Skip to content
AttestLayer

AttestLayer Policy

Enterprise DPA Information

Buying a Buyer Review Pack? The click-to-accept Direct-Client DPA is here → https://buy.attestlayer.com/dpa. This page explains when AttestLayer enters into a data processing addendum for an applicable signed service engagement.

attestlayer.com is the corporate and trust site. Direct-client, partner, Console, Verify, Registry, and API tasks use their dedicated domains.
Updated 25 September 2026 Canonical root-domain policy

Scope

This page is a public summary, not a signed contract. When a service engagement requires AttestLayer to process personal data on documented instructions, the parties may execute an applicable DPA. The direct-client DPA page explains the direct Buyer Review Pack path.

The executed addendum for an engagement is authoritative and defines its covered service, data categories, instructions, security obligations, subprocessors, transfer terms, and incident-notification commitments.

Roles

Where AttestLayer processes customer personal data solely on documented instructions under a covered service, AttestLayer acts as processor and the customer acts as controller, unless applicable law assigns different roles. AttestLayer acts as controller for root-site usage, correspondence, billing administration, and security data processed for its own purposes.

A DPA does not independently create an order, activate a service, or expand the data authorized by the applicable order or agreement.

Subprocessors and international transfers

AttestLayer's current subprocessors are listed on the Subprocessors page. Material updates are reflected there. Where required, personal information is communicated outside Quebec only after the applicable privacy impact assessment concludes that adequate protection is available and a written agreement records the safeguards and other required measures. A signed addendum identifies the mechanisms applicable to that engagement; this public summary is not evidence that a particular assessment or agreement has been completed.

Security and incident notification

Operational security posture is summarized on the Security page. The signed addendum sets the incident-notification timing for processor scenarios.

How to request

To request a DPA in the context of a procurement or signed engagement, email contact@attestlayer.com. AttestLayer does not provide a unilateral signed DPA outside a defined engagement.

Record-only boundary

Standard AttestLayer workflows are designed around records the customer is authorized to provide without endpoint installation or production credentials. Package verification can establish integrity and issuer-receipt authenticity; it does not establish the truth or completeness of supplied records, control effectiveness, compliance, certification, legal sufficiency, or customer approval.