Chainvara

← Legal

Data Processing Addendum

How we process personal data on our customers' behalf (GDPR article 28).

Last updated 8 October 2026

1. Scope and roles

This Addendum applies when Chainvara processes personal data on behalf of a customer to provide the Service: for example the identities of the customer's own customers (external user ids, Travel Rule originator and beneficiary data), counterparties and address book entries. The customer is the controller and Chainvara the processor. It forms part of the Terms of Service.

2. Instructions

We process this data only to provide the Service as configured by the customer, and on its documented instructions, unless the law requires otherwise, in which case we inform the customer unless the law forbids it.

3. Confidentiality and security

Everyone at Chainvara with access to the data is bound by confidentiality. We apply appropriate technical and organizational measures, including: encryption in transit and at rest; sealing of secrets and signing material with a key specific to each organization under a master key in a key management service; isolation of every query by organization and environment; two-factor authentication and least privilege for staff; an append-only, hash-chained audit trail; continuous monitoring and backups.

4. Subprocessors

The customer authorizes the subprocessors listed on the subprocessors page. We impose on them data-protection obligations equivalent to this Addendum and remain responsible for them. We announce new subprocessors 30 days in advance; the customer may object on reasonable grounds, and if we cannot address the objection the customer may terminate the affected part of the Service.

5. Assistance

We help the customer answer requests from data subjects, carry out impact assessments and meet its security obligations, to the extent the Service allows and taking into account the information available to us.

6. Personal data breaches

We notify the customer without undue delay, and within 48 hours of becoming aware of a personal data breach affecting its data, with the information available to help it meet its own obligations, and we take the measures needed to contain it.

7. Deletion and return

At the end of the Service the customer can export its data from the console; on request we then delete it, except where the law requires us to keep it.

8. Audits

We make available the information needed to demonstrate compliance with this Addendum and answer reasonable audit questionnaires. On-site audits are possible once a year with 30 days' notice, at the customer's expense, under confidentiality and without access to other customers' data.

9. International transfers

Transfers outside the European Economic Area rely on an adequacy decision or on the Standard Contractual Clauses (module 2 or 3 as applicable), which are incorporated by reference.