Scope
This page is a public summary, not a signed contract. When a service engagement requires AttestLayer to process personal data on documented instructions, the parties may execute an applicable DPA. The direct-client DPA page explains the direct Buyer Review Pack path.
The executed addendum for an engagement is authoritative and defines its covered service, data categories, instructions, security obligations, subprocessors, transfer terms, and incident-notification commitments.
Roles
Where AttestLayer processes customer personal data solely on documented instructions under a covered service, AttestLayer acts as processor and the customer acts as controller, unless applicable law assigns different roles. AttestLayer acts as controller for root-site usage, correspondence, billing administration, and security data processed for its own purposes.
A DPA does not independently create an order, activate a service, or expand the data authorized by the applicable order or agreement.
Subprocessors and international transfers
AttestLayer's current subprocessors are listed on the Subprocessors page. Material updates are reflected there. Where required, personal information is communicated outside Quebec only after the applicable privacy impact assessment concludes that adequate protection is available and a written agreement records the safeguards and other required measures. A signed addendum identifies the mechanisms applicable to that engagement; this public summary is not evidence that a particular assessment or agreement has been completed.
Security and incident notification
Operational security posture is summarized on the Security page. The signed addendum sets the incident-notification timing for processor scenarios.
Record-only boundary
Standard AttestLayer workflows are designed around records the customer is authorized to provide without endpoint installation or production credentials. Package verification can establish integrity and issuer-receipt authenticity; it does not establish the truth or completeness of supplied records, control effectiveness, compliance, certification, legal sufficiency, or customer approval.