1. Scope and incorporation
This Data Processing Addendum (“DPA”) forms part of the Developer Terms of Service or any Order between Offline Protocol, Inc. (“Offline Protocol”) and Customer (together, the “Agreement”). It applies when Offline Protocol processes Customer Personal Data on Customer’s behalf in providing the Hosted Services. It applies automatically when Customer accepts the Developer Terms. Customers who need a countersigned copy can request one from legal@offlineprotocol.com.
Capitalized terms not defined here have the meanings in the Developer Terms. “Data Protection Laws” means all laws on the processing of personal data that apply to a party’s processing under the Agreement, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and U.S. state privacy laws such as the California Consumer Privacy Act as amended (“CCPA”). “Customer Personal Data” means personal data within Customer Data that Offline Protocol processes as a processor. “Controller”, “processor”, “data subject”, “personal data breach”, and “processing” have the meanings in the GDPR, and “business”, “service provider”, “sell”, and “share” have the meanings in the CCPA.
2. Roles of the parties
For Customer Personal Data, Customer is the controller (or a processor acting for its own controller, in which case Offline Protocol is a subprocessor), and Offline Protocol is the processor. For the purposes of the CCPA, Offline Protocol is Customer’s service provider.
Offline Protocol is an independent controller for Account Data and Service Data, and for aggregated, de-identified data under Section 11. Its privacy policy governs that processing.
3. OfflineID accounts
An End User can use one OfflineID across several Customer Applications and across Offline Protocol’s own apps. For that reason:
- Offline Protocol is an independent controller of the core OfflineID account: the email address or phone number, username, account status, and sign-in security records, and the End User’s own choices about their profile and connections.
- Offline Protocol is Customer’s processor for records about the End User’s use of Customer’s Application, such as the fact and dates of sign-ins to that Application, and any other data Customer’s Application submits.
- When an End User deletes their OfflineID account, it is deleted for every Application. Customer may ask us to remove an End User’s records relating to Customer’s Application without deleting the core account.
4. Processing on instructions
Offline Protocol will process Customer Personal Data only on Customer’s documented instructions, unless the law requires otherwise, in which case it will inform Customer first unless the law prohibits that. The Agreement, Customer’s configuration of the Services (such as enabling telemetry or Proof of Location for an Application), and Customer Applications’ calls to the Hosted Services are Customer’s complete instructions. Offline Protocol will tell Customer if it believes an instruction infringes Data Protection Laws.
Customer is responsible for the lawfulness of its instructions, for giving End Users the notices and obtaining the consents that Data Protection Laws require, and for the accuracy of the data it submits. Customer will not submit special categories of personal data unless an Order allows it.
The subject matter, duration, nature, and purpose of the processing, and the types of personal data and categories of data subjects, are set out in Annex 1.
5. Personnel and confidentiality
Offline Protocol will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and have access only as needed to provide, secure, and support the Services.
6. Security
Offline Protocol will implement and maintain the technical and organizational measures in Annex 2, which are designed to protect Customer Personal Data against a personal data breach. Offline Protocol may update the measures as long as the overall level of protection is not reduced. Customer is responsible for its own security, including keeping API Keys secret, configuring allowed origins and Member roles, and securing Customer Applications and devices.
7. Subprocessors
Customer gives Offline Protocol general authorization to engage subprocessors. The current list is on the subprocessors page. Offline Protocol will impose data protection obligations on each subprocessor that are no less protective than this DPA, and remains responsible for their performance.
Offline Protocol will update the list before a new subprocessor begins processing Customer Personal Data and, for Customers who subscribe, will send notice at least 30 days in advance. Customer may object on reasonable data protection grounds within that period. The parties will then discuss the objection in good faith. If Offline Protocol cannot offer a reasonable alternative, Customer may terminate the affected Services and receive a refund of prepaid fees for the period after termination.
8. Data subject requests and assistance
If Offline Protocol receives a request from a data subject about Customer Personal Data, it will direct the person to Customer where it can identify Customer, and will not respond to the substance of the request except as Customer instructs or the law requires. Taking into account the nature of the processing, Offline Protocol will provide reasonable assistance to Customer in responding to data subject requests, in carrying out data protection impact assessments, and in consultations with supervisory authorities, to the extent Customer cannot do so with the Services’ own features.
9. Personal data breaches
Offline Protocol will notify Customer without undue delay, and where feasible within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice goes to the Organization owner’s email address and will describe, as far as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Offline Protocol will provide further information as it becomes available and take reasonable steps to contain and remedy the breach. Notification is not an acknowledgment of fault.
10. Deletion and return
Customer can retrieve Customer Personal Data through the Hosted Service APIs during the term. An owner can delete an Organization in the portal once any outstanding balance is paid. Deleting it cancels the paid subscription, bills any overage for the final billing period, and deactivates the Organization and its Applications and API Keys immediately. Thirty days later we permanently delete its Customer Data and Organization records, except records we must keep for legal, tax, billing, or security reasons. On termination of the Agreement, or on Customer’s written request to legal@offlineprotocol.com, Offline Protocol will delete Customer Personal Data within 30 days, except where the law requires it to be kept, and except for data in backups, which is deleted as the backups expire and is protected under this DPA until then.
Proof of Location records written to a public blockchain cannot be deleted by Offline Protocol or anyone else. Customer acknowledges this before submitting data to Proof of Location.
11. Aggregated and de-identified data
Customer authorizes Offline Protocol to create aggregated, de-identified data derived from the use of the Hosted Services, including telemetry and usage, and to use, publish, share, and license it for any lawful purpose, provided that it does not identify Customer, any Customer Application, or any individual. Offline Protocol will: (a) remove application and Customer identifiers; (b) keep an aggregate group only when it covers at least 100 distinct devices or app sessions, and discard smaller groups; (c) not attempt to re-identify any person or Customer; (d) contractually prohibit recipients from attempting re-identification; and (e) take reasonable measures to ensure the data cannot reasonably be linked to an identified or identifiable person. Data meeting these conditions is not Customer Personal Data, and Offline Protocol processes it as an independent controller, or not as personal data at all.
Telemetry describes how the mesh network behaves: delivery results, latency, routing, transports, relay roles, queue sizes, encryption session errors, and battery state, with an application ID, app and operating system versions, a country code, and randomly generated session and install identifiers that Offline Protocol hashes with a quarterly rotating key. It does not contain message content, contacts, names, usernames, email addresses, phone numbers, advertising identifiers, or location more precise than the country.
12. Audits and information
Offline Protocol will make available the information reasonably necessary to demonstrate compliance with this DPA, including written responses to reasonable security questionnaires once per year. If that information is not enough to satisfy an obligation under Data Protection Laws, Customer may conduct an audit, at its own cost, no more than once every 12 months, on at least 30 days’ written notice, during business hours, subject to confidentiality, and in a way that does not disrupt the Services or other customers’ data.
13. International transfers
Offline Protocol and its subprocessors may process Customer Personal Data outside the country where it was collected, including in Singapore, the United States, the European Union, and India. Where a transfer of Customer Personal Data from the EEA, Switzerland, or the United Kingdom to a country without an adequacy decision is made under this DPA, the parties agree to the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (the “SCCs”), which are incorporated by reference as follows:
- Module Two (controller to processor) applies where Customer is a controller, and Module Three (processor to processor) applies where Customer is a processor.
- Clause 7 (docking clause) applies. In Clause 9, Option 2 (general authorization) applies, with the notice period in Section 7 of this DPA. The optional language in Clause 11 does not apply.
- In Clauses 17 and 18, the SCCs are governed by the laws of, and disputes resolved by the courts of, Ireland.
- Annexes I and II of the SCCs are completed with Annexes 1 and 2 of this DPA. The competent supervisory authority is the one determined under Clause 13.
- For transfers from the United Kingdom, the International Data Transfer Addendum issued by the UK Information Commissioner (version B1.0) applies, with the tables completed with the information in this DPA, and either party may end it as allowed by its Section 19.
- For transfers from Switzerland, references to the GDPR include the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner is a competent supervisory authority.
14. U.S. state privacy law terms
As Customer’s service provider, Offline Protocol will not: sell or share Customer Personal Data; retain, use, or disclose it for any purpose other than the business purposes in the Agreement, including for any commercial purpose other than providing the Services; retain, use, or disclose it outside the direct business relationship with Customer; or combine it with personal data it receives from other sources, except as permitted by the CCPA. Offline Protocol will comply with the CCPA’s obligations on service providers, will tell Customer if it can no longer meet them, and allows Customer to take reasonable steps to stop unauthorized use. Offline Protocol certifies that it understands these restrictions.
15. Liability and precedence
Each party’s liability under this DPA, and under the SCCs to the extent the SCCs allow, is subject to the exclusions and limitations of liability in the Agreement, including the aggregate cap, except where Data Protection Laws do not allow it. If this DPA conflicts with the Developer Terms, this DPA controls for the processing of Customer Personal Data. If it conflicts with the SCCs, the SCCs control.
Annex 1. Details of processing
| Item | Details |
|---|---|
| Data exporter | Customer, as identified in its Organization. Contact: the Organization owner. |
| Data importer | Offline Protocol, Inc., a Delaware corporation. Contact: legal@offlineprotocol.com. |
| Data subjects | End Users of Customer Applications; Customer’s personnel whose details Customer submits to the Hosted Services. |
| Nature and purpose | Providing the Hosted Services that Customer enables: authenticating End Users and maintaining their OfflineID profiles and connections (OfflineID); storing and forwarding encrypted messages (relay); collecting mesh performance telemetry and producing analytics (telemetry); recording and attesting location claims (Proof of Location); metering, security, and support. |
| Frequency | Continuous, for as long as Customer uses the Hosted Services. |
| Duration | The term of the Agreement and the deletion period in Section 10. |
| Sensitive data | Precise location, when Customer Applications submit profile location or Proof of Location claims. No special categories of data are intended. Safeguards: access controls in Annex 2; exact profile locations visible only to the owner and to connections the owner chooses; Proof of Location coordinates reduced to a coarse geohash before publication and not stored. |
Categories of personal data and retention, by service
| Service | Personal data | Retention |
|---|---|---|
| OfflineID | Email address or phone number; username; profile details (text, picture, social links, optional location); connections and location-sharing choices; off1 device address; push tokens with device model, OS, and app version; per-application sign-in dates and counts; sign-in events. | Until the End User deletes the account (30-day grace period) or Customer requests deletion of its application records. When the grace period ends, we delete the account together with its related records: profile details and connections, relay identity keys, group memberships, and queued messages, uploaded media and profile pictures, Proof of Location commitment secrets and off-chain records, and the person’s profile and events in our product analytics (PostHog). Sign-in codes: 10 minutes. |
| Relay | Sender and recipient addresses and usernames; group and message IDs; message timing and size; end-to-end encrypted message content; public identity keys; group membership; last-seen time; push notification details when enabled. | Queued messages: until delivered, at most 7 days. Keys, groups, and last seen: while the OfflineID account exists. |
| Telemetry | Randomly generated session identifiers and, where the app opts in, install identifiers, hashed on our servers with a quarterly rotating key; application ID; app version; operating system and major version; country code; mesh delivery, latency, routing, transport, relay, queue, encryption session error, and battery measurements. No IP address is stored. | Raw events: 30 days. Per-minute: 48 hours. Live feed: 2 hours. Daily per-application aggregates: life of the Application. Breakdowns by OS and country: 2 years. |
| Proof of Location | Username; application ID; submitted latitude and longitude (not stored); geohash; commitment; transaction hash; secret commitment value; witness attestations. | Off-chain records: while the OfflineID account exists, or until deletion under Section 10. On-chain geohash, time, and commitment: permanent. |
Annex 2. Technical and organizational measures
- Encryption in transit. TLS on every public endpoint of the portal, hosted APIs, and hosted MCP server.
- End-to-end message encryption. Message content sent through the relay is encrypted by the SDK with MLS (RFC 9420); the relay cannot decrypt it.
- Hosting. Databases and services run on Railway in Singapore, with relay servers also in the United States, and uploaded media is stored with Hetzner in the European Union, under those providers’ physical and environmental security controls.
- Authentication. One-time sign-in codes that expire after 10 minutes and are rate limited per identifier and per IP address; signed (RS256) session tokens; revocable API Keys (we store API Keys only as hashes. A key is shown in full once, when it is created, and cannot be shown again.); CLI sign-in session secrets stored only as hashes; CLI sign-in requests that expire after 5 minutes.
- Authorization. Organization roles (owner, admin, developer, billing, analyst, read-only), per-Application access grants, optional email-domain restrictions on membership, and per-Application allowed web origins checked on browser requests.
- Data minimization. The telemetry service does not read client IP addresses and re-hashes session and device identifiers with a quarterly rotating key; Proof of Location does not store raw coordinates; public network statistics round locations to about 1 km and omit usernames; error monitoring has sending of default personal data disabled.
- Payment data. Card details are collected by Stripe on Stripe-hosted pages and never reach Offline Protocol’s systems.
- Access control for staff. Production access limited to personnel who need it for their role.
- Logging and monitoring. Service logs kept by our hosting provider for 90 days or less, error monitoring, and an audit log of CLI sign-ins kept for 12 months, then deleted automatically.
- Availability. Managed hosting, with the relay running in two regions (Singapore and the United States).
- Vulnerability management. Automated dependency updates, a responsible disclosure policy, and coordinated fixes.
- Incident response. Breach notification to Customers as set out in Section 9.
- Subprocessor management. Written agreements with each subprocessor, listed on the subprocessors page.
Annex 3. Subprocessors
The subprocessors authorized under Section 7 are those marked as processing Customer Data on the subprocessors page.
Questions about this document, privacy requests, and anything else policy related: email legal@offlineprotocol.com. Security vulnerabilities: security@offlineprotocol.com. All of our legal documents are listed on the legal page.