Skip to content
Legal documents

Data Processing Agreement (DPA)

Contents

Data Processing Agreement · Art. 28 GDPR · Version 1.0

Verifento and B2B clients are INDEPENDENT CONTROLLERS (Art. 4(7) GDPR) – not a controller and processor. Therefore, the relationship is not governed by a standard DPA under Art. 28 GDPR, but by a Controller-to-Controller Data Sharing Agreement (DSA) under Art. 26 GDPR.

Why Not a DPA?

A traditional DPA (Art. 28 GDPR) is concluded when one entity processes data ON BEHALF OF another (e.g., a cloud provider for a company). In the case of Verifento:

  • Each B2B client (rental company) independently determines the purpose of processing its customers' data → it is an independent controller
  • Verifento manages the network and determines its technical parameters → also an independent controller
  • Both parties share data as equal partners → Art. 26 GDPR (Independent Controllers)

Legal reference: EDPB Opinion 07/2020 (Fashion ID case); CJEU C-634/21 (SCHUFA) – confirmation of independent controller status for scoring platforms.

What Document Applies?

The relationship between Verifento ↔ B2B client is governed by:

→ Controller-to-Controller Data Sharing Agreement (DSA v1.1)

View DSA Agreement →

When Does a DPA Apply to Verifento?

Verifento enters into DPAs under Art. 28 GDPR with its own subprocessors – technical processors:

SubprocessorFunctionAgreement
Supabase Inc.Database hosting (PostgreSQL)DPA with Supabase
Vercel Inc.Application hosting and CDNDPA with Vercel
Resend Inc.Transactional emailsDPA with Resend

These DPAs are internal agreements between Verifento and its providers – they are not relevant to B2B clients of the platform.

Questions about legal classification: privacy@verifento.com