Template · Last updated: January 2025
VerfiX AG · acting as Processor · privacy@verfix.ch
This DPA governs the processing of personal data by VerfiX AG (Processor) on behalf of the Customer (Controller) in connection with the VerfiX platform, under GDPR Art. 28 and the Swiss nFADP.
Processing covers identity, document, biometric and screening data for the purpose of identity verification, for the duration of the service agreement.
VerfiX maintains a current list of sub-processors and notifies Customers of changes. Swiss-dedicated and on-premise deployments restrict or eliminate sub-processing.
VerfiX implements TLS in transit, AES-256 at rest, RBAC, and audit logging, and assists the Controller in responding to data-subject requests.
Request the signed DPA via privacy@verfix.ch.