Effective 2026-08-11 · Last updated 2026-08-11
This Data Processing Addendum ("DPA") forms part of the agreement between The Holding Company ("Processor," "we") and a business customer ("Controller," "you") using USERNAME.md for organization or enterprise purposes, and applies where we process personal data on your behalf.
1. Roles & scope
For end-user account data that we determine the purposes of, we act as an independent controller (see our Privacy Policy). For personal data you provide or configure through org/enterprise features and instruct us to process, we act as your processor under this DPA.
2. Processing details
| Item | Detail |
|---|---|
| Subject matter | Provision of the USERNAME.md identity Service |
| Duration | Term of the agreement plus deletion/return period |
| Nature & purpose | Hosting, serving, signing, and forwarding identity records |
| Data types | Handles, names, emails, profile links, public keys, claims |
| Data subjects | Your members, employees, or authorized users |
3. Our obligations
- Process personal data only on your documented instructions, including for transfers, unless required by law;
- Ensure persons authorized to process are bound by confidentiality;
- Implement appropriate technical and organizational security measures;
- Assist you, taking into account the nature of processing, with data-subject requests and with your security, breach-notification, and impact-assessment obligations;
- Notify you without undue delay after becoming aware of a personal-data breach;
- Delete or return personal data at the end of the agreement, subject to legal retention.
4. Sub-processors
You authorize us to engage sub-processors to provide the Service, including payment (Stripe), email delivery/forwarding, hosting/CDN, and analytics. We impose data-protection terms on sub-processors no less protective than this DPA and remain responsible for their performance. We will inform you of intended changes and give you the opportunity to object.
5. International transfers
Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on an adequacy decision or Standard Contractual Clauses (with the UK Addendum where applicable), which are incorporated by reference.
6. Audits
We will make available information reasonably necessary to demonstrate compliance and allow for audits on reasonable notice, subject to confidentiality and no undue disruption.
7. Liability & conflict
Liability under this DPA is subject to the limitations in the main agreement/Terms. If there is a conflict on data protection, this DPA controls.
8. Contact
To execute a countersigned DPA or add specific SCC modules, contact [email protected].