Authfu

Agreements

Data Processing Addendum

The GDPR Article 28 terms that apply when Authfu processes personal data on your behalf.

Last updated

This Data Processing Addendum (the DPA) is between:

1. the customer identified in the agreement that incorporates this DPA (Customer); and

2. Conversift, Inc., a company whose jurisdiction of incorporation is to be confirmed before general availability and whose registered address is available on request from legal@authfu.com (Conversift).

Conversift operates the Authfu hosted identity service. Customer and Conversift are each a party and together the parties.

This DPA supplements the agreement under which Conversift provides Authfu to Customer (the Service Agreement). It forms part of the Service Agreement when both parties execute it or otherwise validly incorporate it.

01Parties and agreement

1.1. The parties enter into this DPA to govern Conversift’s processing of Customer Personal Data in connection with Authfu.

1.2. This DPA applies only where Conversift processes Customer Personal Data as a processor on Customer’s behalf.

1.3. The Service Agreement continues to govern the service. If this DPA conflicts with the Service Agreement on the processing or protection of Customer Personal Data, this DPA controls to the extent of the conflict.

1.4. Annex I describes the parties and the processing. Annex II describes the technical and organizational measures. Annex III lists the approved subprocessors.

1.5. In this DPA:

  • Applicable Data Protection Law means the data-protection and privacy law that applies to processing under this DPA, including the EU GDPR where applicable;
  • Customer Personal Data means personal data that Conversift processes as a processor on Customer’s behalf through Authfu;
  • EU GDPR means Regulation (EU) 2016/679;
  • personal data, personal data breach, process, processor, controller, and supervisory authority have the meanings given by Applicable Data Protection Law;
  • SCCs means the applicable standard contractual clauses described in section 12; and
  • subprocessor means a processor engaged by Conversift to process Customer Personal Data.

02Scope and roles

2.1. Customer is the controller of Customer Personal Data. Conversift is its processor. Each party will meet the obligations that Applicable Data Protection Law places on it in that role.

2.2. Customer determines why its end users authenticate to Customer’s applications through Authfu. Conversift processes their data to provide and secure that authentication service.

2.3. Conversift is a controller, not a processor, when it processes personal data for its own purposes. This includes data used to create, operate, and secure a Customer representative’s own Authfu account. That controller processing is outside this DPA and is governed by Authfu’s Privacy Policy.

2.4. Annex I states the subject matter, nature, purpose, and duration of processing, the categories of personal data, and the categories of data subjects.

2.5. Customer is responsible for:

  • giving lawful instructions;
  • having a valid legal basis for the processing;
  • giving any notices required by law;
  • configuring and using Authfu lawfully; and
  • ensuring that Customer Personal Data is accurate and appropriate for the stated purposes.

2.6. Customer will not instruct Conversift to process Customer Personal Data in a way that violates Applicable Data Protection Law.

03Processing instructions

3.1. Conversift will process Customer Personal Data only:

  • on Customer’s documented instructions;
  • as needed to provide, secure, support, and maintain Authfu under the Service Agreement; or
  • where law requires the processing.

3.2. The Service Agreement, this DPA, Customer’s documented use and configuration of Authfu, and any later written instructions accepted by Conversift together form Customer’s documented instructions.

3.3. Customer instructs Conversift to process Customer Personal Data for the purposes in Annex I and to use the subprocessors in Annex III.

3.4. Conversift will not sell Customer Personal Data or use it for advertising or analytics. Authfu does not run analytics.

3.5. If law requires Conversift to process Customer Personal Data beyond Customer’s instructions, Conversift will tell Customer about that legal requirement before processing unless the law prohibits notice on important grounds of public interest.

3.6. Conversift will tell Customer promptly if, in its opinion, an instruction violates Applicable Data Protection Law. Conversift may suspend the affected processing while the parties resolve the issue.

3.7. Customer may give additional instructions in writing. If an instruction falls outside Authfu’s agreed scope or requires material additional work, the parties will agree on feasibility, timing, and any reasonable charges before Conversift acts on it.

04Confidentiality

4.1. Conversift will ensure that each person it authorizes to process Customer Personal Data is bound by confidentiality obligations or is under an appropriate statutory duty of confidentiality.

4.2. Conversift will limit authorized access to the Customer Personal Data needed for that person’s assigned work.

4.3. Confidentiality obligations will continue after a person’s authorization ends.

4.4. Conversift will provide relevant privacy and security instructions to people authorized to process Customer Personal Data.

05Security

5.1. Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, as well as the risk to people, Conversift will maintain appropriate technical and organizational measures to protect Customer Personal Data.

5.2. The measures will address, as appropriate, confidentiality, integrity, availability, and resilience, and the ability to restore access following an incident.

5.3. Annex II describes the measures currently used for Authfu.

5.4. Conversift may update the measures as technology and risks change. An update will not materially reduce the overall protection of Customer Personal Data during the term of the Service Agreement.

5.5. Customer is responsible for securely configuring its applications and integration, protecting its own credentials, and using the security features made available through Authfu.

06Subprocessors

6.1. Customer gives Conversift general written authorization to use the subprocessors listed in Annex III.

6.2. Conversift will give Customer at least 30 days’ notice before a new subprocessor begins processing Customer Personal Data or an existing subprocessor takes on a materially different processing role.

6.3. Customer may object during that notice period on reasonable data-protection grounds. The parties will work in good faith to address the objection.

6.4. If the parties cannot resolve a reasonable objection, Customer may stop using the affected part of Authfu. Customer may terminate the affected service by written notice before the new subprocessor begins processing Customer Personal Data.

6.5. Conversift will enter into a written agreement with each subprocessor that imposes data-protection obligations no less protective than the relevant obligations in this DPA, to the extent applicable to the subprocessor’s work.

6.6. Conversift remains responsible to Customer for a subprocessor’s performance of those obligations.

6.7. Conversift will make its current subprocessor list available to Customer.

07Data-subject requests

7.1. Taking into account the nature of the processing, Conversift will use appropriate technical and organizational measures to help Customer respond to requests by people exercising their rights under Applicable Data Protection Law.

7.2. If Conversift receives a request that relates to Customer Personal Data, it will notify Customer without undue delay and will not respond on Customer’s behalf unless Customer instructs it to or law requires it.

7.3. Conversift may direct the requester to Customer where appropriate.

7.4. Customer remains responsible for deciding how to respond and for meeting the applicable deadline.

7.5. Conversift will provide information available through Authfu and reasonable additional assistance needed for Customer’s response, taking into account the nature of processing and the information available to Conversift.

08Security incidents

8.1. Conversift will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.

8.2. As information becomes available, the notice will describe:

  • the nature of the breach, including affected data and people where known;
  • the likely consequences;
  • the measures taken or proposed to contain, investigate, and remedy it; and
  • a contact point for follow-up.

8.3. Conversift may provide information in phases when all details are not available at the same time.

8.4. Conversift will take reasonable steps to contain, investigate, mitigate, and remediate the breach and will reasonably assist Customer with legally required notices.

8.5. A notice under this section is not an admission of fault or liability.

8.6. Customer is responsible for notifying supervisory authorities and affected people when law requires it.

09Assessments and regulator cooperation

9.1. Taking into account the nature of processing and the information available to Conversift, Conversift will reasonably assist Customer with:

  • security obligations under Applicable Data Protection Law;
  • personal-data-breach assessments and notifications;
  • data protection impact assessments; and
  • prior consultation with a supervisory authority.

9.2. Conversift will provide information reasonably needed for those tasks and will cooperate with a competent supervisory authority where Applicable Data Protection Law requires it.

9.3. Customer remains responsible for determining whether an assessment, consultation, or notification is legally required.

10Return and deletion

10.1. At the end of the services involving Customer Personal Data, Conversift will, at Customer’s choice, delete or return Customer Personal Data and delete remaining copies, unless applicable law requires storage.

10.2. Customer must communicate its choice before the services end or within the period specified in the Service Agreement. If Customer does not make a choice, Conversift will delete the data under its then-current deletion process.

10.3. Where law requires continued storage, Conversift will isolate and protect the retained data and process it only for the legally required purpose.

10.4. Conversift will provide reasonable confirmation of deletion on request.

11Information and audits

11.1. Conversift will make available information reasonably necessary to show compliance with Article 28 and equivalent obligations under Applicable Data Protection Law.

11.2. Customer may audit Conversift’s compliance once in any 12-month period and more often after a personal data breach affecting Customer Personal Data or where a supervisory authority requires it.

11.3. The parties will first use current documentation and written responses where those materials can reasonably meet the audit’s purpose.

11.4. If an on-site audit remains reasonably necessary, Customer will give advance written notice and conduct it during normal business hours in a way that minimizes disruption and protects other customers’ data and confidential information.

11.5. The auditor must be independent, appropriately qualified, and bound by confidentiality. It must not be a competitor of Conversift.

11.6. Customer will bear its audit costs. Conversift may charge reasonable costs for supporting an audit that is unusually burdensome, unless the audit identifies a material breach by Conversift of this DPA.

11.7. Conversift will tell Customer promptly if it believes an instruction under this section infringes Applicable Data Protection Law.

12International transfers

12.1. Authfu’s application hosting, PostgreSQL database, avatar object storage, and transactional email delivery are in the United States. Annex III gives the location and purpose of each listed provider.

12.2. Conversift will not transfer Customer Personal Data out of the EEA, UK, or Switzerland unless the transfer complies with Applicable Data Protection Law.

12.3. Where the EU GDPR applies and Customer transfers Customer Personal Data to Conversift in a country that does not receive the transfer without an approved mechanism, the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914 are incorporated into this DPA by reference and form part of it. Module Two, controller to processor, applies.

For those SCCs, Clause 7, the optional docking clause, applies. Under Clause 9(a), Option 2, Customer gives the general authorization in section 6, and the notice period for an intended addition or replacement of a subprocessor is 30 days. The optional independent dispute-resolution body in Clause 11 is not selected. Clause 17, Option 2, applies: the SCCs are governed by the law of the EU Member State in which the data exporter is established, or, where that law does not allow third-party-beneficiary rights, the law of Ireland. Under Clause 18, disputes will be resolved by the courts of the Member State whose law applies under Clause 17.

The competent supervisory authority under Clause 13 is the authority determined by that clause based on the data exporter’s establishment or representative and the people affected by the transfer. The SCCs’ third-party-beneficiary rights, redress rights, and supervision provisions apply without modification. Annex I to this DPA populates SCC Annex I, Annex II to this DPA populates SCC Annex II, and Annex III to this DPA populates SCC Annex III.

For a restricted transfer governed by UK data-protection law, the UK Information Commissioner’s International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0 in force 21 March 2022, is incorporated into this DPA by reference and forms part of it. The selections and appendix information stated above apply to the UK Addendum, adapted as required by its mandatory clauses; both the exporter and importer may end the UK Addendum as provided in its Table 4.

For a transfer governed by Swiss data-protection law, the SCCs are incorporated into this DPA by reference with the adaptations necessary for Switzerland: references to the EU GDPR include the Swiss Federal Act on Data Protection; references to the EU, Member States, and supervisory authorities include Switzerland and the Swiss Federal Data Protection and Information Commissioner; and the SCCs protect data subjects and legal remedies under Swiss law. The Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for those transfers, Swiss law governs to the extent Swiss law requires, and disputes may be brought before the competent Swiss courts.

12.4. If the SCCs or UK Addendum conflict with this DPA, the prescribed transfer instrument controls for the relevant transfer.

12.5. If a transfer mechanism becomes invalid or unavailable, the parties will cooperate in good faith to put a valid mechanism in place or stop the affected transfer.

13Liability and order of precedence

13.1. The liability provisions in the Service Agreement apply to this DPA unless Applicable Data Protection Law or the applicable SCCs require otherwise.

13.2. The following order applies to a conflict about Customer Personal Data:

1. the applicable SCCs or UK transfer instrument;

2. this DPA; and

3. the Service Agreement.

13.3. Nothing in this DPA limits a person’s rights or a party’s liability where Applicable Data Protection Law does not permit that limit.

14Term and termination

14.1. This DPA starts when it is executed or validly incorporated into the Service Agreement.

14.2. It continues while Conversift processes Customer Personal Data.

14.3. Obligations that by their nature must continue—including confidentiality, deletion, audit cooperation, and transfer protections—survive termination for as long as Conversift retains Customer Personal Data.

14.4. Termination does not remove rights or obligations that arose before termination.

15General terms

15.1. Changes to this DPA must be in writing and agreed by authorized representatives of both parties, except for operational updates expressly allowed by this DPA.

15.2. If a provision is unenforceable, the remaining provisions continue. The parties will replace the affected provision with an enforceable one that most closely matches its lawful purpose.

15.3. Notices under this DPA must be sent using the notice process in the Service Agreement. Legal and DPA correspondence to Conversift may be sent to legal@authfu.com.

15.4. The governing law and venue are to be confirmed before general availability; write to legal@authfu.com if this matters to your agreement, except where Applicable Data Protection Law or a prescribed transfer instrument requires otherwise.

15.5. This DPA, its annexes, the applicable transfer instruments, and the Service Agreement are the parties’ complete agreement on its subject matter.

Execution

To execute this DPA, email legal@authfu.com with Customer’s legal entity name and jurisdiction. Conversift will return a countersigned copy for the parties’ records.

16Annex I — Parties and processing

A. List of parties

Data exporter

  • Name: Customer’s legal name in the Service Agreement
  • Address: Customer’s address in the Service Agreement
  • Contact: Customer’s privacy contact provided with the DPA request
  • Role: Controller
  • Activities relevant to the transfer: Customer uses Authfu to authenticate people into Customer’s applications
  • Signature and date: The signature or valid incorporation of this DPA

Data importer

  • Name: Conversift, Inc.
  • Address: available on request from legal@authfu.com
  • Contact: legal@authfu.com
  • Role: Processor
  • Activities relevant to the transfer: Hosting and operating Authfu as a managed identity provider for Customer
  • Signature and date: The signature or valid incorporation of this DPA

B. Description of processing

Categories of data subjects

  • people who use Authfu to sign in to Customer’s applications;
  • Customer’s personnel or members when they sign in to an application for which Customer is controller; and
  • people whose sign-in or administrative activity appears in Customer’s Authfu audit records.

Customer’s representatives acting only as Authfu account holders fall outside this DPA where Conversift processes their account data as controller.

Categories of personal data

  • email address;
  • optional first name, last name, and display name;
  • optional globally unique handle;
  • optional uploaded avatar;
  • encrypted TOTP secret;
  • hashed backup codes;
  • passkey public keys and related public credential records;
  • session records;
  • audit records of sign-in and administrative events; and
  • records of the applications a person has signed in to.

Authfu does not store passkey private keys. It does not process payment-card data.

Sensitive data

The service is not intended for special-category personal data. Authentication data requires strong protection because misuse could affect access to a person’s account.

Frequency of processing

Processing occurs continuously while Authfu hosts configured identity records and on demand when a person registers, signs in, manages an identity, uses a session, or when an authorized administrator performs an allowed administrative action.

Nature and purpose of processing

Conversift collects, stores, organizes, retrieves, transmits, secures, and deletes Customer Personal Data to:

  • provide passwordless email magic-link authentication;
  • verify TOTP before sending a sign-in email when TOTP is enrolled;
  • register and verify passkeys;
  • issue and validate OpenID Connect sessions and tokens;
  • maintain identity profiles and optional avatars;
  • deliver transactional sign-in links and notices;
  • record sign-in and administrative events for security and accountability; and
  • operate, secure, support, and troubleshoot Authfu for Customer.

Subject matter and duration

The subject matter is the managed identity and authentication service Customer uses for its applications. Processing continues for the term of the Service Agreement and until Customer Personal Data is returned or deleted under section 10, unless law requires longer storage.

No fixed post-termination retention period is stated in this DPA.

Competent supervisory authority

For EU transfers, the competent supervisory authority is determined under Clause 13 of the SCCs based on the data exporter’s establishment or representative and the people affected. For Swiss transfers, it is the Swiss Federal Data Protection and Information Commissioner. The UK Addendum determines the competent UK authority for UK restricted transfers.

17Annex II — Technical and organizational measures

The measures below describe verified Authfu architecture. They do not claim a certification, external audit, uptime level, or control that has not been verified.

1. Encryption and credential protection

  • Authfu uses TLS to protect data in transit.
  • TOTP secrets use AWS KMS envelope encryption.
  • A customer master key in AWS KMS in us-east-2 wraps the data key.
  • The plaintext key never leaves AWS.
  • Backup codes are hashed with SHA-256.
  • Passkeys store public keys only. Authfu never receives or stores the private key.

2. Sign-in controls

  • Email sign-in links are single-use and valid for minutes.
  • Where an account has TOTP enrolled, Authfu verifies the TOTP code before it sends any email. Typing another person’s email address alone sends that person nothing.
  • Passkeys use WebAuthn and can replace the email step.
  • Downstream applications integrate through OpenID Connect using PKCE and RS256 ID tokens.
  • Console access uses a signed, HTTP-only, secure, SameSite session cookie.
  • OAuth redirects additionally use a short-lived state cookie.

3. Access control and administrative action

  • Access to identity and administrative functions requires authentication.
  • An organization administrator may start a time-boxed session as a member only if the organization has a DNS-verified domain and the member’s email is on exactly that domain.
  • The administrator must re-authenticate at the moment of use.
  • The administrator must enter a reason.
  • The session lasts no more than one hour.
  • Authfu notifies the affected member.
  • Authfu writes the action to both audit logs.
  • The session cannot change credentials.
  • An application developer gains no ability to act as people merely because they use the developer’s application.

4. Auditability

  • Authfu records sign-in and administrative events in an audit log.
  • Authfu records the applications a person has signed in to.
  • Administrative “act as” use is recorded in both relevant audit logs.

5. Recovery safeguards

  • Loss of a second factor starts a delayed, cancellable recovery.
  • Recovery waits seven days.
  • A single click in an emailed notice cancels the recovery.
  • A recovered session cannot reach the console until two-factor authentication is enrolled again.

6. Data minimization and browser privacy

  • Authfu stores optional profile fields only when used: first name, last name, display name, handle, and avatar.
  • Authfu does not run analytics, tag managers, session recording, or browser error tracking.
  • Fonts are self-hosted at build time, so the browser makes no third-party font request.
  • The authfu.com marketing site sets no cookies.
  • Billing is not live. Authfu does not process card data.

7. Infrastructure separation

  • Railway hosts the application, PostgreSQL database, and avatar object storage in the United States.
  • AWS KMS has custody of encryption keys in us-east-2 and holds no personal data.
  • Resend receives the data needed to deliver transactional email in the United States.
  • Gandi provides domain registration and DNS in the EU and holds no personal data for Authfu’s service processing.

18Annex III — Subprocessors

Customer generally authorizes the providers below, subject to section 6.

ProviderPurposeRegionPersonal-data access
RailwayApplication hosting, PostgreSQL database, and object storage for avatarsUnited StatesHosts Customer Personal Data
Amazon Web Services (KMS)Encryption key custodyus-east-2Holds no personal data
ResendDelivery of transactional email, including sign-in links and noticesUnited StatesReceives transactional email delivery data
GandiDomain registration and DNSEuropean UnionHolds no personal data

There are no other third parties that can touch Authfu data as of the revision date.