Reconstruct Data Processing Addendum
Version: October 11, 2026.
These are our standard Data Processing Addendum (DPA) terms for customers whose personal data we process on their instructions. The DPA takes effect when signed by both parties and supplements the service agreement identified in the signed copy. Viewing this page does not enter you into a DPA. Contact [email protected] to arrange a DPA for your service.
The parties are the customer identified in the signed service agreement (Customer) and Cryptify Corporation, 8 The Green, STE R, Dover, DE 19901, USA (Provider).
1. Scope and roles
This DPA applies only to personal data Provider processes on Customer's documented instructions to deliver the agreed services (Customer Personal Data). Customer acts as controller, or as processor authorized by its controller; Provider acts respectively as processor or subprocessor. Each party complies with data-protection law applicable to its role.
Provider's independent account, billing, security and public-catalog activities are governed by applicable law and the Privacy Policy. Provider must not use Customer Personal Data for its own catalog publication, advertising, general-purpose model training or unrelated product improvement under this DPA.
2. Instructions and confidentiality
Provider processes Customer Personal Data only on documented instructions, including regarding international transfers, unless legally required otherwise. It informs Customer of such a requirement before processing unless prohibited by law. It promptly informs Customer if an instruction, in its opinion, infringes applicable data-protection law and suspends the affected instruction while the parties resolve it.
Customer is responsible for lawful collection, transparency and authority to instruct processing. Provider ensures authorized personnel are bound by confidentiality and have access only as necessary for their duties. Customer may not submit special-category data, criminal-offence data or children's data unless expressly assessed and agreed in Annex A.
3. Security
Provider implements the technical and organizational measures specified in Annex B, appropriate to the risks under applicable law, and does not materially reduce the agreed level of protection during the term. The parties assess additional measures before materially changing inputs, scale or processing methods.
4. Subprocessors
Customer grants general written authorization for the subprocessors identified in completed Annex C. Provider gives at least 30 days' written notice before adding or replacing a subprocessor, allowing Customer to object on reasonable data-protection grounds. The parties seek a resolution; if none is possible before the change, Customer may end the affected processing/service and receive a prorated refund of unused prepaid fees for that service, subject to the underlying agreement and mandatory law. Provider does not transfer the affected data to the proposed subprocessor while a timely objection remains unresolved.
Provider imposes materially equivalent data-protection obligations on subprocessors and remains responsible to Customer for their performance as required by applicable law. Only the subprocessors covered by Customer’s authorization may process Customer Personal Data.
5. Assistance and incidents
Taking account of the nature of processing and available information, Provider assists Customer with data-subject requests and obligations concerning security, breach notification, impact assessments and regulator consultations. Provider forwards requests relating to Customer Personal Data and does not respond substantively except on instructions or where required by law.
Provider notifies Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Notifications describe available facts, affected data/subjects, likely consequences, mitigation and a contact; information may be supplied in phases without undue delay. Provider cooperates with containment, investigation and remediation; notice is not an admission of liability.
6. International transfers
The parties identify each restricted transfer, roles and destination in Annex D and implement a valid mechanism before transfer. International transfers include access from another country and onward transfers to subprocessors, as applicable.
Where required, the parties incorporate the applicable European Commission 2021/914 Standard Contractual Clauses and any applicable UK Addendum, International Data Transfer Agreement or Swiss adaptations into the signed DPA. The relevant modules, options and annexes are agreed with Customer. These transfer instruments are executed separately and are not included merely by viewing this page. The parties cooperate on transfer assessments and supplementary measures. Mandatory transfer terms prevail over conflicting terms of this DPA or the underlying agreement.
7. Return and deletion
At Customer's choice, Provider returns or deletes Customer Personal Data after the end of the relevant service, deletes existing copies unless law requires retention, and provides confirmation on request. Annex A sets export format, active-system deadlines and backup expiry. Legally retained data is isolated and processed only for the required purpose. Restored backups must reapply deletions. The customer-specific Annexes A–D form part of the signed DPA and define the agreed processing, security measures, subprocessors and transfers.
8. Information and audits
Provider makes available information necessary to demonstrate compliance and allows and contributes to audits, including inspections, by Customer or an authorized independent auditor. The parties coordinate proportionate scope, confidentiality and reasonable notice without frustrating mandatory audit rights, urgent incident investigations or supervisory-authority access. Existing evidence may be used where sufficient. Any certification relied on for the service is identified in the signed agreement.
9. Precedence and signatures
This DPA prevails over conflicting processing provisions in the underlying agreement; mandatory transfer instruments prevail over both. Nothing limits statutory rights of data subjects or powers of authorities. Commercial liability provisions apply only to the extent consistent with applicable law and transfer instruments.
The DPA is executed by authorized representatives of Customer and Provider. The signed copy identifies the representatives and signature dates.
Annex A — Processing description and lifecycle
| Required field | Agreed details |
|---|---|
| Service, subject matter and duration | Specified in the customer-specific annex |
| Nature and purpose | Agreed capture or analysis purposes identified in the customer-specific annex |
| Data subjects and categories | Specific data subjects and personal-data fields identified in the customer-specific annex |
| Sensitive data and safeguards | Excluded unless the signed copy says otherwise |
| Frequency, volume and authorized users | Specified in the customer-specific annex |
| Customer instructions/contact | Specified in the customer-specific annex |
| Provider privacy/security contacts | [email protected], [email protected] |
| Export format and return deadline | Specified in the customer-specific annex |
| Active, temporary, logs and provider-copy deletion | Specified in the customer-specific annex |
| Backup expiry and legal retention | Specified in the customer-specific annex |
Annex B — Agreed technical and organizational measures
The customer-specific annex describes the agreed security measures, including access and privileged access; tenant isolation; transmission and storage protection; key and secret management; minimization; logging and redaction; vulnerability and patch management; backup and restore; incident handling; staff confidentiality; deletion; subprocessor review; and verification of those measures. Any agreed certification is identified separately.
Annex C — Authorized subprocessors
The signed copy lists each subprocessor's legal entity, activity, data categories, countries, and transfer mechanism. The list covers the providers authorized to process that customer’s data and may be narrower than the public provider list.
Annex D — Transfers
The signed copy identifies each transfer, the exporter and importer, the countries, the transfer instrument, and any supplementary measures. Transfers are limited to those covered by the agreed annex and applicable transfer safeguards.