Skip to content
thisverify

Data Processing Addendum (DPA)

Last updated: 7 October 2026

This addendum applies to business customers who upload documents containing third-party personal data.

1. Roles

The customer is the database owner (controller); ThisVerify processes the data on its behalf (processor) and on its instructions only.

2. Purpose

Analysing documents to detect forgery and prevent fraud, storing reports and giving the customer access to them.

3. Processor obligations

  • Process data only on documented customer instructions and in line with the Terms of Service.
  • Maintain confidentiality and limit access to personnel who need it.
  • Implement the security measures described on the Security page.
  • Notify the customer without undue delay of a severe security incident.
  • Assist the customer in responding to data-subject requests.
  • Delete or return data at the end of the engagement.

4. Sub-processors

Vercel Inc., Neon Inc. and Google LLC, and — where enabled — the operator of our private model server. Changes will be published on this page.

5. Location

Storage in the EU (Frankfurt). AI processing on Google infrastructure and, where enabled, on our private model server.

6. Audit

Enterprise customers may request reasonable information about our security measures. A custom DPA can be signed: —.