Protect minors, ensure legal compliance, and grow your business safely
Data processing agreement (DPA) between GO.CAM and the Business Customer
DATA PROCESSING AGREEMENT (DPA) Between GO.CAM and the Business Customer
1. Purpose of the Agreement
This Agreement sets out the terms on which GO.CAM, acting as a Data Processor, processes Personal Data on behalf of the Business Customer (the Data Controller), in the context of the GO.CAM Age Verification Service.
It complements the Service Agreement and Users Terms & Conditions, and complies with:
- General Data Protection Regulation (GDPR – EU/UK)
- French Law No. 2020-936 (Articles 21–24)
- UK Online Safety Act (2023)
2. Definitions
Refer to the definitions contained in the Service Agreement and Users Terms & Conditions, including:
- End User: Natural person whose age is verified via GO.CAM
- Business Customer: Legal entity using the GO.CAM service for its website(s)
- End User Data: Any data collected temporarily for age verification purposes
- Age-Verification Methods: The five methods listed in clause 3 below
3. Nature and Purpose of Processing
GO.CAM processes data solely for the purpose of verifying that the End User has reached the Age of Majority.
Duration of Processing
GO.CAM shall process Personal Data for the duration of the Service Agreement and only for as long as necessary to provide the Age Verification Service, unless a longer retention period is required by applicable law or expressly agreed in writing with the Business Customer.
Verification Methods available
- Facial recognition (live selfie check with algorithmic age estimation)
- ID document check (scanned/uploaded government ID)
- Card verification (last 4 digits of a credit/debit card)
- Email + one-time code verification
- NFC contactless electronic identity document verification (compatible electronic passport or identity document with on-device chip reading, age verification and facial comparison)
For the NFC contactless electronic identity document verification method, the MRZ and relevant data contained in the contactless chip, including DG1 and DG2, are processed locally on the End User’s device. Where facial comparison is used, the End User’s selfie and any biometric templates or vectors generated for the comparison are also processed locally on the End User’s device. Such MRZ data, contactless chip data, facial images and biometric templates or vectors are not transmitted to or stored by GO.CAM servers or third-party cloud infrastructure and are deleted from the device’s volatile memory upon completion or termination of the verification session.
Facial images, identity-document data and facial analysis are processed locally on the End User’s device. Limited technical processing, verification-result transmission and external queries may occur where necessary for the selected verification method, service operation, security, fraud prevention or compliance. GO.CAM does not store or retain identifiable End User Data beyond the verification session, except where expressly required by applicable law or documented in the Data Retention Schedule.
4. Categories of Data Subjects and Data
- Subjects: End Users
- Personal Data categories:
- Selfie image (not stored)
- Identity document image (used only if method 2 is selected; deleted within session)
- NFC electronic identity document data (method 5 only), including MRZ data and relevant data read from the contactless chip, including DG1 and DG2; processed locally on the End User’s device and deleted upon completion or termination of the verification session.
- Facial biometric data generated for NFC document-holder verification (method 5 only), including the facial portrait contained in the electronic identity document and any biometric templates or vectors generated for comparison with the End User’s selfie; processed locally on the End User’s device, not transmitted to or stored by GO.CAM, and deleted upon completion or termination of the verification session.
- 4-digit credit/debit card fragment (method 3 only)
- Email address (used only for method 4; not retained; never stored, logged, or persisted in plaintext at any stage of processing)
- Browser and device metadata strictly limited to what is necessary for security and fraud prevention purposes.
- IP addresses are not stored by GO.CAM and are only processed transiently at network level without retention.
- Outcome of verification (boolean or categorical result, e.g. age eligibility)
- Pseudonymised or anonymised verification token (non-identifying)
5. Data Retention and Deletion
- No identifiable End User Data is stored.
- Only limited technical or non-identifying data, including verification outcomes and anonymised or pseudonymised tokens, may be retained where strictly necessary for security, fraud prevention, and compliance purposes, in accordance with the Data Retention Schedule.
- Images, ID data and email addresses are automatically deleted at the end of the session. For the NFC verification method, MRZ data, contactless chip data, facial images and any biometric templates or vectors generated for the verification are processed only transiently on the End User’s device and are deleted upon completion or termination of the verification session.
- Only a signed, anonymised or pseudonymised age verification token, which does not allow identification of the End User, may be retained.
- No raw personal data, including images, identity documents, email addresses, MRZ data, contactless chip data, facial images or biometric templates or vectors, is retained by GO.CAM beyond the verification session. Business Customer data is retained only for contractual or compliance purposes, in accordance with the Privacy Policy.
- Upon termination of the Service Agreement, GO.CAM shall, at the choice of the Business Customer, delete or return the Personal Data processed on its behalf, unless applicable law requires continued storage. Written confirmation of the action taken shall be provided within 10 working days.
6. Roles and Responsibilities
- The Business Customer remains the Controller of End User Data.
- GO.CAM acts as a Data Processor on behalf of the Business Customer for all processing related to age verification. Such processing does not involve the identification of End Users and is limited to what is strictly necessary for the operation and protection of the service.
- GO.CAM acts as an independent Data Controller only for strictly limited processing of pseudonymised or non-identifying technical data, exclusively for security, fraud prevention, and service integrity purposes.
- GO.CAM does not handle Data Subject Rights requests directly and will assist the Business Customer where required, unless legally required to act otherwise.
The Business Customer is responsible for ensuring that it has a valid legal basis for the processing of End User Data and for providing appropriate privacy information to End Users in accordance with applicable data protection laws.
GO.CAM processes End User Data only on documented instructions from the Business Customer and solely for the purpose of providing the Age Verification Service.
GO.CAM shall ensure that any person authorised to process Personal Data on its behalf, including employees and contractors, is subject to an appropriate duty of confidentiality, whether contractual or statutory, and processes Personal Data only as necessary for the performance of their authorised duties.
7. Technical and Organizational Security Measures
GO.CAM ensures:
- Age verification processing occurs primarily locally on the End User’s browser/device.
- For the NFC verification method, access to and reading of the contactless chip, processing of MRZ and relevant chip data, and facial comparison between the End User’s selfie and the facial portrait contained in the electronic identity document are performed locally on the End User’s device. NFC document and biometric data are not transmitted to or stored on GO.CAM infrastructure and are deleted from the device’s volatile memory upon completion or termination of the verification session.
- Communication is encrypted (TLS 1.3 or higher)
- No identifiable personal data is retained on GO.CAM infrastructure. Only limited technical or non-identifying data may be processed and retained where strictly necessary for security, fraud prevention, and compliance purposes.
- Datacenters (if applicable) are located in the EEA and ISO 27001 certified
- Age-estimation model performance is subject to independent external testing and certification. Accuracy and classification performance are assessed externally, while bias and fairness are considered only where included within the scope of the relevant independent evaluation.
- Internal access is logged and restricted
- Plaintext email addresses are never stored, logged, or retained, including in temporary logs or debugging systems.
8. Sub-Processing
GO.CAM may engage sub-processors to perform specific technical functions in connection with the Age Verification Service. These sub-processors may include third-party service providers as well as affiliated companies within the same corporate group.
GO.CAM shall ensure that:
- all sub-processors are subject to written data processing agreements imposing obligations equivalent to those set out in this DPA;
- sub-processors process personal data only for the purposes of providing the Service and strictly within GO.CAM’s instructions;
- an up-to-date list of sub-processors is maintained and made available to the Business Customer upon request.
GO.CAM shall notify the Business Customer in advance of any intended addition or replacement of a sub-processor. The Business Customer shall have a reasonable opportunity to object to the proposed change on legitimate data protection grounds before the new or replacement sub-processor is engaged. Where the Business Customer raises a justified objection, the Parties shall work in good faith to seek an appropriate solution.
These sub-processors may include:
- technical services provided by affiliated companies within the same corporate group;
- external service providers, including Superlative Enterprises Pty Ltd (operator of HaveIBeenPwned.com), used exclusively during the Email + Code verification method to perform a one-time lookup using a partially hashed email address (k-anonymity model), without transmitting or exposing the full email address.
- GO.CAM does not transmit the full email address to the HIBP service and does not store or retain the plaintext email address in connection with this lookup. Only the partial hashed representation required by the k-anonymity process is transmitted to HIBP.
GO.CAM ensures that all sub-processors:
- are subject to written data processing agreements imposing obligations equivalent to this DPA;
- are assessed for compliance with applicable data protection laws;
- only process data within the scope required for the Service, and for no longer than necessary;
- do not retain, store, or reuse any personal data provided by GO.CAM or its End Users beyond what is strictly necessary to perform the service.
9. International Transfers
While GO.CAM processes all End User Data locally and does not transmit personal data outside the EEA during the standard verification process, certain technical sub-processors may operate from outside the EEA. For instance, during Email + Code verification, a partially hashed email address is transmitted on a one-time basis using a k-anonymity model to Superlative Enterprises Pty Ltd (Australia) for a one-time lookup through their HaveIBeenPwned service, which is hosted in the USA (Microsoft Azure – Western region).
The partial hashed representation used for this lookup does not directly identify the End User and does not disclose the full email address to the HIBP service. GO.CAM does not store or retain the plaintext email address in connection with this lookup.
This transfer is limited to a one-time query and no personal data is stored, retained, or reused by GO.CAM or the sub-processor in connection with this process.
In such cases, GO.CAM ensures:
- The use of Standard Contractual Clauses (SCCs) issued by the European Commission,
- Supplementary technical and organizational safeguards (such as pseudonymisation, encryption, and transmission of only pseudonymised or hashed data),
- Prior risk assessments to validate the level of protection,
- If any additional data transfer outside the EEA becomes necessary, GO.CAM will use:
- Standard Contractual Clauses (SCCs)
- Supplementary measures
- Prior notice and approval from the Business Customer
10. Audit and Assistance
- The Business Customer may request an annual audit with 30 days’ notice.
- GO.CAM agrees to provide reasonable assistance for:
- Data protection impact assessments (DPIAs)
- Demonstrating compliance
- Responding to supervisory authorities
11. Personal Data Breaches
- In the event of a Personal Data Breach, GO.CAM shall notify the Business Customer without undue delay after becoming aware of the breach and, in any event, sufficiently promptly to enable the Business Customer to comply with its own notification obligations under applicable data protection law.
- Notification will include: nature of breach, categories of data involved, likely consequences, and mitigation measures.
12. Termination and Return or Deletion of Data
- Upon termination of the Service Agreement:
- GO.CAM shall, at the choice of the Business Customer, delete or return all Personal Data processed on its behalf after the end of the provision of the Services, unless applicable law requires the continued storage of such Personal Data.
- Written confirmation shall be provided within 10 working days.
13. Governing Law and Jurisdiction
- This Agreement shall be governed by French law.
- Jurisdiction is assigned to the Courts of Marseille, unless overriding local laws apply.
14. Final Provisions
- This DPA forms part of the Service Agreement.
- In case of conflict, this DPA prevails over other terms for data protection matters.
- This Agreement may be amended only in writing, signed by both Parties.
Date of last update: 17 Sept 2026
This DPA forms an integral part of the Service Agreement but does not constitute a separately signed document. It is accepted by reference as part of the contractual framework between the Parties.
Simple, secure, and with no setup fees
Protect minors, ensure legal compliance, and grow your business safely