Data Processing Agreement
Last updated: September 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service and applies whenever BadgeSeal processes personal data on behalf of an organization (the "Customer") as a data processor, under Article 28 of the GDPR. It is incorporated automatically — on every plan, at no extra cost — when an organization creates a BadgeSeal account and uploads staff data, alongside the Terms of Service and Privacy Policy. No separate signature is required for this standard version.
1. Roles
The Customer is the data controller for the personal data of its own staff members that it uploads to the Service. BadgeSeal is the data processor, processing that data only as instructed by the Customer and solely to provide the Service.
2. Subject matter, nature, and purpose
Subject matter: hosting and processing of staff and, where the Customer uses BadgeSeal Certificates, certificate recipient personal data, to generate and serve digital business cards, staff badges, certificates, and their QR verification pages, including offline-verifiable badge signing. Nature of processing: storage, image generation, and lookup for verification. Purpose: solely to provide the Service as instructed by the Customer. Duration: for as long as the relevant subscription is active, plus the retention period described in the Privacy Policy.
3. Categories of data subjects and personal data
Data subjects: the Customer's staff members whose cards or badges are created, and, where the Customer uses BadgeSeal Certificates, the individuals to whom certificates are issued. Personal data — staff: name, job title or role, contact details, optional photograph, optional social media links, and badge validity dates. Personal data — certificate recipients: name, programme or qualification title, credential number, optional email address, and certificate validity dates. We do not collect date of birth for certificate recipients; the Customer is responsible for warranting that recipients are adults (see Terms of Service).
4. Processor obligations
- Processes personal data only on the Customer's documented instructions, unless required otherwise by EU or member-state law.
- Ensures anyone authorized to process the data is bound by confidentiality.
- Implements appropriate technical and organizational security measures (see Privacy Policy, Security).
- Engages sub-processors only under the conditions set out in Section 5 below.
- Assists the Customer, taking into account the nature of processing, in responding to data subject rights requests.
- Assists the Customer with its own obligations around security, breach notification, and data protection impact assessments, taking into account the information available to BadgeSeal.
- At the end of the subscription, deletes or returns all personal data at the Customer's choice, and deletes existing copies, unless retention is required by law.
- Makes available information reasonably necessary to demonstrate compliance with this DPA, and allows for audits by the Customer or an auditor it mandates, on reasonable notice and subject to confidentiality.
5. Sub-processors
The Customer authorizes BadgeSeal to engage the sub-processors listed in the Privacy Policy, Section 4 (Cloudflare, Resend, Anthropic, Google, and our payment provider — each only for the specific purpose described there). BadgeSeal will inform Customers of any intended change to this list by updating that section and, on request, will notify the Customer directly at the email on file, giving the Customer the opportunity to object on reasonable data-protection grounds.
6. International transfers
Where a sub-processor processes data outside the European Economic Area, the transfer is made under appropriate safeguards — Standard Contractual Clauses or an equivalent adequacy framework — as described in the Privacy Policy, Section 4.
7. Breach notification
BadgeSeal will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's staff data, providing the information reasonably available to help the Customer meet its own notification obligations.
8. Liability
Each party is liable for damage caused by processing where it has not complied with the obligations of the GDPR specifically directed to it, or where it has acted outside or contrary to the Customer's lawful instructions, in accordance with Article 82 GDPR.
9. Negotiated terms (Organization and Custom plans)
This standard DPA is written to cover most customers without any back-and-forth. Organization and Custom plan customers who need a negotiated agreement, or who need BadgeSeal to countersign their own DPA template for internal procurement or legal requirements, can request this at contact@badgeseal.com — we will work with you directly.
10. Precedence
This DPA applies alongside the Terms of Service and Privacy Policy. Where there is a conflict specifically about data processing terms, this DPA controls.
11. Contact
Questions about this DPA: contact@badgeseal.com.