Data Processing Agreement

How Luhnify processes personal data on your behalf under Art. 28 GDPR.

Last updated: June 2, 2026 — Version 1.0

Incorporated into the Terms of Service. By accepting the Terms of Service, you agree to this DPA. No separate signature is required. Enterprise customers may request a countersigned PDF at [email protected].

Preamble

This Data Processing Agreement ("DPA") forms part of the Terms of Service ("Terms") between Luhnify SL ("Processor", "Luhnify", "we") and the customer who accepted those Terms ("Controller", "you"). It is incorporated into the Terms by reference and governs all processing of personal data carried out by Luhnify on the Controller's behalf in connection with the Luhnify ID format validation API ("Service").

Acceptance of the Terms at account registration constitutes acceptance of this DPA. No separate signature is required. Enterprise customers who require a countersigned PDF version may request one at [email protected]. Terms not defined here have the meanings given in the Terms of Service or the GDPR.

1. Roles of the Parties

For personal data contained in API payloads (country code, document type, document number) submitted by the Controller to the Service, the parties agree that:
  • The Controller determines the purposes and means of processing (i.e. which IDs to validate and why) and is solely responsible for having a lawful basis under Art. 6 GDPR to submit that data to Luhnify.
  • The Processor (Luhnify) processes that data exclusively on the Controller's documented instructions — namely, the API call itself — and for no other purpose.

Scope note: Luhnify's Service performs structural format validation only. It does not verify the authenticity, ownership, or legal validity of any identity document and is not a KYC or identity-verification service. The Controller is solely responsible for any compliance, regulatory, or business decisions made on the basis of API results.

2. Subject Matter, Nature & Duration of Processing

Subject matter: structural format validation of ID strings.

Nature: automated API processing. Each API request is validated and a result (valid / invalid format) is returned synchronously. A scan record is created for every API call containing: the document number masked to its last four characters (e.g. ***1234), country code, document type, validation result, status code, masked request payload, API response payload, IP address, user agent, response time, and billing metadata. The full plaintext document number is never written to storage.

Purpose: exclusively to provide the Service as described in the Terms.

Duration: for the term of the Controller's active subscription. On account deletion or subscription cancellation, Luhnify will cease further processing and will handle any deletion of retained data in accordance with the Privacy Policy.

3. Categories of Personal Data & Data Subjects

Categories of personal data that may be submitted by the Controller:
  • National identity numbers (e.g. DNI, NIF, NIE, SSN, NINO)
  • Passport numbers
  • Tax identification numbers (e.g. EIN, NIF, VAT)
  • Driver's licence numbers
  • Other government-issued ID strings whose format the Service supports

Data subjects: end-users or third parties whose ID strings the Controller submits to the API. Luhnify has no direct relationship with these individuals. The Controller warrants that it has authority to submit their data for processing.

Note on synthetic data: the Controller is encouraged to use synthetic or anonymised test IDs during integration testing and development. Submitting real personal data where a synthetic ID would suffice is a misuse of the Service.

4. Processor Obligations (Art. 28(3) GDPR)

Luhnify agrees to:
  • (a) Process only on instructions. Process personal data solely on the Controller's documented instructions. The API call constitutes the instruction. If Luhnify is required by EU or Member State law to process data for another purpose, it will inform the Controller before doing so unless prohibited by law.
  • (b) Confidentiality. Ensure that all personnel authorised to process the data are bound by confidentiality obligations.
  • (c) Security. Implement the technical and organisational measures described in Annex B and in accordance with Art. 32 GDPR.
  • (d) Sub-processors. Not engage a new sub-processor without giving the Controller at least 30 days' prior written notice (by email or dashboard notification). The Controller may object within that period on reasonable data-protection grounds. Current sub-processors are listed in Annex A.
  • (e) Data subject rights. Assist the Controller in fulfilling its obligations to respond to data subject rights requests. Scan records contain masked data only; if a data subject requests erasure, Luhnify will delete associated scan records on written request to [email protected] within 30 days.
  • (f) Assist with compliance obligations. Taking into account the nature of processing, assist the Controller with Art. 32 security measures, Art. 33–34 breach notifications, Art. 35 DPIAs, and Art. 36 prior consultations, insofar as reasonably possible.
  • (g) Deletion on termination. On expiry or termination of the service, Luhnify will handle deletion of the Controller's data in accordance with the retention policy in the Privacy Policy. The Controller may request written confirmation of deletion by contacting [email protected].
  • (h) Audit assistance. Make available all information reasonably necessary to demonstrate compliance with this DPA. The Controller may, on 30 days' written notice, conduct an audit (or commission a third-party auditor) at its own cost, subject to reasonable confidentiality obligations. Luhnify may satisfy audit requests by providing up-to-date third-party certifications (e.g. ISO 27001, SOC 2 Type II) as an equivalent.

5. Controller Obligations

The Controller warrants and agrees that:
  • It has a valid lawful basis under Art. 6 GDPR (and Art. 9 where special-category data is involved) to submit personal data to the Service.
  • It has provided all required privacy notices to data subjects.
  • It will not use the Service as the sole or primary basis for KYC, AML, credit-risk, or identity-verification decisions.
  • It will promptly notify Luhnify if it becomes aware of any data subject rights request or supervisory authority inquiry that concerns data processed under this DPA.
  • It will not submit special-category data (Art. 9 GDPR) via the API unless strictly necessary and will ensure an appropriate Art. 9(2) exception applies.

6. Data Breach Notification

In the event of a personal data breach affecting data processed under this DPA, Luhnify will:
  • Notify the Controller without undue delay and, where feasible, within 48 hours of becoming aware of the breach.
  • Provide sufficient information for the Controller to fulfil its own Art. 33 notification obligation to the supervisory authority within 72 hours.
  • Cooperate with the Controller and take reasonable steps to mitigate the effects of the breach.

Because document numbers are masked before storage and full plaintext values are never persisted, the exposure in a breach is limited to masked scan records (last 4 digits), IP addresses, user agents, and account data (name, email, billing address). API keys are stored as plaintext tokens; a breach affecting the database would require immediate key rotation for all affected organisations. Breach notifications should be sent to [email protected].

7. International Transfers

Personal data is processed primarily on AWS infrastructure in the EU-West region (Ireland / Frankfurt) and does not leave the EEA under normal operating conditions. Where a sub-processor (e.g. Stripe for billing data) transfers data outside the EEA, that transfer is governed by Standard Contractual Clauses (SCCs) approved by the European Commission under Decision 2021/914/EU, or by an adequacy decision. Details of transfer mechanisms per sub-processor are included in Annex A.

8. Governing Law & Changes

This DPA is governed by the laws of Spain and is subject to the exclusive jurisdiction of the courts of Asturias, Spain, consistent with the Terms of Service.

Luhnify may update this DPA to reflect changes in the law or its processing activities. Material changes will be notified to registered users by email at least 30 days before the effective date. The Controller's continued use of the Service after the effective date constitutes acceptance. The current version is always available at http://luhnify.com/legal/dpa. If the Controller objects to a material change, it may terminate the service before the effective date without penalty.

Annex A — Authorised Sub-processors

The following sub-processors are currently authorised. Luhnify will provide 30 days' notice before adding or replacing any sub-processor.

Sub-processorRoleLocationData processedTransfer safeguard
Amazon Web Services (AWS)Cloud infrastructure & computeEU-West (Ireland / Frankfurt)All data in transit and at restWithin EEA — no transfer
Stripe, Inc.Payment processing & metered billingUSABilling & payment data only — never API payload dataSCCs (Decision 2021/914/EU)
Transactional email provider (TBD)System notificationsEU or SCCsName & email address onlyWithin EEA or SCCs

Annex B — Technical & Organisational Measures (TOMs)

Luhnify implements the following measures in accordance with Art. 32 GDPR:

  • Encryption in transit: TLS 1.2 or higher on all API and dashboard connections.
  • Encryption at rest: AES-256 for all stored data via AWS infrastructure.
  • Document number masking: only the last four characters of any submitted ID string are stored (e.g. ***1234); the full plaintext value is never written to any database or log.
  • API key security: keys are randomly generated tokens (lh_ prefix + 32 random characters); access is protected by authenticated dashboard sessions with no plaintext exposure beyond the dashboard UI.
  • Password security: all user passwords are stored as one-way hashes (bcrypt via Laravel's hashed cast).
  • Access control: least-privilege IAM policies; production access requires MFA-gated VPN; role-based access enforced throughout (Spatie Permissions).
  • Infrastructure security: hosted on AWS in ISO 27001 and SOC 2 Type II certified datacenters in the EU-West region.
  • Vulnerability management: periodic penetration tests; automated dependency scanning; security patches applied within defined SLAs.
  • Incident response: documented IR plan; Controller notified within 48 hours of confirmed breach; supervisory authority notified within 72 hours where required.
  • Personnel: all staff with access to personal data are bound by confidentiality agreements and receive data protection training.
  • Audit logging: all changes to organisation, user, and subscription records are logged via Spatie Activity Log.

For DPA enquiries contact [email protected]. For general data protection questions write to [email protected].