Direct-Buyer Data Processing Addendum
PUBLIC-SURFACE LIMITED GO / CUSTOMER-PROCESSING NO-GO.
Historical policy version 2026-08-18 · The prior PDF is withdrawn from current distribution pending a reviewed successor.
1. Scope
If later expressly activated for a valid order, this DPA would form part of the Terms governing that order. It is intended to apply to Full Buyer Review Pack, Buyer Review Essentials, Response Integrity Pack, and enabled Pipeline Packs unless a separately signed agreement expressly replaces it.
Document revision
The former downloadable file attestlayer-direct-buyer-dpa-2026-08-18-r2.pdf is a historical candidate and is not distributed as the current DPA. A future downloadable successor requires legal approval, current-decision authority, an exact artifact hash, and release-bound evidence.
2. Roles
If later activated for a valid order, the customer would be the controller or business for Customer Personal Data, and AttestLayer would be the processor or service provider, as those terms are used under applicable privacy law.
3. Processing instructions
If later activated, AttestLayer would process Customer Personal Data only to provide, secure, maintain, and support the Service; prevent fraud and abuse; comply with law; and follow the customer's documented instructions expressed through authorized use of the Service.
4. Nature and purpose of processing
If later activated, AttestLayer would process buyer-request information, source records, business contact details, order information, and generated service output to determine request fit, create the selected Buyer Review Pack family output, deliver it, verify package integrity, manage access, and meet legal and security obligations.
5. Categories of data subjects
Data subjects may include the customer's personnel, buyers, prospective buyers, business contacts, and other individuals whose limited business information appears in submitted records.
6. Categories of personal data
Personal data may include business contact details, work email addresses, job titles, information contained in submitted buyer requests, and limited personal information included in customer records. The customer must not submit credentials, private keys, passwords, payment-card data, government identification numbers, health information, source code, or other prohibited information.
7. Confidentiality
If later activated, AttestLayer would ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations or are subject to an appropriate statutory duty of confidentiality.
8. Security measures
If this DPA is later activated, AttestLayer would be contractually required to maintain reasonable technical and organizational measures for the approved direct-buyer service. Candidate source and policy controls include encrypted transport, supported storage encryption, access restrictions, security logging, bounded working-upload handling, and private generated-package lifecycle controls. This clause is not proof that those controls are deployed or operating production-wide.
9. Subprocessors
If this DPA is later activated for a valid order, the customer would authorize AttestLayer to use the subprocessors listed on the Subprocessors page. AttestLayer remains responsible for its subprocessors' processing obligations to the extent required by applicable law.
10. Assistance
If later activated, and taking into account the nature of processing, AttestLayer would provide reasonable assistance through the Service and support channels for privacy requests, security incidents, and required information relating to the direct-buyer Service. Privacy requests may be sent to privacy@attestlayer.com; security incidents may be sent to security@attestlayer.com.
11. Security incidents
If AttestLayer confirms unauthorized access to Customer Personal Data in the direct-buyer Service and applicable law requires notice, AttestLayer will notify the affected customer without undue delay and provide available information reasonably necessary for the customer to meet its notification obligations.
12. Deletion and return
Under a later approved order, request and source bytes, generated private packages, and related order data would be handled according to the Data Retention and Deletion Policy. The customer is responsible for downloading any output it wishes to keep before the applicable access period ends. Payment, invoice, security, and legal-compliance records may be retained as stated in that policy.
13. Audit information
For a later approved order, AttestLayer would make the Security page, Subprocessors page, Data Retention and Deletion Policy, and other published direct-buyer documentation available to customers. The direct-buyer Service does not include an on-site audit right or custom security assessment.
14. Conflict
If this Data Processing Addendum conflicts with the Terms of Service on processing of Customer Personal Data, this Data Processing Addendum controls to the extent of the conflict.
How this DPA is accepted
New self-service acceptance is disabled under the current decision. If later approved, the checkout design is intended to record the accepting company, verified business email, acceptance time, governing document versions and SHA-256 hashes, payment reference, and a tamper-evident acceptance-record digest. Only an acceptance created after the later approval and all applicable release gates would be the parties' record of assent for the selected order. A separately signed agreement supersedes it only to the extent of an express conflict.
Requesting a custom DPA
A custom DPA is not part of the standard self-serve order. It may be considered only for an approved larger annual agreement through security@attestlayer.com. You may also call 1-866-739-0570.
