Data Processing Agreement
1. Roles and scope
1.1 For personal data of Applicants processed to deliver Verifications, the Client is the controller and DoorID is the processor. This agreement governs that processing. Data for which DoorID is itself controller — client account, billing, portal, website and support data — is covered by the Privacy Policy, not this agreement.
1.2 DoorID's data protection contact: Paul Williams, paul@doorid.ai, This Workspace, 18 Albert Road, Bournemouth, BH1 1BZ.
1.3 Terms defined in the Terms of Service have the same meaning here. "Data protection law" means the UK GDPR and the Data Protection Act 2018 and, where the Australian Privacy Annex applies, the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
2. Details of processing (Annex A)
| Subject matter | Live presence verification of Applicants at the Client's instruction, and delivery of the Result and Evidence Pack to the Client |
|---|---|
| Duration | Term of the agreement, plus the retention periods in clause 8 |
| Nature and purpose | Identity-document capture and reading; facial comparison between the document and a live image; live capture of property imagery; device, location and sensor signals; automated analysis; production of a Result and an Evidence Pack; delivery to the Client; and, only where the Order includes Managed Review, human review by DoorID staff |
| Data subjects | Applicants — individuals the Client directs to the service; incidentally, other people who appear in captured imagery |
| Categories of data | Name, date of birth, address, contact number, the Client's reference; driving-licence or identity-document images and extracted data; facial images and biometric data used for identification (special category / sensitive information); photographs and video of the property and surroundings; device, GPS and sensor data; IP address; the Result, analysis results and review notes |
| Special category basis | The Applicant's explicit consent, captured in-session before processing begins, on the notice at Document 4. The Client remains responsible for its own lawful basis for instructing the Verification and for any notice it must give as controller |
| Instructions | Perform the Verification; produce the Result and Evidence Pack; deliver them to the Client; retain and de-identify data as set out in clause 8; assist with data-subject requests and incidents; and nothing else unless agreed in writing |
3. DoorID's obligations as processor
DoorID shall: (a) process Applicant data only on the Client's documented instructions in Annex A, unless required by law to do otherwise, in which case DoorID will inform the Client unless the law prohibits it; (b) ensure that persons authorised to process the data are bound by confidentiality; (c) implement the technical and organisational measures in Annex B; (d) engage sub-processors only under clauses 5 and 6; (e) taking into account the nature of the processing, assist the Client with requests from data subjects; (f) assist the Client with security, breach notification, data protection impact assessments and prior consultation, so far as the information is available to DoorID; (g) delete, return or de-identify the data as set out in clause 8; (h) make available the information necessary to demonstrate compliance and allow audits under clause 9; and (i) inform the Client if, in DoorID's opinion, an instruction infringes data protection law.
4. The Client's obligations as controller
The Client shall: (a) instruct a Verification only where it has a lawful basis and, for Applicants in Australia, only where collection of sensitive information is permitted; (b) give Applicants the information a controller must give, and not rely solely on Document 4 to discharge its own notice obligations; (c) not instruct processing that would breach data protection law; (d) offer Applicants a reasonable alternative that does not use biometrics, and not base a decision with legal or similarly significant effects solely on a Result without human consideration; (e) respond to Applicants' requests to exercise their rights, with DoorID's assistance where DoorID holds the data; (f) download and safeguard Evidence Packs within the availability period in clause 8, as the Client's own record; and (g) tell DoorID promptly if it needs a legal hold under clause 8.6.
5. Sub-processors
5.1 The Client gives general written authorisation to the sub-processors listed in Annex C. DoorID will give at least 30 days' notice of any intended addition or replacement, through the portal and by email, during which the Client may object on reasonable data-protection grounds. If an objection cannot be resolved, the Client may terminate the affected service without penalty for the unused part of any prepaid period.
5.2 DoorID imposes data-protection obligations on each sub-processor that are no less protective than this agreement and remains responsible to the Client for their performance.
6. Annex C — sub-processors at the date of this version
| Sub-processor | Purpose | Location of processing | Transfer safeguard |
|---|---|---|---|
| Amazon Web Services, Inc. (Rekognition) | Face detection and comparison | United Kingdom (London, eu-west-2) | No restricted transfer |
| Ordnance Survey Limited (OS Places) | Address matching (address text only) | United Kingdom | No restricted transfer |
| Ideal Postcodes Ltd | Address matching (address text only) | United Kingdom | No restricted transfer |
| OpenStreetMap Foundation (Overpass API) | Building outline lookup (coordinates only) | United Kingdom and European Union | No restricted transfer (UK) or adequacy (EU) |
| Replit, Inc. and its infrastructure providers | Application hosting, database and file storage | United States | Standard contractual safeguards recognised under UK law (the International Data Transfer Addendum to the EU Standard Contractual Clauses, or the provider's UK-approved transfer terms) as incorporated in each provider's data processing terms, together with encryption in transit and access controls |
| OpenAI, L.L.C. | Document reading and imagery comparison | United States | |
| Google LLC (Maps, Street View, Geocoding) | Address geocoding and reference imagery | United States | |
| Mapbox, Inc. | Static map images of the recorded route (coordinates only) | United States | |
| Twilio Inc. | SMS delivery | United States | |
| Twilio SendGrid | Email delivery | United States | |
| Slack Technologies, LLC | Operational alerts to DoorID staff (reference numbers, status and diagnostic messages) | United States |
Facial comparison and UK address matching are performed in the United Kingdom. Hosting, storage, document reading, mapping and messaging currently take place in the United States as set out above. DoorID intends to move hosting and storage to the United Kingdom; Annex C will be updated by notice under clause 5.1 when that happens. The current list is also published at doorid.ai/sub-processors.
7. Security (Annex B)
DoorID maintains, and will keep under review, measures including: encryption of data in transit; encryption at rest for stored objects provided by the hosting platform; tenant isolation so that one client cannot read another client's data; role-based, least-privilege access for DoorID staff with individual accounts and multi-factor authentication for portal users; magic-link authentication with short-lived tokens; audit logging of access to Verification records and Evidence Packs; signed and expiring evidence links; cryptographic integrity chaining of captured evidence and a fingerprint of every Evidence Pack issued; segregation of test and live data; bounded upload validation; secrets management with production boot checks; provider approval gates so that data is sent only to listed sub-processors; and the de-identification process in clause 8, which limits what any breach could expose. DoorID does not yet hold ISO 27001, SOC 2 or Cyber Essentials certification and does not claim to.
8. Retention, de-identification, deletion and return
8.1 Evidence Pack availability. The Evidence Pack for a Verification is available to the Client for 7 days after the Verification concludes (completed, failed, expired, cancelled or consent declined). The Client's copy is the Client's record. On the Client's written instruction, DoorID may extend availability for a named account to a maximum of 30 days.
8.2 De-identification. From the Retention Start Date shown in the portal for the Client's account, DoorID removes all identifying Applicant data within 7 days after each Verification concludes (or, where the Client has instructed an extended availability period under clause 8.1, at the end of that period): captured video, images, face crops and identity-document images and extracted details; name, contact details and date of birth; precise location and sensor data; the Evidence Pack and any cached copy; and every evidence link, which is revoked. Faces appearing in property imagery are irreversibly obscured or the imagery deleted. Identity captures made first, for a later Verification to rely on (the licence-first journey), are the one exception to that timing: DoorID keeps the captured identity-document images and the identity details extracted from them for 60 days from capture, and for a further 60 days from each Verification that relies on them, up to 180 days from capture in total, so that the later Verification can proceed without asking the Applicant again. The Client may shorten these periods for its account. They are removed in the same way within 7 days after the Verification they were kept for concludes, or at the end of the period, whichever is sooner.
8.3 Before the Retention Start Date, Applicant data is held securely under Annex B and is deleted on the Client's instruction under clause 8.5. The Retention Start Date for each account is shown in the portal and DoorID will notify the Client when it is set.
8.4 What DoorID keeps. After de-identification DoorID retains only de-identified technical data — the Verification identifier, the Client's reference, timestamps, journey type, the Result and its reasons, each check's outcome and score, device class, derived non-identifying attributes (such as age band, document type, connection type, and how the device moved during the Verification measured relative to the property rather than by its position), the settings that applied at the time, integrity hashes, delivery records and the Evidence Pack fingerprint — which cannot identify an Applicant on its own — together with any outcome the Client reports back (its own decision, a complaint, confirmed fraud) and one-way keyed fingerprints of the Applicant's telephone number and identity-document number, which let DoorID recognise a repeat submission but cannot be turned back into the number. The Client instructs DoorID to retain and use this data to maintain, secure and improve the service, to detect repeat and fraudulent use, and to support disputes and audits. DoorID may share it with its auditors, a certification body, or a research partner under a written agreement, only in aggregated or further anonymised form and never in a form that identifies the Client or an Applicant. DoorID keeps the full declared address for 90 days for dispute purposes and then reduces it to outward postcode and property identifier.
8.5 Erasure requests. The Client may instruct deletion of a specific Applicant's data at any time. DoorID acts within 7 days and confirms the deletion.
8.6 Legal hold. Where the Client has a dispute, complaint or legal or regulatory need to preserve a specific Verification, it may place a hold on that Verification in the portal, or instruct one in writing, stating the reason, before de-identification has taken place. A portal hold preserves the Verification for 90 days; a written instruction may extend it to a maximum of 12 months. DoorID records every hold, suspends de-identification for as long as it lasts, and reminds the Client before it expires. The Client also instructs DoorID to place a hold of its own, for up to 12 months, on a Verification that shows indicators of document fraud, impersonation or a synthetic identity, or that the Client reports as confirmed fraud or disputed by the Applicant, so that the evidence is available for investigation; DoorID tells the Client when it does so, and the Client may withdraw this instruction for its account in the portal. Data that has already been de-identified cannot be restored.
8.7 Termination. On termination DoorID de-identifies or deletes remaining Applicant data within 30 days, save where a legal hold applies or the law requires retention, and confirms completion in writing.
8.8 Proof. DoorID records what was removed and when for every Verification, and makes that record available to the Client through the portal and the API.
9. Personal-data breaches and audit
9.1 DoorID notifies the Client without undue delay, and in any event within 48 hours, after becoming aware of a personal-data breach affecting Applicant data, with the information a controller needs for its own notification obligations, and keeps the Client informed as the investigation progresses.
9.2 Once in any 12 months on 30 days' notice, and additionally after a breach, the Client may audit DoorID's compliance with this agreement by written questionnaire and, where reasonably necessary, by remote review with DoorID. Audits must not compromise other clients' data or DoorID's security, and the Client bears its own costs.
10. International transfers
Restricted transfers of Applicant data are made only to the sub-processors and under the safeguards in Annex C. DoorID will not transfer Applicant data to any other country without giving notice under clause 5.1.
11. Australian Privacy Annex
11.1 This Annex applies where the Client is an Australian Client, or where an Applicant is located in Australia. It applies in addition to the rest of this agreement; where the two conflict in relation to Australian processing, this Annex prevails.
11.2 Roles. The Privacy Act 1988 (Cth) does not distinguish controllers from processors. For the purposes of that Act the Client is the entity that collects the Applicant's personal information for its own purposes and DoorID handles that information on the Client's behalf and instructions. Each party will comply with the Australian Privacy Principles (APPs) to the extent they apply to it.
11.3 Sensitive information. Biometric information and biometric templates are sensitive information under the Privacy Act. DoorID collects them only with the Applicant's express consent, given in-session on Document 4. The Client must not instruct a Verification for an Australian Applicant unless the collection is reasonably necessary for the Client's functions or activities and the Applicant has been given the notice APP 5 requires.
11.4 Overseas disclosure (APP 8). The Client acknowledges, and Document 4 tells the Applicant, that Applicant information is disclosed to recipients in the United Kingdom and the United States as listed in Annex C. DoorID takes reasonable steps to ensure that each overseas recipient handles the information in a way consistent with the APPs, by contract and by the safeguards in Annex B.
11.5 Data breaches. DoorID will assist the Client to meet the Notifiable Data Breaches scheme: DoorID will notify the Client under clause 9.1, will complete its assessment of a suspected eligible data breach within the 30 days the scheme allows, and will cooperate with any notification to the Office of the Australian Information Commissioner (OAIC) and to affected individuals. The parties agree that the Client, as the entity with the direct relationship with the Applicant, will make any required notification unless they agree otherwise.
11.6 Access, correction and complaints. Applicants may seek access to or correction of their information through the Client, and DoorID will assist within 7 days of a request. Complaints may be made to DoorID at paul@doorid.ai, to the Client, or to the OAIC at oaic.gov.au.
11.7 Retention. Clause 8 applies. Where an Australian law requires the Client to keep a record for longer, the Client's own copy of the Evidence Pack is the record it retains.
12. Liability and precedence
12.1 Each party's liability under this agreement is subject to the exclusions and cap in the Terms of Service, save where data protection law does not permit that. Each party is liable to the other for fines, damages and costs caused by its own breach of this agreement in proportion to its responsibility.
12.2 If this agreement conflicts with the Terms of Service, this agreement prevails for data-protection matters.
DoorID Ltd · Company number 17176280 · ICO registration ZC153427
This Workspace, 18 Albert Road, Bournemouth, Dorset, BH1 1BZ
