Direct, gecertificeerd en 100% gratis leeftijdsverificatiesysteem

Bescherm minderjarigen, zorg voor wettelijke naleving en laat uw bedrijf veilig groeien

Aanbevolen door

ASACP - Vereniging van Sites die Bescherming van Kinderen Bevorderen
MojoHost – premium hostingprovider

Gecontroleerd

AVG-conform (EU) AVG
100% gratis leeftijdsverificatiesysteem

Verwerkersovereenkomst (DPA) tussen GO.CAM en de zakelijke klant

DATA PROCESSING AGREEMENT (DPA) Between GO.CAM and the Business Customer

1. Purpose of the Agreement

This Agreement sets out the terms on which GO.CAM, acting as a Data Processor, processes Personal Data on behalf of the Business Customer (the Data Controller), in the context of the GO.CAM Age Verification Service.

It complements the Service Agreement and Users Terms & Conditions, and complies with:

  • General Data Protection Regulation (GDPR – EU/UK)
  • French Law No. 2020-936 (Articles 21–24)
  • UK Online Safety Act (2023)

2. Definitions

Refer to the definitions contained in the Service Agreement and Users Terms & Conditions, including:

  • End User: Natural person whose age is verified via GO.CAM
  • Business Customer: Legal entity using the GO.CAM service for its website(s)
  • End User Data: Any data collected temporarily for age verification purposes
  • Age-Verification Methods: The four methods listed in clause 3 below

3. Nature and Purpose of Processing

GO.CAM processes data solely for the purpose of verifying that the End User has reached the Age of Majority.

Duration of Processing

GO.CAM shall process Personal Data for the duration of the Service Agreement and only for as long as necessary to provide the Age Verification Service, unless a longer retention period is required by applicable law or expressly agreed in writing with the Business Customer.

Verification Methods available

  1. Facial recognition (live selfie check with algorithmic age estimation)
  2. ID document check (scanned/uploaded government ID)
  3. Card verification (last 4 digits of a credit/debit card)
  4. Email + one-time code verification

All verification processes occur locally on the End User’s device. GO.CAM does not store or retain identifiable End User Data beyond the session. However, limited technical and non-identifying data may be processed where strictly necessary for the operation, security, fraud prevention, and compliance of the service.

4. Categories of Data Subjects and Data

  • Subjects: End Users
  • Personal Data categories:
    • Selfie image (not stored)
    • Identity document image (used only if method 2 is selected; deleted within session)
    • 4-digit credit/debit card fragment (method 3 only)
    • Email address (used only for method 4; not retained; never stored, logged, or persisted in plaintext at any stage of processing)
    • Browser and device metadata strictly limited to what is necessary for security and fraud prevention purposes.
    • IP addresses are not stored by GO.CAM and are only processed transiently at network level without retention.
    • Outcome of verification (boolean or categorical result, e.g. age eligibility)
    • Pseudonymised or anonymised verification token (non-identifying)

5. Data Retention and Deletion

  • No identifiable End User Data is stored.
  • Only limited technical or non-identifying data, including verification outcomes and anonymised or pseudonymised tokens, may be retained where strictly necessary for security, fraud prevention, and compliance purposes, in accordance with the Data Retention Schedule.
  • Images, ID data, email addresses are automatically deleted at end of session.
  • Only a signed, anonymised or pseudonymised age verification token, which does not allow identification of the End User, may be retained.
  • No raw personal data (including images, identity documents, or email addresses) is retained beyond the verification session.
  • Business Customer data is retained only for contractual or compliance purposes, in accordance with the Privacy Policy.
  • Upon contract termination, data is deleted within 24h, with confirmation issued within 10 working days.

6. Roles and Responsibilities

  • The Business Customer remains the Controller of End User Data.
  • GO.CAM acts as a Data Processor on behalf of the Business Customer for all processing related to age verification. Such processing does not involve the identification of End Users and is limited to what is strictly necessary for the operation and protection of the service.
  • GO.CAM acts as an independent Data Controller only for strictly limited processing of pseudonymised or non-identifying technical data, exclusively for security, fraud prevention, and service integrity purposes.
  • GO.CAM does not handle Data Subject Rights requests directly and will assist the Business Customer where required, unless legally required to act otherwise.

The Business Customer is responsible for ensuring that it has a valid legal basis for the processing of End User Data and for providing appropriate privacy information to End Users in accordance with applicable data protection laws.

GO.CAM processes End User Data only on documented instructions from the Business Customer and solely for the purpose of providing the Age Verification Service.

GO.CAM shall ensure that any person authorised to process Personal Data on its behalf, including employees and contractors, is subject to an appropriate duty of confidentiality, whether contractual or statutory, and processes Personal Data only as necessary for the performance of their authorised duties.

7. Technical and Organizational Security Measures

GO.CAM ensures:

  • Age verification processing occurs primarily locally on the End User’s browser/device.
  • Communication is encrypted (TLS 1.3 or higher)
  • No identifiable personal data is retained on GO.CAM infrastructure. Only limited technical or non-identifying data may be processed and retained where strictly necessary for security, fraud prevention, and compliance purposes.
  • Datacenters (if applicable) are located in the EEA and ISO 27001 certified
  • AI models are validated and bias-tested
  • Internal access is logged and restricted
  • Plaintext email addresses are never stored, logged, or retained, including in temporary logs or debugging systems.

8. Sub-Processing

GO.CAM may engage sub-processors to perform specific technical functions in connection with the Age Verification Service. These sub-processors may include third-party service providers as well as affiliated companies within the same corporate group.

GO.CAM shall ensure that:

  • all sub-processors are subject to written data processing agreements imposing obligations equivalent to those set out in this DPA;
  • sub-processors process personal data only for the purposes of providing the Service and strictly within GO.CAM’s instructions;
  • an up-to-date list of sub-processors is maintained and made available to the Business Customer upon request.

GO.CAM shall notify the Business Customer in advance of any intended addition or replacement of a sub-processor. The Business Customer shall have a reasonable opportunity to object to the proposed change on legitimate data protection grounds before the new or replacement sub-processor is engaged. Where the Business Customer raises a justified objection, the Parties shall work in good faith to seek an appropriate solution.

These sub-processors may include:

  • technical services provided by affiliated companies within the same corporate group;
  • external service providers, including Superlative Enterprises Pty Ltd (operator of HaveIBeenPwned.com), used exclusively during the Email + Code verification method to perform a one-time lookup using a partially hashed email address (k-anonymity model), without transmitting or exposing the full email address.
  • GO.CAM does not have access to the full email address during this process and does not store or retain any email data in connection with this lookup.
  • are subject to written data processing agreements imposing obligations equivalent to this DPA;
  • are assessed for compliance with applicable data protection laws;
  • only process data within the scope required for the Service, and for no longer than necessary;
  • do not retain, store, or reuse any personal data provided by GO.CAM or its End Users beyond what is strictly necessary to perform the service.

9. International Transfers

While GO.CAM processes all End User Data locally and does not transmit personal data outside the EEA during the standard verification process, certain technical sub-processors may operate from outside the EEA. For instance, during Email + Code verification, a partially hashed email address is transmitted on a one-time basis using a k-anonymity model to Superlative Enterprises Pty Ltd (Australia) for a one-time lookup through their HaveIBeenPwned service, which is hosted in the USA (Microsoft Azure – Western region).

The hashed email used for this lookup does not allow GO.CAM or the sub-processor to directly identify the End User, and GO.CAM does not have access to the full email address at any stage of this process.

This transfer is limited to a one-time query and no personal data is stored, retained, or reused by GO.CAM or the sub-processor in connection with this process.

In such cases, GO.CAM ensures:

  • The use of Standard Contractual Clauses (SCCs) issued by the European Commission,
  • Supplementary technical and organizational safeguards (such as pseudonymisation, encryption, and transmission of only pseudonymised or hashed data),
  • Prior risk assessments to validate the level of protection,
  • If any additional data transfer outside the EEA becomes necessary, GO.CAM will use:
    • Standard Contractual Clauses (SCCs)
    • Supplementary measures
    • Prior notice and approval from the Business Customer

10. Audit and Assistance

  • The Business Customer may request an annual audit with 30 days’ notice.
  • GO.CAM agrees to provide reasonable assistance for:
    • Data protection impact assessments (DPIAs)
    • Demonstrating compliance
    • Responding to supervisory authorities

11. Personal Data Breaches

  • In the event of a Personal Data Breach, GO.CAM shall notify the Business Customer without undue delay after becoming aware of the breach and, in any event, sufficiently promptly to enable the Business Customer to comply with its own notification obligations under applicable data protection law.
  • Notification will include: nature of breach, categories of data involved, likely consequences, and mitigation measures.

12. Termination and Return or Deletion of Data

  • Upon termination of the Service Agreement:
    • GO.CAM shall, at the choice of the Business Customer, delete or return all Personal Data processed on its behalf after the end of the provision of the Services, unless applicable law requires the continued storage of such Personal Data.
    • Written confirmation shall be provided within 10 working days.

13. Governing Law and Jurisdiction

  • This Agreement shall be governed by French law
  • Jurisdiction is assigned to the Courts of Marseille, unless overriding local laws apply.

14. Final Provisions

  • This DPA forms part of the Service Agreement.
  • In case of conflict, this DPA prevails over other terms for data protection matters.
  • This Agreement may be amended only in writing, signed by both Parties.

Date of last update: 21 July 2026

This DPA forms an integral part of the Service Agreement but does not constitute a separately signed document. It is accepted by reference as part of the contractual framework between the Parties.

Eenvoudig, veilig en zonder opstartkosten

Bescherm minderjarigen, zorg voor wettelijke naleving en laat uw bedrijf veilig groeien

Online demonstratie

SUPPORT

Neem contact met ons op via e-mail op om go.cam op je webpagina te integreren

Voor verzoeken tot verwijdering van persoonsgegevens kunt u contact opnemen via .

Copyright 2025 GSI Développement SaS