Data Processing Addendum
The terms under which Certivo processes personal data on behalf of customers. This DPA forms part of the agreement between Certivo and the customer.
1. Roles of the parties
This Addendum records the terms required by Article 28 of the EU GDPR (and, where applicable, the UK GDPR) for processing carried out by Certivo on the customer's behalf, and is read together with the Cyprus Data Protection Law 125(I)/2018. For personal data relating to a customer's end users, the customer is the controller and Certivo is the processor. Each party complies with applicable data-protection law in respect of its role. Where this Addendum and the Terms conflict on the processing of personal data, this Addendum prevails.
2. Scope & instructions
Certivo processes personal data only on the customer's documented instructions, including as set out in this DPA and the Order Form, unless required otherwise by law (in which case Certivo notifies the customer where legally permitted). The subject matter, duration, nature and purpose of processing, and the categories of data and data subjects, are described in Annex A.
3. Confidentiality of personnel
Certivo ensures that personnel authorised to process personal data are bound by appropriate confidentiality obligations and are trained on their data-protection responsibilities.
4. Security measures
Certivo implements the technical and organisational measures described in Annex B and on our Security page, appropriate to the risk of the processing.
5. Sub-processing
The customer grants a general authorisation for Certivo to engage sub-processors to deliver the Services. Certivo maintains a current list of sub-processors on our Sub-processors page, imposes data-protection terms on them consistent with this DPA, remains responsible for their performance, and provides advance notice of changes with an opportunity to object.
6. Data-subject requests
Taking into account the nature of the processing, Certivo assists the customer with appropriate technical and organisational measures to respond to data-subject requests to exercise their rights.
7. Personal-data-breach notification
Certivo notifies the customer without undue delay after becoming aware of a personal-data breach affecting the customer's data, and provides reasonable information to assist the customer in meeting its own notification obligations.
8. Deletion & return
On termination or expiry of the Services, Certivo deletes or returns the customer's personal data at the customer's choice, and deletes existing copies unless retention is required by law.
9. Audits & information
Certivo makes available information reasonably necessary to demonstrate compliance with this DPA and, subject to confidentiality and reasonable notice, allows for and contributes to audits conducted by the customer or an appointed auditor.
10. International transfers
Where processing involves a transfer of personal data outside the European Economic Area (EEA), the parties rely on an appropriate transfer mechanism — an EU adequacy decision or the EU Standard Contractual Clauses — together with a transfer risk assessment and any supplementary measures required to protect the data.
11. Breach of this Addendum
Any breach by Certivo of its obligations under this Addendum is treated as a breach of the Terms. Certivo's liability under this Addendum is subject to the limitations of liability in the Terms of Service.
Annex A — Details of processing
| Subject matter | Provision of the Certivo compliance platform to the customer. |
| Duration | For the term of the Services and any wind-down period. |
| Nature & purpose | Identity verification, AML/sanctions screening, KYB, monitoring and case management. |
| Categories of data | Identifiers, contact details, identity-document and biometric/liveness data, screening and KYB results. |
| Categories of data subjects | The customer's end users, applicants and business counterparties. |
Annex B — Technical & organisational measures
Measures include encryption in transit and at rest, role-based access control with least-privilege, tenant isolation, append-only audit logging, secure development practices, vulnerability management, and business-continuity backups. These are described further on our Security page.
Company details
| Registered entity name | Puzzle Piece Ventures Ltd |
| Company number | HE 469272 |
| Registered office | [Registered office — Cyprus, to be confirmed] |
| Jurisdiction | Republic of Cyprus |
| Governing law | the Republic of Cyprus |
| Group | OnyxOne Group |
| General enquiries | management@certivo.uk |
Any bracketed value is a registration detail to be confirmed by the operating entity.
Last updated: 20 July 2026.
This document is published by Certivo (Puzzle Piece Ventures Ltd) and is governed by the laws of the Republic of Cyprus. Questions about it can be directed to management@certivo.uk. It does not constitute legal advice; you should take your own advice on how it applies to your circumstances.