Trust CenterFor business customers whose users we process on their behalf

Data Processing Agreement

This Data Processing Agreement (“DPA”) applies where OnyxOne processes personal data on behalf of a business customer (the “Controller”) as a processor. It forms part of the Terms of Service between the Controller and OnyxOne.

Last updated · 22 July 2026

The contracting entity

The OnyxOne service is operated under the laws of England & Wales. The contracting entity's registered particulars (name, company number and registered office) are being finalised and are shown as placeholders below; the current details are available on request at hello@onyxone.co. This does not affect the operative terms set out in this document.

1. Roles & scope

For personal data processed on the Controller's behalf, the Controller is the controller and OnyxOne is the processor. OnyxOne processes such personal data only on the Controller's documented instructions, including as set out in the Terms and this DPA, unless required otherwise by law.

2. Subject matter & duration

  • Subject matter: provision of the OnyxOne Service.
  • Duration: for the term of the Terms and until deletion or return of the personal data.
  • Nature & purpose: hosting, authentication, account and compliance operations necessary to deliver the Service.
  • Data subjects: the Controller's end users and authorised personnel.
  • Categories: identifiers, wallet addresses, contact data and, where applicable, KYC identity data.

3. Processor obligations

  • Process personal data only on documented instructions.
  • Ensure personnel authorised to process are bound by confidentiality.
  • Implement appropriate technical and organisational security measures (Article 32).
  • Assist the Controller with data-subject requests and with its security, breach-notification and impact-assessment obligations.
  • Make available information necessary to demonstrate compliance.

4. Security measures

  • Encryption in transit and at rest.
  • Strict role-based access control and server-side-only secret handling.
  • Single-use authentication nonces and signed, hardened sessions.
  • Logging, monitoring and a documented incident-response process.

5. Sub-processors

The Controller authorises the use of the sub-processors listed in our Privacy Policy. We impose data-protection obligations on each sub-processor no less protective than this DPA, and remain liable for their performance. We will give notice of intended changes and a chance to object.

6. Personal data breach

We notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, with the information needed for the Controller to meet its own notification duties.

7. Audits

We make available information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, conducted by the Controller or an appointed auditor, subject to reasonable confidentiality and security safeguards.

8. International transfers

Where processing involves transfers outside the UK/EEA, we rely on an appropriate transfer mechanism (adequacy, UK IDTA or Standard Contractual Clauses) with supplementary measures where required.

9. Deletion or return

On termination, we delete or return the Controller's personal data at the Controller's choice, save where retention is required by law (e.g. AML records).