IPQS Data Processing Agreement
Last Revised July 20, 2026
PART I — BASE DPA
1. Scope; Relationship to the Agreement
This Data Processing Agreement (“DPA”) forms part of, and is incorporated by reference into, the IPQS Terms of Service and/or the applicable Master Services Agreement (the “Agreement”) between IPQualityScore, LLC (“IPQS”) and the customer (“Client”), and governs IPQS’s processing of Personal Data on Client’s behalf. A negotiated/custom DPA executed by the parties supersedes this DPA as to its subject matter.
1a. Formation; Self-Execution
This DPA forms part of the Agreement and takes effect when the Client accepts the Terms of Service, registers for an account, or uses the Services, no separate signature is required. Where the EU Standard Contractual Clauses or the UK IDTA apply (Modules B–D), the Client and IPQS are deemed to have entered into and executed them upon that acceptance, on the pre-completed terms in Annex IV, with the party details drawn from the Client’s account registration. The individual accepting the Terms represents they are authorized to bind the Client. Enterprise Clients may instead request a countersigned DPA, which supersedes these defaults.
Restricted-transfer / identity note. For the transfer clauses to have an identified data exporter, a Client transferring EEA/UK/Swiss Personal Data must do so through a registered account (which captures the Client’s legal identity). U.S. and other non-restricted-transfer Clients need no transfer mechanism and are covered by the Base DPA and Module A on acceptance.
2. Definitions
“Personal Data,” “processing,” “controller,” “processor,” “service provider,” “business,” “sale,” “share,” “personal information,” and “data subject/consumer” have the meanings given under Applicable Data Protection Laws.
“Applicable Data Protection Laws” means the EU GDPR, UK GDPR, Swiss FADP, the CCPA/CPRA and other U.S. state privacy laws, Canada’s PIPEDA and Québec Law 25, Brazil’s LGPD, Mexico’s LFPDPPP, Singapore’s PDPA, and other privacy laws applicable to the processing.
“Client Personal Data” means Personal Data IPQS processes on Client’s behalf under the Agreement (described in Annex I). Where a Module defines a term differently as required by its law, the Module controls for that jurisdiction.
3. Roles; Fraud-Prevention Purpose
For Client Personal Data, Client is the controller/business and IPQS is the processor/service provider. IPQS processes Client Personal Data only on Client’s documented instructions (including the Agreement and Client’s authorized use of the Services), except where law requires otherwise (in which case IPQS will inform Client unless legally prohibited).
Fraud-prevention purpose; bases and exemptions. The Services are provided for fraud detection, abuse prevention, and risk scoring. Applicable Data Protection Laws recognize this purpose: fraud prevention is a recognized legitimate interest under the GDPR (Recital 47), and the CCPA/CPRA and comparable U.S. state laws contain exceptions permitting processing necessary to detect and prevent fraud, security incidents, and malicious or illegal activity. Under the EU AI Act, AI systems used for detecting financial fraud are excepted from the high-risk creditworthiness/credit-scoring classification (Annex III, point 5(b)). IPQS processes Client Personal Data on these bases as necessary and proportionate to the fraud-prevention and security purposes; Client, as controller/business, remains responsible for confirming its own lawful basis and for any downstream decision it makes using IPQS’s signals — including any use that would itself be high-risk or regulated, such as creditworthiness assessment.
4. IPQS Obligations
IPQS shall: (a) process Client Personal Data only for the purposes in Annex I and on Client’s instructions; (b) ensure personnel authorized to process are bound by confidentiality; (c) implement the security measures in Annex II; (d) assist Client, taking into account the nature of processing and information reasonably available, with data-subject/consumer requests, security, breach notification, and impact assessments and prior consultations; (e) notify Client without undue delay after becoming aware of a Personal Data Breach; and (f) at Client’s choice, delete or return Client Personal Data at the end of the services and delete existing copies except where retention is legally required.
5. Subprocessors
Client provides general authorization for IPQS to engage subprocessors to host infrastructure and support its operations (e.g., cloud hosting, email, CRM), under written terms consistent with this DPA, and IPQS remains responsible for their performance. IPQS operates its AI-assisted features on its own infrastructure and does not use a third-party artificial-intelligence or large-language-model provider to process Client Personal Data or outputs. IPQS will make a current subprocessor list available to enterprise customers on request and provide a mechanism to notify of, and object to, material changes under custom agreements.
6. Assistance; Audits
Taking into account the nature of processing and information reasonably available, IPQS will provide Client with information reasonably necessary to demonstrate compliance and to support Client’s impact assessments and responses to data-subject/consumer requests. Audit rights may be satisfied through a summary of IPQS’s certifications (confirming that IPQS maintains SOC 2 Type II and ISO 27001), a standard security overview, and a reasonable, confidentiality-protected information-request process. For clarity, the audit and assistance obligations in this Section are satisfied, for all Clients, by IPQS’s published certification summary and standard security overview together with a reasonable, no-more-than-annual, confidentiality-protected information-request process at the requesting Client’s expense. IPQS’s full SOC 2 Type II and ISO 27001 reports, and completed custom security questionnaires, are not provided to Clients generally; they are made available only to Clients on a qualifying paid plan or under a negotiated DPA, in each case under a non-disclosure agreement, at the requesting Client’s cost, on reasonable prior notice, and no more than once per year. Enhanced, on-site, or custom audits and bespoke assistance (including hands-on DPIA support and expedited timelines) are available only to Clients on an applicable paid plan or under a negotiated DPA, and at the requesting Client’s cost.
7. Module Applicability
The Base DPA (Part I) applies to all Clients. In addition, the Module(s) in Part II corresponding to the Client’s and/or the relevant data subjects’ location apply and control for that jurisdiction to the extent of any conflict with the Base DPA. Where more than one Module applies, each applies as to its jurisdiction; where no other Module applies, the Base DPA and Module A (United States) govern. In summary:
|
If the Client / data subjects are in… |
…then this Module applies |
|
United States |
Module A (CCPA/CPRA + comparable state laws) |
|
European Economic Area |
Module B (EU GDPR) |
|
United Kingdom |
Module C (UK GDPR) |
|
Switzerland |
Module D (FADP) |
|
Canada |
Module E (PIPEDA + Québec Law 25) |
|
Latin America (Brazil, Mexico, etc.) |
Module F (LGPD / LFPDPPP) |
|
Asia-Pacific / ASEAN (Singapore, etc.) |
Module G (PDPA + others) |
8. AI-Assisted Features
IPQS’s AI-assisted features process Client inputs and generated outputs to provide conversational fraud/risk assistance, summarization, risk explanation, and investigation support, and to operate, secure, support, and improve the Services and IPQS’s models. Categories of Client Personal Data processed (where included in inputs or outputs) are set out in Annex I. Consistent with §5, no third-party AI provider processes this data.
9. Automated Decision-Making / Profiling
IPQS provides automated risk signals and scores; the Client (as controller/business) makes any decision and is responsible for the notices, human review, appeal, adverse-action, and opt-out obligations that apply. On reasonable request, IPQS will provide information reasonably available to assist Client’s impact assessments and data-subject/consumer requests.
10. Data Retention
IPQS retains Client Personal Data only as long as necessary and, in general, for a maximum of approximately one (1) year, after which it is deleted or de-identified (much data ages out over that period), except where longer retention is required by law. Deletion is subject to routine backup cycles and does not require deletion of lawfully retained, aggregated, or de-identified data.
11. Contacts & Representatives
- Data Protection Officer (GDPR / UK GDPR): Reza Hosseini at: dpo-ipqs@smartech-it.eu.
- EU Representative (GDPR Art. 27) and UK Representative (UK GDPR Art. 27): Reza Hosseini at: dpo-ipqs@smartech-it.eu.
- US Privacy Contact (U.S. state-law requests and general privacy inquiries): IPQS Support, support@ipqualityscore.com.
12. Liability; Precedence; Term
Liability under this DPA is subject to the limitations of liability in the Agreement. In case of conflict: a negotiated/custom DPA > an applicable Module > this Base DPA > the Agreement, as to data protection. This DPA remains in effect for the duration of the processing under the Agreement.
PART II — JURISDICTION MODULES
Module A — United States (CCPA/CPRA + comparable state laws)
Applies where the Client or relevant data subjects are in the United States or the processing is subject to U.S. state privacy laws.
IPQS is a service provider/processor. IPQS shall: (a) not sell or share personal information; (b) not retain, use, or disclose it except to perform the Services under the Agreement or as otherwise permitted by law; (c) not use it outside the direct business relationship or combine it with personal information from other sources except as permitted; and (d) provide the same level of privacy protection as required of businesses. IPQS certifies it understands and will comply with these restrictions, and will assist Client with verifiable consumer requests. IPQS maintains a program designed to comply with applicable U.S. state privacy laws (e.g., Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, and others as enacted) and will provide the processor/service-provider protections those laws require as applicable to a given Client’s data and configuration, including assisting with consumer rights and honoring opt-out preference signals where applicable.
Module B — European Economic Area (EU GDPR)
Applies where the Client or relevant data subjects are in the EEA or the processing is subject to the EU GDPR.
The processor terms in Part I satisfy Article 28(3). For restricted transfers from the EEA, the EU Standard Contractual Clauses (Commission Decision (EU) 2021/914) — Module Two (controller→processor) or Module Three (processor→processor), as applicable — are incorporated by reference and completed in Annex IV; the parties agree to the annexed details, and IPQS applies supplementary measures as appropriate (including its local/dedicated hosting). IPQS assists with DPIAs (Art. 35) and prior consultation (Art. 36) and with data-subject rights (Arts. 12–22), providing information reasonably available. The EU Representative is identified in §11.
Module C — United Kingdom (UK GDPR)
Applies where the Client or relevant data subjects are in the United Kingdom or the processing is subject to the UK GDPR.
The UK GDPR and Data Protection Act 2018 apply. For restricted transfers from the UK, the UK International Data Transfer Addendum (IDTA) to the EU SCCs, or the standalone IDTA, applies as completed in Annex IV. IPQS notifies personal-data breaches consistent with ICO requirements and assists with data-subject rights. The UK Representative is identified in §11.
Module D — Switzerland (FADP)
Applies where the Client or relevant data subjects are in Switzerland or the processing is subject to the Swiss FADP (revDSG).
The EU SCCs apply with Swiss adaptations recognized by the Federal Data Protection and Information Commissioner (FDPIC), references to the GDPR read as references to the FADP, the FDPIC is a competent supervisory authority, and Swiss-resident individuals may enforce as third-party beneficiaries, as completed in Annex IV.
Module E — Canada (PIPEDA + Québec Law 25)
Applies where the Client or relevant data subjects are in Canada.
IPQS processes personal information consistent with PIPEDA, maintaining comparable protection for information transferred to it and cooperating on breach-of-security-safeguards reporting. Where Québec Law 25 applies, IPQS supports Client’s privacy impact assessments for transfers outside Québec, assists with individual rights, and provides information reasonably necessary for Law 25 disclosures.
Module F — Latin America (Brazil LGPD; Mexico LFPDPPP)
Applies where the Client or relevant data subjects are in Brazil, Mexico, or other LATAM jurisdictions.
Brazil (LGPD): IPQS acts as operator (operador), processing on the controller’s instructions, maintaining security, assisting with data-subject rights, and using an international-transfer mechanism recognized by the ANPD (e.g., standard contractual clauses/adequacy) as available. Mexico (LFPDPPP): IPQS acts as processor (encargado), processing solely on the controller’s instructions and consistent with the controller’s privacy notice. Additional LATAM jurisdictions are supported as IPQS’s footprint requires.
Module G — Asia-Pacific / ASEAN (Singapore PDPA + others)
Applies where the Client or relevant data subjects are in Singapore or other supported APAC/ASEAN jurisdictions.
Singapore (PDPA): IPQS supports the Client’s transfer-limitation obligation by providing a comparable standard of protection and processing on the Client’s instructions. Additional APAC jurisdictions (e.g., Australia APPs, Japan APPI) are supported and will be addressed by supplemental terms as IPQS’s footprint requires.
ANNEXES
Annex I — Details of Processing
- Subject matter/duration: provision of the Services for the term of the Agreement.
- Nature/purpose: fraud detection, bot detection, risk scoring, and related services, including AI-assisted features (§8).
- Data subjects: Client’s end users, customers, applicants, account holders, and individuals associated with identifiers Client submits.
- Categories of Personal Data: limited to IP addresses, email addresses, phone numbers, device identifiers, and URLs or domains submitted for fraud and risk analysis (and, for accounts that enable IPQS’s identity or enrichment features, additional identity attributes such as names that IPQS returns from its data sources); for AI-assisted features, the same identifiers together with operational data (prompts and feedback containing them, timestamps, and logs). IPQS does not intentionally process special categories of personal data.
- Special categories: not intended; Client shall not submit sensitive/special-category data except as authorized.
- Retention: per §10 (generally ≤ ~1 year).
Annex II — Technical & Organizational Measures (TOMs)
Access controls and least-privilege; encryption in transit, with encryption at rest for certain data and additional safeguards (such as tokenization/hashing, access controls, and tenant isolation) applied as appropriate; network security; logging and monitoring; abuse-monitoring and prompt-injection safeguards for AI-assisted features; tenant/data isolation; secure development and vulnerability management; personnel confidentiality and training; business continuity, consistent with IPQS’s SOC 2 Type II and ISO 27001 programs.
Annex III — Subprocessors
Categories: hosting/infrastructure/DNS; email; CRM. No third-party AI/LLM provider. Current list available to enterprise customers on request.
Annex IV — Transfer Mechanisms
These defaults apply automatically to self-serve / click-through Clients where a restricted transfer occurs, without separate signature. Enterprise Clients may vary them in a countersigned DPA.
A. When these apply. Only where the Client or its data subjects are in the EEA, UK, or Switzerland and IPQS processes their Personal Data (Modules B–D). U.S. and other non-restricted-transfer Clients need no transfer mechanism.
B. EEA — EU SCCs (Commission Decision (EU) 2021/914), incorporated and executed on acceptance, with these pre-selected options:
- Module: Module Two (controller→processor) by default; Module Three (processor→processor) where the Client acts as a processor for its own controller.
- Clause 7 (docking clause): included.
- Clause 9 (subprocessors): Option 2 — general written authorization, with 30 days’ prior notice of changes (per §5).
- Clause 11 (optional redress body): not selected.
- Clause 17 (governing law): the law of Ireland, unless the law of the exporter’s EU member state is required.
- Clause 18 (forum): the courts of Ireland, or the exporter’s member state where required.
- Annex I.A (parties): Data exporter = the Client, as identified at account registration or on the Order Form, acting through the individual who accepted the Terms; Data importer = IPQualityScore, LLC, contact: dpo-ipqs@smartech-it.eu.
- Annex I.B (processing): as described in DPA Annex I (categories limited to IP addresses, email addresses, phone numbers, device identifiers, and URLs or domains).
- Annex I.C (competent supervisory authority): the SA of the exporter’s EEA establishment or, absent one, the SA of the member state of the exporter’s Art. 27 representative.
- Annex II (measures): DPA Annex II. Annex III (subprocessors): DPA Annex III.
C. UK — International Data Transfer Addendum (IDTA): the ICO’s IDTA (or the UK Addendum to the EU SCCs) applies, with Tables 1–4 populated by reference to Section B above and the Client’s account details; the version in force as issued by the ICO.
D. Switzerland: the EU SCCs in Section B apply with the FDPIC adaptations in Module D.
E. Party identity for self-serve Clients. The Client’s identity and details for these clauses are those provided at account registration; the individual accepting the Terms represents authority to bind the Client. Clients transferring EEA/UK/Swiss data must use a registered account so these clauses have an identified data exporter.
For any questions concerning our Data Processing Agreement (DPA), please contact IPQS.