• Conditions générales de l’utilisateur Tools For Humanity

    Conditions générales de l’utilisateur Tools For Humanity

  • Politique de conservation des données biométriques

    Politique de conservation des données biométriques

  • Politique de confidentialité de Tools for Humanity

    Politique de confidentialité de Tools for Humanity

  • Politique relative aux cookies de Tools for Humanity

    Politique relative aux cookies de Tools for Humanity

  • Demandes D’exécution de la Loi

    Demandes D’exécution de la Loi

  • Tools for Humanity Arbitration Agreement

    Tools for Humanity Arbitration Agreement

  • ANNEXE – Bases juridiques/finalités pour les activités de traitement des données Tools for Humanity

    ANNEXE – Bases juridiques/finalités pour les activités de traitement des données Tools for Humanity

  • Master Services Agreement

    Master Services Agreement

Data Processing Addendum

Version: 1.0Applicable à compter du 22 septembre 2026
Exhibit A: Data Processing Addendum
This Data Processing Addendum, together with its schedules (this “DPA”), is incorporated into and forms part of the Agreement between TFH and Customer, each as defined in the Master Services Agreement (the “MSA”) between TFH and Customer. In the event of a conflict between the MSA and this DPA, the terms of this DPA will apply with respect to the subject matter set forth herein.
How This DPA Applies
Pursuant to the Agreement, TFH may from time-to-time process Personal Data (as defined below) for which Customer may be a “Data Controller” as defined by Applicable Data Protection Law (as defined below), including the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”). When processing such Personal Data, TFH acts as a “Data Processor” as defined by Applicable Data Protection Law. This DPA applies only to TFH’s processing of Personal Data on behalf of Customer in connection with the Services. This includes, for example, the account and administrative data Customer provides to enable its Authorized Users’ access to the Services including through TFH’s enterprise portal. This DPA does not apply to TFH’s processing of user enrollment or verification procedures that occur directly between an individual Authorized User and TFH in connection with that individual’s World ID account, which is governed by TFH’s privacy notice and terms applicable to individual users and not by this DPA.
Because such processing may, from time to time, require the maintenance and implementation of appropriate technical and organizational safeguards, and because such processing may, from time to time, involve the transfer of Personal Data from the European Union to the United States, Customer and TFH agree to execute this DPA in order to ensure that adequate safeguards are established with respect to the protection of Personal Data.
The subject matter and duration of the processing are governed by the underlying Agreement. The rights and obligations of the controller are determined in this DPA in connection with the attached Standard Contractual Clauses and the Agreement.
1. Definitions
All capitalized words not defined below will have meaning set forth in the Agreement.
1.1 “Applicable Data Protection Law” means privacy and data protection laws, regulations applicable to a Party’s processing under this DPA, including, to the extent applicable, Regulation (EU) 2016/679 (“GDPR”), the GDPR as incorporated into United Kingdom law (“UK GDPR”), the Swiss Federal Act on Data Protection (“Swiss FADP”), and the California Consumer Privacy Act of 2018, as amended, and its implementing regulations (“CCPA”).
1.2 “DPA Effective Date” means the Effective Date of the Agreement.
1.3 “Permitted Business Purpose” means TFH's processing of Personal Data for: (i) providing and improving the Services; (ii) ensuring the security, integrity, and continued functioning of the Services; (iii) developing and improving TFH’s biometric verification technologies; (iv) producing anonymized or aggregated analytics; and (v) complying with applicable law.
1.4 “Personal Data” means any information that TFH receives from or on behalf of Customer, or generates on Customer’s behalf, when such information is from or about an identified or identifiable person, including information that can be associated with an individual Data Subject or the household of a Data Subject. Personal Data includes Personal Information as defined in the CCPA, subject to the exclusions under “How This DPA Applies”.
1.5 “Processing”, “Data Controller,” “Data Subject,” “Supervisory Authority,” and “Data Processor” have the same meanings set forth in the GDPR.
1.6 “Standard Contractual Clauses” means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as incorporated and completed under Section 4.
1,7 “Subprocessor” means third-party subcontractors, including a TFH affiliate, that TFH retains from time to time to provide services to TFH necessary for TFH to perform its obligations under the Agreement and that process personal data on behalf of TFH.
1.8 “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, version B1.0, including its mandatory Part 2, as revised in accordance with its terms.
2. Applicability
This DPA to TFH’s processing of Personal Data on Customer’s behalf in connection with the Services applies, whether or not the GDPR or UK GDPR applies. Requirements specific to a jurisdiction apply only to the extent required by Applicable Data Protection Law.
3. Processing of Personal Data
With respect to TFH’s processing of Personal Data on behalf of Customer under this DPA, TFH will:
3.1 when acting as Customer’s Data Processor, process Personal Data for the Services and Permitted Business Purposes in accordance with Applicable Data Protection Law and Customer’s documented instructions, including the Agreement, this DPA and authorized service configurations; promptly inform Customer if an instruction appears unlawful. Such instructions do not apply to TFH’s processing as an independent Data Controller;
3.2 maintain appropriate technical and organizational measures as described in Schedule II without materially reducing their overall protection, and limit personnel access to those with a need to know who are subject to confidentiality obligations;
3.3 when acting as Customer’s Data Processor, promptly forward Data Subject requests to Customer and respond only as instructed or legally required; provide reasonable assistance with such requests and Customer’s security, data protection impact assessment and consultation obligations, taking into account the nature of the processing, available information and Applicable Data Protection Law. TFH handles requests concerning its independent-controller processing separately;
3.4 notify Customer with undue delay of any accidental or unlawful destruction or accidental loss, alteration, or unauthorized disclosure or access of Personal Data processed as Customer’s Data Processor that presents a material risk to the rights of data subjects (a “Data Breach”) or of any processing of Personal Data in a manner inconsistent with the terms of the Agreement and this DPA, with such notification given in accordance with Section 10(d) of the MSA (Notices), and to provide reasonable assistance to Customer with respect to any Data Breach (including without limitation cooperating with Customer with respect to notification of Supervisory Authorities and communicating to Data Subjects regarding a Data Breach);
3.5 promptly notify Customer upon TFH’s or its Subprocessors’ receipt of any request for disclosure of Personal Data from a Supervisory Authority, government entity or court of law of a competent jurisdiction, or pursuant to a subpoena (unless otherwise prohibited by law);
3.6 take reasonable and appropriate steps to stop and remediate unauthorized processing, upon notice by Customer, in the event Customer has determined that TFH is no longer processing data in accordance with the Agreement and this DPA.
4. Subprocessors and International Transfers
4.1 Customer grants TFH general written authorization to engage Subprocessors to process Personal Data on Customer’s behalf under this DPA, including the Subprocessors listed in Schedule III (the “Subprocessor List”) as of the DPA Effective Date. TFH shall engage only Subprocessors providing sufficient guarantees of compliance with Applicable Data Protection Law.
4.2 TFH may update the Subprocessor List by adding or replacing Subprocessors. TFH shall notify Customer by email at least ten (10) calendar days before a proposed addition or replacement begins processing Personal Data on Customer’s behalf. The notice shall identify the Subprocessor, its processing activities and locations, and provide sufficient information regarding its data protection safeguards to enable Customer to assess the change. Customer may object within that period by written notice stating reasonable, substantiated grounds relating to the protection of Personal Data. If Customer does not object within that period, TFH may implement the change and update Schedule III without further authorization or formal amendment of this DPA. Following such an objection, the Parties shall promptly seek to resolve it, and TFH shall not permit the proposed Subprocessor to process the affected Personal Data while the objection remains unresolved.
4.3 TFH shall impose substantially equivalent data protection obligations on each Subprocessor by written agreement and remain responsible to Customer for the Subprocessor’s performance. TFH shall provide copies of those agreements and amendments where required by Applicable Data Protection Law or the Standard Contractual Clauses, subject to redactions necessary to protect confidential information.
4.4 When acting as Customer’s Data Processor, TFH shall provide information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, as required by Applicable Data Protection Law. Customer shall first consider relevant security reports and certifications made available by TFH. Audits shall be subject to reasonable confidentiality, notice and scheduling arrangements and conducted at Customer’s expense, except where prohibited by law. These arrangements shall not restrict mandatory audit or information rights.
4.5 Following the end of the relevant processing Services, TFH shall, at Customer’s choice, delete or return Personal Data processed as Customer’s Data Processor and delete remaining copies, unless applicable law requires retention. TFH shall continue to protect retained Personal Data under this DPA and process it only as legally required. TFH shall certify deletion where required by Applicable Data Protection Law or the Standard Contractual Clauses.
Where Customer transfers Personal Data as Data Controller to the TFH entity identified in Schedule I as Data Processor, and that transfer requires safeguards under Chapter V GDPR, Module Two of the Standard Contractual Clauses is incorporated where applicable, with Customer as data exporter and that TFH entity as data importer, unless the Parties have documented another valid transfer mechanism.
4.6 Schedule I constitutes Annex I to the Standard Contractual Clauses and shall identify the relevant Parties, their roles, the covered transfers and the competent Supervisory Authority determined under Clause 13. Schedule II constitutes Annex II. The Subprocessor List supplies the information concerning authorized Subprocessors. The Parties shall complete the applicable particulars before relying on the Standard Contractual Clauses. United Kingdom transfers are additionally subject to Section 6.
4.7 TFH shall ensure that onward transfers of Personal Data processed as Customer’s Data Processor, including access from another country, are covered by the safeguards required by Applicable Data Protection Law. Where the Standard Contractual Clauses apply, the Parties shall comply with their requirements concerning transfer assessments, supplementary measures, government-access requests and suspension or termination of transfers.
4.8 TFH’s independent-controller processing is not included in the processor transfers governed by this Section or their SCC annexes. Any international transfers associated with that excluded processing require their own assessment and applicable safeguards; they are not authorized or regulated by this DPA. The Standard Contractual Clauses and, where applicable, the UK Addendum prevail over conflicting terms of this DPA or the Agreement.
5. CCPA Clause
TFH will not (i) sell Personal Data; (ii) retain, use, or disclose Personal Data for any purpose other than for the specific purpose of performing the Services for Customer; (iii) retain, use, or disclose Personal Data for a commercial purpose other than providing the services for Customer; (iv) retain, use, or disclose Personal Data outside of the direct business relationship between TFH and Customer; or (v) combine the Personal Data with personal data that TFH receives from or on behalf of any other person, except as permitted by Applicable Data Protection Law or as instructed by Customer.
6. UK and CH Transfer
6.1 Where a transfer of Personal Data processed by TFH as Customer’s Data Processor requires safeguards under UK GDPR, the Standard Contractual Clauses identified in Section 4 apply as amended by the ICO’s International Data Transfer Addendum, version B1.0, including its mandatory Part 2, as revised in accordance with its terms (the “UK Addendum”), unless another valid transfer mechanism has been documented.
Table 1 of the UK Addendum is completed with the Parties’ details in Schedule I and the DPA Effective Date. Table 2 identifies Module Two and the selections in Section 4.6. Table 3 comprises Schedules I and II and the Subprocessor List. Table 4 selects “neither Party”. Any additional required particulars shall be completed before the transfer.
6.2 The UK Addendum’s mandatory amendments, including its governing-law, jurisdiction and hierarchy provisions, apply to the relevant UK transfers.
6.3 Where a transfer governed by the Swiss FADP relies on the Standard Contractual Clauses, references to the GDPR include the Swiss FADP to the extent applicable, and the Federal Data Protection and Information Commissioner is the competent Swiss supervisory authority. References to a Member State include Switzerland to the extent necessary to preserve Data Subjects’ rights, including their right to bring proceedings in Switzerland. Where the GDPR also applies, its protections and the jurisdiction of the competent EU supervisory authority remain unaffected.
7. Miscellaneous
7.1 This DPA shall remain in full force and effect until the earlier of:
7.1.1 the expiration or termination of the Agreement; or
7.1.2 the mutual agreement of the parties to terminate.
7.2 This DPA prevails over conflicting terms of the Agreement concerning its subject matter. The Standard Contractual Clauses and the UK Addendum prevail to the extent required by their respective hierarchy provisions.
7.3 Customer is responsible for the lawfulness of its instructions, its provision of Personal Data to TFH and its use of the Services and their outputs, including required notices and legal bases for processing concerning its personnel. TFH remains responsible for its own obligations under Applicable Data Protection Law, including in respect of its independent-controller processing.

Schedule I
Description of Transfers
This Schedule constitutes Annexes I and II to the Standard Contractual Clauses and applies only where, and to the extent that, those Clauses apply to processing under this DPA.
A. List of Parties
Data exporter(s):
Name: The Customer named in the Order Form.
Address: As specified in the Agreement
Contact person’s name, position and contact details: As specified in the Agreement.
Activities relevant to the data transferred under the Standard Contractual Clauses: Customer uses the Services provided by TFH under the Agreement.
Signature and date: As of the Effective Date of the Agreement.
Role (controller/processor): Controller
Data importer(s):
Name: Tools for Humanity Corporation.
Address: As specified in the Agreement.
Contact person’s name, position and contact details: As specified in the Agreement.
Activities relevant to the data transferred under the Standard Contractual Clauses: TFH processes enterprise account and administrative data, related analytics on Customer’s behalf as described in Part B. The independent-controller processing excluded under “How This DPA Applies” is outside this Schedule.
Signature and date: As of the Effective Date of this Agreement
Role (controller/processor): Processor
B. Description of Transfer
Categories of data subjects whose personal data is transferred:
  • Customer's Authorized Users (employees and personnel provisioned with access to the Services).
Categories of personal data transferred (may include):
  • Name, email address, department, and other employee registry data provided by Customer to enable Authorized Users' access to the Services; and
  • Service usage and administrative records, including analytics to the extent they contain Personal Data,
  • Enterprise account and user identifiers, opt-in records and authentication timestamps, to the extent processed on Customer’s behalf for enterprise administration and delivery of verification results.
  • Facial images captured from the video stream of a meeting in which Customer has enabled the Services, obtained by TFH via Zoom's real-time media streaming (RTMS) integration and used to perform the verification match described below.
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures:
Facial images obtained via RTMS
Safeguards: such images are used solely to perform the verification match and generate the resulting verification/badge status; they are retained only for the period specified by Customer's applicable configuration in TFH's enterprise portal; they are encrypted in transit and at rest; access is restricted to personnel and systems necessary to perform the verification; and they are not used for any purpose beyond the verification and badge functions described above. TFH separately processes biometric data (including facial images captured by the Orb and images submitted through the World ID mobile app) as part of the underlying verification technology, but that processing occurs directly between the individual Authorized User and TFH in connection with that individual's World ID account, is not directed by or transferred to Customer, and is governed by TFH's Privacy Policy applicable to individual users rather than this DPA (see “How This DPA Applies” above).
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis):
On an ongoing basis during the provision of the Services, including account provisioning, registry updates and delivery of verification results.
Nature of the processing:
Collection, receipt, hosting, organisation, retrieval, disclosure and deletion of enterprise administrative data and verification-status records. This includes provisioning Authorized Users, operating Customer’s enterprise portal and delivering and administering verification results.
Purpose(s) of the data transfer and further processing:
To administer Customer’s enterprise account, enable Authorized Users’ access to the Services and provide Customer with verification status and related service information..
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period:
Personal Data is retained for the duration necessary to provide the relevant enterprise Services, subject to Customer’s documented instructions and applicable retention settings. On termination, Personal Data is deleted or returned in accordance with this DPA and TFH’s policies, unless applicable law requires retention.
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing:
Subprocessors provide hosting, infrastructure and other support for the processor activities described above, for the duration necessary to provide those services and subject to this DPA’s retention and deletion requirements as specified above.
C. Competent Supervisory Authority
Identify the competent supervisory authority/ies in accordance with Clause 13 of the Standard Contractual Clauses:
The Bavarian Data Protection Supervisory Authority (BayLDA). Not applicable where the Standard Contractual Clauses do not apply to the processing and transfers covered by this DPA.
Schedule II
Technical and Organisational Measures including Technical and Organisational Measures to ensure the Security of the Data
This Schedule describes the technical and organizational measures applicable to Personal Data processed by TFH as Customer’s Data Processor under this DPA. TFH maintains a comprehensive, written information security program that contains administrative, technical, and physical safeguards that, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing of personal information as well as the associated risks, are appropriate to (a) the type of information that TFH will store as personal information; and (b) the need for security and confidentiality of such information. TFH’s security program is designed to:
  • Protect the confidentiality, integrity, and availability of personal information in TFH’s possession or control or to which TFH has access;
  • Protect against any anticipated threats or hazards to the confidentiality, integrity, and availability of personal information;
  • Protect against unauthorized or unlawful access, use, disclosure, alteration, or destruction of personal information;
  • Protect against accidental loss or destruction of, or damage to, personal information; and
  • Safeguard information as set forth in any local, state or federal regulations by which TFH may be regulated.
Without limiting the generality of the foregoing, TFH’s security program includes:
1. Security Awareness and Training. Mandatory employee security awareness and training programs, which include:
1.1 Training on how to implement and comply with its information security program; and
1.2 Promoting a culture of security awareness.
2. Access Controls. Policies, procedures, and logical controls:
2.1 To limit access to its information systems and the facility or facilities in which they are housed to properly authorized persons;
2.2 To prevent those workforce members and others who should not have access from obtaining access; and
2.3 To remove access in a timely basis in the event of a change in job responsibilities or job status.
3. Physical and Environmental Security. Controls that provide reasonable assurance that access to physical servers at the data centers housing personal information is limited to properly authorized individuals and that environmental controls are established to detect, prevent and control destruction due to environmental extremes.
4. Security Incident Procedures. A security incident response plan that includes procedures to be followed in the event of any security breach of any application or system directly associated with the accessing, processing, storage or transmission of personal information.
5. Contingency Planning. Policies and procedures for responding to an emergency or other occurrence (for example, fire, vandalism, system failure, pandemic flu, and natural disaster) that could damage personal information or production systems that contain personal information.
6. Audit Controls. Technical or procedural mechanisms put in place to promote efficient and effective operations, as well as compliance with policies.
7. Data Integrity. Policies and procedures to ensure the confidentiality, integrity, and availability of personal information and to protect it from disclosure, improper alteration, or destruction.
8. Storage and Transmission Security. Security measures to guard against unauthorized access to personal information that is being transmitted over a public electronic communications network or stored electronically.
9. Secure Disposal. Policies and procedures regarding the secure disposal of tangible property containing personal information, taking into account available technology so that such data cannot be practicably read or reconstructed.
10 Assigned Security Responsibility. Assigning responsibility for the development, implementation, and maintenance of its information security program, including:
10.1 Designating a security official with overall responsibility; and
10.2 Defining security roles and responsibilities for individuals with security responsibilities.
11. Testing. Regularly testing the key controls, systems and procedures of its information security program to validate that they are properly implemented and effective in addressing the threats and risks identified.
12. Monitoring. Network and systems monitoring, including error logs on servers, disks and security events for any potential problems. Such monitoring includes:
12.1 Reviewing changes affecting systems handling authentication, authorization, and auditing;
12.2 Reviewing privileged access to TFH production systems processing personal information; and
12.3 Engaging third parties to perform network vulnerability assessments and penetration testing on a regular basis.
13. Change and Configuration Management. Maintaining policies and procedures for managing changes TFH makes to production systems, applications, and databases processing personal information. Such policies and procedures include:
13.1 A process for documenting, testing and approving the patching and maintenance of the TFH Service;
13.2 A security patching process that requires patching systems in a timely manner based on a risk analysis; and
13.3 A process for TFH to utilize a third party to conduct web application-level security assessments.
14. Program Adjustments. TFH monitors, evaluates, and adjusts, as appropriate, the security program in light of:
14.1 Any relevant changes in technology and any internal or external threats to TFH or the personal information;
14.2 Security and data privacy regulations applicable to TFH; and
14.3 TFH's own changing business arrangements, such as mergers and acquisitions, alliances and joint ventures, outsourcing arrangements, and changes to inform.

Schedule III
Sub-Processors
PROCESSOR PURPOSE DATA PROCESSED ADDRESS
Algolia
Search engine for public docs
Account info, query/usage data, integration data
3790 El Camino Real
Unit #518
Palo Alto, CA 94306
Amazon Web Services
Hosting for backend/server infrastructure
Account data, Orb data, metadata, phone numbers, event data
410 Terry Avenue North
Seattle, WA 98109
Apple
App store for Apple phones
Account data, device information and country, app usage data, performance data
1 Apple Park Way
Cupertino, CA 95014
Apple
Integrity check
Device identifiers, operating system, system and network information
1 Apple Park Way
Cupertino, CA 95014
Braze
Push notification as a service
Account data, device information, location, usage and app data, opt-in/opt-out notification info
63 Madison Building
28 East 28th Street, Fl. 12
New York, NY 10016
Braze
Customer Engagement Platform
Device information, metadata
63 Madison Building
28 East 28th Street, Fl. 12
New York, NY 10016
Cloudflare
DNS, DDoS, WAF
Network info/traffic, performance metrics, HTTP requests, metadata
405 Comal Street
Austin, TX 78702
CookiePro
Cookie consent and DSAR tool
Account info, support data, consent records, cookies, email, audit logs
1200 Abernathy Road
Suite 700
Atlanta, GA 30328
DataDog
Observability platform
Account info, billing info, app/performance/infrastructure data
620 8th Avenue, 45th Floor
New York, NY 10018
Hasura Cloud
Data querying engine
Account data, query, performance and usage data
576 Folsom Street, Floor 3
San Francisco, CA 94105
Mongo Atlas
Main Orb backend database provider
Account information, database content, query data, usage, integration and performance data
3405 Piedmont Road NE # 110
Atlanta, GA 30305
PactSafe / IronClad
Tracking users interacting with legal screens
Account data, signer information, usage data and metadata
650 California St #1100
San Francisco, CA 94108
PostHog
Events management
Account data, usage data, analytics, security data
2261 Market St #4008
San Francisco, CA 94114
SEON
Fraud engine
Account information, metadata, risk scores
310 Comal Street, 2nd floor, Austin, TX 78702
Snowflake
Data warehouse
All categories of personal information stored in our database
North Virginia, US / Frankfurt, Germany
Tenderly
Debugging on-chain transactions
Account info, blockchain transaction and smart contract data, performance and usage data
16 Maiden Lane
San Francisco, CA 94108
Twilio
SMS as a service
Account data, country, message data and metadata
101 Spear Street, Fifth Floor, San Francisco, CA 94105
Vercel
Frontend tooling (incl. World ID Analytics, Docs)
Account data, usage data, telemetry data, API/integration data
440 N Barranca Avenue #4133, Covina, CA 91723
Zendesk
Support provider
Account data, support data, metadata, phone number
989 Market Street,
San Francisco, CA 94103

EDPA20260921