Data Processing Addendum
How we process personal data on our customers' behalf. Last updated July 2026.
This Data Processing Addendum ("DPA") forms part of the agreement between Digital Treasury Inc. ("Processor", "we") and a customer ("Controller", "you") for the Digital Treasury platform, and applies where we process personal data on your behalf. A signed copy is available to customers on request; this page is the reference version.
1. Roles
For personal data you submit about your own customers and counterparties, you are the Controller and we are the Processor. For data we determine the purposes of (for example, your account administrators), we act as an independent controller under our Privacy Policy.
2. Scope & instructions
We process personal data only to provide the service, as documented in the agreement and this DPA, and on your documented instructions — unless law requires otherwise, in which case we notify you where permitted.
3. Confidentiality & security
Personnel with access are bound by confidentiality. We maintain technical and organizational measures appropriate to the risk — encryption in transit and at rest, tenant isolation, least-privilege and audited administrative access — described further on our Security page.
4. Sub-processors
You authorize us to engage the sub-processors listed on our Sub-processors page. We impose data-protection terms on each that are no less protective than this DPA, and we give notice of changes with an opportunity to object.
5. Data-subject requests & assistance
We assist you in responding to data-subject requests and, taking into account the nature of processing, in meeting your security, breach-notification, and data-protection-impact-assessment obligations. See Your Privacy Rights.
6. Breach notification
We notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information reasonably available to help you meet your obligations.
7. International transfers
Where personal data is transferred across borders, we rely on an appropriate transfer mechanism (such as the Standard Contractual Clauses) incorporated by reference into this DPA.
8. Return & deletion
On termination we delete or return personal data as instructed, except where retention is required by law or for financial-records and compliance obligations.
9. Audits
We make available information necessary to demonstrate compliance and allow for audits, subject to reasonable confidentiality and security safeguards.
To execute a countersigned DPA (including the SCCs and a processing schedule), contact us via the contact page.