
How Bureau Protects Your Personal Data
Data Processing Addendum
Updated 15 September 2026
1. About this Addendum
Version 1.0. Effective 15 September 2026. Published by Bureau at bureau.id.
Reference. GDPR Article 28; Digital Personal Data Protection Act, 2023; standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914.
Contact. Questions about this Addendum should be sent to Bureau's Data Protection Officer at dpo@bureau.id.
2. Scope and Structure
This Data Processing Addendum ("Addendum") forms part of the agreement between the Customer and Bureau under which Bureau provides identity verification, fraud prevention, business verification, screening or authentication services (the "Services"). It applies wherever Bureau processes personal data on the Customer's behalf in the course of providing the Services.
Where the Customer and Bureau have signed a bilateral data processing agreement, that agreement prevails over this Addendum to the extent of any conflict. Otherwise this Addendum applies in full and is incorporated into the agreement by reference.
This Addendum is published so that Customers and prospective Customers can review Bureau's processor commitments before contracting. Bureau may update it to reflect changes in law, the Services, or its sub-processors; material changes will be notified in accordance with the Sub-processing section below.
3. Definitions
"Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach" and "Supervisory Authority" have the meanings given in the GDPR. "Data Fiduciary", "Data Processor" and "Data Principal" have the meanings given in the Digital Personal Data Protection Act, 2023. "GDPR" means Regulation (EU) 2016/679 and, where applicable, the UK GDPR. "SCCs" means the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914. "Sub-processor" means any processor engaged by Bureau to process Personal Data on behalf of the Customer.
4. Roles of the Parties
For Personal Data submitted to the Services by the Customer, or collected by Bureau on the Customer's instruction from the Customer's end users, the Customer is the Controller and Bureau is the Processor. Under the Digital Personal Data Protection Act, 2023, the Customer is the Data Fiduciary and Bureau is the Data Processor.
Bureau is a Controller in respect of personal data it processes for its own purposes, including data about its own personnel, contractors, applicants and business contacts, and data processed for the security, integrity and improvement of the Services where Bureau determines the purposes and means. That processing is described in Bureau's Data Privacy Policy and is outside the scope of this Addendum.
The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subjects are set out in Annex I(B).
5. Processing on Documented Instructions
Bureau shall process Personal Data only on the Customer's documented instructions, including with regard to transfers of Personal Data to a third country, unless required to do otherwise by applicable law. Where Bureau is required by law to process Personal Data other than on the Customer's instructions, it shall inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
The agreement, this Addendum, the Customer's configuration of the Services and the Customer's use of the Services through the applicable interfaces together constitute the Customer's documented instructions.
Bureau shall immediately inform the Customer if, in its opinion, an instruction infringes the GDPR, the Digital Personal Data Protection Act, 2023 or other applicable data protection law. Bureau may suspend performance of the affected instruction until it is confirmed, amended or withdrawn.
6. Confidentiality
Bureau shall ensure that persons authorised to process Personal Data are bound by an appropriate statutory or contractual obligation of confidentiality, that access is limited to those who require it to deliver the Services, and that such persons receive data protection and information security training. Confidentiality obligations survive the termination of the individual's engagement with Bureau.
7. Security of Processing
Bureau shall implement and maintain the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk to the rights and freedoms of Data Subjects.
Bureau may update the measures in Annex II provided that the updated measures do not materially reduce the overall level of security of the Services.
8. Sub-processing
The Customer grants Bureau general written authorisation to engage Sub-processors for the purposes of delivering the Services. Bureau's current Sub-processors are listed at the location given in Annex III.
Bureau shall give the Customer at least thirty (30) days' advance notice of the addition or replacement of a Sub-processor. The Customer may object on reasonable data-protection grounds within that period. Where an objection cannot be resolved, the Customer may terminate the affected Services without penalty for the unexpired term.
Bureau shall impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this Addendum, and remains fully liable to the Customer for the performance of each Sub-processor's obligations.
9. Assistance with Data Subject Rights
Taking into account the nature of the processing, Bureau shall assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests to exercise Data Subject rights under Articles 12 to 23 of the GDPR and sections 11 to 14 of the Digital Personal Data Protection Act, 2023.
Where a Data Subject contacts Bureau directly in respect of Personal Data processed on the Customer's behalf, Bureau shall not respond substantively to the request. Bureau shall tell the Data Subject without undue delay that the request must be directed to the Customer, and shall inform the Customer of the request.
Intake route. Requests and instructions under this section should be sent to dpo@bureau.id.
Identifiers. The Customer shall provide the identifiers necessary for Bureau to locate the relevant Personal Data, which may include the Customer's own end-user identifier, the transaction or session reference, or the entity identifier used by the Service.
Service level. Bureau shall acknowledge a Customer instruction under this section within two (2) business days and complete it within ten (10) business days, or shall inform the Customer within that period where the request requires longer and why.
10. Assistance with Security, Breach Notification and Impact Assessments
Taking into account the nature of the processing and the information available to it, Bureau shall assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR, including security of processing, notification of Personal Data Breaches, communication of breaches to Data Subjects, data protection impact assessments and prior consultation with a Supervisory Authority.
11. Personal Data Breach
Bureau shall notify the Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Personal Data processed on the Customer's behalf.
The notification shall describe, to the extent known at the time and supplemented as further information becomes available, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and the contact point from which further information may be obtained. Bureau shall cooperate with the Customer and take the reasonable steps the Customer directs to assist in the investigation and remediation of the breach.
Bureau's notification is not an acknowledgement of fault or liability.
12. Deletion and Return of Personal Data
On termination or expiry of the agreement, Bureau shall at the Customer's election delete or return the Personal Data processed on the Customer's behalf and delete existing copies, unless applicable law requires continued storage. Where the Customer makes no election within thirty (30) days of termination, Bureau shall delete the Personal Data.
Bureau shall delete Personal Data on the Customer's documented instruction during the term, in accordance with the retention position recorded in Annex I(B). Bureau shall provide a certificate of deletion on the Customer's written request.
Personal Data retained in backups is deleted in accordance with Bureau's backup cycle and remains subject to this Addendum until deleted.
13. Audit and Demonstration of Compliance
Bureau shall make available to the Customer the information necessary to demonstrate compliance with the obligations in Article 28 of the GDPR, and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.
Bureau shall provide its current ISO/IEC 27001 certificate and, on request and subject to confidentiality obligations, its most recent SOC 2 report and a summary of its most recent penetration test.
Where those materials do not satisfy the Customer's audit obligation, the Customer may conduct an audit on at least thirty (30) days' written notice, no more than once in any twelve-month period unless required by a Supervisory Authority or following a Personal Data Breach.
Audits shall take place during business hours, shall not unreasonably disrupt Bureau's operations, and shall not extend to the data or systems of other Bureau customers.
14. International Transfers
Where the Customer is established in the European Economic Area or the United Kingdom, or is otherwise subject to the GDPR, and the processing involves a transfer of Personal Data to a country not benefiting from an adequacy decision, the SCCs apply and are incorporated into this Addendum by reference, completed as set out in Annex I and Annex II.
Module Two (Controller to Processor) applies to transfers from the Customer to Bureau.
Module Three (Processor to Processor) applies to onward transfers by Bureau to a Sub-processor, together with the onward-transfer terms in Clause 8.7 of the SCCs.
United Kingdom. The UK International Data Transfer Addendum to the EU SCCs applies to transfers subject to the UK GDPR.
India. Transfers of personal data out of India are made in accordance with section 16 of the Digital Personal Data Protection Act, 2023 and any restriction notified by the Central Government.
The optional docking clause in Clause 7 of the SCCs applies. Where Clause 17 or Clause 18 of the SCCs requires an election, the governing law and forum are those stated in the Governing Law section of this Addendum.
15. Special Categories of Personal Data
Where the Services include facial verification, liveness detection or face de-duplication, Bureau processes biometric data for the purpose of uniquely identifying a natural person. That processing includes the derivation and, where face de-duplication is enabled by the Customer, the storage and one-to-many comparison of a facial vector template. A facial vector template is personal data within Article 4(14) of the GDPR and a special category of personal data within Article 9(1); it is not anonymised or pseudonymised data.
Bureau processes such data only on the Customer's documented instruction and in reliance on the lawful basis the Customer establishes. The Customer warrants that it has obtained the explicit consent of the Data Subject under Article 9(2)(a) of the GDPR, or has established another condition under Article 9(2), before submitting biometric data to the Services, and that it has complied with any additional requirement of the law applicable to the Data Subject.
Where the Services include screening against sanctions, politically exposed person or adverse-media sources, Bureau may process data relating to criminal convictions and offences within Article 10 of the GDPR. The Customer warrants that its use of that Service is authorised by law.
16. Automated Decision-Making and Profiling
Bureau returns verification results, match outcomes and risk signals to the Customer. Bureau does not take any decision in relation to a Data Subject and does not determine the consequences of a result. The Customer decides what action, if any, to take.
Where a Customer's use of a Bureau output forms part of a decision based solely on automated processing that produces legal effects concerning a Data Subject or similarly significantly affects them, the Customer is responsible for meeting the requirements of Article 22 of the GDPR, including providing the Data Subject with the right to obtain human intervention, to express a point of view and to contest the decision.
Certain Services involve profiling within the meaning of Article 4(4) of the GDPR, including alternate-data risk scoring, face de-duplication and behavioural analytics. Bureau shall provide the Customer, on request, with the information about the logic involved and the significance and envisaged consequences of that processing that the Customer requires to meet its own transparency obligations.
17. Customer Warranties
The Customer warrants that it has a valid lawful basis for the processing it instructs, and has provided all notices and obtained all consents required by applicable law.
The Customer warrants that its instructions comply with applicable data protection law and that it is entitled to transfer the Personal Data to Bureau for processing.
The Customer warrants that it will not submit to the Services any special category personal data other than as contemplated by the Special Categories section, and will not submit personal data of children except where it has obtained verifiable consent as required by applicable law.
18. Liability
Each party's liability arising out of or related to this Addendum is subject to the limitations and exclusions of liability set out in the agreement. Nothing in this Addendum limits either party's liability to a Data Subject under applicable data protection law.
19. Term, Termination and Survival
This Addendum takes effect on the effective date of the agreement and continues until the agreement terminates or expires. The obligations in the Confidentiality, Deletion and Return, and Liability sections survive termination for as long as Bureau retains Personal Data processed on the Customer's behalf.
20. Governing Law and Jurisdiction
This Addendum is governed by the law and subject to the jurisdiction stated in the agreement, except where applicable data protection law requires otherwise.
Where the SCCs apply and the agreement does not specify the law of an European Economic Area Member State, the governing law elected under Clause 17 of the SCCs is the law of the Member State in which the Customer is established, and the forum elected under Clause 18 is the courts of that Member State. Where the Customer is not established in the European Economic Area, the law and forum are those of Ireland.
21. Order of Precedence
In the event of conflict, the following order of precedence applies: the SCCs, where they apply; this Addendum; the agreement. A bilateral data processing agreement signed by both parties prevails over this Addendum.
22. Contact
Questions about this Addendum, and instructions under it, should be addressed to Bureau's Data Protection Officer at dpo@bureau.id.
23. Annex I(A) — List of Parties
Data exporter: the Customer, acting as Controller in respect of the Personal Data processed under the agreement. The Customer's name, address, contact person and activities relevant to the transfer are those stated in the agreement.
Data importer: the Bureau entity that contracts with the Customer, acting as Processor. Bureau's group entities are:
BureauID India Private Limited (India). Operating and processing entity, and contracting processor for India-based Customers. Owns and operates the infrastructure used to deliver the Services, including resources in non-India regions.
Bureau, Inc. (Delaware, USA). Contracting entity for international Customers, and data importer under the SCCs where those apply. Holds no processing environment or data storage; processing is performed by BureauID India Private Limited.
Junoon Tech Pte. Ltd. (Singapore). Bureau group entity, and contracting party where named as such in the agreement. Where this entity is the contracting party, the entity that performs the processing is identified in the Sub-processor list referred to in Annex III.
The data importer for the purposes of this Addendum, and of the SCCs where they apply, is the Bureau entity named as the contracting party in the agreement. Its registered address and contact details are those stated in the agreement. The Data Protection Officer is the contact point for data protection matters for every Bureau entity and may be reached at dpo@bureau.id.
Where the Bureau entity that contracts with the Customer is not the entity that performs the processing, Bureau shall ensure that the processing entity is bound by data protection obligations no less protective than those in this Addendum, whether by an intra-group agreement incorporating Module Three of the SCCs or by that entity acceding to the SCCs under the docking clause, and the contracting entity remains fully liable to the Customer for that entity's performance. The processing entity is identified in the Sub-processor list referred to in Annex III.
24. Annex I(B) — Description of the Processing
Categories of Data Subjects. End users and customers of the Customer. Where the Customer operates in the European Economic Area or the United Kingdom, Data Subjects in those territories are in scope.
Categories of Personal Data. Identity attributes (name, phone, email, address, date of birth); government identifiers; financial identifiers; business identifiers; identity document images; facial vector template; device and network signals; IP address; location data; telecom attributes; behavioural signals; income-verification data. The categories actually processed depend on the Services the Customer enables.
Special categories of Personal Data. Biometric data processed for the purpose of uniquely identifying a natural person, namely the facial vector template derived from a facial image and liveness capture, where facial verification or face de-duplication is enabled. Data relating to criminal convictions and offences within Article 10, where screening Services are enabled.
Nature of the processing. Receipt of Customer-submitted data through API or SDK; validation against issuer, government and licensed partner sources; document authenticity checks; face match, liveness detection and face de-duplication; device and behavioural signal collection and risk scoring; end-user authentication; storage and deletion on Customer instruction; return of a verification result or risk signal.
Purpose of the processing. Identity verification and KYC compliance support; fraud and risk assessment; business verification; screening; and end-user authentication, in each case on the documented instruction of the Customer.
Duration of the processing. The term of the agreement, plus the retention period applicable to each category of Personal Data, followed by deletion or return.
Frequency of the transfer. Continuous and transaction-triggered, for the duration of the agreement.
Retention. Personal Data is retained for the period the Customer instructs, within the limits of Bureau's Data Retention and Deletion Policy. Retention periods applicable to the Services the Customer has enabled are recorded in the Customer's order documentation or service configuration. Where the Customer gives no instruction, Bureau applies the shortest period consistent with delivering the Service.
Automated decision-making. Bureau returns verification results and risk signals only and takes no decision producing legal or similarly significant effects. See the Automated Decision-Making and Profiling section.
25. Annex I(C) — Competent Supervisory Authority
The competent Supervisory Authority is the authority of the European Economic Area Member State in which the Customer is established. Where the Customer is not established in the European Economic Area but has appointed a representative under Article 27 of the GDPR, it is the authority of the Member State in which that representative is established. Where the Customer is not established in the European Economic Area and has appointed no representative, it is the authority of the Member State in which the Data Subjects whose Personal Data is transferred are located.
26. Annex II — Technical and Organisational Measures
The measures below are implemented by the Bureau entity that performs the processing.
Encryption in transit. TLS 1.2 or above enforced on external interfaces.
Encryption at rest. AES-256, with keys managed in a cloud key management service.
Access control. Role-based access on a need-to-know basis; multi-factor authentication enforced; no direct production data access, API-mediated only; periodic user access reviews.
Network controls. Private virtual private cloud; zero-trust access controls for administrative paths; web application firewall at the edge.
Minimisation. Processing is confined to the attributes the Customer submits for the requested check. Application and system logs are designed to exclude end-user personal data.
Certification and assurance. ISO/IEC 27001:2022 certified. SOC 2 Type II reporting in progress. Reports are available to Customers under confidentiality obligations on request.
Personnel. Background verification on hire; contractual confidentiality obligations; annual security and privacy awareness training.
Vulnerability management. Vulnerability scanning and remediation; periodic penetration testing; documented patch management.
Logging and monitoring. Centralised logging with continuous monitoring and alerting; cloud management-event logging.
Incident management. Documented incident response and breach management procedures, including a processor-to-Controller notification path.
Resilience and continuity. Documented business continuity and disaster recovery arrangements with periodic testing; automated backups with point-in-time recovery.
Sub-processor management. Risk assessment before onboarding; contractual flow-down of Article 28(3) obligations; maintained Sub-processor register.
Deletion. Deletion or return of Personal Data on termination; deletion on Customer instruction; certificate of deletion on request.
27. Annex III — Sub-processors
Bureau engages Sub-processors in the categories set out below. The categories a particular Customer's processing involves depend on the Services that Customer has enabled.
Cloud infrastructure. Compute, storage, database, key management and networking used to host and deliver the Services.
Content delivery and network security. Content delivery, web application firewall and zero-trust access controls at the network edge.
Analytical data platform. Storage and querying of event and telemetry data used to deliver risk and fraud analytics.
Identity and authentication platform. End-user authentication, where the Customer has enabled Bureau-hosted authentication.
Identity data sources and verification partners. Government, regulatory and licensed commercial sources against which identity, address, document and business attributes are verified, in each jurisdiction where the Customer has enabled verification Services.
Biometric verification partners. Partners performing facial comparison, liveness detection or face de-duplication in jurisdictions where those Services are delivered through a partner.
Telecommunications data partners. Phone-network, porting and telecom attribute signals used by alternate-data Services.
Screening data providers. Sanctions, politically exposed person and adverse-media data, where screening Services are enabled.
Bureau group entities. Bureau group companies that perform processing or hold infrastructure on behalf of the contracting entity.
Bureau maintains a current list naming each Sub-processor, the category in which it is engaged, the country in which it processes Personal Data and the transfer mechanism that applies. Bureau shall provide that list to the Customer on written request to dpo@bureau.id, and shall provide it before onboarding on request. The list is provided for the Customer's use in meeting its own transparency and record-keeping obligations and is subject to the confidentiality terms of the agreement.
Bureau shall notify the Customer at least thirty (30) days in advance of engaging a new Sub-processor or replacing an existing one. Notice is given to the contact the Customer nominates for that purpose, or failing nomination to the Customer's notice address in the agreement. The Customer's right to object is set out in the Sub-processing section of this Addendum.










