Legal

Data Processing Addendum

How we process personal data on our customers' behalf. Last updated July 2026.

This Data Processing Addendum ("DPA") forms part of the agreement between Digital Treasury Inc. ("Processor", "we") and a customer ("Controller", "you") for the Digital Treasury platform, and applies where we process personal data on your behalf. A signed copy is available to customers on request; this page is the reference version.

1. Roles

For personal data you submit about your own customers and counterparties, you are the Controller and we are the Processor. For data we determine the purposes of (for example, your account administrators), we act as an independent controller under our Privacy Policy.

2. Scope & instructions

We process personal data only to provide the service, as documented in the agreement and this DPA, and on your documented instructions — unless law requires otherwise, in which case we notify you where permitted.

3. Confidentiality & security

Personnel with access are bound by confidentiality. We maintain technical and organizational measures appropriate to the risk — encryption in transit and at rest, tenant isolation, least-privilege and audited administrative access — described further on our Security page.

4. Sub-processors

You authorize us to engage the sub-processors listed on our Sub-processors page. We impose data-protection terms on each that are no less protective than this DPA, and we give notice of changes with an opportunity to object.

5. Data-subject requests & assistance

We assist you in responding to data-subject requests and, taking into account the nature of processing, in meeting your security, breach-notification, and data-protection-impact-assessment obligations. See Your Privacy Rights.

6. Breach notification

We notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information reasonably available to help you meet your obligations.

7. International transfers

Where personal data is transferred across borders, we rely on an appropriate transfer mechanism (such as the Standard Contractual Clauses) incorporated by reference into this DPA.

8. Return & deletion

On termination we delete or return personal data as instructed, except where retention is required by law or for financial-records and compliance obligations.

9. Audits

We make available information necessary to demonstrate compliance and allow for audits, subject to reasonable confidentiality and security safeguards.

To execute a countersigned DPA (including the SCCs and a processing schedule), contact us via the contact page.

Back to Legal Center →