Skip to content
Invisproof
Log inRequest access

Use cases

Board and leadership materialBoard packs, strategy papers and minutesTransactions and due diligenceMemoranda, term sheets and disclosure documentsPre-release film, music and artworkScreeners, mixes and stills before releaseResearch and product developmentSpecifications, designs and findingsEmbargoed announcementsResults, press releases and launch materialSource identificationA found copy matched to the copy it came from
OverviewAll use cases

Industries

Legal servicesLaw firms and legal departmentsFinancial servicesBanks, funds and advisersMedia and entertainmentStudios, labels, publishers and game developersTechnology and manufacturingTechnology companies and manufacturers
OverviewAll industries

Company

About usSecurityContact

Legal

Terms of ServicePrivacy PolicyData Processing Addendum

Invisproof is provided to organizations by approval.

Request access
Board and leadership materialBoard packs, strategy papers and minutesTransactions and due diligenceMemoranda, term sheets and disclosure documentsPre-release film, music and artworkScreeners, mixes and stills before releaseResearch and product developmentSpecifications, designs and findingsEmbargoed announcementsResults, press releases and launch materialSource identificationA found copy matched to the copy it came from
Legal servicesLaw firms and legal departmentsFinancial servicesBanks, funds and advisersMedia and entertainmentStudios, labels, publishers and game developersTechnology and manufacturingTechnology companies and manufacturers
About usSecurityContactTerms of ServicePrivacy PolicyData Processing Addendum
Request accessLog in

Invisproof Data Processing Addendum

Last Updated: October 7, 2026

These Data Processing Terms form part of the Terms of Service (“Agreement”) between Invisproof and you and apply when we process Personal Data on your behalf in the course of providing the services provided by Invisproof (the “Services”). These Data Processing Terms do not apply where we are the Controller. Defined and/or capitalized terms not defined here have the meanings given to them in the Agreement. If not defined in the Agreement, capitalized terms have the meaning given to them, or an equivalent term, in applicable data protection, privacy or security laws (“Privacy Laws”). “Personal Data” has the same meaning as “Personal Information” in the Agreement. These Data Processing Terms take precedence over any other terms of the Agreement in relation to the Processing of Personal Data. For your convenience, you may sign these Data Processing Terms and return a copy to us at legal@invisproof.com.

1. Parties

“Invisproof”, “we”, “us” or “our” means Invisproof LLC. “You” or “your” means collectively the other entity(ies) executing or assenting to the Order Form. “Affiliate” means any entity that controls, is controlled by, or is under common control with, another entity. An entity “controls” another if it owns directly or indirectly a sufficient voting interest to elect a majority of the directors or managing authority or otherwise direct the affairs or management of the entity.

2. Processing

With respect to the Processing of Personal Data, you act as a Controller, “business”, or Processor and Invisproof is a Processor or “service provider”. We will only Process Personal Data as permitted under the Agreement and applicable Privacy Laws. We will not “sell” Personal Data. You agree that the Agreement represents your complete instructions to us and any additional changes you require must be mutually agreed. We will inform you if we believe that any of your instructions violate law, unless prohibited on important grounds of public interest. Details regarding the Processing of Personal Data are specified in Annex 1. You are solely responsible for complying with Privacy Laws regarding the Processing of Personal Data (including obtaining consents) and warrant that you comply with the same. You shall indemnify us, our Affiliates, subcontractors, and licensors from all third-party claims or losses arising from the Processing of Personal Data in accordance with this Agreement.

3. Subprocessors

You authorize us to use other Processors, including Invisproof affiliates and service providers, (“Subprocessors”) to Process Personal Data, so long as they are required to abide by terms substantially similar to these Data Processing Terms. We will be liable to you for the performance of our Subprocessor’s obligations under the Agreement. Our current Subprocessors are listed in Annex 3.

We may change the list of Subprocessors with thirty (30) days’ notice to you (which notice may be by email or posting on our website). You may object to our change in such Subprocessors on reasonable data protection grounds by notifying us in writing within fourteen (14) days of our notice. If we and you cannot resolve the objection through commercially reasonable efforts, we may (without liability to you) terminate the portion of the Agreement relating to the Services that cannot reasonably be provided without the objected-to new Subprocessor.

4. Security

We will implement appropriate technical and organizational measures to protect Personal Data, as described in Annex 2 (“Security Measures”). We may update or modify the Security Measures, so long as the overall security level of the Services is maintained. You are solely responsible for determining whether the Security Measures meet your requirements. You agree that the level of security provided by the Security Measures is appropriate to the risk inherent in the Services. You are responsible for configuring the Services in a manner which enables you to comply with applicable Privacy Laws. We will ensure that only authorized personnel who are under written obligations of confidentiality or are under an appropriate statutory obligation of confidentiality may access Personal Data.

The Services are not designed to Process Special Categories of Data, cardholder data subject to the Payment Card Industry Security Standard (“PCI DSS”), protected health information, children’s Personal Data, or other Personal Data inappropriate for the nature of the Services (collectively, “Prohibited Data”). You shall not submit Prohibited Data to us or to the Services, unless authorized to do so in writing by Invisproof.

5. Security Incident

We will notify you without undue delay after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorized access, disclosure or use of Personal Data while processed by us (each a “Security Incident”) in relation to the Services under the Agreement. We will investigate the Security Incident and provide you with relevant information about the Security Incident as required under Privacy Laws. We will use reasonable efforts to assist you in mitigating, where possible, the adverse effects of any Security Incident.

6. Compliance

On written request and subject to obligations of confidentiality, we will provide to you information reasonably necessary, including any relevant certifications, to demonstrate our compliance with these Data Processing Terms. With respect to Subprocessors, we may fulfill our responsibilities under this Section 6 by providing you with audit reports or certifications provided by such Subprocessors.

7. Data Transfers

The location in which your files and records are stored is set out in Section 8.7 of the Terms of Service. You authorize us and our Subprocessors to transfer Personal Data to locations outside of its country of origin for the performance of the Agreement, provided that we implement appropriate transfer safeguards to comply with applicable Privacy Laws.

If we transfer Personal Data from the European Economic Area (“EEA”), UK, Switzerland or from any other jurisdiction that restricts the cross-border transfer of Personal Data to locations outside that jurisdiction, you shall be bound by the standard contractual clauses approved by the European Commission in Commission Decision 2021/914 dated 4 June 2021, for transfers of personal data to countries not otherwise recognized as offering an adequate level of protection for personal data by the European Commission (as amended and updated from time to time) (“SCCs”) in the capacity of “data exporter”, and Invisproof in the capacity of “data importer” as those terms are defined therein. The SCCs will be deemed to have been signed by each Party and are hereby incorporated by reference into the Agreement in their entirety as if set out in full as an annex to this Agreement. The Parties acknowledge that the information required to be provided in the appendices to the SCCs is set out in Annex 1 below as a “Description of the Transfer” and “Security Measures” as a “Description of the Technical Organizational Measures” in Annex 2. Audits under Section 8.9 of the SCCs shall be carried out in accordance with the above Section 6. The SCCs will prevail over these Data Processing Terms or the Agreement, in the event of conflict.

8. Cooperation

We will cooperate with you to respond to requests, complaints or inquiries from data subjects, supervisory authorities, or other third parties, conduct a privacy impact assessment and prior consultation with supervisory authorities, provided that you reimburse us for all reasonably incurred costs. If we receive a data subject request relating to Personal Data, we will provide it to you. We will not respond to the data subject request unless required by applicable law.

9. Termination

Upon termination of the Agreement, we will return and delete Personal Data as set out in Section 12.4 of the Terms of Service, except to the extent set out in that Section, in which case these Data Processing Terms will continue to apply to the retained Personal Data. Any certification of deletion will be provided to you only upon your written request.

10. Signature

Upon execution of these Data Processing Terms, you represent that you are the authorized signatory for your organization.

The customer completes this block, and only if it wants a signed copy. These Data Processing Terms apply without it.

Customer To be completed by the customer
Company
Name
Title
Date
Signature

Annex 1: Description of the Processing and Transfer (Module 2: Controller to Processor)

A. List of the parties

Role Party
Controller / Data Exporter You and your Affiliates, as set forth in the Agreement.
Processor / Data Importer Invisproof LLC, 30 N Gould St Ste N, Sheridan, WY 82801, United States. Contact: privacy@invisproof.com.

B. Details of processing and transfer

Item Description
Categories of data subjects The Personal Data processed and transferred is determined and controlled by you in your sole discretion and may include, without limitation, the following categories of Data Subjects: Authorized Users of the Services; Recipients for whom Marked Copies are made; any other individual whose Personal Data is contained in Customer Content; any other data subject as described in the Agreement.
Categories of Personal Data The Personal Data processed and transferred is determined and controlled by you in your sole discretion and may include, without limitation, the following categories of data: name, email address, role in your organization, sign-in credentials, IP addresses and browser type; for Recipients, a reference (such as an email address) kept as a keyed pseudonym, a name kept in protected form, and the record of which Marked Copy was made for which Recipient; any Personal Data contained in Customer Content.
Special categories of data The Services are not intended for the Processing of Special Categories of Data or Prohibited Data, and you shall not transfer them, directly or indirectly, to us.
Frequency The Personal Data transfers under the Agreement will take place on a continuous basis.
Nature of the processing Invisproof and its Subprocessors are providing the Services or fulfilling contractual obligations to you, as described in the Agreement. These Services may include the processing of Personal Data by Invisproof and/or its Subprocessors.
Purpose of processing and transfer Your Personal Data is processed and transfer is made for the following purposes: (i) providing the Services, including making Marked Copies and Trace Reports; (ii) identity management and security; (iii) any other scope and purpose as described in the Agreement.
Retention Your Personal Data will be retained in accordance with the Agreement unless applicable law requires storage of the Personal Data for a longer period.
Transfer to Subprocessors Invisproof may process and transfer Personal Data to Subprocessors in relation to the performance of the Agreement. Subject matter: the Personal Data. Nature of the processing: as described above. Duration: determined by you and as set forth in the Agreement.

C. Competent supervisory authority

For the purposes of Clause 13 of the SCCs, the competent supervisory authority for the Customer shall be the supervisory authority applicable to the Customer in its EEA country of establishment or, where it is not established in the EEA, in the EEA country where its representative has been appointed pursuant to Article 27(1) of Regulation (EU) 2016/679.

D. Governing law and choice of forum

For the purposes of Clause 17 of the SCCs, the parties select the law of Ireland. For the purposes of Clause 18 of the SCCs, the parties agree that the courts of Ireland will have jurisdiction.

E. Other

Where the SCCs identify optional provisions or provisions with multiple options the following will apply:

  • For Clause 7 (Docking Clause), the optional provision will apply.
  • For Clause 9(a), option 2 will apply. The parties will follow the process agreed in Section 3 (Subprocessors).
  • For Clause 11(a) (Redress), the optional provision will not apply.
  • For Clause 12 (Liability), the limitation of liability in the Terms of Service applies to these Data Processing Terms.

Annex 2: Security Measures

This Annex 2 describes the Security Measures designed to protect and secure our Services when we process Personal Data under the Agreement. We may update or modify the Security Measures from time to time provided that such updates and modifications do not result in a material degradation of the overall security of the Services provided under the Agreement. Beta offerings may be subject to different practices.

Category Practices
Personnel security Invisproof personnel engaged in data processing are under a written obligation of confidentiality and may not collect, process or use Personal Data without authorization.
Data handling Each customer organization’s records are kept in a database of its own, separate from those of other organizations. Files and records are stored in the location the customer selects, European Union or United States. Recipient references are kept only as keyed pseudonyms, and Recipient names are kept in protected form.
Access control Secure log-in with unique user accounts; passwords are kept in hashed form; passkeys and two-step sign-in are supported, and an organization can require a second step or its own sign-in provider. Role based access (least privilege). Invisproof staff see Recipient pseudonyms; a Recipient’s name is shown to staff only through a look-up that requires a stated reason and is recorded.
Auditing and logging Actions on files, Marked Copies and checks, and administrative changes, are recorded in logs that cannot be edited or deleted one by one.
Processing by Subprocessors Files are sent to the computing Subprocessor only to be marked or read; no information about Recipients is sent with them, and the files are not kept there after the job.
Backup Database recovery history is kept for thirty (30) days. Backup copies are made nightly.
Third parties Invisproof uses Cloudflare for its cloud computing infrastructure and data center facilities for the Services. Invisproof relies on the physical and environmental controls of its third-party cloud providers.

Annex 3: Subprocessors

Subprocessor What it does for us Where it processes
Cloudflare, Inc. Hosting, databases, file storage, delivery of the Services, email sending and logs Stored files and records: the location you select, European Union or United States. Other processing: Cloudflare’s network, in the United States and other countries.
Modal Labs, Inc. Computing that adds forensic watermarks to files and reads them Not fixed to a region; includes the United States.
Backblaze, Inc. Storage of backup copies United States
Invisproof

Use cases

  • Board material
  • Transactions
  • Pre-release media
  • Research
  • Announcements
  • Investigations

Solutions

  • Legal
  • Finance
  • Media
  • Technology

Company

  • About us
  • Security
  • Contact

Legal

  • Terms
  • Privacy
  • Data processing

© 2026 Invisproof LLC

Icons: Solar Icon Set by 480 Design CC BY 4.0