SybilZero
  • Why SybilZero
  • How It Works
  • What We Check
  • Pricing
  • FAQ
Log In Try freeStart Free Trial →
  • Why SybilZero
  • How It Works
  • What We Check
  • Pricing
  • FAQ
  • Log In

Legal

Data Processing Addendum

Last updated 9 October 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between the Customer and Josue Kouka, a sole proprietor operating as SybilZero in British Columbia, Canada ("SybilZero"). It applies where SybilZero processes personal data on the Customer's behalf and the GDPR, the UK GDPR or a similar law applies. It applies automatically when the Customer uses the Service; a signed copy is available on request at [email protected].

1. Definitions

"Personal data", "controller", "processor", "data subject", "processing" and "supervisory authority" have the meanings in the GDPR. "Customer Personal Data" means personal data of the Customer's end users that SybilZero processes for the Customer through the Service. "Sub-processor" means a third party SybilZero engages to process Customer Personal Data.

2. Roles

The Customer is the controller of Customer Personal Data (or a processor acting for its own controller) and SybilZero is its processor. SybilZero is the controller of its own account and billing data, which the Privacy Policy covers.

3. Instructions

SybilZero processes Customer Personal Data only to provide the Service as described in Annex A, and on the Customer's documented instructions: these terms, its use of the dashboard and API, and written instructions that are consistent with them. SybilZero will tell the Customer if it thinks an instruction breaches data protection law. The Customer confirms it has a lawful basis to send the data and has given the notices the law requires.

4. Confidentiality

SybilZero ensures that anyone it authorises to process Customer Personal Data is bound by a duty of confidentiality.

5. Security

SybilZero applies the technical and organisational measures in Annex B and keeps them appropriate to the risk.

6. Sub-processors

The Customer gives general authorisation to the sub-processors in Annex C. SybilZero will tell the Customer by email at least 30 days before adding or replacing one that handles Customer Personal Data. The Customer may object on reasonable data protection grounds within that time; if the parties cannot resolve it, the Customer may end the affected Service and receive a refund of prepaid fees for the unused period. SybilZero stays responsible for its sub-processors and binds each to data protection duties no less protective than this DPA.

7. Data subject requests

SybilZero will promptly forward to the Customer any request it receives from a data subject about Customer Personal Data, and will not answer it itself except to say it has been passed on. Taking into account the nature of the processing, SybilZero will help the Customer answer requests, including by deleting individual records, which the Customer can also do in the dashboard.

8. Personal data breaches

SybilZero will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a breach affecting Customer Personal Data, with the information it has to help the Customer meet its own notification duties, and will keep it informed as the facts become clear.

9. Assistance

SybilZero will give reasonable help with the Customer's data protection impact assessments and consultations with supervisory authorities, taking into account the information available to it.

10. Deletion and return

Check records are deleted automatically after 90 days (see Annex A). When the agreement ends, SybilZero deletes the remaining Customer Personal Data within 30 days, unless the law requires it to be kept, after giving the Customer the chance to export what it needs.

11. Audits

SybilZero will give the Customer the information needed to show compliance with this DPA, and allow reasonable audits by the Customer or its auditor on 30 days' written notice, no more than once a year unless a breach or a regulator requires otherwise, during business hours, under confidentiality, and at the Customer's cost. SybilZero may first offer written answers and documentation.

12. International transfers

SybilZero is based in Canada and hosts data in the United States. Where Customer Personal Data subject to the GDPR is transferred to a country without an adequacy decision, the parties agree that the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor) or Module Three (processor to processor) are incorporated by reference, with: the Customer as data exporter and SybilZero as data importer; Clause 7 (docking) included; Option 2 (general authorisation) in Clause 9 with the notice period in section 6; the optional wording in Clause 11 omitted; Clause 17 governed by the law of Ireland; Clause 18 with the courts of Ireland; and Annexes I to III completed by Annexes A to C of this DPA. For transfers subject to the UK GDPR, the UK Addendum to those clauses is incorporated in the same way, with the same details. SybilZero will promptly tell the Customer if it can no longer meet these obligations.

13. Liability and precedence

Each party's liability under this DPA is subject to the limits in the Terms of Service, except where the law or the Standard Contractual Clauses provide otherwise. If this DPA conflicts with the Terms on data protection, this DPA prevails; if it conflicts with the Standard Contractual Clauses, they prevail.

Annex A: Details of the processing

Subject matterScoring sign-ups, logins and reward claims for signs that one person controls several accounts, and the optional exclusion list.
DurationThe term of the agreement, plus up to 30 days to delete data. Individual check records are deleted automatically after 90 days; exclusion list entries stay until the Customer removes them.
Nature and purposeReceiving, storing, hashing, comparing and scoring the data below; returning a risk score, verdict and reasons to the Customer; linking accounts within the Customer's own data.
Data subjectsThe Customer's end users: people who sign up, sign in or claim rewards on the Customer's websites or apps.
Types of personal dataEmail address; IP address and what it resolves to (country, city, time zone, network type); user agent and request headers; device fingerprint and browser signals; optional identifiers (phone number, payment-method fingerprint, payout account, crypto wallet) stored only as keyed hashes; promotion or reward identifiers; other fields the Customer chooses to send; outcomes (score, verdict, reasons); exclusion list entries and their reasons.
Special categoriesNone. The Customer must not send any.
FrequencyContinuous, each time the Customer runs a check.

Annex B: Security measures

  • Encryption in transit (TLS) on all public endpoints.
  • Optional identifiers are normalised and replaced by HMAC-SHA256 hashes under a secret key held outside the database, scoped per customer; raw values are never stored and are removed from stored metadata.
  • Passwords and API keys are stored only as hashes; API keys are scoped to a single project.
  • Logical separation of customers' data: every query is scoped to the customer's project, and account matching never crosses customers.
  • Access to production systems is restricted to the operator, with key-based authentication.
  • Automatic deletion of check records after the retention period; server logs rotated and deleted after 30 days.
  • Automated tests, dependency and vulnerability scanning in the build pipeline, and prompt patching.
  • Incident handling and customer notification as set out in section 8.

Annex C: Sub-processors

ProviderWhat it does for usData involvedLocation
Akamai Connected Cloud (Linode)Hosting of the application and its databaseAll data processed by the serviceFremont, California, United States
CloudflareDNS, proxy and content delivery for the website, and email routing for a former domainWeb requests to sybilzero.com (IP address, URL, user agent) pass through its network; the API host is DNS onlyGlobal network
IPLocate (iplocate.io)Looking up where an IP address is and what kind of network it belongs to (country, city, time zone, provider, VPN, proxy, Tor and hosting flags)IP addresses sent in checksProvider's own infrastructure
StripeSubscription billing and payments for CustomersCustomer billing contact and payment details (end users' data is not sent to Stripe)United States and Canada
Google (Google Workspace)Email and support correspondenceMessages you send usProvider's own infrastructure
jsDelivrContent delivery network that serves the open-source ThumbmarkJS library loaded by the SybilZero agent in end users' browsersEnd users' IP address and browser request details, seen by the CDN when the library is fetchedGlobal network

Questions about this page? Write to [email protected]. See also: Terms of Service, Privacy Policy, Data Processing Addendum.

SybilZero ONE PLAYER. ONE BONUS.
  • Terms
  • Privacy
  • DPA
  • API Docs
  • Support
© 2026 SybilZero