Skip to content
VerifiX — secured by ITSEC

Legal

Data Processing Addendum

This addendum applies where ITSEC processes personal data on behalf of a VerifiX customer. It forms part of the agreement between the customer (controller) and ITSEC (processor).

Effective
1 August 2026
Provider
ITSEC

These terms describe how the platform is supplied. Enterprise agreements, order forms, and any negotiated amendments take precedence over this page where they conflict.

1.Roles and instructions

The customer determines the purposes and means of processing and is the controller. ITSEC processes personal data only on the customer's documented instructions, which are the agreement, the order form, this addendum, and the configuration the customer sets in the console.

If ITSEC believes an instruction breaches applicable data protection law, it will notify the customer and may pause the affected processing.

2.Subject matter, duration, and nature of processing

Subject matter: provision of identity verification, business verification, screening, transaction monitoring, Travel Rule messaging, case management, and decisioning services. Duration: the term of the agreement plus the retention and deletion periods below. Nature: collection, storage, structuring, matching, screening, scoring, disclosure to the customer, and deletion.

3.Categories of data subject and personal data

  • Data subjects: the customer's applicants, customers, beneficial owners, directors, authorized signatories, counterparties, and its own console users.
  • Identity data: name, date of birth, nationality, gender, government identifier where captured, and address.
  • Document data: identity document images, extracted document fields, and document security check results.
  • Biometric data: facial images and liveness capture frames used for face comparison, where the customer enables those modules.
  • Business data: company identifiers, registry filings, ownership and control structures, and officer records.
  • Screening data: sanctions, PEP, watchlist, and adverse-media match records with source and timestamp.
  • Transaction and wallet data: addresses, counterparties, exposure indicators, and monitoring alerts.
  • Operational data: case notes, reviewer decisions, and audit events, including console user identifiers.

4.Security measures

  • Hosting in UAE regions on Amazon Web Services and Microsoft Azure.
  • Encryption in transit and at rest, with managed key services and scheduled key rotation.
  • Role-based, least-privilege access control with logged administrative access and separation of environments.
  • An immutable audit trail of verification, decision, and review events.
  • Change management, vulnerability management, and logging and monitoring under ITSEC's ISO/IEC 27001 controls, with business continuity managed under ISO 22301.
  • Personnel screening, confidentiality obligations, and security training for staff with access to production systems.

5.Sub-processors

The customer authorizes the sub-processors listed on the sub-processors page. ITSEC imposes data protection obligations on each sub-processor no less protective than this addendum and remains responsible for their performance.

ITSEC will give notice before adding or replacing a sub-processor that processes customer personal data, and the customer may object on reasonable data protection grounds, in which case the parties will discuss a workable alternative.

6.International transfers

Platform data is held in the UAE. Where a screening, registry, analytics, or Travel Rule source is located outside the UAE, only the data required for that specific query is transferred, under contractual protections with the recipient and subject to the customer's configuration of the module.

7.Assistance to the controller

  • Support with data subject requests, including access to the records held for a case and correction or deletion where instructed.
  • Assistance with data protection impact assessments and prior consultations, to the extent the information is within ITSEC's control.
  • Notification of a personal data breach affecting customer data without undue delay after becoming aware of it, with the information available at the time and updates as the investigation proceeds.

8.Audit and information rights

ITSEC will make available the information reasonably needed to demonstrate compliance with this addendum, including current certifications and the security documentation pack. Customer audits are arranged on reasonable notice, no more than once a year absent a security incident or regulatory requirement, and are subject to confidentiality and to controls that protect other customers' data.

9.Retention, return, and deletion

Retention periods for case records are configured by the customer to match its own record-keeping obligations. During the term the customer can export its records and evidence at any time through the console and API.

On termination, the customer has the retrieval window recorded in the order form to export data, after which ITSEC deletes or anonymizes customer personal data, except where retention is required by law. Backups age out on their normal cycle.

10.Order of precedence and contact

Where a signed data processing agreement exists between the parties, that document prevails over this page. To request the signature-ready addendum, the security pack, or a DDQ response, write to sales@verifix.ae.