Regula Data Processing Agreement
Version 1.0.0 · Effective from 1 October 2026 · Zug, Switzerland
Document key: dpa · Scope: all users (binding on Owners and Relying Parties acting for an organisation) · Language: English (authoritative)
Parties: KROIN AG, Ahornstrasse 6, 6300 Zug, Switzerland (CHE-498.889.894) — and the organisation on whose behalf a user signs these documents as Owner of an Entity or as a Relying Party (the "Customer"). For individual users this Agreement describes the roles and safeguards that apply to their data; it creates obligations on KROIN AG, not on them.
Read together with the Regula Terms of Service and the Regula Privacy Policy, each version 1.0.0. Terms defined there have the same meaning here.
1. Roles
- KROIN AG is the controller of account, identity-verification, attestation, security and billing data, whose purposes it determines (Privacy Policy, Sections 2–3).
- KROIN AG is a processor where it stores, relays or records personal data on the Customer's documented instructions: the Entity's documents, the record of its members' roles and the reasons attached to role changes, the grants its users sign towards it, and any ciphertext its users direct through the Platform.
- For content encrypted on the user's device, KROIN AG is a blind processor: it stores and relays ciphertext it cannot read.
- Each Relying Party is an independent controller of the Verified Data a user chooses to share with it.
- Each Entity is the controller of its members' role records and of the reasons its members write; KROIN AG processes them for the Entity as described in Section 4.
2. Subject-matter, duration, nature, purpose
- Subject-matter and purpose: providing the Regula identity wallet, HumanSigned, Login with Regula and the Entity services.
- Duration: the term of the Terms of Service and any legally required retention (Privacy Policy, Sections 7–8).
- Nature: collection, encryption relay, storage of ciphertext, keyed-index lookup, signature verification, fingerprinting and anchoring, encrypted storage of reasons, deletion and crypto-shredding.
- Data subjects: the Customer's users, members, employees and representatives.
- Categories: account identifiers (encrypted, indexed), wallet addresses, Level attestations, Entity documents (encrypted), role records, reasons (encrypted), grants, technical metadata, payment references. Identity documents and biometric results are processed by KROIN AG as controller under the Privacy Policy, Section 7, and are never disclosed to the Customer.
3. Processor obligations
KROIN AG shall: (a) process the Customer's data only on documented instructions, the Terms and this Agreement being the instructions; (b) bind persons authorised to process to confidentiality; (c) implement the measures in Section 6; (d) engage sub-processors only under Section 5; (e) assist the Customer in answering data-subject requests, within the limits of what KROIN AG can read; (f) assist with security, breach notification and impact assessments; (g) at the end of the service, delete or return the Customer's data, subject to legal retention and to the permanence of anchors; (h) make available the information needed to demonstrate compliance and allow audits, on 30 days' notice, once a year or after an incident, at the Customer's cost unless the audit reveals a material breach.
4. The record of mandates and the reasons
4.1 Every change of a member's role is a signed act of the acting member; KROIN AG verifies the signature, records the act and anchors its fingerprint. The Entity is responsible for the lawfulness of the acts its members sign.
4.2 The reason attached to a freeze, demotion, removal or rejection is personal data of the affected member and is written by the acting member on the Entity's behalf. KROIN AG stores it encrypted and returns it only to the affected member and to members holding the Entity's audit permission. It is never anchored, published or disclosed to a Relying Party.
4.3 The affected member's statement in reply is stored under the same rules and shown beside the act to the same readers.
4.4 The Entity may export the record of a member or of the Entity as a signed file; the export is itself a recorded act naming who exported and for whom. Exports containing reasons are encrypted towards the recipient.
4.5 When an Entity is closed, its record is retained for ten years for the Entity's and its members' benefit, then destroyed.
5. Sub-processors
The Customer authorises the following sub-processors. KROIN AG notifies material changes thirty days in advance; the Customer may object on reasonable data-protection grounds, in which case the parties seek a solution and, failing one, the Customer may terminate.
| Sub-processor | Location | Purpose | Data handled |
|---|---|---|---|
| Amazon Web Services EMEA SARL | EU (Frankfurt) | hosting, compute, storage, e-mail delivery (SES), write-once archive | ciphertext, fingerprints, metadata, e-mail addresses for transactional mail |
| Pinata Technologies, Inc. | USA (with EU/CH safeguards) | encrypted object storage (IPFS) | ciphertext only |
| Shufti Pro Ltd. | United Kingdom | identity verification and screening (KROIN AG as controller) | identity data, for the duration of the verification |
| Stripe Payments Europe, Ltd. | Ireland | payment processing | payment data (Stripe as its own controller), payment reference |
| Vonage (Vonage Group) | EU/USA (with safeguards) | SMS one-time codes | mobile number, code |
| Expo (650 Industries, Inc.) | USA (with safeguards) | push-notification delivery | device token, notification title |
| Sentry (Functional Software, Inc.) | EU data region | error monitoring | technical metadata, no personal content |
6. Security measures
Encryption in transit (TLS 1.2+) and at rest; content encrypted on the user's device with keys KROIN AG does not hold; keyed one-way indexes for identifiers; identity dossiers sealed under a two-of-three threshold and kept on write-once, offline storage (Privacy Policy, Section 7); reasons encrypted with access by permission; signed, append-only records of acts with anchored fingerprints; role-based access control with least privilege and separation between production and test environments; least-data logging; encrypted backups with periodic restore tests; secrets management with a boot-time check refusing placeholder secrets in production; monitoring of the network's certificates and connectivity; token revocation within one second of a member's freeze for the Entity's services.
7. International transfers
Where a sub-processor processes personal data outside Switzerland or the EEA, transfers rely on an adequacy decision (United Kingdom) or on the EU Standard Contractual Clauses with the Swiss addendum, in addition to encryption, so that the data transferred are, wherever possible, ciphertext or fingerprints.
8. Personal-data breach
KROIN AG notifies the Customer without undue delay, and in any case within 72 hours, after becoming aware of a breach affecting the Customer's data, with the information reasonably available, and cooperates in remediation and in any notification the Customer must make. A breach of storage exposes ciphertext and fingerprints, not readable content, except for data the Customer itself keeps in clear.
9. Deletion and return
On termination, or on instruction, KROIN AG deletes or returns the Customer's data within 90 days, subject to the retention periods in the Privacy Policy and to the permanence of anchors, and effects crypto-shredding where content is encrypted towards keys it can destroy.
10. Liability, law, forum
Liability under this Agreement is subject to the Terms of Service, Section 16. This Agreement is governed by Swiss law; the courts of Zug have jurisdiction. The FADP and, where applicable, the GDPR govern personal-data matters.
11. Contact
KROIN AG · Ahornstrasse 6, 6300 Zug, Switzerland · privacy@kroin.net.