• Tools For Humanity 利用規約

    Tools For Humanity 利用規約

  • 生体データ保持ポリシー

    生体データ保持ポリシー

  • Tools for Humanityプライバシーポリシー

    Tools for Humanityプライバシーポリシー

  • Tools for Humanity クッキーポリシー

    Tools for Humanity クッキーポリシー

  • 法執行機関からの要求

    法執行機関からの要求

  • Tools for Humanity Arbitration Agreement

    Tools for Humanity Arbitration Agreement

  • 付属書 – Tools for Humanityによるデータ処理活動の法的根拠/目的

    付属書 – Tools for Humanityによるデータ処理活動の法的根拠/目的

  • Master Services Agreement

    Master Services Agreement

Data Processing Addendum

バージョン: 1.1発効日 2026年9月23日

Exhibit A: Data Processing Addendum

This Data Processing Addendum, together with its schedules (this “DPA”), is incorporated into and forms part of the Agreement between TFH and Customer, each as defined in the Master Services Agreement (the “MSA”) between TFH and Customer. In the event of a conflict between the MSA and this DPA, the terms of this DPA will apply with respect to the subject matter set forth herein.

How This DPA Applies

Pursuant to the Agreement, TFH may from time-to-time process Personal Data (as defined below) for which Customer may be a “Data Controller” as defined by Applicable Data Protection Law (as defined below), including the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”). When processing such Personal Data, TFH acts as a “Data Processor” as defined by Applicable Data Protection Law. This DPA applies only to TFH’s processing of Personal Data on behalf of Customer in connection with the Services. This includes, for example, the account and administrative data Customer provides to enable its Authorized Users’ access to the Services including through TFH’s enterprise portal. This DPA does not apply to TFH’s processing of user enrollment or verification procedures that occur directly between an individual Authorized User and TFH in connection with that individual’s World ID account, which is governed by TFH’s privacy notice and terms applicable to individual users and not by this DPA.

Because such processing may, from time to time, require the maintenance and implementation of appropriate technical and organizational safeguards, and because such processing may, from time to time, involve the transfer of Personal Data from the European Union to the United States, Customer and TFH agree to execute this DPA in order to ensure that adequate safeguards are established with respect to the protection of Personal Data.

The subject matter and duration of the processing are governed by the underlying Agreement. The rights and obligations of the controller are determined in this DPA in connection with the attached Standard Contractual Clauses and the Agreement.

1. Definitions

All capitalized words not defined below will have meaning set forth in the Agreement.

1.1 “Applicable Data Protection Law” means privacy and data protection laws, regulations applicable to a Party’s processing under this DPA, including, to the extent applicable, Regulation (EU) 2016/679 (“GDPR”), the GDPR as incorporated into United Kingdom law (“UK GDPR”), the Swiss Federal Act on Data Protection (“Swiss FADP”), and the California Consumer Privacy Act of 2018, as amended, and its implementing regulations (“CCPA”).

1.2 “DPA Effective Date” means the Effective Date of the Agreement.

1.3 “Permitted Business Purpose” means TFH's processing of Personal Data for: (i) providing and improving the Services; (ii) ensuring the security, integrity, and continued functioning of the Services; (iii) developing and improving TFH’s biometric verification technologies; (iv) producing anonymized or aggregated analytics; and (v) complying with applicable law.

1.4 “Personal Data” means any information that TFH receives from or on behalf of Customer, or generates on Customer’s behalf, when such information is from or about an identified or identifiable person, including information that can be associated with an individual Data Subject or the household of a Data Subject. Personal Data includes Personal Information as defined in the CCPA, subject to the exclusions under “How This DPA Applies”.

1.5 “Processing”, “Data Controller,” “Data Subject,” “Supervisory Authority,” and “Data Processor” have the same meanings set forth in the GDPR.

1.6 “Standard Contractual Clauses” means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as incorporated and completed under Section 4.

1,7 “Subprocessor” means third-party subcontractors, including a TFH affiliate, that TFH retains from time to time to provide services to TFH necessary for TFH to perform its obligations under the Agreement and that process personal data on behalf of TFH.

1.8 “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, version B1.0, including its mandatory Part 2, as revised in accordance with its terms.

2. Applicability

This DPA to TFH’s processing of Personal Data on Customer’s behalf in connection with the Services applies, whether or not the GDPR or UK GDPR applies. Requirements specific to a jurisdiction apply only to the extent required by Applicable Data Protection Law.

3. Processing of Personal Data

With respect to TFH’s processing of Personal Data on behalf of Customer under this DPA, TFH will:

3.1 when acting as Customer’s Data Processor, process Personal Data for the Services and Permitted Business Purposes in accordance with Applicable Data Protection Law and Customer’s documented instructions, including the Agreement, this DPA and authorized service configurations; promptly inform Customer if an instruction appears unlawful. Such instructions do not apply to TFH’s processing as an independent Data Controller;

3.2 maintain appropriate technical and organizational measures as described in Schedule II without materially reducing their overall protection, and limit personnel access to those with a need to know who are subject to confidentiality obligations;

3.3 when acting as Customer’s Data Processor, promptly forward Data Subject requests to Customer and respond only as instructed or legally required; provide reasonable assistance with such requests and Customer’s security, data protection impact assessment and consultation obligations, taking into account the nature of the processing, available information and Applicable Data Protection Law. TFH handles requests concerning its independent-controller processing separately;

3.4 notify Customer with undue delay of any accidental or unlawful destruction or accidental loss, alteration, or unauthorized disclosure or access of Personal Data processed as Customer’s Data Processor that presents a material risk to the rights of data subjects (a “Data Breach”) or of any processing of Personal Data in a manner inconsistent with the terms of the Agreement and this DPA, with such notification given in accordance with Section 10(d) of the MSA (Notices), and to provide reasonable assistance to Customer with respect to any Data Breach (including without limitation cooperating with Customer with respect to notification of Supervisory Authorities and communicating to Data Subjects regarding a Data Breach);

3.5 promptly notify Customer upon TFH’s or its Subprocessors’ receipt of any request for disclosure of Personal Data from a Supervisory Authority, government entity or court of law of a competent jurisdiction, or pursuant to a subpoena (unless otherwise prohibited by law);

3.6 take reasonable and appropriate steps to stop and remediate unauthorized processing, upon notice by Customer, in the event Customer has determined that TFH is no longer processing data in accordance with the Agreement and this DPA.

4. Subprocessors and International Transfers

4.1 Customer grants TFH general written authorization to engage Subprocessors to process Personal Data on Customer’s behalf under this DPA, including the Subprocessors listed in Schedule III (the “Subprocessor List”) as of the DPA Effective Date. TFH shall engage only Subprocessors providing sufficient guarantees of compliance with Applicable Data Protection Law.

4.2 TFH may update the Subprocessor List by adding or replacing Subprocessors. TFH shall notify Customer by email at least ten (10) calendar days before a proposed addition or replacement begins processing Personal Data on Customer’s behalf. The notice shall identify the Subprocessor, its processing activities and locations, and provide sufficient information regarding its data protection safeguards to enable Customer to assess the change. Customer may object within that period by written notice stating reasonable, substantiated grounds relating to the protection of Personal Data. If Customer does not object within that period, TFH may implement the change and update Schedule III without further authorization or formal amendment of this DPA. Following such an objection, the Parties shall promptly seek to resolve it, and TFH shall not permit the proposed Subprocessor to process the affected Personal Data while the objection remains unresolved.

4.3 TFH shall impose substantially equivalent data protection obligations on each Subprocessor by written agreement and remain responsible to Customer for the Subprocessor’s performance. TFH shall provide copies of those agreements and amendments where required by Applicable Data Protection Law or the Standard Contractual Clauses, subject to redactions necessary to protect confidential information.

4.4 When acting as Customer’s Data Processor, TFH shall provide information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, as required by Applicable Data Protection Law. Customer shall first consider relevant security reports and certifications made available by TFH. Audits shall be subject to reasonable confidentiality, notice and scheduling arrangements and conducted at Customer’s expense, except where prohibited by law. These arrangements shall not restrict mandatory audit or information rights.

4.5 Following the end of the relevant processing Services, TFH shall, at Customer’s choice, delete or return Personal Data processed as Customer’s Data Processor and delete remaining copies, unless applicable law requires retention. TFH shall continue to protect retained Personal Data under this DPA and process it only as legally required. TFH shall certify deletion where required by Applicable Data Protection Law or the Standard Contractual Clauses.

Where Customer transfers Personal Data as Data Controller to the TFH entity identified in Schedule I as Data Processor, and that transfer requires safeguards under Chapter V GDPR, Module Two of the Standard Contractual Clauses is incorporated where applicable, with Customer as data exporter and that TFH entity as data importer, unless the Parties have documented another valid transfer mechanism.

4.6 Schedule I constitutes Annex I to the Standard Contractual Clauses and shall identify the relevant Parties, their roles, the covered transfers and the competent Supervisory Authority determined under Clause 13. Schedule II constitutes Annex II. The Subprocessor List supplies the information concerning authorized Subprocessors. The Parties shall complete the applicable particulars before relying on the Standard Contractual Clauses. United Kingdom transfers are additionally subject to Section 6.

4.7 TFH shall ensure that onward transfers of Personal Data processed as Customer’s Data Processor, including access from another country, are covered by the safeguards required by Applicable Data Protection Law. Where the Standard Contractual Clauses apply, the Parties shall comply with their requirements concerning transfer assessments, supplementary measures, government-access requests and suspension or termination of transfers.

4.8 TFH’s independent-controller processing is not included in the processor transfers governed by this Section or their SCC annexes. Any international transfers associated with that excluded processing require their own assessment and applicable safeguards; they are not authorized or regulated by this DPA. The Standard Contractual Clauses and, where applicable, the UK Addendum prevail over conflicting terms of this DPA or the Agreement.

5. CCPA Clause

TFH will not (i) sell Personal Data; (ii) retain, use, or disclose Personal Data for any purpose other than for the specific purpose of performing the Services for Customer; (iii) retain, use, or disclose Personal Data for a commercial purpose other than providing the services for Customer; (iv) retain, use, or disclose Personal Data outside of the direct business relationship between TFH and Customer; or (v) combine the Personal Data with personal data that TFH receives from or on behalf of any other person, except as permitted by Applicable Data Protection Law or as instructed by Customer.

6. UK and CH Transfer

6.1 Where a transfer of Personal Data processed by TFH as Customer’s Data Processor requires safeguards under UK GDPR, the Standard Contractual Clauses identified in Section 4 apply as amended by the ICO’s International Data Transfer Addendum, version B1.0, including its mandatory Part 2, as revised in accordance with its terms (the “UK Addendum”), unless another valid transfer mechanism has been documented.

Table 1 of the UK Addendum is completed with the Parties’ details in Schedule I and the DPA Effective Date. Table 2 identifies Module Two and the selections in Section 4.6. Table 3 comprises Schedules I and II and the Subprocessor List. Table 4 selects “neither Party”. Any additional required particulars shall be completed before the transfer.

6.2 The UK Addendum’s mandatory amendments, including its governing-law, jurisdiction and hierarchy provisions, apply to the relevant UK transfers.

6.3 Where a transfer governed by the Swiss FADP relies on the Standard Contractual Clauses, references to the GDPR include the Swiss FADP to the extent applicable, and the Federal Data Protection and Information Commissioner is the competent Swiss supervisory authority. References to a Member State include Switzerland to the extent necessary to preserve Data Subjects’ rights, including their right to bring proceedings in Switzerland. Where the GDPR also applies, its protections and the jurisdiction of the competent EU supervisory authority remain unaffected.

7. Miscellaneous

7.1 This DPA shall remain in full force and effect until the earlier of:

7.1.1 the expiration or termination of the Agreement; or

7.1.2 the mutual agreement of the parties to terminate.

7.2 This DPA prevails over conflicting terms of the Agreement concerning its subject matter. The Standard Contractual Clauses and the UK Addendum prevail to the extent required by their respective hierarchy provisions.

7.3 Customer is responsible for the lawfulness of its instructions, its provision of Personal Data to TFH and its use of the Services and their outputs, including required notices and legal bases for processing concerning its personnel. TFH remains responsible for its own obligations under Applicable Data Protection Law, including in respect of its independent-controller processing.

Schedule I

Description of Transfers

This Schedule constitutes Annexes I and II to the Standard Contractual Clauses and applies only where, and to the extent that, those Clauses apply to processing under this DPA.

A. List of Parties

Data exporter(s):

Name: The Customer named in the Order Form.

Address: As specified in the Agreement

Contact person’s name, position and contact details: As specified in the Agreement.

Activities relevant to the data transferred under the Standard Contractual Clauses: Customer uses the Services provided by TFH under the Agreement.

Signature and date: As of the Effective Date of the Agreement.

Role (controller/processor): Controller

Data importer(s):

Name: Tools for Humanity Corporation.

Address: As specified in the Agreement.

Contact person’s name, position and contact details: As specified in the Agreement.

Activities relevant to the data transferred under the Standard Contractual Clauses: TFH processes enterprise account and administrative data, related analytics on Customer’s behalf as described in Part B. The independent-controller processing excluded under “How This DPA Applies” is outside this Schedule.

Signature and date: As of the Effective Date of this Agreement

Role (controller/processor): Processor

B. Description of Transfer

Categories of data subjects whose personal data is transferred:

  • Customer's Authorized Users (employees and personnel provisioned with access to the Services).

Categories of personal data transferred (may include):

  • Name, email address, department, and other employee registry data provided by Customer to enable Authorized Users' access to the Services; and
  • Service usage and administrative records, including analytics to the extent they contain Personal Data,
  • Enterprise account and user identifiers, opt-in records and authentication timestamps, to the extent processed on Customer’s behalf for enterprise administration and delivery of verification results.
  • Facial images captured from the video stream of a meeting in which Customer has enabled the Services, obtained by TFH via Zoom's real-time media streaming (RTMS) integration and used to perform the verification match described below.

Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures:

Facial images obtained via RTMS

Safeguards: such images are used solely to perform the verification match and generate the resulting verification/badge status; they are retained only for the period specified by Customer's applicable configuration in TFH's enterprise portal; they are encrypted in transit and at rest; access is restricted to personnel and systems necessary to perform the verification; and they are not used for any purpose beyond the verification and badge functions described above. TFH separately processes biometric data (including facial images captured by the Orb and images submitted through the World ID mobile app) as part of the underlying verification technology, but that processing occurs directly between the individual Authorized User and TFH in connection with that individual's World ID account, is not directed by or transferred to Customer, and is governed by TFH's Privacy Policy applicable to individual users rather than this DPA (see “How This DPA Applies” above).

The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis):

On an ongoing basis during the provision of the Services, including account provisioning, registry updates and delivery of verification results.

Nature of the processing:

Collection, receipt, hosting, organisation, retrieval, disclosure and deletion of enterprise administrative data and verification-status records. This includes provisioning Authorized Users, operating Customer’s enterprise portal and delivering and administering verification results.

Purpose(s) of the data transfer and further processing:

To administer Customer’s enterprise account, enable Authorized Users’ access to the Services and provide Customer with verification status and related service information..

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period:

Personal Data is retained for the duration necessary to provide the relevant enterprise Services, subject to Customer’s documented instructions and applicable retention settings. On termination, Personal Data is deleted or returned in accordance with this DPA and TFH’s policies, unless applicable law requires retention.

For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing:

Subprocessors provide hosting, infrastructure and other support for the processor activities described above, for the duration necessary to provide those services and subject to this DPA’s retention and deletion requirements as specified above.

C. Competent Supervisory Authority

Identify the competent supervisory authority/ies in accordance with Clause 13 of the Standard Contractual Clauses:

The Bavarian Data Protection Supervisory Authority (BayLDA). Not applicable where the Standard Contractual Clauses do not apply to the processing and transfers covered by this DPA.

Schedule II

Technical and Organisational Measures including Technical and Organisational Measures to ensure the Security of the Data

This Schedule describes the technical and organizational measures applicable to Personal Data processed by TFH as Customer’s Data Processor under this DPA. TFH maintains a comprehensive, written information security program that contains administrative, technical, and physical safeguards that, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing of personal information as well as the associated risks, are appropriate to (a) the type of information that TFH will store as personal information; and (b) the need for security and confidentiality of such information. TFH’s security program is designed to:

  • Protect the confidentiality, integrity, and availability of personal information in TFH’s possession or control or to which TFH has access;
  • Protect against any anticipated threats or hazards to the confidentiality, integrity, and availability of personal information;
  • Protect against unauthorized or unlawful access, use, disclosure, alteration, or destruction of personal information;
  • Protect against accidental loss or destruction of, or damage to, personal information; and
  • Safeguard information as set forth in any local, state or federal regulations by which TFH may be regulated.

Without limiting the generality of the foregoing, TFH’s security program includes:

1. Security Awareness and Training. Mandatory employee security awareness and training programs, which include:

1.1 Training on how to implement and comply with its information security program; and

1.2 Promoting a culture of security awareness.

2. Access Controls. Policies, procedures, and logical controls:

2.1 To limit access to its information systems and the facility or facilities in which they are housed to properly authorized persons;

2.2 To prevent those workforce members and others who should not have access from obtaining access; and

2.3 To remove access in a timely basis in the event of a change in job responsibilities or job status.

3. Physical and Environmental Security. Controls that provide reasonable assurance that access to physical servers at the data centers housing personal information is limited to properly authorized individuals and that environmental controls are established to detect, prevent and control destruction due to environmental extremes.

4. Security Incident Procedures. A security incident response plan that includes procedures to be followed in the event of any security breach of any application or system directly associated with the accessing, processing, storage or transmission of personal information.

5. Contingency Planning. Policies and procedures for responding to an emergency or other occurrence (for example, fire, vandalism, system failure, pandemic flu, and natural disaster) that could damage personal information or production systems that contain personal information.

6. Audit Controls. Technical or procedural mechanisms put in place to promote efficient and effective operations, as well as compliance with policies.

7. Data Integrity. Policies and procedures to ensure the confidentiality, integrity, and availability of personal information and to protect it from disclosure, improper alteration, or destruction.

8. Storage and Transmission Security. Security measures to guard against unauthorized access to personal information that is being transmitted over a public electronic communications network or stored electronically.

9. Secure Disposal. Policies and procedures regarding the secure disposal of tangible property containing personal information, taking into account available technology so that such data cannot be practicably read or reconstructed.

10 Assigned Security Responsibility. Assigning responsibility for the development, implementation, and maintenance of its information security program, including:

10.1 Designating a security official with overall responsibility; and

10.2 Defining security roles and responsibilities for individuals with security responsibilities.

11. Testing. Regularly testing the key controls, systems and procedures of its information security program to validate that they are properly implemented and effective in addressing the threats and risks identified.

12. Monitoring. Network and systems monitoring, including error logs on servers, disks and security events for any potential problems. Such monitoring includes:

12.1 Reviewing changes affecting systems handling authentication, authorization, and auditing;

12.2 Reviewing privileged access to TFH production systems processing personal information; and

12.3 Engaging third parties to perform network vulnerability assessments and penetration testing on a regular basis.

13. Change and Configuration Management. Maintaining policies and procedures for managing changes TFH makes to production systems, applications, and databases processing personal information. Such policies and procedures include:

13.1 A process for documenting, testing and approving the patching and maintenance of the TFH Service;

13.2 A security patching process that requires patching systems in a timely manner based on a risk analysis; and

13.3 A process for TFH to utilize a third party to conduct web application-level security assessments.

14. Program Adjustments. TFH monitors, evaluates, and adjusts, as appropriate, the security program in light of:

14.1 Any relevant changes in technology and any internal or external threats to TFH or the personal information;

14.2 Security and data privacy regulations applicable to TFH; and

14.3 TFH's own changing business arrangements, such as mergers and acquisitions, alliances and joint ventures, outsourcing arrangements, and changes to inform.

Schedule III

Sub-Processors

PROCESSOR

PURPOSE

DATA PROCESSED

ADDRESS

Algolia

Search engine for public docs

Account info, query/usage data, integration data

3790 El Camino Real

Unit #518

Palo Alto, CA 94306

Amazon Web Services

Hosting for backend/server infrastructure

Account data, Orb data, metadata, phone numbers, event data

410 Terry Avenue North

Seattle, WA 98109

Apple

App store for Apple phones

Account data, device information and country, app usage data, performance data

1 Apple Park Way

Cupertino, CA 95014

Apple

Integrity check

Device identifiers, operating system, system and network information

1 Apple Park Way

Cupertino, CA 95014

Braze

Push notification as a service

Account data, device information, location, usage and app data, opt-in/opt-out notification info

63 Madison Building

28 East 28th Street, Fl. 12

New York, NY 10016

Braze

Customer Engagement Platform

Device information, metadata

63 Madison Building

28 East 28th Street, Fl. 12

New York, NY 10016

Cloudflare

DNS, DDoS, WAF

Network info/traffic, performance metrics, HTTP requests, metadata

405 Comal Street

Austin, TX 78702

CookiePro

Cookie consent and DSAR tool

Account info, support data, consent records, cookies, email, audit logs

1200 Abernathy Road

Suite 700

Atlanta, GA 30328

DataDog

Observability platform

Account info, billing info, app/performance/infrastructure data

620 8th Avenue, 45th Floor

New York, NY 10018

Hasura Cloud

Data querying engine

Account data, query, performance and usage data

576 Folsom Street, Floor 3

San Francisco, CA 94105

Mongo Atlas

Main Orb backend database provider

Account information, database content, query data, usage, integration and performance data

3405 Piedmont Road NE # 110

Atlanta, GA 30305

PactSafe / IronClad

Tracking users interacting with legal screens

Account data, signer information, usage data and metadata

650 California St #1100

San Francisco, CA 94108

PostHog

Events management

Account data, usage data, analytics, security data

2261 Market St #4008

San Francisco, CA 94114

SEON

Fraud engine

Account information, metadata, risk scores

310 Comal Street, 2nd floor, Austin, TX 78702

Snowflake

Data warehouse

All categories of personal information stored in our database

North Virginia, US / Frankfurt, Germany

Tenderly

Debugging on-chain transactions

Account info, blockchain transaction and smart contract data, performance and usage data

16 Maiden Lane

San Francisco, CA 94108

Twilio

SMS as a service

Account data, country, message data and metadata

101 Spear Street, Fifth Floor, San Francisco, CA 94105

Vercel

Frontend tooling (incl. World ID Analytics, Docs)

Account data, usage data, telemetry data, API/integration data

440 N Barranca Avenue #4133, Covina, CA 91723

Zendesk

Support provider

Account data, support data, metadata, phone number

989 Market Street,

San Francisco, CA 94103

EDPA20260921