The contracting entity
The OnyxOne service is operated under the laws of England & Wales. The contracting entity's registered particulars (name, company number and registered office) are being finalised and are shown as placeholders below; the current details are available on request at hello@onyxone.co. This does not affect the operative terms set out in this document.
1. Roles & scope
For personal data processed on the Controller's behalf, the Controller is the controller and OnyxOne is the processor. OnyxOne processes such personal data only on the Controller's documented instructions, including as set out in the Terms and this DPA, unless required otherwise by law.
2. Subject matter & duration
- Subject matter: provision of the OnyxOne Service.
- Duration: for the term of the Terms and until deletion or return of the personal data.
- Nature & purpose: hosting, authentication, account and compliance operations necessary to deliver the Service.
- Data subjects: the Controller's end users and authorised personnel.
- Categories: identifiers, wallet addresses, contact data and, where applicable, KYC identity data.
3. Processor obligations
- Process personal data only on documented instructions.
- Ensure personnel authorised to process are bound by confidentiality.
- Implement appropriate technical and organisational security measures (Article 32).
- Assist the Controller with data-subject requests and with its security, breach-notification and impact-assessment obligations.
- Make available information necessary to demonstrate compliance.
4. Security measures
- Encryption in transit and at rest.
- Strict role-based access control and server-side-only secret handling.
- Single-use authentication nonces and signed, hardened sessions.
- Logging, monitoring and a documented incident-response process.
5. Sub-processors
The Controller authorises the use of the sub-processors listed in our Privacy Policy. We impose data-protection obligations on each sub-processor no less protective than this DPA, and remain liable for their performance. We will give notice of intended changes and a chance to object.
6. Personal data breach
We notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, with the information needed for the Controller to meet its own notification duties.
7. Audits
We make available information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, conducted by the Controller or an appointed auditor, subject to reasonable confidentiality and security safeguards.
8. International transfers
Where processing involves transfers outside the UK/EEA, we rely on an appropriate transfer mechanism (adequacy, UK IDTA or Standard Contractual Clauses) with supplementary measures where required.
9. Deletion or return
On termination, we delete or return the Controller's personal data at the Controller's choice, save where retention is required by law (e.g. AML records).