This Data Processing Agreement ("DPA") is entered into between Alpaka Ltd, a company incorporated in England and Wales under company number 10461680 whose registered office is at 6 The Leys, Northampton, NN2 6QZ ("Alpaka", "Processor"), and the Customer who has accepted the Presence Tools Terms of Service ("Controller").
This DPA forms part of and is incorporated into the Presence Tools Terms of Service. By accepting the Terms of Service, the Controller agrees to the terms of this DPA. This DPA governs the processing of personal data by Alpaka on behalf of the Controller in connection with the Presence Tools platform and API.
Article 28 UK GDPR. This agreement satisfies the requirement under Article 28 of the UK GDPR for a written contract governing the processing of personal data by a processor on behalf of a controller.
"Controller" has the meaning given to it in the UK GDPR and refers to the Customer in this context.
"Processor" has the meaning given to it in the UK GDPR and refers to Alpaka in this context.
"Data Subject" means an identified or identifiable natural person whose personal data is processed under this DPA, including End Users whose presence is verified through the Services.
"Personal Data" has the meaning given to it in the UK GDPR.
"Processing" has the meaning given to it in the UK GDPR.
"Services" means the Presence Tools platform, API and Console operated by Alpaka.
"Sub-processor" means any third party engaged by Alpaka to process Personal Data in connection with the Services.
"UK GDPR" means the retained EU law version of the General Data Protection Regulation as it forms part of the law of England and Wales, together with the Data Protection Act 2018.
2.1 In connection with the Services, the Controller submits Personal Data relating to End Users to Alpaka for processing. In respect of that data, the Controller is the data controller and Alpaka is the data processor.
2.2 Alpaka processes Personal Data only on the documented instructions of the Controller, as set out in this DPA and the Terms of Service, and only to the extent necessary to provide the Services.
2.3 Alpaka will inform the Controller promptly if, in its opinion, an instruction given by the Controller infringes the UK GDPR or other applicable data protection law.
| Detail | Description |
|---|---|
| Subject matter | Operation of the Presence Tools API for identity verification and presence checking |
| Duration | For the term of the Controller's account, plus any applicable retention period |
| Nature | Collection, storage, retrieval, comparison (face matching), transmission and deletion of identity and session data |
| Purpose | To enable the Controller to verify the physical presence of End Users through configurable challenges |
| Types of Personal Data | Names, email addresses, mobile numbers, external reference IDs, captured photographs, confidence scores, geolocation data, session metadata |
| Categories of Data Subjects | End Users: individuals whose identity is enrolled and whose presence is verified by the Controller |
| Special category data | Biometric data processed for face matching purposes, subject to the Biometric Acceptable Use Policy |
Alpaka shall:
5.1 Alpaka maintains technical and organisational measures appropriate to the risk, including:
5.2 All Customer Data is hosted in AWS eu-west-1 (Dublin, Ireland). No Personal Data is transferred outside the UK or EEA for storage purposes without appropriate safeguards.
6.1 The Controller grants Alpaka general authorisation to engage the following Sub-processors in connection with the Services:
| Sub-processor | Location | Purpose |
|---|---|---|
| Amazon Web Services (AWS) | eu-west-1, Dublin, Ireland | Infrastructure, storage, compute |
| Clerk | United States (EU data residency available) | Developer account authentication |
| Stripe | United States / Ireland | Payment processing |
6.2 Alpaka will notify the Controller of any intended changes to Sub-processors by updating this DPA or providing notice via the Console or email. The Controller may object to a new Sub-processor on reasonable grounds within 14 days of notice.
7.1 Alpaka will, to the extent possible and within a reasonable timeframe, assist the Controller in fulfilling its obligations to respond to requests from Data Subjects exercising rights under UK GDPR, including rights of access, rectification, erasure, restriction, portability and objection.
7.2 Where a Data Subject contacts Alpaka directly, Alpaka will direct the request to the Controller without undue delay.
7.3 The Controller is responsible for ensuring that End Users are provided with appropriate privacy notices explaining how their data will be processed through the Services.
8.1 Alpaka will notify the Controller without undue delay, and in any event within 72 hours where feasible, after becoming aware of a personal data breach affecting Personal Data processed under this DPA.
8.2 Notification will include, to the extent then known: the nature of the breach, categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed to address the breach.
8.3 The Controller remains responsible for notifying the ICO and affected Data Subjects where required.
Personal Data processed under this DPA is stored and processed within the EEA (AWS eu-west-1). Where any Sub-processor processes data outside the UK or EEA, Alpaka ensures that appropriate transfer mechanisms are in place, including reliance on adequacy decisions or standard contractual clauses as applicable.
10.1 This DPA remains in force for the duration of the Controller's use of the Services.
10.2 On expiry or termination of the Services, Alpaka will, at the Controller's election, delete or return all Personal Data within 30 days, except where retention is required by applicable law.
This DPA is governed by the laws of England and Wales. Any disputes arising in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales.
For any questions about this DPA or data protection matters, contact Alpaka at hello@presence.tools.