Third Party Index

Snapshot 17429

Document
Data processing addendum
URL
https://www.daon.com/dpa/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
143479 bytes
SHA-256 (raw)
89a94f73870e633f4866e3e35bb9d556ae99380fa3124c35a8e1f9518f2f49ee
SHA-256 (normalized text)
86ce3114ff758c48c3b8ee8b33ae46fd0344e59a31197e4e954cb7b99d5f7d29

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Solutions
Identity Continuity
Orchestration Platforms
Identity Verification (IDV)
Identity Authentication
Contact Center Authentication
Workforce Identity Fraud Prevention
Age Verification
AI.X Deepfake Defense
Travel Document Validation
Products
IdentityX | hosted platform
TrustX | SaaS platform
xAuth | multi-factor authentication
xFace | facial authentication
xProof | identity verification (IDV)
xVoice | voice authentication
xDeTECH | synthetic voice detection
VeriFLY | travel document validation
Technologies
Orchestration
Facial Biometrics
Passkeys
Voice Biometrics
Document Verification
Liveness Detection
Multi-Factor Authentication
FIDO Authentication
NFC
Mobile Driver’s License
Deepfake
Industries
Crypto
Financial Services
Healthcare
Public Sector
Retail
Telecom
Travel & Hospitality
Other
Use Cases
About Us
The Daon Difference
Customer Experience
Our Customers
Our Partners
Media Center
Careers
Resources
Thought Leadership
Events
Support
Compliance
Developers
Contact Us
Search
Free Demo
10 July 2027 is coming fast. Is your organization preparing for EU AMLR? LEARN MORE
Contact Us
Connect with a Daon solutions expert
Let us know how we can assist you
Product/Solution Information
Product Demonstration
Request for Proposal
Partnership Opportunities
See why many of the world’s strongest brands chose Daon to help them build lasting trust with their customers.
Data Processing Addendum
This Data Processing Addendum (“DPA”) is made by and between Daon and Licensee, hereinafter, jointly or individually, referred to as the “Parties” or a “Party”.
Part I
Definitions.
“Biometric Data” means any information, regardless of how it is captured, converted, stored, or shared, based on an individual’s retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry.
“Business Contact Information” means the names, mailing addresses, email addresses, and phone numbers regarding the other Party’s employees, directors, vendors, agents and licensees maintained by a Party for its own business purposes as further described in section 17 below.
“Consents” includes all necessary consents, permissions, as well as notices and authorizations necessary for the processing or onward transfer by Daon of Personal Data which is required to perform the Services, including transfer of Personal Data outside of the country(ies) of origin and any of the foregoing, as applicable, from employees or third parties; valid consent from or notices to applicable data subjects; and authorization from regulatory authorities, employee representatives bodies or other applicable third parties.
“Data Protection Laws” means the applicable data protection and data privacy laws, rules and regulations to which Licensee Personal Data are subject. Such laws may include: the EU General Data Protection Regulation 2016/679 (“GDPR”), the Federal Data Protection Act of 19 June 1992 (Switzerland), the UK Data Protection Act 2018, and any US state or federal Laws or regulations pertaining to the collection, use, disclosure, security or protection of personal data, or to security breach notification, e.g., the California Consumer Privacy Act of 2018.
“Personal Data” means any information relating to an identified or identifiable natural person, including Biometric Data, that is processed by Daon as a result of, or in connection with, the provision of the Services under the Agreement; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.
“Sub-processors” means third parties authorized under the terms of this DPA to have access to and process Licensee Personal Data.
This DPA is subject to the terms of the Agreement and is incorporated into the Agreement. Interpretations and defined terms set forth in the Agreement apply to the interpretation of this DPA. Annex 1 forms part of this DPA and will have effect as if set out in full in the body of this DPA and any reference to this DPA includes the Annex. In the case of conflict or ambiguity between:
any provision contained in the body of this DPA and any provision contained in Annex 1, the provision in the body of this DPA will prevail;
the terms of any accompanying invoice or other documents annexed to this DPA and any provision contained in Annex 1, the provision contained in Annex 1 will prevail;
any of the provisions of this DPA and those of the Agreement, the provisions of this DPA will prevail; and
any of the provisions of this DPA and any executed SCC (as defined below), the provisions of the executed SCC will prevail.
Compliance with Laws. The parties shall comply with all Data Protection Laws and regulations in their use of Personal Data. This obligation includes, in the event Licensee is a relying party under the terms of the UK Digital Identity and Attributes Trust Framework (“DIATF”) and is utilising the Services to deliver a DIATF-certified service, Licensee shall be certified under DIATF and/or have fulfilled their obligations thereunder.
Processing Roles. Licensee and Daon acknowledge that for the purpose of providing the Services and the processing Personal Data therefore, Licensee is the controller and Daon is the processor. As a result, Clauses 5 to 23 of this DPA will apply to the processing. For such processing, the Parties acknowledge that Licensee is responsible for its compliance obligations under the Data Protection Laws, including providing any required notices, obtaining any required consents, and its processing instruction.
Controller Obligations:. The Parties agree to the following allocation of responsibility for compliance with obligations under Data Protection Laws in respect of the processing of Personal Data. Licensee is responsible for:
ensuring that a legal basis is in place for the processing of the Personal Data;
ensuring that Personal Data is kept for no longer than is necessary;
ensuring that data subjects have been provided with information required by Data Protection Laws including obtaining all required consents;
responding to any data subject requests received by either party in respect of Personal Data (including requests under Articles 15 to 22 GDPR) in accordance with Data Protection Laws; and
if applicable, informing data subjects that Personal Data may be transferred outside the EEA in accordance with the GDPR.
Processor Obligations:
Daon shall process Personal Data only on documented instructions from Licensee for the duration of the Agreement. The Agreement, including any applicable statement of work, together with this DPA and Annex 1 attached hereto, constitute Licensee’s complete and final instructions to Daon regarding the processing of Personal Data.
Daon may process Personal Data other than on the instructions of Licensee if it is required under applicable law. In such a case, Daon shall inform Licensee of such legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
If Daon is unable to comply with Licensee’s instructions or this DPA due to changes in legislation or, if Daon believes (without having to conduct a comprehensive legal analysis) that any instruction from Licensee will violate applicable law or for any other reason, Daon shall promptly notify Licensee in writing.
Daon shall promptly comply with any Licensee request or instruction to amend, transfer, delete, or otherwise process Personal Data, or to stop, mitigate, or remedy any unauthorized processing.
Daon will ensure that Daon personnel authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Additionally, Daon will not disclose Personal Data to third parties unless Licensee has specifically authorized such disclosure, or is required by appliable law. If a court, law, regulator or supervisory authority requires Daon to process or disclose Licensee Personal Data, Daon will first, to the extent permitted by law, inform Licensee of such requirement to give Licensee the opportunity to object or challenge the requirement.
Daon will reasonably assist Licensee in ensuring compliance with the obligations pursuant to the applicable Data Protection Laws, considering the nature of processing and the information available to Licensee.
Daon will promptly notify Licensee of any changes to appliable Data Protection Laws that may adversely affect Daon’s performance of the Agreement.
Daon will keep detailed, accurate, and up-to-date records of its processing under this DPA that are sufficient to enable Licensee to verify Daon’s compliance with its obligations hereunder. Copies of such records are available on written request.
If Licensee uses the Services provided by Daon to process any categories of data not expressly covered by this DPA, then Licensee acts at its own risk and Daon is not responsible for any potential compliance deficits related thereto.
Licensee agrees that at all times Licensee shall only provide instructions to Daon that are lawful and that Daon shall not be liable for any claim brought by a data subject arising from or related to Licensee’s action or omission, to the extent that Daon was acting in accordance with Licensee’s instructions.
Biometric Data. In the event Licensee is collecting or processing biometrics within the United States, the terms of the US Biometric Data Annex attached hereto shall apply.
Security.
Daon has implemented and agrees to maintain the security measures indicated in the Daon Data Security Standards located at www.daon.com/security-exhibit. The security measures are subject to technical progress and further developments. Daon shall be permitted in principle to implement alternative security measures that do not reduce the overall level of security. Any substantial change to security measures shall be documented and notified to Licensee.
Daon is responsible for assessing its requirements with respect to appropriate technical and organizational measures to ensure compliance with Data Protection Law, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, making an independent determination and satisfying itself that the security measures specified in the Daon Data Security Standard meet its requirements.
Data Subject Requests. Daon shall, considering the nature of the processing and the information available to Daon, assist Licensee by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of its obligation to respond to requests for exercising a data subject’s rights under applicable Data Protection Laws. The parties acknowledge that such assistance will be provided following agreement between the Parties on the scope and timing of such assistance, and the fees chargeable by Daon for such assistance. Daon shall notify Licensee immediately if it receives any complaint, notice, or communication that relates to the processing of Personal Data hereunder or to either Party’s compliance with Data Protection Laws. Daon will notify Licensee within ten (10) business days if it receives a data subject request. Daon will not disclose the relevant Personal Data to a data subject or third-party other than at Licensee’s instruction, as provided in this DPA, or as required by law.
Deletion. Daon shall delete or return the Personal Data to Licensee after the end of the provision of Services, and delete existing copies unless applicable law requires further storage of the Personal Data.
Compliance. Daon shall make available to Licensee all reasonable information necessary to demonstrate compliance with the obligations laid down in this DPA.
Sub-processing.
Except as set forth in Annex 1 herein, Daon shall not engage any sub-processors without prior specific written authorisation of Licensee. Where, Daon engages a sub-processor to carry out specific processing activities on behalf of Licensee, the same data protection obligations as set out in this DPA shall be imposed by Daon on that sub-processor, in particular providing sufficient guarantees to implement the security measures set forth in the Daon Data Security Standard at Part III. Where the sub-processor fails to fulfil its data protection obligations, Daon shall remain fully liable to Licensee for the performance of that sub-processor’s obligations.
Licensee agrees that Daon may use such Sub-processors as are specified in the relevant annex to this DPA and in all cases may use Amazon Web Services (“AWS“) to host the Software. Daon and AWS have executed an AWS Licensee Agreement available at https://aws.amazon.com/agreement/, (as updated from time to time) and an AWS Data Processing DPA thereto. The guarantees provided by AWS regarding the technical and organizational measures to ensure the processing meets its legal requirements are set out in the AWS Security Standards and AWS Processing Addendum. Daon will inform Licensee of any intended changes concerning the addition or replacement of AWS, giving the Licensee the opportunity to object to such changes.
Warranty: Licensee warrants and represents that Daon’s processing of the Personal Data pursuant to this DPA and its instructions will comply with the Data Protection Laws.
Data Breach. Daon shall notify Licensee without undue delay, and in any event within two (2) days, after of becoming aware of a Personal Data Breach. Such notice shall include reasonable details: e.g. the nature of the Personal Data Breach including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of Personal Data records concerned.
Co-operation. Daon shall cooperate, on request, with the supervisory authority in the performance of its tasks. In the event a court and/or a data protection authority, initiates proceedings against a party, the other party shall cooperate in good faith and without undue delay to assist at no additional cost such party, to the extent it requires during such proceedings.
Cross-Border Transfers of Licensee Personal Data.Licensee acknowledges that Daon may transfer and process Personal Data to and where its Affiliates or sub-processors maintain data processing operations, including to locations outside of the EU/EEA. In accordance with chapter V of the GDPR, Daon has entered into an intra-group data transfer agreement for the purpose of such transfers.
Changes in Laws. In the event of (i) any newly enacted Data Protection Law, (ii) any change to an existing Data Protection Law (including generally-accepted interpretations thereof), (iii) any interpretation of a new or existing Data Protection Law by Licensee, or (iv) any material new or emerging cybersecurity threat, which individually or collectively requires a change in the manner by which Daon is delivering the Services to Licensee, the parties shall agree upon how Daon’s delivery of the Services will be impacted and shall make equitable adjustments to the terms of the Agreement and the Services by agreement in writing with both parties acting in good faith.
Data Indemnity. Licensee agrees to defend, indemnify and hold harmless Daon and any of Daon’s affiliates, subsidiaries, directors, officers, employees, representatives, and agents from and against any claim (including but not limited to any class action litigation) demand, cause of action, loss, settlement, fines, fees, penalties, regulatory investigation or enforcement action, judgment, liability, and expenses related thereto (including but not limited to reasonable fees and disbursements of attorneys and other professional advisors) resulting from, arising out of or relating to: (i) Daon acting in accordance with the instructions of Licensee in processing Personal Data hereunder; and/or (ii) a failure by Licensee or any third party acting on behalf of Licensee, to comply with Data Protection Laws or the provisions of this DPA.
Use of Business Contact Information. Each party consents to the other party using its Business Contact Information for contract management, payment processing, service offering, and business development purposes related to the Agreement. For such purposes, and notwithstanding anything else set forth in the Agreement or this DPA with respect to Personal Data in general, each party shall be considered a controller with respect to the other party’s Business Contact Information and shall be entitled to transfer such information to any country where such party’s global organization operates.
Liability: Neither Party shall be liable for any loss of profit, loss of goodwill, loss of opportunity, loss of business or any indirect, special or consequential loss arising from this DPA, regardless of whether the Party was aware of the possibility of the same. Licensee acknowledges that Daon is reliant on Licensee for direction as to the extent to which Daon is entitled to process Personal Data on behalf of Licensee in performance of the Services. As a result, Daon will not be liable under the Agreement or this DPA for any losses arising from a claim brought by a data subject, or other third party, arising from any action or omission by Daon, to the extent that such action or omission resulted from Licensee’s instructions or from Licensee’s failure to comply with its obligations under Data Protection Laws. Notwithstanding any provisions to the contrary included in this DPA, each Party’s liability towards the other Party under or in connection with this DPA will be limited in accordance with the provisions of the Agreement.
Term & Termination . This DPA will remain in full force and effect as long as the Agreement remains in effect. Any provision of this DPA that expressly or impliedly shall come into or continue in force on or after the termination of the Agreement in order to protect Personal Data will remain in full force and effect. If a change in any Data Protection Law prevents either party from fulfilling all or part of its Agreement obligations, the parties will suspend the processing of Personal Data until such processing complies with the new requirements. If the parties are unable to bring Personal Data processing into compliance with the Data Protection Laws within thirty (30) days, they may terminate the Agreement on written notice to the other Party without liability.
Modification. In the event of a change in Data Protection Law, the Parties agree to negotiate in good faith to amend this DPA as is reasonable and appropriate given the change in Data Protection Law.
US Biometric Annex
If Licensee is offering its services and collecting and processing the Biometric Data (as defined below) of Data Subjects within the United States of America, the terms and conditions of this Annex shall apply in addition to those of the DPA above. Defined terms not defined below shall have the same meaning as those in the DPA.
Biometric Data Processing
Definitions:
“Biometric Data” means any information, regardless of how it is captured, converted, stored, or shared, based on an individual’s retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry.
“Biometric Law” means any applicable law or regulation that governs the collection and processing of an end-user’s Biometric Data; this may include the following laws: 740 ILCS 14/10 et seq., Rev. Code Wash. § 19.375.010 et seq., and Tex. Bus. & Com. Code § 503.001.
“Biometric Services” means functions involving Biometric Data processed by Daon on behalf of Licensee.
“Biometric Users” means the end-users of Services for the processing of their biometric data.
Biometric Services Requirements. Before Licensee or a Biometric User is permitted to use Biometric Services in a jurisdiction where laws and regulations potentially govern such use, Licensee will comply with all requirements imposed by applicable Biometric Law and the requirements of this annex.. To the extent there is a conflict between the requirements herein and Biometric Law, Licensee will comply with the applicable Biometric Law.
Biometric Data Policy. Licensee will implement, distribute and make available to the public, a written policy establishing the Licensee’s policy with respect to the use of Biometric Data. Such policy will include:
a retention schedule and guidelines for permanently destroying Biometric Data; and
a commitment to destroy Biometric Data when the initial purpose for collecting or obtaining such identifiers or information has been satisfied or within three (3) years of the individual’s last interaction with Licensee, whichever occurs first; and
any additional required elements as required by applicable Biometric Law.
Biometric User Notice and Consent. Licensee will provide notice and procure and retain appropriate written Consents or releases from Biometric Users in the manner and to extent the same are required by applicable law, including:
notifying Biometric Users in writing that Licensee, its vendors, and/or Daon are collecting, capturing, or otherwise obtaining Biometric Users’ Biometric Data; that Licensee is providing such Biometric Information to its vendors, including to Daon; and specifying the purpose(s) and length of time for which Biometric User’s Biometric Data is being collected, stored, and used; and
obtaining a written release or Consent from Biometric Users (or their legally authorized representative) authorizing Licensee and its vendors (including Daon) to collect, store, and use the individual’s Biometric Data for the specific purpose disclosed by Licensee (which shall include all purposes described in this Agreement), and authorizing Licensee to provide such Biometric Data to its vendors (including Daon); and if requested by Daon, providing to Daon copies of the required Consents or releases collected and retained by Licensee, and/or certifying to Daon that such Consents or releases have been obtained.
Retention and Purging of Biometric Data. Licensee will work with Daon to ensure that Biometric Data is retained and purged in accordance with applicable Biometric Law. In the absence of such cooperation, Daon will delete all Biometric either in accordance with it standard retention policy or at the termination of the Agreement, whichever is earlier.. To the extent necessary for the purging or deletion of such Biometric Data, Licensee agrees to provide timely notification to Daon of the satisfaction of the purpose for which Biometric Data was collected with respect to any given Biometric User. Daon is not responsible for Licensee’s failure to provide timely notification of the termination of the satisfaction of the purpose for which Biometric Data was collected with respect to any given Biometric User.
Storage of Biometric Data. Licensee agrees that it shall use a reasonable standard of care consistent with potentially applicable law to store, transmit and protect from disclosure any Biometric Data. Such storage, transmission, and protection from disclosure shall be performed in a manner that is the same as or more protective than the manner in which the Licensee stores, transmits and protects from disclosure other confidential and sensitive information, including personal information that can be used to uniquely identify an individual or an individual’s account or property, such as genetic markers, genetic testing information, account numbers, PINs, driver’s license numbers and social security numbers.
Additional Termination Provisions for Biometric Services. If Daon determines that Licensee has failed to comply with any potentially applicable Biometric Law or regulations applicable to the Biometric Services, Daon may, in its sole discretion and upon written notice to Licensee, immediately suspend or terminate the Biometric Services.
Biometric Indemnity. Licensee agrees to defend, indemnify and hold harmless Daon and any of Daon’s affiliates, subsidiaries, directors, officers, employees, representatives, and agents from and against any claim (including but not limited to any class action litigation) demand, cause of action, loss, settlement, fines, fees, penalties, regulatory investigation or enforcement action, judgment, liability, and expenses related thereto (including but not limited to reasonable fees and disbursements of attorneys and other professional advisors) resulting from, arising out of or relating to any act or omission by Licensee or its vendors or subcontractors that violates or is alleged to violate any Biometric Law or that causes or results in Daon violating or alleging violating any Biometric Law, including, but not limited to alleged or actual failure to secure advance, adequate, express, written, verifiable consent from data subjects relating to the collection, use, processing, or disclosure of personal data or biometric information.
Arbitration Requirement. Licensee must ensure that all disputes with Users based in the United States regarding the provision of the Services and/or Software (including the processing of biometric information) are pursued through individual arbitration as opposed to proceedings in US federal or state courts. To achieve this, an arbitration clause containing a non-severable class action waiver must be incorporated in Licensee’s terms and conditions with Users based in the United States expressly naming Daon as a third-party beneficiary entitled to enforce the individual arbitration clause containing the non-severable class action waiver.
ANNEX 1
DAON DATA PROCESSING MATRIX
Daon will process personal data for the services purchased by Licensee and set out in its Order in accordance with the following:
Subject Matter	Nature & Purpose of Processing	Data Subjects	Personal Data Types	Duration of Processing	Sub-Processors	Location of Data / Transfers
TrustX
(Daon hosted)
xProof:
(onboarding verification)
Daon will analyze face / document images in order to authenticate / verify the individual / document (identity proofing).
Individuals utilizing the Services
Licensee Employees
Data submitted to the system, extracted from an ID document or an external data system which may include:
Name
date of birth
address
ID document details such as document number, issuance and expiry dates, etc.
Any other details printed on ID documents
Non-ID document images
Other meta-data that is derived during the identity verification process (e.g. IP address)
Data retrieved from/provided by (optional) integrated third party services where we agree such a third party is to be used.
Licensee end-user identifier
Special Category Personal Data (i.e. Biometric Data):
Face Images & Biometric templates
Identity Document Images
Term of the Agreement
Daon Affiliates
Amazon Web Services (hosting)
EU, USA, Serbia, Australia
TrustX
(Daon hosted)
xFace:
(facial authentication)
Daon will analyze face images in order to authenticate / verify the individual.
Individuals utilizing the Services
Licensee Employees
Special Category Personal Data (i.e. Biometric Data):
Face Images
Facial biometric templates
Term of the Agreement
Daon Affiliates
Amazon Web Services (hosting)
EU, USA, Serbia, Australia
TrustX
(Daon hosted)	xProof:
(document verification)Daon will analyze document images and data in order to authenticate / verify the document
Individuals utilizing the Services
Licensee Employees
Data submitted to the system, extracted from an ID document or an external data system which may include:
Name
date of birth
address
ID document details such as document number, issuance and expiry dates, etc.
Any other details printed on ID documents
Non-ID document images
Other meta-data that is derived during the identity verification process (e.g. IP address)
Data retrieved from/provided by (optional) integrated third party services where we agree such a third party is to be used.
Licensee end-user identifier
Special Category Personal Data (i.e. Biometric Data):
Face Images & Biometric templates
Identity Document Images
Term of the Agreement
Daon Affiliates
Amazon Web Services (hosting)
EU, USA, Serbia, Australia
TrustX
(Daon hosted)
Authentication: voice
Daon will analyze voice recordings and voiceprints in order to authenticate / verify the individual.
Individuals utilizing the Services
Licensee Employees
Special Category Personal Data (i.e. Biometric Data):
Voiceprints
Voice recordings
Term of the Agreement
Daon Affiliates
Amazon Web Services (hosting)
EU, USA, Serbia, Australia
TrustX
(Daon hosted)
Authentication: FIDO*
Individuals utilizing the Services
Licensee Employees
N/A	Term of the Agreement	N/A	N/A
TrustX
(Daon hosted)
Support services:
Daon will provide technical support for its services.
Individuals utilizing the Services
Licensee Employees
Data submitted to the system, extracted from an ID document or an external data system which may include:
Name
date of birth
address
ID document details such as document number, issuance and expiry dates, etc.
Any other details printed on ID documents
Non-ID document images
Other meta-data that is derived during the identity verification process (e.g. IP address)
Data retrieved from/provided by (optional) integrated third party services where we agree such a third party is to be used.
Licensee end-user identifier
Special Category Personal Data (i.e. Biometric Data):
Face Images & Biometric templates
Identity Document Images
Term of the Agreement
Daon Affiliates
Amazon Web Services (hosting)
EU, USA, Serbia, Australia
IdentityX
(Daon hosted)	xProof (onboarding)
Individuals utilizing the Services
Licensee Employees
Data submitted to the system, extracted from an ID document or an external data system which may include:
Name
date of birth
address
ID document details such as document number, issuance and expiry dates, etc.
Any other details printed on ID documents
Non-ID document images
Other meta-data that is derived during the identity verification process (e.g. IP address)
Data retrieved from/provided by (optional) integrated third party services where we agree such a third party is to be used.
Licensee end-user identifier
Special Category Personal Data (i.e. Biometric Data):
Face Images & Biometric templates
Identity Document Images
Term of the Agreement
Daon Affiliates
Amazon Web Services (hosting)
EU, USA, Serbia, Australia
IdentityX
(Daon hosted)	xAuth (non-FIDO) (authentication):
Daon will analyze self-images and documents order to authenticate / verify the individual.
Individuals utilizing the Services
Licensee Employees
Data submitted to the system, extracted from an ID document or an external data system which may include:
Name
date of birth
address
ID document details such as document number, issuance and expiry dates, etc.
Any other details printed on ID documents
Non-ID document images
Other meta-data that is derived during the identity verification process (e.g. IP address)
Data retrieved from/provided by (optional) integrated third party services where we agree such a third party is to be used.
Licensee end-user identifier
Special Category Personal Data (i.e. Biometric Data):
Face Images & Biometric templates
Identity Document Images
Term of the Agreement
Daon Affiliates
Amazon Web Services (hosting)
EU, USA, Serbia, Australia
IdentityX
(Daon hosted)	xVoice (voice authentication :
Daon will analyze voice prints order to authenticate / verify the individual.
Individuals utilizing the Services
Licensee Employees
Voiceprints
Voice recordings
Term of the Agreement
Daon Affiliates
Amazon Web Services (hosting)
EU, USA, Serbia, Australia
IdentityX
(Daon hosted)	Support services
Individuals utilizing the Services
Licensee Employees
Data submitted to the system, extracted from an ID document or an external data system which may include:
Name
date of birth
address
ID document details such as document number, issuance and expiry dates, etc.
Any other details printed on ID documents
Non-ID document images
Other meta-data that is derived during the identity verification process (e.g. IP address)
Data retrieved from/provided by (optional) integrated third party services where we agree such a third party is to be used.
Licensee end-user identifier
Special Category Personal Data (i.e. Biometric Data):
Face Images & Biometric templates
Identity Document Images
Term of the Agreement
Daon Affiliates
Amazon Web Services (hosting)
EU, USA, Serbia, Australia
IdentityX
(Daon hosted)	xAuth (FIDO)*
Individuals utilizing the Services
Licensee Employees
N/A	Term of the Agreement	N/A	N/A
IdentityX
(Customer hosted)**	Support services
Licensee Employees
Individuals utilizing Licensee’s services
Data submitted to the system, extracted from an ID document or an external data system which may include:
Name
date of birth
address
ID document details such as document number, issuance and expiry dates, etc.
Any other details printed on ID documents
Non-ID document images
Other meta-data that is derived during the identity verification process (e.g. IP address)
Data retrieved from/provided by (optional) integrated third party services where we agree such a third party is to be used.
Licensee end-user identifier
Special Category Personal Data (i.e. Biometric Data):
Face Images & Biometric templates
Identity Document Images
Term of the Agreement
Daon Affiliates	EU, USA, Serbia, Australia
*FIDO authentication does not involved Daon processing any personal data as the authentication is done in the user’s phone.
** Customer-hosted services do not involve Daon processing any personal data except for the provision of support services.