Skip to content
Legal

Data Processing Addendum

The terms under which Certivo processes personal data on behalf of customers. This DPA forms part of the agreement between Certivo and the customer.

1. Roles of the parties

This Addendum records the terms required by Article 28 of the EU GDPR (and, where applicable, the UK GDPR) for processing carried out by Certivo on the customer's behalf, and is read together with the Cyprus Data Protection Law 125(I)/2018. For personal data relating to a customer's end users, the customer is the controller and Certivo is the processor. Each party complies with applicable data-protection law in respect of its role. Where this Addendum and the Terms conflict on the processing of personal data, this Addendum prevails.

2. Scope & instructions

Certivo processes personal data only on the customer's documented instructions, including as set out in this DPA and the Order Form, unless required otherwise by law (in which case Certivo notifies the customer where legally permitted). The subject matter, duration, nature and purpose of processing, and the categories of data and data subjects, are described in Annex A.

3. Confidentiality of personnel

Certivo ensures that personnel authorised to process personal data are bound by appropriate confidentiality obligations and are trained on their data-protection responsibilities.

4. Security measures

Certivo implements the technical and organisational measures described in Annex B and on our Security page, appropriate to the risk of the processing.

5. Sub-processing

The customer grants a general authorisation for Certivo to engage sub-processors to deliver the Services. Certivo maintains a current list of sub-processors on our Sub-processors page, imposes data-protection terms on them consistent with this DPA, remains responsible for their performance, and provides advance notice of changes with an opportunity to object.

6. Data-subject requests

Taking into account the nature of the processing, Certivo assists the customer with appropriate technical and organisational measures to respond to data-subject requests to exercise their rights.

7. Personal-data-breach notification

Certivo notifies the customer without undue delay after becoming aware of a personal-data breach affecting the customer's data, and provides reasonable information to assist the customer in meeting its own notification obligations.

8. Deletion & return

On termination or expiry of the Services, Certivo deletes or returns the customer's personal data at the customer's choice, and deletes existing copies unless retention is required by law.

9. Audits & information

Certivo makes available information reasonably necessary to demonstrate compliance with this DPA and, subject to confidentiality and reasonable notice, allows for and contributes to audits conducted by the customer or an appointed auditor.

10. International transfers

Where processing involves a transfer of personal data outside the European Economic Area (EEA), the parties rely on an appropriate transfer mechanism — an EU adequacy decision or the EU Standard Contractual Clauses — together with a transfer risk assessment and any supplementary measures required to protect the data.

11. Breach of this Addendum

Any breach by Certivo of its obligations under this Addendum is treated as a breach of the Terms. Certivo's liability under this Addendum is subject to the limitations of liability in the Terms of Service.

Annex A — Details of processing

Subject matterProvision of the Certivo compliance platform to the customer.
DurationFor the term of the Services and any wind-down period.
Nature & purposeIdentity verification, AML/sanctions screening, KYB, monitoring and case management.
Categories of dataIdentifiers, contact details, identity-document and biometric/liveness data, screening and KYB results.
Categories of data subjectsThe customer's end users, applicants and business counterparties.

Annex B — Technical & organisational measures

Measures include encryption in transit and at rest, role-based access control with least-privilege, tenant isolation, append-only audit logging, secure development practices, vulnerability management, and business-continuity backups. These are described further on our Security page.

Company details

Registered entity namePuzzle Piece Ventures Ltd
Company numberHE 469272
Registered office[Registered office — Cyprus, to be confirmed]
JurisdictionRepublic of Cyprus
Governing lawthe Republic of Cyprus
GroupOnyxOne Group
General enquiriesmanagement@certivo.uk

Any bracketed value is a registration detail to be confirmed by the operating entity.

Last updated: 20 July 2026.

This document is published by Certivo (Puzzle Piece Ventures Ltd) and is governed by the laws of the Republic of Cyprus. Questions about it can be directed to management@certivo.uk. It does not constitute legal advice; you should take your own advice on how it applies to your circumstances.