DLBR / LEGAL

DATA PROCESSING AGREEMENT

Last updated: 11 October 2026

This Data Processing Agreement ("DPA") sets out how DALIBOR GOGIC PR DLBR ("DLBR") processes personal data for a business customer ("Customer") when providing DLBR EID verification services. DLBR's registered address is Laze Kostića 16, 22320 Inđija, Serbia (registration number 66796060; tax identification number 113398540). Privacy contact: privacy@dlbr.app. It is intended to meet the processor-contract requirements of applicable data protection law, including Article 28 GDPR where it applies.

1. When this DPA applies

This DPA applies only to personal data that DLBR processes on Customer's documented instructions to provide DLBR EID ("Customer Data"). For verification transactions, Customer decides why and how a person is verified and is the controller; DLBR processes the verification data as processor. If Customer is itself a processor, Customer must have authority from the relevant controller to appoint DLBR as a subprocessor and must pass on the relevant instructions.

DLBR acts as an independent controller for its own website, business contacts, account administration, billing, and service security, as described in the Privacy Policy. Those activities are outside this DPA.

This DPA becomes binding when a signed agreement, order form, or other legally binding written record between Customer and DLBR expressly incorporates it. Merely visiting this page does not appoint DLBR as a processor. The DPA version in force is the version identified in that record; later changes apply as allowed by the Customer Agreement or when both parties agree to them.

"Data Protection Laws" means the privacy and data protection laws applicable to the processing, including the GDPR, the UK GDPR, and Serbia's Personal Data Protection Law, as applicable. The Customer Agreement governs commercial matters and liability. If a transfer agreement or standard contractual clauses are separately completed, they govern to the extent of a conflict about that transfer.

2. Customer's instructions and responsibilities

Customer instructs DLBR to process Customer Data as needed to provide the service, as described in the Customer Agreement, Customer's service configuration, and further documented instructions agreed by the parties. DLBR will process Customer Data only on those instructions, including for international transfers, unless a law binding on DLBR requires other processing. Where permitted, DLBR will tell Customer about that legal requirement before processing.

Customer is responsible for the lawfulness of its instructions, its legal basis, privacy notices to individuals, the data it chooses to request, and the accuracy and scope of the configured verification. Customer must not instruct DLBR to process data in a way that violates Data Protection Laws. DLBR will inform Customer if, in its reasonable opinion, an instruction infringes those laws.

3. DLBR's processor obligations

DLBR will:

  • process Customer Data only on documented instructions and for the purposes in this DPA;
  • ensure that people authorised to process Customer Data are bound by confidentiality obligations and receive access only as needed for their work;
  • implement and maintain the security measures in Schedule 2, taking account of the nature of the processing and the risks to individuals;
  • assist Customer, taking account of the processing and information available to DLBR, with requests from individuals and with Customer's duties concerning security, personal data breaches, impact assessments, and consultation with a regulator;
  • notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, provide information reasonably available to DLBR, and cooperate with Customer's response;
  • make available information reasonably necessary to demonstrate compliance with this DPA and support audits as described below; and
  • at the end of the services, delete or return Customer Data as described in section 7.

DLBR will not use Customer Data for advertising, create advertising profiles from it, or decide whether an individual qualifies for Customer's product or service. DLBR may use information that has been irreversibly anonymised so it no longer relates to an identifiable person.

4. Subprocessors

Customer gives DLBR general written authorisation to use the subprocessor listed in Schedule 3. DLBR will impose data protection obligations on each subprocessor that protect Customer Data to the standard required by this DPA and remains responsible to Customer for the subprocessor's performance of those obligations.

DLBR will give Customer at least 30 days' notice before adding or replacing a subprocessor, by email or another agreed service notice. Customer may object in writing within that period on reasonable, documented data protection grounds. The parties will work in good faith to address the objection. If they cannot resolve it before the change takes effect, Customer may terminate the affected service before the new subprocessor processes Customer Data.

5. Individual requests and compliance assistance

If DLBR receives a request from an individual about Customer Data, DLBR will direct the individual to Customer where appropriate and promptly notify Customer, unless law prohibits that notice. DLBR will not respond on Customer's behalf or disclose Customer Data except on Customer's instructions or as required by law.

Taking account of the processing and information available to DLBR, DLBR will provide reasonable assistance so Customer can respond to requests and meet its obligations under Data Protection Laws, including obligations relating to security, breach notifications, data protection impact assessments, and prior consultation. Customer remains responsible for deciding how to respond and for notifying regulators or individuals where required.

6. Security incidents

DLBR will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data. The notice will describe, to the extent then known, the nature of the breach, the affected data and individuals, likely consequences, containment or mitigation steps taken or planned, and a contact for follow-up. DLBR will provide additional information as it becomes available and reasonably assist Customer with its investigation and required notifications. A notice is not an admission of fault or liability.

7. Retention, return, and deletion

Customer Data is processed for the term of the Customer Agreement and according to Customer's documented retention instructions. In the current service configuration, selected claim values and verification details are held in temporary session storage for result delivery and deleted within 30 seconds after the result. A minimal terminal session status and status-only event history may remain after claims and verification details are removed. Verification audit records are stored in the Gateway runtime D1 database, which is configured for Cloudflare's EU jurisdiction; they never contain claim values, but may contain session and client identifiers, statuses, credential and issuer details, diagnostic categories, and timing information. Some idempotency, audit, and webhook-failure metadata has no automatic age-based deletion configured. The applicable retention and deletion terms for these records must be documented in each pilot customer's agreement or retention schedule before production processing.

When the service ends, Customer may instruct DLBR to return exportable Customer Data or delete it. If Customer does not make a choice, DLBR will delete Customer Data, subject to records and retention periods documented in the Customer Agreement or pilot-specific retention schedule. DLBR will also delete Customer Data when Customer instructs it to do so, unless law requires retention. Data in backups may remain until the normal backup cycle replaces it; access remains restricted, and restored data is subject to the same deletion instructions. DLBR may retain records it must keep by law, and will continue to protect them and limit their use to that legal requirement.

8. Records and audits

On request, DLBR will provide information reasonably necessary for Customer to verify compliance with this DPA, including relevant security information and available independent assurance reports. If that information does not reasonably demonstrate compliance, Customer or an independent auditor bound by confidentiality may audit the processing on at least 30 days' written notice, during normal business hours, no more than once in a 12-month period unless a personal data breach or regulator requires an additional audit. Audits must be proportionate, protect other customers' information, avoid unreasonable disruption, and follow reasonable security requirements. Customer bears its audit costs. DLBR will cooperate and promptly address material findings.

9. International transfers

DLBR is established in Serbia. The production configuration selects a Cloudflare Durable Object namespace in Cloudflare's EU jurisdiction for verification sessions and configures the Gateway runtime D1 database for verification audit records in that jurisdiction. These storage settings do not guarantee that Worker request execution or all related processing, logs, traces, queues, analytics, backups, or provider operations stay in the EU. Other service components used to operate DLBR EID may involve processing outside the European Economic Area. DLBR's own controller activities remain outside this DPA, as described in section 1.

Before any transfer of Customer Data that requires a transfer mechanism under Data Protection Laws, Customer and DLBR must identify and document the applicable mechanism and any required supplementary measures in a transfer addendum or other binding transfer record. Where the EU Standard Contractual Clauses are used, the correct module and completed appendices must be agreed for the actual parties, processing, recipients, and transfer. This DPA page does not itself execute or complete those clauses, a transfer impact assessment, or other transfer safeguards. Customer must not instruct a restricted transfer, and DLBR must not carry one out, until the required transfer record is in place.

DLBR will provide information reasonably available to it to help Customer assess the transfer and applicable safeguards. Customer may contact privacy@dlbr.app to request the transfer documentation applicable to its service.

10. Duration and contact

This DPA remains in effect for as long as DLBR processes Customer Data under the Customer Agreement, including any limited processing needed to return or delete that data. Contact privacy@dlbr.app about this DPA or a data protection request.

Schedule 1 — Processing details

  • Subject matter: DLBR's provision of the identity-verification service configured by Customer.
  • Duration: The Customer Agreement term and the limited period needed to return or delete Customer Data afterward.
  • Nature and purpose: Receiving and processing verification requests, carrying out the configured wallet or credential verification flow, returning verification results, delivering configured events or webhooks, and protecting and supporting the service.
  • Data subjects: Individuals whose identity or eligibility Customer asks DLBR EID to verify.
  • Personal data: Session and transaction identifiers; selected identity or credential attributes and proofs submitted in a verification; verification status and results; timestamps; and delivery, diagnostic, and security metadata associated with the transaction. The exact fields depend on Customer's configuration and instructions.
  • Sensitive data: Customer must identify any special-category or criminal-offence data in its documented instructions and may send it only where permitted by law and supported by agreed safeguards.
  • Processing operations: Collection, receipt, validation, transmission, temporary storage, retrieval, use to produce a verification result, disclosure to Customer or its configured endpoint, and deletion.
  • Retention: Selected claims and verification details are deleted within 30 seconds after the result in the current service configuration. Minimal terminal status and status-only event history may remain. Audit and security metadata follows the applicable documented retention schedule.

Schedule 2 — Security measures

DLBR maintains technical and organisational measures appropriate to the service and risk, including:

  • access controls and authentication for systems and administrative functions;
  • tenant separation and access restrictions designed to prevent one Customer from accessing another Customer's data;
  • encryption in transit for service communications;
  • operational audit controls and security monitoring;
  • short-lived verification session storage and deletion or expiry after result delivery; and
  • confidentiality obligations for personnel authorised to access Customer Data.

DLBR may update these measures as technology and risks change, provided the overall level of protection is not materially reduced.

Schedule 3 — Authorised subprocessor

  • Cloudflare, Inc. and relevant Cloudflare group companies: Cloudflare platform infrastructure, including compute, storage, networking, databases, queues, analytics, and transactional email services used to operate DLBR EID. Processing locations depend on the service component; some components use Cloudflare's global network.
PrivacyTermsDPA

Building DLBR EID, an EUDI Wallet verification API and SDK. Focused on digital identity, eIDAS 2, and privacy-preserving verification.

contact@dlbr.app ↗
HomeBlogPILOT
Declared usePrivacyTermsDPAImpressum

© 2026 DLBRv0.1.0 · 35f4b4f