1. Scope & Order of Precedence
This Data Processing Agreement ("DPA") supplements the phoneveriflo Terms of Service and applies to the processing of Customer Personal Data by phoneveriflo Ltd. in connection with providing verification services.
In the event of any conflict between this DPA and the Terms of Service, the provisions of this DPA shall prevail with respect to data protection obligations.
2. Controller & Processor Roles
- Customer as Controller: The Customer determines the purposes and means of processing Customer Personal Data and warrants that it has established a valid lawful basis (including necessary consents or notices) prior to submitting datasets.
- phoneveriflo as Processor: phoneveriflo shall process Customer Personal Data strictly upon the documented instructions of the Customer and in accordance with applicable Data Protection Legislation (GDPR Art. 28(3)(a)).
3. Technical & Organizational Measures (TOMs)
phoneveriflo implements and maintains appropriate technical and organizational measures to protect Customer Personal Data against unauthorized access, destruction, loss, or alteration (GDPR Art. 32):
- Envelope Encryption: AES-256-GCM encryption for all stored files, cache records, and preflight outputs.
- In-Transit Cryptography: TLS 1.3 encryption with strict cipher suites for all network ingress and egress.
- Pseudonymized Indexing: Blind HMAC-SHA256 nonces for cache lookups, preventing plain PII indexing.
- Role-Based Access: Multi-factor authentication, least-privilege RBAC, and immutable audit trails for administrative access.
4. Sub-processor Authorization
The Customer grants general written authorization to phoneveriflo to engage technical sub-processors (cloud hosting, database replication, email delivery) to provide the Service.
phoneveriflo imposes equivalent data protection obligations on all sub-processors under binding written contracts and remains fully liable for the performance of its sub-processors' obligations.
5. Data Subject Rights Assistance
Taking into account the nature of processing, phoneveriflo provides self-service tools and technical assistance to enable the Customer to fulfill its obligations to respond to data subject requests under GDPR Chapter III (access, rectification, erasure, restriction, and portability).
6. Security Incident Notification
In the event of a confirmed Personal Data Breach affecting Customer Personal Data, phoneveriflo shall notify the Customer without undue delay and in any event within forty-eight (48) hours of becoming aware of the breach, providing relevant details to assist the Customer in regulatory notifications.
7. Data Deletion & Return
Upon termination of services or upon customer request, phoneveriflo shall delete or return all Customer Personal Data in accordance with our rolling retention policies, except where retention is required by applicable statutory law.
8. Standard Contractual Clauses (SCCs)
For data transfers to third countries not recognized as providing an adequate level of data protection, the parties incorporate by reference the European Commission Standard Contractual Clauses (Module 2: Controller to Processor).