The template DPA Stamp offers to vendors. Covers the narrow band of personal data where the vendor is the controller and Stamp is the processor; the reference-customer relationship is covered by the Privacy Policy directly.
EFFECTIVE: 11 June 2026 (DRAFT) · CONTACT: VERIFY@STAMPCERTIFIED.COM
This Data Processing Agreement (the "DPA") is entered into between:
This DPA forms part of the Customer's use of Stamp and governs the processing of personal data by Stamp on the Customer's behalf in the context of that use. Where this DPA conflicts with the underlying service terms, this DPA prevails for processing of personal data.
Scope note. This DPA applies to the narrow band of personal data described in Annex I where the Customer is the controller and Stamp is the processor. Stamp is not a processor for the reference-customer identity data submitted to Stamp via the consent flows at /approve/[token], /r/[token], and the LinkedIn OAuth identity check; for that data Stamp acts as a controller in its own right, and its processing is governed by the Stamp Privacy Policy rather than this DPA. The Customer warrants that it has read and understood this distinction.
Terms used in this DPA have the meanings given to them in the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), including the definitions of personal data, processing, controller, processor, data subject, sub-processor, and personal data breach. Other terms have the meanings given in the underlying service agreement.
The Customer instructs Stamp to process personal data described in Annex Ifor the purpose of providing the Stamp service: receiving and storing assets the Customer submits, running prescreening on those assets, presenting them to reviewers, and making them available within the Customer's Stamp account. Stamp will not process the data for any other purpose without prior documented instructions from the Customer or unless required by EU or Dutch law.
This DPA takes effect when the Customer begins using the Stamp service or accepts this DPA, whichever is earlier. It remains in effect for the duration of that use and any further period necessary for Stamp to comply with its obligations on termination (see Section 12).
Stamp will process personal data only on the Customer's documented instructions, including the instructions given by the Customer's use of the configurable settings of the service (account settings, opt-ins, retention settings) and the instruction inherent in the Customer submitting an asset to Stamp for processing. Stamp will inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data-protection law.
Stamp ensures that persons authorised to process the personal data covered by this DPA have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Internal access is gated through provider authentication controls (Supabase, Vercel, GitHub) and limited to named operators.
Stamp implements the technical and organisational measures described in Annex III and on the Stamp security page, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks to data subjects. Stamp will not materially weaken these measures during the term of the DPA.
The Customer authorises Stamp to engage the sub-processors listed in Annex II. Stamp will:
Taking into account the nature of the processing, Stamp will assist the Customer by appropriate technical and organisational measures to fulfil its obligation to respond to requests from data subjects exercising their rights under Chapter III of the GDPR (access, rectification, erasure, restriction, portability, objection, right to withdraw consent). If Stamp receives a request directly from a data subject relating to data Stamp processes on the Customer's behalf under this DPA, Stamp will forward it to the Customer within five business days and will not respond to the data subject directly except to acknowledge receipt and indicate that the request has been forwarded.
Stamp will notify the Customer of a personal data breach affecting personal data processed under this DPA without undue delay and, where feasible, no later than 72 hours after Stamp becomes aware of the breach. The notification will include, to the extent known at the time of notification:
Stamp will cooperate with the Customer to investigate, mitigate, and remediate the breach.
Stamp will make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA. The Customer may audit Stamp's compliance no more than once per twelve-month period, on at least 30 days' written notice, during business hours, subject to confidentiality, and to the extent that the audit does not unduly disrupt Stamp's operations or compromise the confidentiality of other Stamp customers. Stamp may satisfy an audit request by providing the relevant attestations, summaries, or test results from its sub-processors (e.g. Supabase's SOC 2 Type 2 or Vercel's SOC 2 Type 2 / ISO 27001:2022) together with Stamp's own controls description.
The Customer's data is hosted in the EU (Supabase, Frankfurt). Where the use of a sub-processor located outside the EEA is necessary for the service (currently Anthropic and DigiCert; see Annex II), Stamp will rely on the European Commission's Standard Contractual Clauses (the "SCCs") Module 3 (processor to sub-processor) and supplementary technical measures (encryption in transit, redaction of personal data from asset text prior to AI processing, and minimisation of what is transferred) to lawfully effect the transfer.
On termination of the underlying service, at the Customer's choice, Stamp will return or delete all personal data processed under this DPA within 30 days, and will delete existing copies, unless EU or Dutch law requires storage of the data. Stamp will provide written confirmation of deletion on request.
Limitation of automated deletion. Some deletion workflows are handled manually today by a named operator, rather than by automated cron. This limitation is documented on the Stamp security page. Manual deletion will be completed within the time frame above; automation of the purge is on the engineering roadmap.
The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the underlying service agreement. Nothing in this DPA limits or excludes either party's liability for breach of the GDPR or for the rights of data subjects.
This DPA is governed by the laws of the Netherlands. The courts of Amsterdam have exclusive jurisdiction over any dispute arising out of or in connection with this DPA, without prejudice to the rights of data subjects to bring claims before the supervisory authority or competent courts of their EU member state.
Processing of personal data submitted by the Customer to Stamp in the context of the Customer's use of the Stamp service, for the duration of that use plus the periods required for deletion or return.
Receiving and storing assets, running automated prescreening (including local redaction of personal data within the asset text prior to AI calls), presenting assets to reviewers, generating certificate artefacts, and serving the assets through the Stamp service surfaces (dashboard, public profile, embeds).
Personal data that may appear in Customer-submitted asset content, including:
Reference-customer identity data captured directly via Stamp's consent flows is excluded from this Annex; see the Scope note in the Preamble.
Individuals named in the Customer's submitted assets; the Customer's own employees and contractors with Stamp accounts.
Continuously, for the duration of the Customer's use of the service.
The Customer authorises Stamp to engage the following sub-processors:
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Supabase | Database, authentication, storage | EU (Frankfurt) | Intra-EU |
| Vercel | Hosting and delivery | EU edge + US | SCCs + DPA |
| Anthropic | AI drafting and prescreening | US | SCCs Module 3 + redaction |
| DigiCert | RFC 3161 timestamping (hash only) | US | SCCs + content hash, not content |
| Resend | Transactional email delivery | EU + US | SCCs + DPA |
| KvK | NL business registry lookup | NL | Public registry call |
| VIES | EU VAT registry lookup | EU | Public registry call |
| OAuth identity sign-in | EU + US | OAuth; outbound profile read only |
Changes to this list are notified per Section 7.
Stamp implements at least the following measures, in addition to those described on the Stamp security page:
identity_mapping table; SELECT policy restricts reads to the Stamp reviewer role; live anon REST probe verifies the restriction.The most current detailed description of these measures lives on the Stamp security page; this Annex incorporates that page by reference.