is handled directly by Stripe Identity — we never receive the raw ID document or selfie. API keys are stored as cryptographic hashes, never in plaintext. Session content is hash-chained and signed so any tampering is independently detectable. Storage access runs only through server-side, service-role-authenticated routes, never direct client access.

5. Sub-processing and international transfer

Our subprocessors are primarily US-based (see /subprocessors for each one's location). Where Customer or its end users are located outside the US, data is transferred to and processed in the US.

6. Assistance with data subject rights

Where Customer needs to respond to one of its end users' data subject requests (access, deletion, etc.) concerning data processed through GenID, contact us at the address below and we'll provide reasonable assistance — including, for deletion, the same scope described in our Privacy Policy (a finalized, certified session's hash-chain records and stored image are retained to preserve third-party verifiability, and nothing can be removed from a Polygon anchor once confirmed).

7. Breach notification

We'll notify Customer without undue delay after becoming aware of a security breach affecting Customer's data processed under this DPA.

8. Term

This DPA is effective for as long as Customer uses the GenID API to process personal data on behalf of its own end users, and terminates automatically when the underlying Terms of Service terminate.

9. Contact

Questions about this DPA, or to request a countersigned copy for your own records: legal@genid.app