Data Processing Agreement

Version 1.0.0 (Draft) · Effective Date: April 25, 2026

Note: This Data Processing Agreement (“DPA”) is a working version pending outside-counsel review. It is structured to align with Article 28 of the EU/UK General Data Protection Regulation, the Singapore Personal Data Protection Act 2012, and applicable regulatory guidance on processing personal data through blockchain technology. This DPA is incorporated by reference into the UTXOS Terms of Service and any applicable Services Agreement between UTXOS and Customer.

1. Definitions

Capitalized terms not defined here have the meanings given in the GDPR. “Personal Data”, “Controller”, “Processor”, “Data Subject”, “Processing”, and “Personal Data Breach” have the meanings given in Article 4 GDPR.

2. Roles and Scope

For Personal Data that Customer or its End Users provide to or generate within the Services, Customer is the Controller and UTXOS is the Processor. UTXOS will process such Personal Data solely to provide the Services in accordance with the Services Agreement and Customer’s documented instructions.

3. Processing on Documented Instructions

UTXOS will process Personal Data only on documented instructions from Customer, including with regard to transfers of Personal Data to a third country, unless required to do so by Singapore law, EU law, or other applicable law to which UTXOS is subject. In such a case, UTXOS will inform Customer of the legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

4. Confidentiality of Personnel

UTXOS ensures that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5. Security Measures

UTXOS implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as set out in Annex 2 below.

6. Sub-processors

Customer provides general authorisation for UTXOS to engage Sub-processors to assist in providing the Services, subject to the conditions of this Section. UTXOS maintains a current list of Sub-processors at utxos.dev/subprocessors and will notify Customer at least fourteen (14) days before adding or replacing a Sub-processor. Customer may object on reasonable data-protection grounds within the notice period, in which case the parties will work in good faith to resolve the objection. UTXOS will impose on each Sub-processor data-protection obligations no less protective than those in this DPA.

7. Data Subject Rights Assistance

Taking into account the nature of the processing, UTXOS will assist Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling Customer’s obligations to respond to Data Subject requests under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making).

8. Personal Data Breach Notification

UTXOS will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notification will include, to the extent known: the nature of the Breach, categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed to address the Breach and mitigate possible adverse effects.

9. Data Protection Impact Assessment Assistance

UTXOS will provide reasonable assistance to Customer with any data protection impact assessments and prior consultations with supervisory authorities required under Articles 35 and 36 GDPR, taking into account the nature of the processing and the information available to UTXOS.

10. International Transfers

UTXOS Pte. Ltd. is incorporated in Singapore. Where Customer transfers Personal Data of EEA or UK Data Subjects to UTXOS, the parties agree that the EU Standard Contractual Clauses (Module 2, Controller-to-Processor) set out in Commission Implementing Decision (EU) 2021/914 are incorporated by reference into this DPA, with the module selections and annexes set out in Annex 3. For Singapore PDPA Section 26 purposes, UTXOS ensures that Sub-processors are bound to standards comparable to the PDPA Data Protection Provisions.

11. Audits

UTXOS will make available to Customer all information necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by Customer or another auditor mandated by Customer, on the following proportionate terms:

  • UTXOS will, on Customer’s reasonable written request (no more than once per twelve-month period absent regulator order), provide a written attestation of compliance with this DPA and respond to Customer’s reasonable security questionnaire
  • Where a third-party security assessment has been conducted, UTXOS will, on request and under non-disclosure, provide an executive summary
  • On-site audits may be conducted only on material cause, with at least thirty (30) days’ written notice, during normal business hours, by an auditor not in competition with UTXOS, under non-disclosure, and at Customer’s cost

12. Return or Deletion on Termination

Upon termination of the Services Agreement, UTXOS will, at Customer’s option, return or delete all Customer Personal Data within thirty (30) days, and will delete existing copies unless applicable law requires retention. UTXOS will provide written certification of deletion on request.

This obligation does not extend to Personal Data that has been committed to a public blockchain as part of the Services, which is by design immutable. UTXOS will, however, delete any off-chain linking data (including OAuth identifiers, email addresses, and wallet-address mappings) such that the on-chain data is no longer attributable to an identified or identifiable natural person, consistent with applicable regulatory guidance.

13. Liability, Term, Governing Law, and Notices

This DPA forms part of the Services Agreement and is subject to the liability, term, governing law, and notice provisions of the Services Agreement and the UTXOS Terms of Service. The EU Standard Contractual Clauses incorporated by reference under Section 10 are governed by the law of the EEA member state agreed in Annex 3, as required by Clause 17 of those Clauses.

Annex 1 — Processing Details

FieldDetail
ControllerThe Customer (as identified in the Services Agreement)
ProcessorUTXOS Pte. Ltd. (UEN 202542261H), Singapore
Subject matterWallet-as-a-Service (social-login wallet creation) and Transaction Sponsorship (Cardano transaction fee sponsoring)
DurationTerm of the Services Agreement
Nature and purpose(a) Creating and managing non-custodial Cardano wallets; (b) Co-signing sponsored Cardano transactions on behalf of Customer’s End Users
Personal data categoriesOAuth provider user ID (Google sub, Apple sub, Discord ID, Twitter/X ID); email address from OAuth profile; Cardano wallet public address; transaction hashes and timestamps; usage logs (request metadata, IP address, timestamps)
Data subject categoriesEnd Users of Customer’s platform who authenticate via OAuth or use sponsored transactions
Sub-processorsPublished at utxos.dev/subprocessors
Transfer mechanismEU SCCs Module 2 (Controller-to-Processor), incorporated by reference (see Annex 3)
RetentionDuration of the Services Agreement plus thirty (30) days after termination (off-chain); on-chain data per Section 12

Annex 2 — Technical and Organisational Measures

  • Key management: appropriate cryptographic protections for wallet-key material
  • Encryption at rest: user data and developer-controlled wallet private keys encrypted at rest
  • Access controls: role-based access to administrative systems; audit logging on administrative access
  • Backup and disaster recovery: documented backup and disaster recovery plan with defined recovery objectives
  • Incident response: documented incident response procedures, including the breach notification commitment in Section 8 of this DPA
  • Security assessment: where a third-party security assessment has been conducted, an executive summary is made available to Customers under non-disclosure
  • Privacy by design: sensitive payloads kept off-chain; only references and hashes committed on-chain
  • Personnel: confidentiality obligations under written agreement

Annex 3 — EU Standard Contractual Clauses

The EU Commission Decision (EU) 2021/914 Standard Contractual Clauses are incorporated by reference, with the following selections:

  • Module 2 (Controller to Processor) selected
  • Docking clause (Clause 7): enabled
  • Sub-processor clause (Clause 9): Option 2 (general authorisation), with at least fourteen (14) days’ prior notice
  • Liability (Clause 12): as set out in the Clauses
  • Governing law (Clause 17): the law of the EEA member state of Customer’s establishment, or as otherwise agreed in writing between the parties
  • Forum (Clause 18): the courts of the EEA member state agreed under Clause 17
  • Annex I.A — parties: as identified in the Services Agreement
  • Annex I.B — description of transfer: as set out in Annex 1 above
  • Annex I.C — competent supervisory authority: the supervisory authority of the EEA member state of Customer’s establishment
  • Annex II — technical and organisational measures: as set out in Annex 2 above
  • Annex III — sub-processors: as published at utxos.dev/subprocessors

Revision History

VersionDateChange
1.0.0 (Draft)2026-04-25Initial publication, pending outside-counsel review