DRAFT — not yet legally reviewed. This template provides reasonable SaaS defaults aligned with the Data Protection (Jersey) Law 2018 and adjacent UK/EU norms. Items marked TODO must be filled in by the founder; the full document must be reviewed by a qualified legal adviser before publication.

Legal

Data Processing Agreement (DPA) — B2B Template

Standard processor DPA template for B2B partners — DNA laboratories, OPCLS Gateway registries, and white-label deployments — engaging ScanToProve as a data processor under the Data Protection (Jersey) Law 2018 and adjacent UK/EU laws.

Effective date: 1 March 2026Last updated: 25 February 2026

1. About this DPA template

2. Definitions

3. Scope and purpose

4. Obligations of the Processor

4.1. Detailed obligations

5. Sub-processors

6. International transfers

7. Blockchain anchoring — important caveat

8. Liability

9. Governing law

Annex 1 — Details of Processing

Annex 2 — Technical and organisational measures

Annex 3 — Authorised Sub-processors