Legal
Data Processing Addendum
Last updated 9 October 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between the Customer and Josue Kouka, a sole proprietor operating as SybilZero in British Columbia, Canada ("SybilZero"). It applies where SybilZero processes personal data on the Customer's behalf and the GDPR, the UK GDPR or a similar law applies. It applies automatically when the Customer uses the Service; a signed copy is available on request at [email protected].
1. Definitions
"Personal data", "controller", "processor", "data subject", "processing" and "supervisory authority" have the meanings in the GDPR. "Customer Personal Data" means personal data of the Customer's end users that SybilZero processes for the Customer through the Service. "Sub-processor" means a third party SybilZero engages to process Customer Personal Data.
2. Roles
The Customer is the controller of Customer Personal Data (or a processor acting for its own controller) and SybilZero is its processor. SybilZero is the controller of its own account and billing data, which the Privacy Policy covers.
3. Instructions
SybilZero processes Customer Personal Data only to provide the Service as described in Annex A, and on the Customer's documented instructions: these terms, its use of the dashboard and API, and written instructions that are consistent with them. SybilZero will tell the Customer if it thinks an instruction breaches data protection law. The Customer confirms it has a lawful basis to send the data and has given the notices the law requires.
4. Confidentiality
SybilZero ensures that anyone it authorises to process Customer Personal Data is bound by a duty of confidentiality.
5. Security
SybilZero applies the technical and organisational measures in Annex B and keeps them appropriate to the risk.
6. Sub-processors
The Customer gives general authorisation to the sub-processors in Annex C. SybilZero will tell the Customer by email at least 30 days before adding or replacing one that handles Customer Personal Data. The Customer may object on reasonable data protection grounds within that time; if the parties cannot resolve it, the Customer may end the affected Service and receive a refund of prepaid fees for the unused period. SybilZero stays responsible for its sub-processors and binds each to data protection duties no less protective than this DPA.
7. Data subject requests
SybilZero will promptly forward to the Customer any request it receives from a data subject about Customer Personal Data, and will not answer it itself except to say it has been passed on. Taking into account the nature of the processing, SybilZero will help the Customer answer requests, including by deleting individual records, which the Customer can also do in the dashboard.
8. Personal data breaches
SybilZero will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a breach affecting Customer Personal Data, with the information it has to help the Customer meet its own notification duties, and will keep it informed as the facts become clear.
9. Assistance
SybilZero will give reasonable help with the Customer's data protection impact assessments and consultations with supervisory authorities, taking into account the information available to it.
10. Deletion and return
Check records are deleted automatically after 90 days (see Annex A). When the agreement ends, SybilZero deletes the remaining Customer Personal Data within 30 days, unless the law requires it to be kept, after giving the Customer the chance to export what it needs.
11. Audits
SybilZero will give the Customer the information needed to show compliance with this DPA, and allow reasonable audits by the Customer or its auditor on 30 days' written notice, no more than once a year unless a breach or a regulator requires otherwise, during business hours, under confidentiality, and at the Customer's cost. SybilZero may first offer written answers and documentation.
12. International transfers
SybilZero is based in Canada and hosts data in the United States. Where Customer Personal Data subject to the GDPR is transferred to a country without an adequacy decision, the parties agree that the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor) or Module Three (processor to processor) are incorporated by reference, with: the Customer as data exporter and SybilZero as data importer; Clause 7 (docking) included; Option 2 (general authorisation) in Clause 9 with the notice period in section 6; the optional wording in Clause 11 omitted; Clause 17 governed by the law of Ireland; Clause 18 with the courts of Ireland; and Annexes I to III completed by Annexes A to C of this DPA. For transfers subject to the UK GDPR, the UK Addendum to those clauses is incorporated in the same way, with the same details. SybilZero will promptly tell the Customer if it can no longer meet these obligations.
13. Liability and precedence
Each party's liability under this DPA is subject to the limits in the Terms of Service, except where the law or the Standard Contractual Clauses provide otherwise. If this DPA conflicts with the Terms on data protection, this DPA prevails; if it conflicts with the Standard Contractual Clauses, they prevail.
Annex A: Details of the processing
| Subject matter | Scoring sign-ups, logins and reward claims for signs that one person controls several accounts, and the optional exclusion list. |
|---|---|
| Duration | The term of the agreement, plus up to 30 days to delete data. Individual check records are deleted automatically after 90 days; exclusion list entries stay until the Customer removes them. |
| Nature and purpose | Receiving, storing, hashing, comparing and scoring the data below; returning a risk score, verdict and reasons to the Customer; linking accounts within the Customer's own data. |
| Data subjects | The Customer's end users: people who sign up, sign in or claim rewards on the Customer's websites or apps. |
| Types of personal data | Email address; IP address and what it resolves to (country, city, time zone, network type); user agent and request headers; device fingerprint and browser signals; optional identifiers (phone number, payment-method fingerprint, payout account, crypto wallet) stored only as keyed hashes; promotion or reward identifiers; other fields the Customer chooses to send; outcomes (score, verdict, reasons); exclusion list entries and their reasons. |
| Special categories | None. The Customer must not send any. |
| Frequency | Continuous, each time the Customer runs a check. |
Annex B: Security measures
- Encryption in transit (TLS) on all public endpoints.
- Optional identifiers are normalised and replaced by HMAC-SHA256 hashes under a secret key held outside the database, scoped per customer; raw values are never stored and are removed from stored metadata.
- Passwords and API keys are stored only as hashes; API keys are scoped to a single project.
- Logical separation of customers' data: every query is scoped to the customer's project, and account matching never crosses customers.
- Access to production systems is restricted to the operator, with key-based authentication.
- Automatic deletion of check records after the retention period; server logs rotated and deleted after 30 days.
- Automated tests, dependency and vulnerability scanning in the build pipeline, and prompt patching.
- Incident handling and customer notification as set out in section 8.
Annex C: Sub-processors
| Provider | What it does for us | Data involved | Location |
|---|---|---|---|
| Akamai Connected Cloud (Linode) | Hosting of the application and its database | All data processed by the service | Fremont, California, United States |
| Cloudflare | DNS, proxy and content delivery for the website, and email routing for a former domain | Web requests to sybilzero.com (IP address, URL, user agent) pass through its network; the API host is DNS only | Global network |
| IPLocate (iplocate.io) | Looking up where an IP address is and what kind of network it belongs to (country, city, time zone, provider, VPN, proxy, Tor and hosting flags) | IP addresses sent in checks | Provider's own infrastructure |
| Stripe | Subscription billing and payments for Customers | Customer billing contact and payment details (end users' data is not sent to Stripe) | United States and Canada |
| Google (Google Workspace) | Email and support correspondence | Messages you send us | Provider's own infrastructure |
| jsDelivr | Content delivery network that serves the open-source ThumbmarkJS library loaded by the SybilZero agent in end users' browsers | End users' IP address and browser request details, seen by the CDN when the library is fetched | Global network |
Questions about this page? Write to [email protected]. See also: Terms of Service, Privacy Policy, Data Processing Addendum.