Proof

Data Processing Addendum

Proof has launched a portable digital identity solution specifically designed for banks, accompanied by a comprehensive set of legal documents including a Data Processing Addendum, various supplemental terms, partner terms, and additional legal policies accessible through their website.

New

Proof launches portable digital identity for banks

Introducing portable identity

Learn more

Notarize now Log in

General Terms

Supplemental Terms

Supplemental Terms Acceptable Use Supplement API and SDK Supplement Data Processing Addendum Individual Digital Certificate Supplement In-House Notary Supplement Link Supplement Notary User Supplement Organization Digital Certificate Supplement Real Estate Supplement Subscriber Supplement U.S. Postal Service Form 1583 Supplement

Partner Terms

Affiliate Partner Terms Referral Partner Terms

Additional Terms

Biometric Class Action Waiver Certificate Policy Certification Practice Statement Glossary Legal Terms Archive Privacy Policy Registration Practice Statement Security Statement

Data Processing Addendum

Last Modified Date:

September 25, 2026

Download PDF

This Data Processing Addendum (“ DPA”) is incorporated into the Proof General Terms (“ General Terms”) and is a Supplement for purposes of the Agreement. Capitalized terms not otherwise defined have the meanings given in the General Terms, the Proof Glossary, or the Order Form. This Data Processing Addendum replaces both the Data Processing Supplement and the Data Privacy Supplement. Any reference to the Data Processing Supplement or the Data Privacy Supplement in the Order Form or elsewhere in the Agreement shall be read to refer to this Data Processing Addendum.

  1. 1.

    Applicability. This DPA applies to Proof and to each User that is a Company. This DPA does not apply to Users acting in an individual capacity, whose Personal Information Proof processes as described in the Proof Privacy Policy. Proof is the corporate entity that processes Personal Information on behalf of the Company.

    ‍

  2. 2.

    Definitions.

    2.1 “Authorized Persons” means persons or categories of persons that Company authorizes to give Proof material personal information processing instructions.

    2.2 “Company” means the corporate entity that determines the material personal information processing instructions.

    2.3 “Company Personal Information” means Personal Information that Company provides to Proof, or that Proof collects or Processes on Company’s instructions, in connection with the Agreement. Company Personal Information does not include (a) Personal Information that Proof collects directly from End Users under the Proof General Terms and the Proof Privacy Policy, including an End User’s Digital Identity and identity-verification artifacts, or (b) Electronic Notarial Records.

    2.4 “ Company Purpose” means provision of Services or access to the Platform.

    2.5“ Data Subject” means an individual who is the subject of Personal Information.

    ‍ 2.6 “Personal Information” means any information Proof processes for Company that (a) identifies or relates to an individual who can be identified directly or indirectly from that data alone or in combination with other information in Proof’s possession or control or that Proof is likely to have access to, or (b) information the relevant Privacy and Data Protection Requirements otherwise define as covered data. Personal Information includes the portions of User Data and Subscriber Data that identify or relate to an identifiable individual.

    2.7 “Privacy and Data Protection Requirements” means all applicable federal, state, municipal, and foreign laws and regulations relating to the processing, protection, or privacy of Personal Information, including guidance and codes of practice issued by regulatory bodies in any relevant jurisdiction applicable to Proof’s processing activities under this DPA.

    2.8 “Processing, processes, or process” means operation or set of operations which is performed on Personal Information or on sets of Personal Information, whether or not by automated means or that the relevant Privacy and Data Protection Requirements may otherwise include in the definition of processing, processes, or process. Examples include, collecting, receiving, recording, storing, organizing, amending, retrieving, using, disclosing, erasing, or destroying it. Processing also includes transferring Personal Information to third parties.

    ‍ ‍

  3. 3.

    Company Obligations and Personal Information Types.

    3.1 Company remains responsible for its compliance obligations under the Privacy and Data Protection Requirements.

    3.2 Upon request, Proof will provide the general Personal Information categories and Data Subject types that Proof may process to fulfill the Company Purpose.

    ‍ ‍

  4. 4.

    Proof Obligations. 4.1 Proof will Process Personal Information as necessary to perform its obligations under the Agreement and in accordance with applicable law. Company’s documented instructions for processing are deemed to be those set forth in the Agreement, together with any additional written instructions from Authorized Persons. Proof will not Process Personal Information for any other purpose or in a way that does not comply with this DPA or the Privacy and Data Protection Requirements. Proof must promptly notify Company if, in its opinion, Company’s instruction would not comply with the Privacy and Data Protection Requirements.

    4.2 Proof must promptly respond to any reasonable Company request or instruction requiring Proof to stop, mitigate, or remedy any unauthorized processing.

    4.3 Proof will maintain the confidentiality of all Personal Information, will not sell it to anyone, and will not disclose it to third parties unless the disclosure is necessary to accomplish the Company Purpose, Company instructs Proof to make the disclosure, this DPA specifically authorizes the disclosure, or if the disclosure is required by law.

    4.4 Proof will reasonably assist Company with meeting Company’s compliance obligations under the Privacy and Data Protection Requirements, taking into account the nature of Proof’s processing and the information available to Proof.

    4.5 Proof must promptly notify Company of any changes to Privacy and Data Protection Requirements that may adversely affect Proof’s performance of the Agreement.

    4.6 Company acknowledges that Proof is under no duty to investigate the completeness, accuracy, or sufficiency of any specific Company instructions from Authorized Persons or the Personal Information other than as required under the Privacy and Data Protection Requirements.

    4.7 Personal Information and identity-verification artifacts that Proof collects directly from End Users under the Proof General Terms and Privacy Policy are Processed to provide the Services, to comply with applicable law, and for fraud prevention. Nothing in this DPA grants Company a right to in-Platform display of such information.

    ‍ ‍

  5. 5.

    Proof Employees. 5.1 Proof will limit Personal Information access to those of its employees who require Personal Information access to meet Proof’s obligations under this DPA and the Agreement; and

    ‍

    5.2 Proof will ensure that all employees:

    (a) are informed of Personal Information’s confidential nature and use restrictions;

    (b) have undertaken training on the Privacy and Data Protection Requirements relating to handling Personal Information and how it applies to their particular duties; and

    (c) are aware of Proof’s duties and their personal duties and obligations under the Privacy and Data Protection Requirements and this DPA.

    ‍ ‍

  6. 6.

    Cross-Border Transfers. Upon request, Proof will provide a list of the countries where Proof may receive, access, transfer, or store Personal Information.

    ‍ ‍

  7. 7.

    Subcontractors. 7.1 Proof may authorize a subcontractor to process Personal Information only if:

    (a) Proof makes available a current list of its subcontractors which Proof may satisfy by posting the list at a URL or within the Platform;

    (b) Proof provides notice of additions to that list which may be given by updating the posted list and gives Company an opportunity to object to a new subcontractor on reasonable data-protection grounds;

    (c) Proof enters into a written contract with the subcontractor that contains terms substantially the same as those in this DPA and, upon Company’s written request, provides Company with a copy of the contract; and

    (d) Proof maintains control over all Personal Information it entrusts to the subcontractor.

    ‍ 7.2 Upon request, Proof will provide a list of its approved subcontractors, including each subcontractor’s name and location which Proof may satisfy by posting the list at a URL or within the Platform.

    7.3 If a subcontractor fails to fulfill its obligations under a written agreement with Proof, Proof remains fully liable to Company for the subcontractor’s performance of its obligations under this DPA.

    7.4 Proof is deemed to control any Personal Information controlled by or in the possession of its subcontractors.

    ‍ ‍

  8. 8.

    Data Subject Requests.

    8.1 Proof will notify Company if it receives a Data Subject request that relates to Company’s use of the Services.

    8.2 If Proof or Company receives a request from a Data Subject for deletion of their Personal Information, Proof will delete that data unless retention is required or permitted by law, including Applicable Notary Law, or the Agreement.

    8.3 Proof will reasonably cooperate with Company in responding to any complaint, notice, or Data Subject request.

    ‍ ‍

  9. 9.

    Aggregate and De-identified Data. Notwithstanding anything in this DPA to the contrary, Proof retains the right to Process De-Identified Data for its own purposes, provided the processing is consistent with applicable law. ‍

  10. 10.

    Term and Termination. 10.1 This DPA will remain in full force and effect so long as the Agreement remains in effect, and thereafter so long as Proof possesses or controls Personal Information related to the Agreement.

    10.2 Any provision of this DPA that expressly or by implication should come into or continue in force on or after termination of the Agreement in order to protect Personal Information will remain in full force and effect.

    10.3 If a change in Privacy and Data Protection Requirements prevents either party from fulfilling any of its obligations under the Agreement, the parties will suspend active Processing of Personal Information until that processing complies with the new requirements. If the parties are unable to bring Personal Information Processing into compliance, either party may terminate the Agreement on written notice to the other party. ‍

  11. 11.

    Data Return and Destruction. 11.1 At Company’s request, Proof will give Company a copy of, or access to, all or part of the Company Personal Information in its possession or control.

    11.2 On termination of the Agreement for any reason and receipt of a written request, Proof will securely destroy or return all or any Company Personal Information related to the Agreement in its possession or control, excluding Personal Information Proof is permitted to retain under the Agreement or required to retain to comply with legal obligations or industry standards. Company may not require Proof to return, destroy, or delete Personal Information that is not Company Personal Information, including Personal Information Proof collects directly from End Users and Electronic Notarial Records, which Proof retains and Processes as described in the Proof General Terms, the Proof Privacy Policy, and applicable law.

    11.3 Company acknowledges that in-Platform display of certain Personal Information including identity-verification artifacts, identification-document images, and audio-visual recordings may be conditioned on Company completing Proof’s verification of Company, and Proof may restrict in-Platform display of such information pending verification. Such restrictions do not limit Proof’s obligations under this Data Return and Destruction section.

    11.4 Proof may satisfy any request under this DPA through a secure delivery method of Proof’s choosing, including secure file transfer outside the Platform.

    11.5 Proof may require reasonable verification of the identity and authority of any person or entity making a request under this DPA before fulfilling the request. ‍

  12. 12.

    Records. Proof will keep detailed, accurate, and up-to-date records regarding any Processing of Personal Information it carries out for Company, including but not limited to, the access, control, and security of the Personal Information, approved subcontractors and affiliates, the processing purposes, and any other records required by the Privacy and Data Protection Requirements (“ Records”). Proof will ensure that Records are sufficient to enable Company to verify Proof’s compliance with its obligations under this DPA. ‍

  13. 13.

    Audit. At Company’s reasonable request, Proof will provide information relevant to Proof’s handling of Personal Information and Proof’s compliance with this DPA. ‍

  14. 14.

    Warranties. 14.1 Proof represents and warrants that:

    (a) its employees, subcontractors, agents, and any other person or persons accessing Personal Information on its behalf have received commercially reasonable training on the Privacy and Data Protection Requirements relating to the Personal Information; and

    (b) it and anyone operating on its behalf will process Personal Information in material compliance with the terms of this DPA and the Privacy and Data Protection Requirements; and

    (c) it understands this DPA’s restrictions and prohibitions on selling Personal Information and retaining, using, or disclosing Personal Information outside of the parties’ direct business relationship, and it will comply with them.

    14.2 Company represents and warrants that Proof’s use of the Personal Information for the Company Purpose and as specifically instructed by Company will comply with all Privacy and Data Protection Requirements. ‍

  15. 15.

    Indemnification. Proof will defend Company against third-party claims arising from Proof’s breach of its obligations under this DPA and will indemnify Company against damages finally awarded against Company, or amounts in settlements approved by Proof in writing, with respect to those claims. Any limitation of liability in the Agreement applies to the foregoing indemnity and reimbursement obligations.