Data processing agreement

The terms on which Pruvyo processes personal data on your instruction, written to the structure Article 28 of the GDPR requires. Where you are the controller and we are the processor, this is the agreement between us.

1. What this is, and how it fits

This agreement forms part of the terms between us and applies whenever we process personal data on your behalf. Where it differs from the rest of those terms on a question about personal data, this agreement governs.

Controller, processor, personal data, processing, data subject and personal data breach carry the meanings given by the GDPR. GDPR means Regulation 2016/679 and, where it applies to the processing, the United Kingdom version of it together with the Data Protection Act 2018.

This agreement runs for as long as we process personal data for you, and the clauses that are meant to outlive it do so.

2. What is being processed, and why

  • Subject matter: providing the Pruvyo service, being transaction monitoring, investigation, and regulatory reporting for a regulated institution.
  • Duration: for as long as you hold an account, and afterwards only for the period your own retention obligations require.
  • Nature and purpose: reading records from providers you connect, keeping them on one book, evaluating them against rules you write, recording the decisions your people take, and preparing filings.
  • Types of personal data: identity and contact details of your customers, their transactions, wallet addresses and account identifiers, their verification status, documents an analyst attaches to a case, and the names and actions of your own staff.
  • Categories of data subject: your customers, the counterparties to their payments, and your own personnel.

3. What each of us promises

We process personal data only on your documented instructions, which are given by your configuration of the service, by this agreement, and by anything else you tell us in writing. That includes instructions about transfers. If we believe an instruction breaks data protection law we will say so rather than carry it out quietly, and we may pause that instruction until it is resolved.

We do not use your data for our own purposes. It is not sold, not shared with other customers, and not used to train any model. If the law obliges us to process it otherwise, we will tell you before we do unless that law forbids it.

You promise that you have a lawful basis for everything you instruct us to do, that you have given the data subjects whatever notices your own law requires, that the data you connect is accurate and that you are entitled to give it to us. You remain responsible for the rules you write and the decisions your people take.

4. Confidentiality

Everyone at Pruvyo with access to your data is bound to confidentiality, and access is limited to those who need it to run or support the service.

5. Security

We take the measures required by Article 32. What they actually are is in Annex B rather than described in the abstract here, because a security clause that cannot be checked is not a security clause.

We may change a measure for one that is at least as protective, and Annex B is kept current.

6. Sub-processors

You give general authorisation for the sub-processors listed in Annex C. Each is engaged under a written contract imposing obligations no weaker than these, and we remain responsible to you for what they do.

We will give you at least thirty days' notice before adding or replacing one. If you object on reasonable data protection grounds within that period, we will work with you to find a way round it. If we cannot, you may end the affected part of the service on written notice, and that is the remedy for an objection.

7. Helping you answer your customers

Where one of your customers exercises a right, the request comes to you and Pruvyo helps you answer it. The product is built so that you can do most of it yourself: a customer's record, their payments, their documents and every decision taken about them are together and exportable.

If a request reaches us directly we will not answer it. We will pass it to you and tell the person we have done so.

8. Breaches, and assessments

If we become aware of a personal data breach affecting your data we will tell you without undue delay, with what we know and what we are doing, so that your own notification clock can start. We will keep telling you as we learn more.

We will give you the information you reasonably need for a data protection impact assessment or a consultation with your supervisory authority.

Where the help you ask for under this clause or clause 7 goes well beyond what the service already provides, we may charge our reasonable costs, agreed with you first.

9. Return and deletion

At the end of the relationship you choose: your data back, or deleted. We will do it within ninety days of being asked, and certify it if you ask us to.

Where anti money laundering law obliges either of us to keep something for a fixed period, that period is honoured and nothing beyond it is kept, and what is kept stays subject to this agreement.

10. Audit

We will make available the information needed to show these obligations are met, and allow an audit by you or an independent auditor you appoint.

An audit takes place once in any twelve months, on thirty days' written notice, during working hours, at your cost, under confidentiality, and without access to another customer's data or to anything that would weaken the security of the service. There is no limit where your regulator requires more, or after a breach affecting your data.

11. International transfers

The database, its file storage and the application all run inside the European Union, and the sub-processors in Annex C are engaged on that basis.

The people who support the service reach that data from the United Kingdom, which the European Commission has decided offers an adequate level of protection. If that decision lapses or is annulled, the standard contractual clauses apply to those transfers from that moment, and we will tell you.

12. Liability

Liability under this agreement is subject to the exclusions and the limit in the terms between us, and the two are one aggregate limit rather than one each.

Nothing here limits what either of us owes a data subject or a supervisory authority under the GDPR itself.

Annex A · What is held

  • Customer records: name, reference, type, country, risk rating, verification state, onboarding date and expected activity.
  • Payments: amount, currency, direction, date, counterparty, and the account or wallet on each side.
  • Wallets and accounts belonging to your customers, and the screening results attached to them.
  • Alerts, the rule run behind each one including what the rule could not measure, cases, and every decision with the name of the person and the time.
  • Documents an analyst attaches to a case, and what the checks made of them.
  • Your own people: name, email address, role, and what they did in the system.

Annex B · Security measures

  • Credentials you give Pruvyo for your own providers are read only, and the product has no code path that instructs a payment. What leaves the system is a verdict.
  • Provider credentials are encrypted before storage. Data is encrypted in transit and at rest.
  • Authority is enforced in the database rather than the interface: an account without the standing to approve is refused by the row it tries to write, so a second signature cannot be skipped by a crafted request.
  • Every address the system is asked to call is checked against private and internal ranges when it is saved and again each time it is used.
  • Uploaded files are checked on content rather than on the name they arrived with.
  • Verification documents stay with your KYC provider and cross into Pruvyo only when an analyst selects one for a case.
  • Retention is enforced by a scheduled job rather than by anybody remembering.
  • Access to production is limited to those who need it, and administrative action is recorded.

Annex C · Sub-processors

Pruvyo engages a small number of suppliers to host the service, to deliver platform email and to assist with reading documents. Each is bound by obligations no weaker than those in this agreement, and each processes inside the European Union.

The current list, naming each supplier, what it does and where it does it, is provided to you before you sign and whenever it changes, on request to info@pruvyo.com. It is not published, because who a firm runs on is not a fact a stranger needs.

Pruvyo Limited, a company registered in England and Wales. Last updated 29 August 2026.

Questions about any of this go to a person.