DRAFT, PENDING LEGAL REVIEW.This document accurately reflects Stamp's current technical reality but has not yet been reviewed by external counsel. Use it as a working draft; do not rely on it as final legal advice or a binding instrument until this banner is removed.
Home / Legal / Data Processing Agreement

Data Processing Agreement

The template DPA Stamp offers to vendors. Covers the narrow band of personal data where the vendor is the controller and Stamp is the processor; the reference-customer relationship is covered by the Privacy Policy directly.

EFFECTIVE: 11 June 2026 (DRAFT) · CONTACT: VERIFY@STAMPCERTIFIED.COM

Preamble

This Data Processing Agreement (the "DPA") is entered into between:

  • 3DGE (the "Processor" or "Stamp"), a sole proprietorship registered in the Netherlands, operating the Stamp verification service at stampcertified.com; and
  • The vendor accepting this DPA (the "Customer" or "Controller"), as identified in the underlying service agreement or in the acceptance flow on the Stamp dashboard.

This DPA forms part of the Customer's use of Stamp and governs the processing of personal data by Stamp on the Customer's behalf in the context of that use. Where this DPA conflicts with the underlying service terms, this DPA prevails for processing of personal data.

Scope note. This DPA applies to the narrow band of personal data described in Annex I where the Customer is the controller and Stamp is the processor. Stamp is not a processor for the reference-customer identity data submitted to Stamp via the consent flows at /approve/[token], /r/[token], and the LinkedIn OAuth identity check; for that data Stamp acts as a controller in its own right, and its processing is governed by the Stamp Privacy Policy rather than this DPA. The Customer warrants that it has read and understood this distinction.

1Definitions

Terms used in this DPA have the meanings given to them in the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), including the definitions of personal data, processing, controller, processor, data subject, sub-processor, and personal data breach. Other terms have the meanings given in the underlying service agreement.

2Scope and subject matter

The Customer instructs Stamp to process personal data described in Annex Ifor the purpose of providing the Stamp service: receiving and storing assets the Customer submits, running prescreening on those assets, presenting them to reviewers, and making them available within the Customer's Stamp account. Stamp will not process the data for any other purpose without prior documented instructions from the Customer or unless required by EU or Dutch law.

3Duration

This DPA takes effect when the Customer begins using the Stamp service or accepts this DPA, whichever is earlier. It remains in effect for the duration of that use and any further period necessary for Stamp to comply with its obligations on termination (see Section 12).

4Customer instructions

Stamp will process personal data only on the Customer's documented instructions, including the instructions given by the Customer's use of the configurable settings of the service (account settings, opt-ins, retention settings) and the instruction inherent in the Customer submitting an asset to Stamp for processing. Stamp will inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data-protection law.

5Confidentiality

Stamp ensures that persons authorised to process the personal data covered by this DPA have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Internal access is gated through provider authentication controls (Supabase, Vercel, GitHub) and limited to named operators.

6Technical and organisational measures

Stamp implements the technical and organisational measures described in Annex III and on the Stamp security page, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks to data subjects. Stamp will not materially weaken these measures during the term of the DPA.

7Sub-processors

The Customer authorises Stamp to engage the sub-processors listed in Annex II. Stamp will:

  • impose data-protection obligations on each sub-processor that are no less protective than those in this DPA;
  • remain responsible to the Customer for the performance of each sub-processor;
  • give the Customer at least 14 days' prior notice before adding or replacing a sub-processor, via an email to the address on file. The Customer may object to the change in writing within that period, in which case the parties will negotiate in good faith. If a resolution is not reached, the Customer may terminate the underlying service for cause.

8Data-subject rights assistance

Taking into account the nature of the processing, Stamp will assist the Customer by appropriate technical and organisational measures to fulfil its obligation to respond to requests from data subjects exercising their rights under Chapter III of the GDPR (access, rectification, erasure, restriction, portability, objection, right to withdraw consent). If Stamp receives a request directly from a data subject relating to data Stamp processes on the Customer's behalf under this DPA, Stamp will forward it to the Customer within five business days and will not respond to the data subject directly except to acknowledge receipt and indicate that the request has been forwarded.

9Personal data breach

Stamp will notify the Customer of a personal data breach affecting personal data processed under this DPA without undue delay and, where feasible, no later than 72 hours after Stamp becomes aware of the breach. The notification will include, to the extent known at the time of notification:

  • the nature of the breach, the categories and approximate number of data subjects and personal data records concerned;
  • the likely consequences of the breach;
  • the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.

Stamp will cooperate with the Customer to investigate, mitigate, and remediate the breach.

10Audits

Stamp will make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA. The Customer may audit Stamp's compliance no more than once per twelve-month period, on at least 30 days' written notice, during business hours, subject to confidentiality, and to the extent that the audit does not unduly disrupt Stamp's operations or compromise the confidentiality of other Stamp customers. Stamp may satisfy an audit request by providing the relevant attestations, summaries, or test results from its sub-processors (e.g. Supabase's SOC 2 Type 2 or Vercel's SOC 2 Type 2 / ISO 27001:2022) together with Stamp's own controls description.

11International transfers

The Customer's data is hosted in the EU (Supabase, Frankfurt). Where the use of a sub-processor located outside the EEA is necessary for the service (currently Anthropic and DigiCert; see Annex II), Stamp will rely on the European Commission's Standard Contractual Clauses (the "SCCs") Module 3 (processor to sub-processor) and supplementary technical measures (encryption in transit, redaction of personal data from asset text prior to AI processing, and minimisation of what is transferred) to lawfully effect the transfer.

12Return or deletion of data

On termination of the underlying service, at the Customer's choice, Stamp will return or delete all personal data processed under this DPA within 30 days, and will delete existing copies, unless EU or Dutch law requires storage of the data. Stamp will provide written confirmation of deletion on request.

Limitation of automated deletion. Some deletion workflows are handled manually today by a named operator, rather than by automated cron. This limitation is documented on the Stamp security page. Manual deletion will be completed within the time frame above; automation of the purge is on the engineering roadmap.

13Liability

The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the underlying service agreement. Nothing in this DPA limits or excludes either party's liability for breach of the GDPR or for the rights of data subjects.

14Governing law and jurisdiction

This DPA is governed by the laws of the Netherlands. The courts of Amsterdam have exclusive jurisdiction over any dispute arising out of or in connection with this DPA, without prejudice to the rights of data subjects to bring claims before the supervisory authority or competent courts of their EU member state.

Annex I. Details of processing

A. Subject matter and duration

Processing of personal data submitted by the Customer to Stamp in the context of the Customer's use of the Stamp service, for the duration of that use plus the periods required for deletion or return.

B. Nature and purpose of processing

Receiving and storing assets, running automated prescreening (including local redaction of personal data within the asset text prior to AI calls), presenting assets to reviewers, generating certificate artefacts, and serving the assets through the Stamp service surfaces (dashboard, public profile, embeds).

C. Types of personal data

Personal data that may appear in Customer-submitted asset content, including:

  • names, job titles, employers, and quotes of individuals referenced in case studies and testimonials;
  • email addresses inadvertently included in PDF or URL content;
  • identifiers of the Customer's own employees (names, email addresses, roles) used to administer the Stamp account.

Reference-customer identity data captured directly via Stamp's consent flows is excluded from this Annex; see the Scope note in the Preamble.

D. Categories of data subjects

Individuals named in the Customer's submitted assets; the Customer's own employees and contractors with Stamp accounts.

E. Frequency of transfer

Continuously, for the duration of the Customer's use of the service.

Annex II. Sub-processors

The Customer authorises Stamp to engage the following sub-processors:

Sub-processorPurposeLocationTransfer mechanism
SupabaseDatabase, authentication, storageEU (Frankfurt)Intra-EU
VercelHosting and deliveryEU edge + USSCCs + DPA
AnthropicAI drafting and prescreeningUSSCCs Module 3 + redaction
DigiCertRFC 3161 timestamping (hash only)USSCCs + content hash, not content
ResendTransactional email deliveryEU + USSCCs + DPA
KvKNL business registry lookupNLPublic registry call
VIESEU VAT registry lookupEUPublic registry call
LinkedInOAuth identity sign-inEU + USOAuth; outbound profile read only

Changes to this list are notified per Section 7.

Annex III. Technical and organisational measures

Stamp implements at least the following measures, in addition to those described on the Stamp security page:

EncryptionTLS in transit; AES-256 at rest on the database provider's infrastructure.
Access controlRow-level security on all sensitive tables; multi-tenant isolation enforced at the database layer via Postgres policies; production access restricted to named operators.
Identity vaultReference-customer identity stored in a separated identity_mapping table; SELECT policy restricts reads to the Stamp reviewer role; live anon REST probe verifies the restriction.
RedactionAsset text submitted for prescreening is redacted locally on Stamp's infrastructure (no outbound HTTP) before any AI call.
PseudonymisationAnonymous certificates scrub name, role, and company at the data layer; only seniority, function, industry, and size band are visible publicly.
Audit loggingReviewer decisions are recorded in an immutable-by- convention manual_reviews log; certificate status transitions are timestamped on the certificate row.
Incident responseDocumented breach-notification process (Section 9); 72-hour notification commitment.
Supplier oversightSub-processors selected for documented attestations (SOC 2 Type 2, ISO 27001) where applicable; see Annex II.
Backup and restoreDaily automated backups via the database provider; backups encrypted; restoration tested.
Vulnerability managementDependency advisories monitored; security headers applied at the application layer (X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, X-DNS-Prefetch-Control); documented residual risks tracked.

The most current detailed description of these measures lives on the Stamp security page; this Annex incorporates that page by reference.