Skip to content
idleakcheck
LEGAL, DATA PROCESSING ADDENDUM

Data Processing Addendum (Overview)

LAST UPDATED, 17 / 05 / 2026

This page provides an overview of the data-processing relationship between IDLeakCheck and our enterprise customers when IDLeakCheck processes personal data on behalf of an enterprise (e.g. when an enterprise workspace submits searches or uploads subject lists). It is intended for enterprise data-protection officers, privacy counsel, and security reviewers.

For a fully executable Data Processing Addendum that can be countersigned, contact legal@idleakcheck.com. The executable DPA tracks this overview substantively and adds standard contractual clauses (SCCs) for international transfers, audit rights, and termination procedures.

01

Parties and roles

When an enterprise customer uses the Service, the enterprise is the data controller (or business under CCPA) for personal data it submits through the Service, and IDLeakCheck is the data processor (or service provider under CCPA) for that data. Personal data that IDLeakCheck independently collects from public sources is processed under IDLeakCheck’s own Privacy Policy as data controller.

02

Subject matter and duration

IDLeakCheck processes personal data submitted by the enterprise for the duration of the enterprise’s subscription and for a defined return-or-deletion period after termination (see § 10).

03

Nature and purpose

Processing is limited to providing the Service to the enterprise: receiving search inputs, returning search results, returning profile reports, supporting API access, generating audit logs, and providing customer support.

04

Categories of personal data

Categories submitted by enterprise customers typically include: identifiers (name, email, account ID, IP address), subject identifiers (name, address, telephone, date of birth), and any additional identifiers the enterprise chooses to submit through the API.

05

Categories of data subjects

Categories include: the enterprise’s own personnel using the Service, the enterprise’s own customers, and individuals who are the subject of the enterprise’s search activity.

06

Sub-processors

IDLeakCheck’s current sub-processors are listed at /legal/subprocessors. We provide at least 30 days’ advance notice of any addition or change. Sub-processors are bound by data-protection obligations no less protective than this DPA.

07

Technical and organisational measures

IDLeakCheck maintains technical and organisational measures to protect personal data, including: encryption in transit (TLS 1.2+), encryption of payload envelopes (AES-256-GCM) for browser-facing endpoints, encryption of database backups, role-based access controls with mandatory two-factor authentication for personnel access, audit logging of all personnel access to customer data, network isolation, vendor-vetted hosting (see /legal/subprocessors), and an incident response programme.

08

Data subject rights assistance

IDLeakCheck will reasonably assist the enterprise in responding to data-subject requests (access, deletion, correction, restriction, portability, objection) where the requested information is within IDLeakCheck’s control as processor. Standard assistance is provided at no additional charge; bespoke engineering work may be quoted separately.

09

Breach notification

IDLeakCheck will notify the enterprise without undue delay, and in any event within 72 hours of becoming aware, of any personal-data breach affecting personal data processed on the enterprise’s behalf. Notification will include the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed.

10

Return or deletion on termination

On termination of the enterprise’s subscription, IDLeakCheck will, at the enterprise’s choice and within 30 days of written request, either (a) return all personal data processed on behalf of the enterprise in a commonly used machine-readable format, or (b) delete all such personal data. Audit logs and backups retained for security or legal compliance are exempt and will be deleted in accordance with our standard retention schedule.

11

International transfers

Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a jurisdiction not recognised as providing adequate protection, the transfer is governed by the European Commission’s Standard Contractual Clauses (2021/914) Module 2 (controller-to-processor), the UK International Data Transfer Addendum, or the Swiss FDPIC-approved version, as applicable. These clauses are incorporated by reference into the executable DPA.

12

Audit rights

IDLeakCheck will provide reasonable cooperation with the enterprise’s audit and inspection rights under applicable data-protection law. In lieu of an on-site audit, IDLeakCheck may provide third-party audit reports (SOC 2 Type II once available) and written responses to security questionnaires. Audit requests must be submitted with at least 30 days’ notice except in connection with a regulatory investigation or actual breach.

13

Liability

Liability under this DPA tracks the limitation of liability set out in the enterprise’s Service Agreement.

14

Governing law

This DPA is governed by the same law and dispute-resolution provisions as the enterprise’s Service Agreement (typically the laws of the State of Delaware and the dispute-resolution provisions of our Terms of Service § 15).

15

Contact

  • To request the executable DPA: legal@idleakcheck.com
  • Data Protection Officer (DPO): dpo@idleakcheck.com