Legal

Data Processing Agreement

The Article 28 terms governing personal data that OnchainSuite processes on behalf of customers, including the technical and organisational measures we apply.

Last updated: 11 August 2026 · All legal documents

1. Parties and role

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the Customer (the “Controller”) and OnchainSuite Ltd (the “Processor”). It applies where OnchainSuite processes personal data on the Customer’s behalf. Where there is a conflict on data protection matters, this DPA prevails.

2. Definitions

“UK GDPR”, “controller”, “processor”, “personal data”, “processing”, “data subject”, and “personal data breach” have the meanings in the UK GDPR and the Data Protection Act 2018. “Applicable Data Protection Law” means the UK GDPR, the DPA 2018, and, where relevant, the EU GDPR.

3. Processing on documented instructions

OnchainSuite processes personal data only on the Customer’s documented instructions (including as set out in the Terms and this DPA), unless required by law, in which case we will inform the Customer unless legally prohibited. We will tell the Customer if, in our opinion, an instruction infringes Applicable Data Protection Law.

4. Details of processing (Annex 1)

5. Confidentiality

We ensure that personnel authorised to process personal data are bound by confidentiality and are trained on their obligations, on a need-to-know, least-privilege basis.

6. Security

Taking account of the state of the art and the risk, we implement the technical and organisational measures set out in Annex 2 below, and may update them provided protection is not materially reduced.

7. Sub-processors

The Customer gives general authorisation for OnchainSuite to engage sub-processors to provide the service. A current list is maintained on our Sub-processors page. We impose data protection obligations on each sub-processor that are no less protective than this DPA and remain responsible for their performance. We will give at least 30 days’ notice of new sub-processors (via the Sub-processors page or email), during which the Customer may object on reasonable data protection grounds.

8. Assistance to the Controller

  • We assist the Customer, by appropriate measures, to respond to data subject requests (access, rectification, erasure, restriction, portability, objection).
  • We assist with the Customer’s obligations on security, breach notification, data protection impact assessments, and prior consultation (Articles 32–36), taking account of the information available to us.
  • We notify the Customer without undue delay after becoming aware of a personal data breach affecting their data, with the information reasonably available to help them meet their notification duties.

9. Return or deletion

On termination, and at the Customer’s choice, we delete or return the personal data and delete existing copies, unless retention is required by law. Routine deletion occurs within 90 days of termination.

10. Audits

We make available information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, by the Customer or an auditor it mandates, subject to reasonable notice, confidentiality, and frequency. We may satisfy audit requests by providing third-party reports or certifications where available.

11. International transfers

Any transfer of personal data outside the UK is made under an approved transfer mechanism as described on our International Data Transfers page, which forms part of this DPA.

12. Liability & governing law

Each party’s liability under this DPA is subject to the limitations in the Terms. This DPA is governed by the laws of England and Wales.

Annex 2, Technical and organisational measures

  • Encryption, personal data encrypted in transit (TLS) and at rest.
  • Access control, role-based, least-privilege access; unique credentials; multi-factor authentication for administrative access; prompt revocation on role change.
  • Non-custodial, read-only chain access, we never custody assets and never initiate or sign transactions; on-chain access is read-only.
  • Pseudonymisation & data minimisation, we collect and link contact identifiers only on opt-in and only what is needed for the service.
  • Network & application security, segregation, hardened infrastructure, secrets management, dependency and vulnerability management.
  • Logging & monitoring, audit logging of administrative access and security-relevant events.
  • Resilience, backups, recovery procedures, and tested business continuity.
  • Vendor management, due diligence and data protection terms with sub-processors.
  • Personnel, confidentiality undertakings and security awareness training.
  • Breach response, documented incident response and notification process.

[Align this annex with your actual implemented controls and any certification you hold or are pursuing (e.g. ISO 27001 / SOC 2).]