Data Processing Agreement
Last updated 31 August 2026
Parties and scope
This agreement is between you (the Controller) and KYCWire (operated by the account owner; company details on request at [email protected]) (the Processor). It applies to all personal data you submit to the screening API, batch and monitoring features (Screening Data) and forms part of the Terms of Service. It is accepted by using the service or by clicking Accept DPA in your dashboard, which records the time of acceptance.
Nature and purpose of processing
Comparing Screening Data against sanctions lists; returning candidate matches; storing screening records for the retention period you chose; re-screening monitored entities when lists change; delivering results via API, webhooks and email. Duration: while your account exists, plus the retention period.
Categories of data subjects: your customers, counterparties, employees or other persons you screen. Categories of data: names and aliases, dates of birth, nationality or country, identity-document and registration numbers, and any reference you attach. No biometric or special-category data is required or expected.
Processor obligations
We process Screening Data only on your documented instructions (the API calls you make), keep it confidential, apply the security measures below, assist you with data-subject requests and impact assessments as far as the information is in our hands, delete or return the data at the end of the service, and make available the information needed to demonstrate compliance.
We do not use Screening Data to train models, to build profiles, or for any purpose of our own.
Sub-processors
Current sub-processors: OVH SAS (hosting, EU); Cloudflare, Inc. (network, DNS, bot protection); Stripe (card payments, account data only); CoinGate and Heleket (crypto payments, account data only). We notify you by email at least 14 days before adding or replacing a sub-processor; you may object, and if we cannot accommodate the objection you may terminate the service.
Security
Encryption in transit (TLS 1.2+); API keys stored as SHA-256 hashes; access limited to the operator; daily encrypted backups with 30-day rotation; audit log of every screening; rate limiting and bot protection; alerting on failed list updates. We notify you of a personal-data breach affecting Screening Data without undue delay and no later than 72 hours after becoming aware of it.
International transfers
Screening Data is stored in the EU. Cloudflare may process request metadata at edge locations worldwide under its Standard Contractual Clauses.
Deletion
Screening records are deleted automatically at the end of the retention period, or earlier at your request via the API or [email protected]. On account deletion all Screening Data is deleted within 30 days, except backups which expire within a further 30 days.
Audit
On written request, no more than once a year, we provide the information reasonably necessary to demonstrate compliance with this agreement. Where that is insufficient, we will allow an audit at your expense, on reasonable notice, limited to the systems that process your data.