Data Processing Agreement
How Onetela processes personal data on behalf of customers when providing the platform.
When you use the Onetela platform to verify identities, run compliance workflows, issue credentials, or operate surveillance and security capabilities, we often process personal data on your behalf. This page summarises our standard Data Processing Agreement (“DPA”), which implements UK GDPR Article 28 and forms part of your customer contract unless otherwise agreed in writing.
For a countersigned copy tailored to your organisation, contact legal@onetela.io.
1. Roles
You are the controller for personal data you submit or cause to be processed through the services. Onetela acts as processor, processing that data only on your documented instructions as set out in the agreement, this DPA, and your configuration of the platform.
2. Subject matter and duration
Processing supports delivery of agreed services — for example identity verification, screening, credential lifecycle, video analytics, alerts, audit logs, and related support. Processing continues for the term of your subscription or project, plus any agreed wind-down or retention period for export and deletion.
3. Types of data and data subjects
Depending on your use cases, this may include:
- identity and contact details, document images, biometric references, and verification outcomes;
- compliance screening results, case notes, and transaction or behaviour signals you choose to analyse;
- workforce or customer credential metadata and presentation records;
- video-derived events, zone alerts, and detection metadata from cameras you connect;
- administrator and operator account data for your authorised users.
Data subjects may include your customers, employees, contractors, visitors, and other individuals whose data you process through the platform. You are responsible for lawful collection and for providing appropriate notices and consents.
4. Processor obligations
We will:
- process personal data only on your instructions, unless law requires otherwise (and we will inform you where permitted);
- ensure personnel with access are bound by confidentiality;
- implement appropriate technical and organisational security measures;
- assist with data subject requests and with security, breach notification, DPIAs, and regulator consultation where applicable;
- notify you without undue delay of personal data breaches affecting your data;
- support audits and provide information reasonably required to demonstrate compliance, subject to confidentiality and scheduling limits in the full DPA.
5. Sub-processors
We may use sub-processors for infrastructure, communications, monitoring, and specialised processing. We maintain a list available on request and will provide notice of material changes where required by your agreement. Sub-processors are bound by written terms offering protection substantially equivalent to this DPA.
6. International transfers
We design services to meet your agreed data residency and transfer requirements. Where personal data is transferred outside the UK or EEA, we use appropriate safeguards such as adequacy regulations, the UK International Data Transfer Agreement, or other mechanisms recognised under applicable law.
7. Deletion and return
On termination or expiry, you may export your data using platform tools where available. Following your instructions, we will delete or return personal data within the timeframe in your contract, except where retention is required by law or encrypted backups are deleted on their normal rotation cycle.
8. Liability and governing law
Liability under the DPA is subject to the limitations in your master agreement. The DPA is governed by the law specified in that agreement, defaulting to England and Wales where not stated.
Annex — illustrative security measures
| Area | Measures (summary) |
|---|---|
| Access control | Role-based access, authentication, and logging for administrative and customer tenant access. |
| Encryption | Encryption in transit; encryption at rest where applicable to the service tier. |
| Monitoring | Security monitoring, alerting, and incident response procedures. |
| Resilience | Backup, recovery, and business continuity aligned to service commitments. |
| Personnel | Background checks where appropriate, training, and confidentiality obligations. |
Summary last updated: 31 July 2026.