Legal
Data Processing Agreement
Last updated: 2 October 2026
1. Scope and roles
This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Controller") and OATHERA ("Processor") for use of the Services. It applies where OATHERA processes personal data on the Controller's behalf. Where terms conflict, this DPA governs for data-protection matters.
2. Definitions
"Personal data", "processing", "controller", "processor", and "data subject" have the meanings given in applicable data protection law, including the EU/UK GDPR. "Sub-processor" means a third party engaged by OATHERA to process personal data.
3. Processing of personal data
OATHERA processes personal data only on documented instructions from the Controller, including as set out in the agreement and this DPA, unless required by law. The subject matter is the provision of the agentic identity Services; the nature and purpose is issuing and verifying agent identities and maintaining audit records; the types of data include account and operational identifiers; and the duration is the term of the agreement.
4. Confidentiality
OATHERA ensures that personnel authorised to process personal data are bound by confidentiality obligations.
5. Security measures
OATHERA implements appropriate technical and organisational measures, including encryption in transit, least-privilege access, non-exportable key custody, short-lived credentials, a fail-closed enforcement model, and tamper-evident audit logging.
6. Sub-processors
The Controller authorises OATHERA to engage the sub-processors listed at oathera.ai/subprocessors. OATHERA imposes data-protection obligations on each sub-processor no less protective than this DPA and remains responsible for their performance. We will give notice of intended changes so the Controller can object on reasonable grounds.
7. Data subject rights
Taking into account the nature of the processing, OATHERA assists the Controller with appropriate measures to respond to data subject requests to exercise their rights under applicable law.
8. Personal data breaches
OATHERA notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data and provides information reasonably available to assist the Controller's own obligations.
9. International transfers
Where processing involves transfers outside the EEA or UK, OATHERA relies on an approved transfer mechanism such as the Standard Contractual Clauses, incorporated by reference where applicable.
10. Return and deletion
On termination, OATHERA deletes or returns personal data at the Controller's choice, except where retention is required by law.
11. Audits
OATHERA makes available information necessary to demonstrate compliance with this DPA and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality and scheduling.
12. Contact
To request a signed copy of this DPA or ask questions, email privacy@oathera.ai.