EpochCore  ·  Proof
DPA template · proof.epochpay.today

Data Processing Agreement template.

Builder-tone draft for procurement teams. Reflects our actual subprocessor list, retention windows, and security measures — not boilerplate. Hand to your legal team; they'll adapt the placeholder fields. Final DPA is executed in counterpart per the engagement; email privacy@epochcoreqcs.com to start.

What this is: the substantive shape of the DPA we'll sign. What it isn't: a final legal instrument. Every field marked […] is a placeholder; the "Subprocessors" and "Security measures" sections track the live Trust page so this document stays in sync as the substrate evolves.

1. Parties.

Controller: [Customer legal name], with principal place of business at [Customer address] ("Controller").
Processor: EpochCore LLC, a North Carolina limited liability company with principal place of business at Charlotte, North Carolina, United States ("Processor").

This Data Processing Agreement ("DPA") forms part of the Master Services Agreement or Terms of Service between the Parties (the "Principal Agreement") and applies whenever Processor processes personal data on behalf of Controller in connection with the proof.epochpay.today services (the "Services"), including the patent-watermark surface, the Tribunal at /tribunal, and the public-read chain endpoint at chain.epochcoreqcs.com.

2. Subject matter, nature, and purpose.

Processor processes personal data on Controller's behalf to provide cryptographic-receipt issuance, public-chain anchoring, and adversarial-verification services. The processing is performed solely to deliver the Services contracted under the Principal Agreement.

3. Duration.

This DPA takes effect on the effective date of the Principal Agreement and continues for as long as Processor processes personal data on Controller's behalf. The post-termination obligations in Section 11 survive expiration.

4. Categories of personal data processed.

  • Email Of Controller's contact persons, used solely for service communication (walkthrough scheduling, security disclosures, support). Not used for marketing.
  • Network IP address + user-agent in standard Cloudflare access logs, retained 30 days for security and abuse-prevention.
  • Payload hash SHA-256 of any decision payload submitted to /api/tribunal/decide or document submitted to /api/watermark. The hash is committed to the public chain. The raw payload itself is processed in-request and is not persisted server-side.

5. Sub-processors.

Controller authorizes Processor to engage the following sub-processors. Processor will notify Controller of any addition or replacement at least 14 days in advance via the Trust page, and Controller may object on reasonable grounds within that window.

  • Cloudflare Cloudflare, Inc. (U.S.). Workers, KV, Browser Rendering, DNS, CDN. Edge logs retained 30 days.
  • IBM Cloud International Business Machines Corp. (U.S. + EU regions). watsonx Orchestrate bridge for tournament_decision skill invocations originating from Watson.x. Payloads pass through but are not persisted.
  • Resend Resend, Inc. (U.S.). Transactional email (walkthrough confirmations, security disclosures). No marketing email.
  • OpenTimestamps Public Bitcoin-timestamping calendar pool (a.pool.opentimestamps.org). Receives 32-byte SHA-256 digests of daily activity summaries. No personal data leaves Processor; only the hash.
  • Chain chain.epochcoreqcs.com — Processor-operated public read endpoint. Receipts are append-only and publicly readable.

6. Security measures.

Processor implements appropriate technical and organizational measures, including:

  • Crypto Ed25519 (FIPS 186-5) classical signature and ML-DSA-87 (FIPS 204 Level 5) post-quantum signature on every receipt. Per-receipt signing-key IDs published in the receipt body. Annual key-rotation cadence.
  • Transit TLS 1.3 in-transit. All endpoints HTTPS-only.
  • Hashing Payloads SHA-256 hashed before any chain commit. Raw payload bytes are not persisted server-side.
  • Access Role-based access control on the swarm orchestrator. Audit log of admin actions. v2 (planned) adds tenant-scoped SSO + per-tenant audit-log export.
  • Incident 24-hour acknowledgment, 72-hour notice to affected Controllers on confirmed data-incident. Disclosure path at /.well-known/security.txt.

7. Controller instructions.

Processor will process personal data only on Controller's documented instructions, including with regard to transfers to a third country, unless required to do so by Union or Member State law (in which case Processor will inform Controller of that legal requirement before processing, unless prohibited from doing so).

8. Data-subject rights.

Processor will, to the extent technically feasible, assist Controller with requests from data subjects to exercise their rights under applicable data-protection law. Note: receipts already written to the public chain are append-only by design and cannot be redacted. The hash on the chain is a one-way SHA-256 and, without the original payload, is not personal data on its own.

9. International transfers.

Where personal data is transferred outside the EEA, UK, or Switzerland to a jurisdiction that does not benefit from an adequacy decision, the Parties incorporate by reference the Standard Contractual Clauses ("SCCs") Module Two (Controller-to-Processor) as published by the European Commission (2021/914), with the following modifications:

  • Clause 7 Docking clause: applies.
  • Clause 9(a) General written authorisation, 14-day notice (per Section 5 above).
  • Clause 11(a) Optional language not included.
  • Clause 17 Governing law: [Member State law to be selected by Controller].
  • Clause 18(b) Forum: courts of [same Member State].
  • Annex I Parties as per Section 1; Description of Transfer as per Sections 2 and 4; Competent Supervisory Authority per Controller's establishment.
  • Annex II Technical and Organisational Measures as per Section 6.
  • Annex III Sub-processors as per Section 5.

10. Audit rights.

Once per calendar year, Controller may, with at least 30 days' written notice, request an audit of Processor's compliance with this DPA. Processor may satisfy the audit obligation by providing a current SOC 2 Type II report (target Q4 2026) or equivalent third-party attestation in lieu of on-site audit.

11. Termination.

Upon termination of the Principal Agreement, Processor will, at Controller's choice, delete or return all personal data unless retention is required by applicable law. Chain receipts are immutable and remain on the public chain for their retention window (7 years); deletion is technically impossible for already-anchored hashes. Subsequent issuance ceases on termination.

12. Liability.

Liability under this DPA is governed by the limitation-of-liability provisions in the Principal Agreement.

13. Signature.

For Controller:
Signature: ____________________________
Name: [Authorized signer name]
Title: [Title]
Date: [YYYY-MM-DD]

For Processor:
Signature: ____________________________
Name: John Vincent Ryan
Title: Founder, EpochCore LLC
Date: [YYYY-MM-DD]

Draft for procurement review. This template is a builder-tone working draft reflecting the live substrate at proof.epochpay.today. Final DPA will be reviewed by qualified counsel and executed in counterpart per the engagement. Email privacy@epochcoreqcs.com with subject "DPA review" to start.