Data Processing Addendum
Last updated September 17, 2026
This Data Processing Addendum, including its Annexes (“DPA”), forms part of and is incorporated into the written or electronic agreement between IRDB LLC d/b/a IRCODE (“IRCODE”) and the customer identified in that agreement (“Customer”) governing Customer's access to and use of the IRCODE Services (the “Agreement”). This DPA applies to the extent IRCODE Processes Customer Personal Data in connection with the Agreement.
If there is a conflict between this DPA and the Agreement with respect to the subject matter of this DPA, this DPA controls. Except as expressly modified by this DPA, the Agreement remains in full force and effect.
1. Definitions
1.1 Defined Terms. Capitalized terms not defined in this DPA have the meanings given in the Agreement. The following terms apply to this DPA:
- “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Personal Data Breach,” “Processing” (and “Process”) and “Supervisory Authority” have the meanings given in the GDPR and, where applicable, the equivalent terms under the UK GDPR.
- “Customer Personal Data” means Personal Data that IRCODE Processes solely on behalf of, and under the documented instructions of, Customer in IRCODE's capacity as a Processor in connection with the provision of the Services under the Agreement. Customer Personal Data does not include Personal Data that IRCODE Processes as an independent Controller as described in Section 3.3.
- “Data Protection Laws” means all laws and regulations applicable to the Processing of Personal Data under this DPA, including, to the extent applicable, the GDPR, the UK GDPR, and the UK Data Protection Act 2018.
- “EU SCCs” means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- “GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation).
- “Restricted Transfer” means a transfer of Customer Personal Data that is subject to the transfer restrictions of the GDPR or UK GDPR and for which no adequacy decision or other lawful transfer basis (other than the SCCs) applies.
- “Services” means the products and services provided by IRCODE under the Agreement, including IRCODE's proprietary computer-vision and image-recognition technology and associated recognition, routing, analytics, attribution, and reporting functionality, whether delivered directly, through an SDK, or through integration into a Customer or third-party application, operating system, or platform.
- “Sub-processor” means a third party engaged by IRCODE to Process Customer Personal Data.
- “UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018, in force from 21 March 2022.
- “UK GDPR” has the meaning given in the UK Data Protection Act 2018.
2. Scope and Applicability
2.1 Application. This DPA applies only to the extent that IRCODE Processes Customer Personal Data as a Processor on behalf of Customer. It does not apply to Personal Data that IRCODE Processes as an independent Controller (Section 3.3) or to any data that is not Personal Data.
2.2 No Automatic Application. Publication of this DPA on IRCODE's website, and its availability alongside IRCODE's Terms and Conditions and Privacy Policy, do not by themselves amend any existing agreement between IRCODE and any customer or cause this DPA to apply to any relationship. This DPA governs only where it is incorporated into an Agreement by reference or by execution, or otherwise expressly agreed by the parties.
2.3 Variable and Configurable Processing. The categories, nature, and extent of Processing depend on the Services ordered and on the features, integrations, and configurations enabled by Customer. Accordingly, a category of Customer Personal Data described in Annex I applies only to the extent that Customer's configuration and use of the Services actually results in IRCODE Processing that category on Customer's behalf.
3. Roles of the Parties
3.1 Customer as Controller. As between the parties, Customer is the Controller (or, where Customer acts on behalf of a third-party controller, the Processor) of Customer Personal Data, and IRCODE is the Processor, in each case with respect to Processing carried out by IRCODE on Customer's documented instructions.
3.2 Customer Responsibilities. Customer is responsible for the accuracy, quality, and legality of Customer Personal Data and for the means by which Customer acquired it; for establishing and maintaining a lawful basis (including any required consents and notices to Data Subjects) for the Processing contemplated by the Agreement; and for the accuracy of its Processing instructions.
3.3 IRCODE as Independent Controller. To the extent IRCODE Processes Personal Data for purposes for which IRCODE independently determines the purposes and means of Processing, IRCODE acts as an independent Controller with respect to such Processing, and such Processing is outside the scope of this DPA. Nothing in this Section expands IRCODE's rights to Process Personal Data beyond the rights granted under the Agreement or applicable law.
3.4 Joint Controllers. Nothing in this DPA, by itself, establishes the parties as joint Controllers. To the extent the parties jointly determine the purposes and means of a particular Processing activity and therefore constitute joint Controllers under applicable Data Protection Laws, that Processing is outside the Processor provisions of this DPA, and the parties will address their respective responsibilities with respect to such Processing as required by Article 26 GDPR, including through the Agreement, an applicable SOW, or another written arrangement.
4. Processing of Customer Personal Data
4.1 Documented Instructions. IRCODE will Process Customer Personal Data only on Customer's documented instructions, including with respect to international transfers, unless required to do otherwise by applicable law to which IRCODE is subject; in such a case, IRCODE will inform Customer of that legal requirement before Processing, unless the law prohibits such information on important grounds of public interest. The Agreement (including this DPA and any order form, SOW, or configuration selected by Customer) constitutes Customer's complete and final documented instructions for the Processing of Customer Personal Data.
4.2 Lawfulness of Instructions. IRCODE will inform Customer if, in IRCODE's reasonable opinion, an instruction infringes Data Protection Laws, provided that IRCODE is not obligated to conduct a legal review of the adequacy of Customer's instructions and this does not derogate from Customer's responsibilities under Section 3.2.
4.3 Special Categories of Personal Data. The Services are not intended for the Processing of special categories of Personal Data within the meaning of Article 9 GDPR. Customer will not provide, or configure the Services to Process, special categories of Personal Data as Customer Personal Data unless IRCODE expressly agrees otherwise in writing and subject to any additional measures the parties agree are required.
4.4 AI and Model Use. With respect to Customer Personal Data: (a) IRCODE will not use Customer Personal Data to train third-party or publicly available generative artificial intelligence models or large language models; (b) IRCODE will not disclose Customer Personal Data to a third-party artificial intelligence provider for that provider's own model-training purposes; and (c) nothing in this DPA grants IRCODE any right to use Customer Personal Data, Customer Content, or Customer Confidential Information for model training, development, tuning, or improvement beyond the rights IRCODE has under the Agreement and Customer's documented instructions. This Section 4.4 does not restrict the operation, maintenance, tuning, support, or improvement of IRCODE's proprietary computer-vision and image-recognition technology where that Processing is permitted by the Agreement and Customer's documented instructions.
4.5 Details of Processing. The subject matter, duration, nature and purposes of the Processing, the categories of Data Subjects, and the categories of Customer Personal Data are described in Annex I.
5. Confidentiality
5.1 Confidentiality of Processing. IRCODE will ensure that personnel authorized to Process Customer Personal Data are subject to appropriate obligations of confidentiality (whether contractual or statutory) and Process Customer Personal Data only in accordance with Customer's instructions, and will limit access to Customer Personal Data to personnel who need access to provide the Services.
6. Security
6.1 Technical and Organizational Measures. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risks to Data Subjects, IRCODE will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as further described in Annex II.
6.2 Evolution of Measures. Customer acknowledges that the measures in Annex II are subject to technical progress and development, and that IRCODE may update or modify them from time to time, provided that such updates do not materially decrease the overall level of protection for Customer Personal Data during the term of the Agreement.
6.3 Customer Security Responsibilities. Customer is responsible for its own use and configuration of the Services, including implementing appropriate measures within its own environment and enabling security-relevant configuration options made available by IRCODE.
7. Personal Data Breach
7.1 Breach Notification. IRCODE will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
7.2 Breach Information. To the extent available to IRCODE, such notice will describe the nature of the Personal Data Breach, the likely consequences, and the measures taken or proposed to address it, and will be supplemented as further information becomes available.
7.3 Cooperation. IRCODE will provide Customer with reasonable assistance and cooperation to enable Customer to meet any obligations it may have to notify Supervisory Authorities or affected Data Subjects. IRCODE's notification of or response to a Personal Data Breach is not an acknowledgment of fault or liability.
8. Assistance to Customer
8.1 Data Subject Requests. Taking into account the nature of the Processing, IRCODE will provide reasonable assistance to Customer, by appropriate technical and organizational measures and insofar as possible, to enable Customer to respond to requests from Data Subjects to exercise their rights under Data Protection Laws. If IRCODE receives such a request directly from a Data Subject relating to Customer Personal Data, IRCODE will, unless legally prohibited, promptly inform the Data Subject to direct the request to Customer or forward the request to Customer, and will not otherwise respond except on Customer's instructions.
8.2 DPIAs and Consultation. Taking into account the nature of the Processing and the information available to IRCODE, IRCODE will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with Supervisory Authorities under Articles 35 and 36 GDPR (and equivalent provisions), in each case solely in relation to the Processing of Customer Personal Data by IRCODE.
8.3 Fees for Assistance. IRCODE may charge a reasonable fee for assistance under this Section 8 and under Section 9.3 to the extent the requested assistance exceeds what IRCODE is required to provide free of charge under Data Protection Laws or requires material effort, provided IRCODE notifies Customer of such fees in advance where practicable.
9. Audits and Compliance
9.1 Compliance Information. IRCODE will make available to Customer information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA, primarily through IRCODE's then-current third-party audit reports, certifications, and security documentation, subject to appropriate confidentiality undertakings.
9.2 Audits. Where the information made available under Section 9.1 is not sufficient to demonstrate compliance, IRCODE will allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer, subject to the following: (a) audits occur no more than once per twelve (12) month period, except where required by a Supervisory Authority or following a Personal Data Breach affecting Customer Personal Data; (b) Customer provides at least thirty (30) days' prior written notice; (c) audits are conducted during regular business hours, subject to IRCODE's reasonable security and confidentiality policies, and in a manner that does not disrupt IRCODE's operations or compromise the security or confidentiality of other customers' data; (d) the auditor is bound by appropriate confidentiality obligations and is not a competitor of IRCODE; and (e) Customer bears the costs of such audit. The scope of any audit is limited to information and systems relevant to the Processing of Customer Personal Data.
9.3 Audit Cooperation. IRCODE will provide reasonable cooperation in connection with audits performed under this Section 9.
10. Sub-processors
10.1 General Authorization. Customer provides general authorization for IRCODE to engage Sub-processors to Process Customer Personal Data, subject to this Section 10. A list of IRCODE's current Sub-processors is set out in, or made available as described in, Annex III.
10.2 Flow-Down Obligations. IRCODE will impose on each Sub-processor, by written contract, data protection obligations that are substantially equivalent to those in this DPA to the extent applicable to the nature of the services provided by that Sub-processor. IRCODE remains responsible for the performance of each Sub-processor's obligations to the same extent IRCODE would be liable if performing the services directly.
10.3 Changes and Objection. IRCODE will provide Customer with notice of the addition or replacement of a Sub-processor (which may be given by updating Annex III or an online list, or by email where Customer has subscribed to notifications), with reasonable advance notice before the new Sub-processor begins Processing Customer Personal Data. Customer may object on reasonable data-protection grounds within fifteen (15) days of such notice. The parties will work together in good faith to resolve the objection. If the parties cannot reasonably resolve the objection, Customer may, as its sole and exclusive remedy, terminate the portion of the Services that cannot be provided without the objected-to Sub-processor, in accordance with the termination provisions of the Agreement.
11. International Transfers
11.1 General. IRCODE is established in the United States and Processes Customer Personal Data in the United States and in other locations where IRCODE or its Sub-processors operate. IRCODE will not make a Restricted Transfer of Customer Personal Data except in accordance with this Section 11. IRCODE does not represent that it participates in the EU–U.S. Data Privacy Framework or any other certification unless separately and expressly stated in writing.
11.2 EU Transfers. Where a Restricted Transfer of Customer Personal Data is subject to the GDPR, the EU SCCs are incorporated into this DPA by reference and apply, with the applicable Module determined by the roles of the parties in the relevant transfer: (a) Module Two (Controller to Processor) applies where the data exporter is a Controller and IRCODE, as data importer, is a Processor with respect to the transfer; (b) Module Three (Processor to Processor) applies where the data exporter is a Processor and IRCODE, as data importer, is a Sub-processor with respect to the transfer; and (c) Module One (Controller to Controller) applies where each party is an independent Controller with respect to the transfer, in which case Module One applies as separately agreed by the parties for the relevant independent-controller transfer.
11.3 EU SCC Selections. For the EU SCCs so incorporated: (a) the optional docking clause in Clause 7 applies; (b) in Clause 9, Option 2 (general written authorization) applies, with the notice period specified in Section 10.3; (c) the optional language in Clause 11 does not apply; (d) in Clauses 17 and 18, the SCCs are governed by the law of the Republic of Ireland and disputes are resolved before the courts of the Republic of Ireland; and (e) for transfers under Module Two or Module Three, Annexes I, II, and III to the EU SCCs are populated with the information in Annexes I, II, and III to this DPA and the details of the parties as set out in the Agreement. For transfers under Module One, the corresponding SCC annexes are completed as separately agreed by the parties for the relevant independent-controller transfer.
11.4 UK Transfers. Where a Restricted Transfer is subject to the UK GDPR, the UK Addendum is incorporated by reference and applies to the EU SCCs as modified for the applicable Module. Table 1 of the UK Addendum is completed with the parties' details in the Agreement; Tables 2 and 3 are completed by reference to the applicable EU SCCs and Annexes as set out above; and in Table 4, neither party may end the UK Addendum except as set out in Section 19 of the UK Addendum.
11.5 Precedence and Invalidation. In the event of a conflict between this DPA and the SCCs, the SCCs prevail with respect to Restricted Transfers. IRCODE may adopt an alternative lawful transfer mechanism for any Restricted Transfer, in which case that mechanism applies in place of the mechanism in this Section 11 to the extent it provides a valid basis for the transfer. If a transfer mechanism relied on under this Section 11 is held invalid or is required to be supplemented, suspended, or restricted by a competent authority or applicable law, the parties will cooperate in good faith to implement an alternative mechanism, additional measures, or restrictions on Processing so as to permit the lawful continuation of the affected Processing.
12. Deletion or Return
12.1 Deletion or Return. Upon expiry or termination of the Agreement, or otherwise on Customer's written request, IRCODE will, at Customer's election, delete or return Customer Personal Data Processed on Customer's behalf and delete existing copies, except to the extent that applicable law requires IRCODE to retain some or all of the Customer Personal Data, or to the extent the data has been irreversibly anonymized such that it no longer constitutes Personal Data under applicable Data Protection Laws.
12.2 Backup and Archival Systems. Customer Personal Data residing in archival or backup systems maintained in accordance with IRCODE's standard backup and retention practices need not be deleted at the time of the request, provided that such Personal Data remains protected in accordance with this DPA and is not further Processed except as required for backup and restoration, security, legal compliance, or similar limited purposes, and is deleted or overwritten in the ordinary course of IRCODE's backup cycle.
12.3 Retention Criteria. The timing and manner of deletion, return, and retention will be determined by the applicable Agreement or Customer configuration, Customer's documented instructions, the necessity of the data for provision of the Services, and applicable legal requirements. Where IRCODE retains Customer Personal Data as permitted under this Section 12, IRCODE will continue to protect it in accordance with this DPA and will Process it only as necessary for the applicable retention purpose.
13. Liability and Relationship to the Agreement
13.1 Limitation of Liability. Each party's and its affiliates' aggregate liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the exclusions and limitations of liability set out in the Agreement, to the fullest extent permitted by applicable law. Any reference in the Agreement to the liability of a party means the aggregate liability of that party and its affiliates under the Agreement and this DPA together.
13.2 No Additional Rights. This DPA does not grant Customer any rights over IRCODE's technology, models, analytics, aggregated or de-identified data, intellectual property, systems, or security materials beyond those Customer has under the Agreement.
13.3 Legal Compliance. Nothing in this DPA limits either party's ability to comply with applicable law or to respond to lawful and binding requests from public authorities.
14. General
14.1 Term. This DPA takes effect on the effective date of the Agreement (or, if later, when incorporated into the Agreement) and continues until IRCODE ceases to Process Customer Personal Data.
14.2 Governing Law. Except as otherwise required for the SCCs under Section 11, this DPA is governed by the governing law of the Agreement.
14.3 Severability. If any provision of this DPA is held invalid or unenforceable, the remainder of this DPA remains in effect.
Annex I - Description of Processing
A. List of Parties. The parties' roles apply as relevant to the particular Processing and transfer, consistent with Section 11.
- Data exporter: Customer, as identified in the Agreement, acting as Controller or Processor of Customer Personal Data with respect to the relevant transfer.
- Data importer: IRDB LLC d/b/a IRCODE, acting as Processor or Sub-processor of Customer Personal Data with respect to the relevant transfer. Contact: privacy@ircode.com.
B. Description of Transfer. The following applies only to the extent applicable to the particular Services and Customer deployment or configuration.
Categories of Data Subjects
- Individuals who use, view, scan, or otherwise interact with the IRCODE-enabled Services and Customer content or platform (e.g., viewers, application users, and consumers);
- Customer's authenticated account holders or subscribers, where Customer enables login or account linking; and
- Customer's personnel or authorized users who administer or access the Services on Customer's behalf.
Categories of Customer Personal Data
- Device, session, and account identifiers used to engage with the Services and Customer content (which may include device identifiers, hardware or serial identifiers, user-logging identifiers, and subscription identifiers passed by Customer);
- Network information, including IP address and user-agent string, and information derived from them (such as approximate or coarse location);
- Interaction and content-engagement data, such as scan and recognition events, the content or asset scanned, playback or viewing context, and associated analytics and attribution data; and
- Where enabled or supplied by Customer, additional identifiers or account-linked information that Customer instructs IRCODE to Process on its behalf.
Special Categories of Personal Data. None. The Services are not intended for, and Customer will not configure the Services to Process, special categories of Personal Data as Customer Personal Data except as expressly agreed in writing under Section 4.3.
Frequency of Transfer. On a continuous basis, as necessary for the provision of the Services.
Nature and Purpose of Processing. Provision of the Services, including content recognition, routing to associated experiences or destinations, analytics, attribution, and reporting, and related support, in each case on Customer's behalf and in accordance with the Agreement and Customer's instructions.
Duration of Processing. For the term of the Agreement and thereafter as set out in Section 12, subject to the retention criteria in Section 12.3.
C. Competent Supervisory Authority. As determined under Section 11 and the applicable EU SCCs (default: the Irish Data Protection Commission), or, for transfers subject to the UK GDPR, the UK Information Commissioner's Office.
Annex II - Technical and Organizational Measures
IRCODE maintains the following technical and organizational measures, as applicable to the Services and subject to Section 6.2. Certain measures are provided by or shared with IRCODE's infrastructure providers.
- Encryption. Encryption of Personal Data in transit using TLS/HTTPS, and encryption of Personal Data at rest, in each case using industry-standard encryption.
- Access Control. Role-based access controls applied on a least-privilege basis; enforced multi-factor authentication for administrative and production access; and periodic access reviews.
- Infrastructure and Hosting Security. Hosting on established cloud infrastructure providers offering physical and environmental security controls, with physical security of data centers being the responsibility of those providers; network protections including edge security, web application firewall, and distributed-denial-of-service mitigation provided through IRCODE's edge provider.
- Segregation. Logical separation of data as appropriate to the architecture of the Services.
- Secure Development and Change Management. Change-management and secure development lifecycle practices.
- Monitoring and Incident Response. Logging, monitoring, and documented incident-response procedures.
- Vendor Management. A vendor and Sub-processor management process, including diligence and contractual data-protection requirements.
- Retention and Deletion. Documented data-retention and secure-deletion practices consistent with Section 12.
- Resilience. Business continuity and disaster recovery arrangements leveraging cloud infrastructure resilience.
Annex III - Sub-processors
IRCODE engages the following Sub-processors to support the provision of the Services. Whether a given Sub-processor Processes Customer Personal Data depends on the Services and the features and configurations enabled by Customer. This list may be updated in accordance with Section 10.3.
- Google Cloud Platform (Google LLC). Cloud hosting and infrastructure supporting the Services.
- Cloudflare, Inc.. Edge network, content delivery, web application firewall, and distributed-denial-of-service mitigation.
- Qdrant Cloud. Vector database and recognition-infrastructure services supporting IRCODE's image-recognition functionality.
- Firebase Authentication / Google Identity. Authentication services, used only where Customer enables account, login, or authenticated-user functionality.
Processing locations may vary by Service and Customer configuration, and Customer Personal Data may be Processed in the United States and in other locations where IRCODE or the applicable Sub-processor operates.