Legal
Data Processing Agreement
This Data Processing Agreement ("DPA") template applies between Acredia ("Processor") and an institution using the Acredia platform ("Controller"). To execute a binding DPA, contact us at acredia.stellar@gmail.com.
Template version: 8 August 2026
Service stage: Stellar test network
Acredia currently operates on the Stellar test network on a beta basis. Controllers should not process production student records through the Service until it moves to the Stellar public network.
1. Definitions
- "Controller" — the institution that determines the purposes and means of processing student personal data.
- "Processor" — Acredia, which processes personal data on behalf of the Controller.
- "Personal Data" — any information relating to an identified or identifiable natural person, as defined in GDPR Art. 4(1).
- "Processing" — any operation performed on personal data, including storage, retrieval, and deletion.
- "Sub-processor" — a third party engaged by the Processor to process personal data (see Schedule B).
2. Subject matter & scope
Acredia processes student personal data solely to provide the credential issuance and verification services described in the Terms of Service. The categories of personal data processed and the purposes of processing are set out in Schedule A.
3. Processor obligations
Acredia shall:
- Process personal data only on documented instructions from the Controller, unless required by law.
- Ensure that persons authorised to process personal data have committed to confidentiality.
- Implement appropriate technical and organisational security measures (Art. 32 GDPR).
- Not engage sub-processors without prior general or specific written authorisation.
- Assist the Controller in fulfilling data-subject rights requests.
- Delete or return all personal data upon termination of the agreement, subject to legal retention requirements.
- Make available all information necessary to demonstrate compliance and allow audits.
4. Controller obligations
The Controller shall:
- Ensure there is a valid lawful basis to issue credentials containing student personal data.
- Provide accurate data and promptly notify Acredia of corrections.
- Inform students that their credential data will be stored on Acredia and anchored on the Stellar blockchain.
5. On-chain data & erasure
Blockchain immutability notice
Credential issuance writes a SHA-256 hash (not personal data) to the Stellar blockchain. This record is technically immutable. Both parties acknowledge that this hash is pseudonymous and relies on the Art. 17(3)(b) GDPR exemption. All personally identifiable fields (name, email, metadata JSONB) will be redacted from Acredia's database and the IPFS document will be unpinned upon a valid erasure request, but the on-chain hash cannot be removed.
6. Security measures (Art. 32)
- TLS 1.2+ encryption for all data in transit.
- AES-256-GCM encryption for credential documents stored on IPFS.
- Row Level Security (RLS) enforced at the database layer.
- API rate limiting and bearer-token authentication on all data endpoints.
- Regular security reviews and a responsible-disclosure process for reported vulnerabilities.
7. Personal data breach notification
Acredia shall notify the Controller without undue delay and, where feasible, within 48 hoursof becoming aware of a personal data breach affecting the Controller's data. The notification will describe, to the extent known: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; and the measures taken or proposed to address it and mitigate its effects.
Acredia shall provide reasonable assistance to enable the Controller to meet its own obligations under Art. 33 and 34 GDPR, including any notification to a supervisory authority or to affected data subjects. Reporting a breach is not an admission of fault or liability by either party.
8. International transfers
The Controller acknowledges that Acredia's database and authentication sub-processor hosts data in the Asia-Pacific region, and its IPFS pinning sub-processor in the United States (see Schedule B). Personal data processed under this DPA is therefore stored outside the EEA and the UK.
Each such transfer is made under an appropriate safeguard permitted by Chapter V GDPR — principally the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), incorporated through Acredia's agreement with each sub-processor. On request, Acredia will provide the Controller with the information needed to complete a transfer impact assessment.
The Controller acknowledges that the Stellar network and IPFS are public, globally distributed systems whose node locations cannot be controlled by either party. Only irreversible hashes, wallet addresses and encrypted content are published to those networks; no plain-text personal data is transferred to them.
9. Duration & termination
This DPA takes effect when the Controller begins using the Service and remains in force for as long as Acredia processes personal data on the Controller's behalf. On termination, Acredia will delete or return the Controller's personal data at the Controller's choice, save where storage is required by law and save for the immutable on-chain hashes described in §5. Clauses which by their nature should survive termination (including confidentiality and §5) continue to apply.
Schedule A — Data categories
| Category | Subjects | Purpose |
|---|---|---|
| Name, email | Students, institution staff | Account creation & credential association |
| Credential metadata (degree, grade, dates) | Students | Credential issuance & verification |
| Stellar wallet address | Students, institutions | Blockchain credential anchoring |
Schedule B — Sub-processors
| Sub-processor | Country | Purpose | Safeguard |
|---|---|---|---|
| Supabase | Asia-Pacific | Database & auth | DPA + SCCs |
| Pinata | US | IPFS pinning | DPA + SCCs; content encrypted before upload |
| Stellar Network | Global (decentralised) | Blockchain anchoring | No PII on-chain (hashes only) |