Not effective until signed

Data Processing Addendum

Draft updated: August 24, 2026

Alentra is a brand operated by Komplete10 LTD, a company registered in the United Kingdom and operating from Sweden. This DPA names Komplete10 LTD as the proposed Processor, but remains a production draft and does not become effective through website use or API integration. The customer must be identified, the company and notice addresses and processing and transfer schedules completed, an evidence period chosen, and the DPA signed before covered production processing. No SCCs, UK Addendum, transfer-impact assessment, or sector addendum is represented as executed by this page.

1. Roles and scope

This DPA will form part of the signed order between the customer (Controller) and Komplete10 LTD, operating the Alentra brand (Processor). It applies only to personal data Alentra processes on the customer's behalf through production sessions. Komplete10 LTD remains an independent controller for its own account security, billing, fraud prevention, legal compliance, and business operations where applicable.

2. Documented instructions

Alentra will process customer personal data only to provide, secure, support, and bill the service; preserve completed evidence; handle lawful requests; and follow additional documented instructions agreed in writing. If Alentra believes an instruction violates applicable data-protection law, it will notify the customer unless prohibited.

The customer instructs Alentra to preserve every completed result and its original signed documents, signatures, proofs, signer and wallet evidence, audit record, and integrity links for at least the Evidence Period stated in the signed schedule and for any applicable legal hold. The period defines a minimum preservation obligation; its expiry does not create a customer deletion or mutation right. This instruction survives account closure.

3. Confidentiality and access

Alentra will limit access to people and service accounts with a business need, require confidentiality, use role-scoped staff access, and log privileged actions where supported. The customer business can access its authorized audit tier. age_verify identity is withheld from that tier. Full decrypted evidence is restricted to authorized legal staff handling a validated request.

4. Security measures

  • TLS for network transport and request-bound JWE or HPKE wallet-response encryption where supported.
  • Firebase Authentication, tenant-scoped authorization, server-only sensitive writes, and separate internal staff authorization.
  • Server-computed SHA-256 document and manifest hashes; exact-byte review for sign.
  • Fresh AES-256-GCM data keys for sensitive audit fields, with each data key wrapped by Google Cloud KMS.
  • Immutable per-step audit records with canonical record hashes and per-session previous-hash links.
  • RFC 3161 timestamp requests with explicit deferred status and append-only recovery when a configured TSA is unavailable.
  • HMAC-signed, timestamped, at-least-once webhooks with stable delivery IDs for deduplication.
  • Document viewer MIME allowlisting, download-only fallback, sandboxing, and restrictive browser security headers.

Certifications, penetration-test cadence, recovery objectives, employee screening, and audit-report delivery are not promised unless stated in a signed security schedule.

5. Sub-processors

The customer generally authorizes the providers listed on the Sub-processors page, subject to the signed DPA's notice and objection process. Alentra remains responsible for their processing to the extent required by applicable law and its agreements. Providers not identified there must be disclosed before they process production customer data.

6. Data-subject and authority requests

Taking into account the nature of processing, Alentra will reasonably assist the customer with verified data-subject requests, regulator inquiries, assessments, and consultations. Alentra will not respond as controller for customer session data unless authorized or legally required. Assistance may be charged where permitted and agreed.

7. Security incidents

Alentra will notify the customer without undue delay after confirming a personal-data breach affecting customer personal data and will provide available information needed for the customer's obligations. Notification is not an admission of fault. The signed schedule must define security contacts and any stricter timing commitment.

8. Return, deletion, and immutable evidence

At the end of service, Alentra will return or delete disposable customer personal data as stated in the signed retention schedule, subject to backups, security records, billing and tax records, legal obligations, and legal holds.

Customer instructions, account closure, and self-service requests cannot alter, delete, or crypto-shred a completed result or its original signed documents, signatures, proofs, signer and wallet evidence, audit row, or hash-chain links. If a law appears to require incompatible treatment, Alentra must place the request into legal review; the customer receives no mechanism that mutates completed evidence.

9. International transfers

The current architecture uses US processing locations and plane-isolated KMS resources: symmetric envelope-encryption keys and separate asymmetric audit-signing keys. Before EEA, UK, Swiss, or other restricted-transfer production data is processed, the parties must identify a lawful transfer mechanism and complete any required SCC module, UK Addendum, annexes, transfer assessment, supplementary measures, and local-law review. This draft does not preselect Ireland, Delaware, or another forum.

10. Audit information

Alentra will make information reasonably necessary to demonstrate the signed DPA obligations available, subject to confidentiality, security, third-party rights, and reasonable limits. The parties must agree any audit process, independent report, frequency, cost, and remediation procedure before production.

Annex A — processing details to complete

  • Subject matter: government-credential identify, age_verify, light_sign, and sign sessions and supporting evidence.
  • Data subjects: customer personnel and end users invited into sessions.
  • Data: requested government-credential attributes; DOB used for age computation; wallet and device evidence; signatures; uploaded documents; inline terms; session, webhook, network, and customer metadata.
  • Special data: depends on customer-selected claims and document content; the customer must prohibit or separately approve categories not required by the use case.
  • Duration and minimum Evidence Period: to be completed in the signed order; expiry does not create a customer deletion right over completed evidence.
  • Processor: Komplete10 LTD, registered in the United Kingdom and operating from Sweden. Company number, registered-office and notice address, privacy contact, and security contact remain to be completed.
  • Controller: customer legal entity, address, privacy contact, and security contact remain to be completed.

Annex B — transfer details

No transfer module is completed by this webpage. Data-exporter/importer identities, competent authority, governing law, forum, processing descriptions, onward transfers, and technical and organizational measures must be completed in the executed transfer addendum.

Contact

To request a reviewable, completed DPA, use the private contact form. Alentra must not accept covered paid production traffic until the customer identity, addresses, schedules, and signatures are complete.

Government-wallet proof, ready to repeat.

Start with Alentra