Note: This is a Data Processing Agreement (DPA) template. This document defines the data processing relationship between LoginMe (as Data Processor) and our customers (as Data Controllers) in accordance with GDPR Article 28 and applicable data protection laws.

Data Processing Agreement (DPA)

Last updated: July 21, 2026

1. Definitions

For the purposes of this Data Processing Agreement (DPA), the following definitions apply:

  • "Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. In this context, the Controller is the customer using LoginMe services.
  • "Processor" means LoginMe, which processes personal data on behalf of the Controller.
  • "Personal Data" means any information relating to an identified or identifiable natural person, including but not limited to user IDs, email addresses, authentication tokens, and profile information.
  • "Processing" means any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
  • "Data Subject" means the natural person whose personal data is processed.
  • "Sub-processor" means any third party engaged by the Processor to process personal data on behalf of the Controller.
  • "GDPR" means the General Data Protection Regulation (EU) 2016/679.
  • "SCCs" means Standard Contractual Clauses for international data transfers.

2. Scope and Subject Matter

This DPA governs the processing of personal data by LoginMe (Processor) on behalf of the Controller in connection with the provision of authentication and Customer Identity and Access Management (CIAM) services.

Subject Matter: The Processor shall process personal data solely for the purpose of providing authentication services, user management, and access control as specified in the main service agreement.

This DPA supplements and forms part of the Terms of Service and any other agreements between the Controller and Processor.

3. Data Processing Activities

3.1 Nature and Purpose of Processing

The Processor processes the following categories of personal data:

  • User identification data (user IDs, email addresses)
  • Authentication credentials (hashed passwords, OAuth tokens)
  • Profile information from OAuth providers (name, email, profile picture)
  • Session and token data (JWT tokens, session identifiers)
  • Organization and account metadata
  • Authentication event logs and audit trails

3.2 Categories of Data Subjects

Personal data relates to the following categories of data subjects:

  • End users who authenticate through the Controller's applications
  • Administrators and organization members using the Controller's account

3.3 Duration of Processing

Personal data will be processed for the duration of the service agreement and in accordance with the Controller's instructions, unless deletion is required earlier by applicable law.

4. Security Measures and Technical Safeguards

The Processor implements the following technical and organizational measures to ensure the security of personal data:

  • Encryption: Data encrypted in transit using TLS/SSL and at rest using industry-standard encryption algorithms
  • Access Controls: Multi-factor authentication, role-based access controls, and principle of least privilege
  • Data Isolation: Multi-tenant architecture with per-organization data isolation and unique JWT secrets
  • Token Security: Secure JWT token generation, management, and validation with per-tenant secrets
  • Network Security: Firewalls, intrusion detection, and DDoS protection
  • Audit Logging: Comprehensive audit trails for all authentication events and data access
  • Security Monitoring: Continuous monitoring, threat detection, and incident response procedures
  • Regular Assessments: Security audits, vulnerability assessments, and penetration testing
  • Compliance Standards: SOC 2 compliance, GDPR compliance measures, and industry best practices

The Processor will maintain and update these security measures as necessary to address evolving threats and maintain compliance with applicable data protection laws.

5. Sub-Processor Disclosures and Approval Process

5.1 Authorized Sub-Processors

The Processor uses the following sub-processors to provide services:

  • OAuth Providers: Google, GitHub, Facebook, Microsoft, Apple (for social authentication services)
  • Cloud Infrastructure: [Cloud Provider Name] (for hosting, storage, and compute services)
  • Email Services: [Email Service Provider] (for transactional and notification emails)
  • Analytics and Monitoring: [Analytics Provider] (for service monitoring and performance analytics)

5.2 Sub-Processor Obligations

The Processor ensures that all sub-processors:

  • Are bound by contractual obligations equivalent to those in this DPA
  • Implement appropriate technical and organizational measures to protect personal data
  • Comply with applicable data protection laws, including GDPR
  • Process personal data only as instructed by the Processor

5.3 Changes to Sub-Processors

The Processor will:

  • Notify the Controller of any intended changes to sub-processors
  • Provide the Controller with reasonable opportunity to object to new sub-processors
  • Maintain an up-to-date list of sub-processors available upon request

If the Controller objects to a new sub-processor and the parties cannot resolve the objection, the Controller may terminate the affected services.

6. Data Breach Notification Procedures

In the event of a personal data breach, the Processor will:

  • Notification Timeline: Notify the Controller without undue delay and, where feasible, within 72 hours after becoming aware of the breach, in accordance with GDPR Article 33
  • Breach Details: Provide information about the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach
  • Ongoing Updates: Provide additional information as it becomes available
  • Assistance: Assist the Controller in meeting its obligations under GDPR Article 33 (notification to supervisory authority) and Article 34 (notification to data subjects)

The Processor will document all personal data breaches, including the facts, effects, and remedial actions taken.

7. Data Transfer Safeguards (Standard Contractual Clauses)

Where personal data is transferred outside the European Economic Area (EEA) or to countries without adequacy decisions, the Processor will ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs): The Processor uses EU-approved Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) for international data transfers
  • Additional Safeguards: Where necessary, additional technical and organizational measures are implemented to ensure an adequate level of data protection
  • Sub-Processor Transfers: All sub-processors engaged in international transfers are bound by equivalent safeguards

The Controller acknowledges that the use of LoginMe services may involve international data transfers and consents to such transfers subject to the safeguards described above.

8. Data Subject Rights and Assistance

The Processor will assist the Controller in responding to requests from data subjects to exercise their rights under GDPR, including:

  • Right of Access: Providing access to personal data processed on behalf of the Controller
  • Right to Rectification: Correcting inaccurate or incomplete personal data
  • Right to Erasure: Deleting personal data upon request (subject to legal retention requirements)
  • Right to Restrict Processing: Limiting processing as requested by data subjects
  • Right to Data Portability: Providing data in a structured, machine-readable format
  • Right to Object: Respecting objections to processing where applicable

The Processor will:

  • Respond to data subject requests forwarded by the Controller
  • Provide technical assistance to enable the Controller to respond to data subject requests
  • Notify the Controller promptly of any data subject requests received directly

The Controller is responsible for verifying the identity of data subjects and making final decisions on data subject requests.

9. Audit Rights and Compliance

The Processor will:

  • Make available to the Controller all information necessary to demonstrate compliance with this DPA and applicable data protection laws
  • Allow and contribute to audits conducted by the Controller or an independent auditor, subject to reasonable notice and confidentiality obligations
  • Provide access to relevant documentation, including security policies, procedures, and audit reports
  • Maintain records of processing activities as required by GDPR Article 30

Audits will be conducted during normal business hours, with reasonable advance notice, and in a manner that does not disrupt the Processor's operations or compromise the security of other customers' data.

10. Termination and Data Return Procedures

Upon termination of the service agreement or upon the Controller's request, the Processor will:

  • Data Return: Return all personal data to the Controller in a structured, commonly used, and machine-readable format, or delete it as instructed by the Controller
  • Deletion: Delete all personal data from the Processor's systems, except where retention is required by applicable law
  • Sub-Processor Deletion: Ensure that all sub-processors delete personal data in accordance with this section
  • Certification: Provide written certification of deletion upon request

Retention Requirements: The Processor may retain personal data if required by applicable law, but will limit processing to what is necessary for compliance purposes.

Data return and deletion will be completed within 30 days of termination or request, unless a different timeline is agreed upon or required by law.

11. Liability and Indemnification

Each party will be liable for any damages caused by its breach of this DPA or applicable data protection laws. The Processor's liability is limited as set forth in the Terms of Service, except where:

  • The Processor has acted outside the Controller's instructions
  • The Processor has failed to comply with its obligations under this DPA
  • Liability cannot be limited under applicable law

The Processor will indemnify the Controller against claims, damages, and expenses arising from the Processor's breach of this DPA or failure to comply with applicable data protection laws, subject to the limitations set forth in the Terms of Service.

12. Governing Law

This DPA is governed by the laws of [Jurisdiction], without regard to conflict of law principles. However, the parties acknowledge that data protection laws of the jurisdiction where the Controller is established or where data subjects are located may also apply.

Any disputes arising from this DPA will be resolved in accordance with the dispute resolution provisions of the Terms of Service.

13. Contact Information

For questions about this DPA or data processing activities, please contact:

Data Protection Officer / Privacy Contact:

Email: authlessclient@gmail.com

Website: Contact Us

Important Note

This DPA template is provided for informational purposes. For enterprise customers or customers requiring a signed DPA, please contact us to execute a formal Data Processing Agreement.

By using LoginMe services, you acknowledge that LoginMe acts as a Data Processor on your behalf, and you agree to the data processing terms outlined in this DPA and our Terms of Service.