Legal
Data Processing Agreement
1. Purpose and Scope of this DPA
This Data Processing Agreement ("DPA") governs the processing of Personal Data by Miguel Casares Robles, sole trader (autonomo), operating sanctionlistcheck.com, with registered address Horno de Haza, 34 2A, 18002 Granada, Spain (the "Processor"), on behalf of the customer ("Controller"). This DPA forms an integral part of the Terms of Service agreed between the Controller and the Processor for the use of sanctionlistcheck.com's services, and applies where the Processor processes Personal Data as a processor on behalf of the Controller, pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and any applicable national implementing laws.
The purpose of this DPA is to ensure compliance with the requirements of applicable data protection laws, including the GDPR, in relation to the processing of Personal Data.
2. Subject Matter, Duration, and Nature of Processing
The Subject Matter of the processing under this DPA is the screening of Controller-submitted name lists (including company or individual names, and optionally country and date-of-birth context fields) against public, official sanctions and denied-party lists (such as OFAC SDN, US Consolidated Screening List, EU Consolidated Sanctions List, UK Sanctions List, and UN Security Council Consolidated List).
The Nature of the processing involves the Controller uploading a CSV or XLSX file, or typing one name for a free single-name check. The sanctionlistcheck.com service normalizes and fuzzy-matches each name against snapshots of official sanctions lists. A CSV, JSON, and PDF report is then generated based on the screening results.
The Duration of processing for a batch screening job lasts the length of that job. Uploaded files and generated reports are stored temporarily in Cloudflare R2 (location hint EEUR) and are deleted automatically no later than 24 hours after upload. Where the Controller uses the API, API screening records, including screened names, hits, and list versions used, are kept for 90 days by default. The Controller can set the retention period from 1 to 365 days per API key, can delete any single record or the whole key with its records at any time, and can export the records. No customer data is used to train any Artificial Intelligence (AI) model, and no AI or Large Language Model (LLM) is used to process, read, or make judgments about the Controller's uploaded data at any point.
3. Categories of Data Subjects and Personal Data
The Categories of Data Subjects whose Personal Data may be processed under this DPA are typically the individuals or company representatives named in the Controller's uploaded list. These individuals are generally the Controller's own counterparties, such as suppliers, customers, or business partners.
The Categories of Personal Data processed are: name, and optionally country and date of birth, as submitted by the Controller. The Processor does not knowingly process any special categories of data, as defined in Article 9 of the GDPR.
Personal Data may also be processed in the form of identifiers that a sanctioning authority publishes alongside a designation and that the Processor reproduces in the screening report. These can include national register numbers and personal identification numbers (for example PESEL, KRS, NIP, REGON, DUNS) and tax or vessel identification numbers (for example IMO). This data originates from the official public sanctions lists, not from the Controller's upload, and the Processor does not use it to determine a match.
4. Processor Obligations
The Processor shall:
- Process the Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by Union or Member State law to which the Processor is subject. In such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
- Ensure that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:
- Encryption: Data in transit is encrypted using Transport Layer Security (TLS).
- Data Storage: Stored data, including uploaded files, generated reports, and API screening records, is placed in Cloudflare's Eastern Europe region (location hint EEUR) for Cloudflare D1 and Cloudflare R2. Requests may be processed at Cloudflare's global edge network, and no legal EU-jurisdiction pinning is applied.
- Retention Policy: Uploaded files and generated reports are deleted automatically no later than 24 hours after upload. API screening records are kept for 90 days by default, with the Controller able to set the retention period from 1 to 365 days per API key.
- Advertising/Tracking: No third-party advertising or tracking cookies are used within the product.
- Take all measures required pursuant to Article 32 of the GDPR.
- Assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR, taking into account the nature of processing and the information available to the Processor.
- At the choice of the Controller, delete or return all the Personal Data to the Controller after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage of the Personal Data. (Note: for job-specific data, automatic deletion occurs within 24 hours as described in Section 7).
- Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. The Processor shall inform the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.
5. Sub-processors
The Controller provides general authorisation for the Processor to engage sub-processors. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of other sub-processors, thereby giving the Controller the opportunity to object to such changes.
The Processor currently engages the following sub-processors:
- Cloudflare: Cloudflare provides hosting, storage (R2), database (D1), and compute services. Stored data uses the Eastern Europe location hint EEUR; requests may be processed at Cloudflare's global edge network, and no legal EU-jurisdiction pinning is applied.
- Resend: Resend provides transactional email delivery for sign-in links, job notifications, alerts, and API key delivery emails; its location is EU or US.
- Hetzner: Hetzner Online GmbH (Germany) provides hosting of the name-matching engine on a server in Helsinki, Finland; normally, the service sends the screened names and the fields sent for matching (country, date of birth and entity type, where given) to that server, which processes them in memory only for the duration of the request and does not write screened names to disk or to its logs. If that server is not available or returns an error, or if we switch it off, the matching runs in Cloudflare's network instead, which can be outside the EU.
Where a sub-processor carries out specific processing activities on behalf of the Processor, the Processor shall ensure that the same data protection obligations as set out in this DPA shall be imposed on that sub-processor by way of a contract or other legal act under Union or Member State law, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of the GDPR.
Paddle (Merchant of Record): Paddle acts as the Merchant of Record for paid purchases, handling payment processing, tax collection, and invoice issuance. The contracting entity is Paddle.com Market Limited, England and Wales, company no. 8172165, registered office 30 Old Bailey, London EC4M 7AU, or the regional Paddle entity named on the Controller's invoice (Paddle.com Inc. in the United States; Paddle.com (Canada) Ltd in Canada). Paddle acts as an independent controller for the payment, tax and invoicing data it collects, under the Paddle Privacy Notice.
6. Data Subject Rights Assistance
Taking into account the nature of the processing, the Processor will reasonably assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III of the GDPR (including rights of access, rectification, erasure, restriction of processing, data portability, and objection). The Processor shall notify the Controller without undue delay if it receives a request from a data subject concerning the Personal Data processed on the Controller's behalf.
7. Data Deletion and Retention
Upon termination of the Controller's use of the services, uploaded batch job files and generated reports are automatically deleted under the 24-hour retention period described in Section 2, requiring no separate manual deletion request for such job data. Where the Controller utilises the API, API screening records are retained for the retention period configured per API key, which is 90 days by default and configurable from 1 to 365 days. The Controller may export these records and delete any individual record or the entire key, along with its associated records, at any time. For account-level deletion requests, the Controller may contact support.
8. International Transfers
Stored data for Cloudflare D1 and Cloudflare R2 is placed in Cloudflare's Eastern Europe region (location hint EEUR). Cloudflare may process requests at its global edge network, which can be outside the EU. No legal EU-jurisdiction pinning is applied, as a location hint is a placement preference, not a legal jurisdiction restriction. The sub-processor Hetzner Online GmbH processes screened names on a server in Helsinki, Finland, which is inside the EU, so that processing is not a transfer to a third country; if that server is not available or returns an error, or if we switch it off, the matching runs in Cloudflare's network instead, which can be outside the EU. The sub-processor Resend processes email data, including sign-in links, job notifications, alerts, and API key delivery emails, in the EU or US.
9. Liability
Liability under this DPA shall be subject to the same caps and limitations as stated in the Terms of Service between the Controller and the Processor. In no event shall the Processor's total aggregate liability under this DPA exceed the fees actually paid by the Controller to the Processor during the preceding twelve (12) months.
The Controller acknowledges that sanctionlistcheck.com is provided as a due-diligence aid, and is never intended to be a compliance certification or legal advice. The product does not, at any point, state that a match is 'safe' or 'clear', nor does it provide legal opinions on screening results.
10. Governing Law
This DPA shall be governed by and construed in accordance with the laws of Spain.
11. Contact
For any matters related to privacy, data protection, or this Data Processing Agreement, the Controller may contact the Processor at: [email protected].