Data processing agreement
Last updated: 5 August 2026
When your systems submit identity documents to the GoParse API, you determine why and how that personal data is processed — which makes you the controller and LIZZIT Michele your processor within the meaning of Article 28 GDPR. This agreement (“DPA”) governs that processing and forms part of our terms of service.
1. Subject matter and duration
The subject matter is the transient, automated parsing of identity documents (passports, identity cards, driving licences) submitted by the customer via the API, in order to return structured person data to the customer. The DPA applies for as long as the customer holds an account and ends automatically when the account is closed.
2. Nature and purpose of processing
Processing consists of receiving document images over an encrypted connection, extracting and validating the data they contain (including ICAO 9303 MRZ check-digit validation), merging front and back sides where applicable, and returning the result in the API response. Processing is fully automated, happens exclusively in memory, and serves no purpose other than producing the response the customer requested. Document contents are not used for training, analytics, or any purpose of our own.
3. Categories of data subjects and personal data
- Data subjects: the holders of the identity documents the customer submits.
- Personal data: the contents of identity documents — photographs of the document and the fields extracted from it, such as family and given names, date of birth, sex, place of birth, citizenship, document type and number, and issuing authority. Identity document data warrants special care: it can reveal citizenship and is a prime target for identity fraud, which is why our architecture never persists it.
4. Documented instructions
We process document contents only on the customer's documented instructions. Each API request constitutes such an instruction; additional instructions require written form (email suffices). We will inform the customer if, in our view, an instruction infringes the GDPR. If EU or member state law requires us to process beyond the customer's instructions, we will inform the customer before processing unless that law prohibits it.
5. Confidentiality
Persons authorised to operate the processing systems are bound by contractual confidentiality obligations. By design, personnel have no routine access to document contents at all — the data exists only in memory for the seconds a request is in flight.
6. Technical and organisational measures
Taking into account the state of the art and the risks of processing identity documents, we implement in particular:
- In-memory-only processing — document images and extracted fields are held exclusively in volatile memory while a request is processed;
- no persistence of document contents — no writes to disk, databases, backups, caches or log files;
- TLS encryption in transit for all API and dashboard traffic;
- hashed API keys — credentials are stored only as hashes and cannot be recovered from our systems;
- access controls — least-privilege access to production systems for authorised personnel only;
- metadata-only logging — operational logs record document type, counts, timings and status codes, never contents.
7. Sub-processors
The customer authorises the following sub-processors. We will announce any intended change in advance, giving the customer the opportunity to object.
| Sub-processor | Purpose | Location & safeguards |
|---|---|---|
| Stripe | Payments, subscription billing and invoicing | EU / US — EU Standard Contractual Clauses |
| Hosting provider | Infrastructure the service runs on | EU |
Note that Stripe processes billing data only — document contents are processed solely on EU hosting infrastructure and never reach any other party.
8. Assistance and data subject rights
We assist the customer, insofar as possible, in fulfilling data subject requests and in meeting the obligations of Articles 32–36 GDPR (security, breach notification, data protection impact assessments). In practice, requests concerning document contents will usually be answered by the customer alone: we hold no copy of the data. We will notify the customer without undue delay after becoming aware of a personal data breach affecting the customer's data.
9. Audit rights
On request, we make available the information necessary to demonstrate compliance with Article 28 GDPR, and we allow for and contribute to audits — including inspections — conducted by the customer or an auditor mandated by the customer, with reasonable notice and during business hours.
10. Deletion on termination
Document contents require no end-of-contract deletion: they are deleted from memory when each API response is returned and are never stored. On termination of the account, we delete the remaining customer-related data (account and usage metadata) in line with the retention periods in the privacy policy, unless EU or member state law requires longer storage.
Need a countersigned DPA?
For a signed copy of this agreement — or the custom DPA that comes with enterprise agreements — email privacy@goparse.it and we will send one over.