Skip to content
PUBLIC-SURFACE LIMITED GO / CUSTOMER-PROCESSING NO-GO. Public information and synthetic examples may remain available; live files, checkout, production package generation, Registry-dependent issuance, and customer activation are paused.

Direct-Buyer Data Processing Addendum

Version 2026-08-18 · Effective 2026-08-18Scope: Customer personal data processed for the direct-buyer Buyer Review Pack workflow.Policy contact: privacy@attestlayer.comRelated: Terms of Service · Privacy Notice · Subprocessors · Data Retention and Deletion Policy · Security and Data Handling

PUBLIC-SURFACE LIMITED GO / CUSTOMER-PROCESSING NO-GO.

Historical policy version 2026-08-18 · The prior PDF is withdrawn from current distribution pending a reviewed successor.

This page preserves prospective contract language for review only. It is not open for new self-service acceptance and does not authorize live customer processing. The prior PDF and metadata endpoints are withdrawn until a reviewed successor is bound to a later dated GO.

1. Scope

If later expressly activated for a valid order, this DPA would form part of the Terms governing that order. It is intended to apply to Full Buyer Review Pack, Buyer Review Essentials, Response Integrity Pack, and enabled Pipeline Packs unless a separately signed agreement expressly replaces it.

Document revision

The former downloadable file attestlayer-direct-buyer-dpa-2026-08-18-r2.pdf is a historical candidate and is not distributed as the current DPA. A future downloadable successor requires legal approval, current-decision authority, an exact artifact hash, and release-bound evidence.

2. Roles

If later activated for a valid order, the customer would be the controller or business for Customer Personal Data, and AttestLayer would be the processor or service provider, as those terms are used under applicable privacy law.

3. Processing instructions

If later activated, AttestLayer would process Customer Personal Data only to provide, secure, maintain, and support the Service; prevent fraud and abuse; comply with law; and follow the customer's documented instructions expressed through authorized use of the Service.

4. Nature and purpose of processing

If later activated, AttestLayer would process buyer-request information, source records, business contact details, order information, and generated service output to determine request fit, create the selected Buyer Review Pack family output, deliver it, verify package integrity, manage access, and meet legal and security obligations.

5. Categories of data subjects

Data subjects may include the customer's personnel, buyers, prospective buyers, business contacts, and other individuals whose limited business information appears in submitted records.

6. Categories of personal data

Personal data may include business contact details, work email addresses, job titles, information contained in submitted buyer requests, and limited personal information included in customer records. The customer must not submit credentials, private keys, passwords, payment-card data, government identification numbers, health information, source code, or other prohibited information.

7. Confidentiality

If later activated, AttestLayer would ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations or are subject to an appropriate statutory duty of confidentiality.

8. Security measures

If this DPA is later activated, AttestLayer would be contractually required to maintain reasonable technical and organizational measures for the approved direct-buyer service. Candidate source and policy controls include encrypted transport, supported storage encryption, access restrictions, security logging, bounded working-upload handling, and private generated-package lifecycle controls. This clause is not proof that those controls are deployed or operating production-wide.

9. Subprocessors

If this DPA is later activated for a valid order, the customer would authorize AttestLayer to use the subprocessors listed on the Subprocessors page. AttestLayer remains responsible for its subprocessors' processing obligations to the extent required by applicable law.

10. Assistance

If later activated, and taking into account the nature of processing, AttestLayer would provide reasonable assistance through the Service and support channels for privacy requests, security incidents, and required information relating to the direct-buyer Service. Privacy requests may be sent to privacy@attestlayer.com; security incidents may be sent to security@attestlayer.com.

11. Security incidents

If AttestLayer confirms unauthorized access to Customer Personal Data in the direct-buyer Service and applicable law requires notice, AttestLayer will notify the affected customer without undue delay and provide available information reasonably necessary for the customer to meet its notification obligations.

12. Deletion and return

Under a later approved order, request and source bytes, generated private packages, and related order data would be handled according to the Data Retention and Deletion Policy. The customer is responsible for downloading any output it wishes to keep before the applicable access period ends. Payment, invoice, security, and legal-compliance records may be retained as stated in that policy.

13. Audit information

For a later approved order, AttestLayer would make the Security page, Subprocessors page, Data Retention and Deletion Policy, and other published direct-buyer documentation available to customers. The direct-buyer Service does not include an on-site audit right or custom security assessment.

14. Conflict

If this Data Processing Addendum conflicts with the Terms of Service on processing of Customer Personal Data, this Data Processing Addendum controls to the extent of the conflict.

How this DPA is accepted

New self-service acceptance is disabled under the current decision. If later approved, the checkout design is intended to record the accepting company, verified business email, acceptance time, governing document versions and SHA-256 hashes, payment reference, and a tamper-evident acceptance-record digest. Only an acceptance created after the later approval and all applicable release gates would be the parties' record of assent for the selected order. A separately signed agreement supersedes it only to the extent of an express conflict.

Requesting a custom DPA

A custom DPA is not part of the standard self-serve order. It may be considered only for an approved larger annual agreement through security@attestlayer.com. You may also call 1-866-739-0570.