US State Privacy Addendum
Version 1.0 — July 2026
No signature required
This Addendum is accepted in the Xident Dashboard. Xident is bound by publishing it, you are bound by accepting it, and we record the version, a hash of the text you accepted, your name and title, and the timestamp. There is nothing to countersign and nothing to negotiate — the terms are identical for every customer. If your legal team needs a countersigned copy for its files, email [email protected].
Which document applies to you?
This Addendum supplements — it does not replace — the Data Processing Agreement. If you are subject only to US state privacy law, this Addendum governs and the DPA applies to everything it does not address. If you are subject to both EU and US law, both apply. Accepting takes one click either way.
United States State Privacy Addendum to the Xident Data Processing Agreement
Between the Customer (“Business” or “Controller”) and Xident (“Service Provider” or “Processor”)
Table of Contents
- Scope, Precedence, and Acceptance
- Definitions
- Roles of the Parties
- Service Provider Obligations and Restrictions
- Biometric Identifiers and Biometric Information
- Sensitive Personal Information
- Deidentified and Aggregate Data
- Consumer Rights Requests
- Security and Breach Notification
- Subcontractors
- Assessments and Audits
- Cross-Border Processing
- Term, Termination, and Survival
- General Provisions
- Annexes
1. SCOPE, PRECEDENCE, AND ACCEPTANCE
1.1 Purpose. This Addendum supplements the Xident Data Processing Agreement (the “DPA”) where the Customer is subject to one or more United States state privacy laws. It exists so that a Customer established in the United States receives terms written for the law that actually applies to it, rather than terms drafted solely for Regulation (EU) 2016/679.
1.2 Application. This Addendum applies to Processing of Personal Information about Consumers who are residents of a US state whose privacy law applies to the Customer, including but not limited to the laws listed in Annex A.
1.3 Precedence. In the event of a conflict, the order of precedence is: (a) this Addendum, for Processing subject to US State Privacy Laws; (b) the DPA; (c) the Agreement. The DPA continues to apply in full to all other Processing. Nothing in this Addendum reduces any protection afforded under the DPA.
1.4 Acceptance. This Addendum is accepted electronically through the Xident Dashboard. Xident is bound by publication of this Addendum; the Customer is bound upon acceptance. Xident records the version accepted, a cryptographic hash of the accepted text, the name and title of the accepting individual, the originating IP address, and the timestamp. That record is the parties’ evidence of execution and no countersignature is required.
1.5 No Separate Negotiation Required. This Addendum is offered on identical terms to all Customers. A Customer requiring a countersigned copy for its own records may request one at [email protected]; this does not change the terms.
2. DEFINITIONS
2.1 Terms not defined here have the meaning given in the DPA or, where the context requires, in the applicable US State Privacy Law.
2.2 Mapping of Terms. The DPA uses the vocabulary of Regulation (EU) 2016/679. For Processing subject to US State Privacy Laws, the following terms are equivalent:
| DPA term (EU) | Equivalent term (US) |
|---|---|
| Controller | Business (California) / Controller (all other states) |
| Processor | Service Provider or Contractor (California) / Processor (all other states) |
| Data Subject | Consumer |
| Personal Data | Personal Information |
| Special Category Data | Sensitive Personal Information / Sensitive Data |
| Sub-Processor | Subcontractor |
| Personal Data Breach | Security Breach / Breach of the Security of the System |
2.3 “US State Privacy Laws” means the state statutes and their implementing regulations listed in Annex A, as amended, together with any successor or additional state privacy law that comes into effect and applies to the Customer.
2.4 “Biometric Data” means, collectively, “biometric identifiers” and “biometric information” as defined under 740 ILCS 14/10, “biometric identifier” as defined under Tex. Bus. & Com. Code § 503.001, “biometric data” as defined under Wash. Rev. Code § 19.375.010, and equivalent terms under any other US State Privacy Law.
3. ROLES OF THE PARTIES
3.1 Allocation. The Customer is the Business or Controller. Xident is the Service Provider or Processor. Xident Processes Personal Information solely on the Customer’s documented instructions and solely to perform the Services.
3.2 Determination of Purposes. The Customer determines the age threshold, the verification method configuration, the countries in which verification is offered, and the retention configuration available to it. Xident does not determine the purposes of Processing.
3.3 Not a Sale or Share. The parties acknowledge and agree that the disclosure of Personal Information by the Customer to Xident is made for a Business Purpose, is not a “sale” and is not a “share” as those terms are defined under the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), and that no monetary or other valuable consideration is exchanged for the Personal Information itself. Xident’s fees are consideration for the Services only.
3.4 Independent Controller Processing. Xident acts as an independent Controller only with respect to (a) Xident account holders who create an account directly with Xident, and (b) Service operational data such as billing records, security logs, and aggregate usage metrics that contain no Consumer Personal Information. Such Processing is governed by the Xident Privacy Policy and not by this Addendum.
4. SERVICE PROVIDER OBLIGATIONS AND RESTRICTIONS
4.1 Certification. Xident certifies that it understands the restrictions in this Section 4 and will comply with them. This certification is given for the purposes of Cal. Civ. Code § 1798.140(ag)(1)(D) and the equivalent provisions of the other US State Privacy Laws.
4.2 Restrictions. Xident shall not:
- (a) sell or share the Personal Information, as those terms are defined under the CCPA;
- (b) retain, use, or disclose the Personal Information for any purpose other than performing the Services specified in the Agreement, including for any commercial purpose other than those Services;
- (c) retain, use, or disclose the Personal Information outside the direct business relationship between Xident and the Customer;
- (d) combine the Personal Information with Personal Information received from or on behalf of another person, or collected from its own interaction with a Consumer, except where permitted by Cal. Civ. Code § 1798.140(ag)(1) — and specifically excepting the Xident identity network described in Section 4.3, which operates only on the Consumer’s own instruction;
- (e) use the Personal Information to build or improve a profile about a Consumer for any purpose other than performing the Services;
- (f) train general-purpose machine-learning models on Consumer Personal Information. Xident’s age-recognition models are trained on separately sourced, consented datasets and are not trained on Customer verification data.
4.3 The Xident Identity Network. Where a Consumer voluntarily creates a Xident account, that Consumer may reuse a previously verified age bracket across Customers. This reuse occurs on the Consumer’s own instruction, at the moment of verification, and the Customer receives only a pass/fail result. Xident does not disclose to any Customer that a Consumer has verified with another Customer, and does not disclose any Customer’s identity to another Customer.
4.4 Same Level of Protection. Xident shall provide the same level of privacy protection as the Customer is required to provide under the applicable US State Privacy Law.
4.5 Notification of Inability to Comply. Xident shall notify the Customer without undue delay, and in any event within five (5) business days, if it determines that it can no longer meet its obligations under the applicable US State Privacy Law.
4.6 Customer Remediation Rights. The Customer may take reasonable and appropriate steps to stop and remediate any unauthorised use of Personal Information by Xident, including by directing Xident to cease specified Processing, requiring deletion, or suspending the transmission of Personal Information.
4.7 Limitation on Instructions. Xident shall notify the Customer if, in Xident’s reasonable opinion, an instruction from the Customer would cause Xident to violate an applicable US State Privacy Law, and may decline to act on that instruction.
5. BIOMETRIC IDENTIFIERS AND BIOMETRIC INFORMATION
This Section applies to all Processing of Biometric Data and takes precedence over any conflicting provision.
5.1 What Xident Processes and What It Does Not.
| Processing step | What leaves the Consumer’s device | What Xident stores |
|---|---|---|
| Liveness detection | Nothing. Runs entirely in the browser. | Pass/fail result and a challenge identifier. No image. |
| Age recognition (Path A) | Nothing. The model runs on-device via ONNX/WebAssembly. | A binary above/below result per threshold. No image. |
| Document verification (Path B) | The document image and a selfie, over TLS, to storage in the European Union. | A 512-dimension facial embedding, retained for the period the Customer selects in the dashboard (0 to 365 days; default 365) and in no case for more than one (1) year, per Section 5.3. The images are deleted on completion of OCR processing and in all cases within twenty-four (24) hours of upload, retained during that window only to support retakes and abuse reporting. |
| Returning-user verification (Path D) | Nothing new. | Nothing new. A previously stored embedding is compared. |
5.2 No Raw Biometric Retention. Xident does not retain facial images. It retains a mathematical embedding from which the original image cannot be reconstructed. The embedding is encrypted at rest.
5.3 Retention and Destruction Schedule. For the purposes of 740 ILCS 14/15(a) and Tex. Bus. & Com. Code § 503.001(c-2), Xident’s written retention schedule and destruction guidelines are:
| Data | Destruction trigger |
|---|---|
| Document and selfie images | Immediately upon completion of OCR processing, and in all cases within twenty-four (24) hours of upload |
| Facial embeddings | At the end of the retention period the Customer selects in the dashboard (0, 30, 90, 180 or 365 days from collection; default 365), on satisfaction of the purpose for which they were collected, on Consumer or Customer deletion request, or no later than one (1) year after the Consumer’s last interaction with the Customer, whichever occurs first |
| Liveness data | On completion of the verification session; not retained |
| Verification session records | Ninety (90) days after session completion, then hard deleted |
The one-year outer limit is deliberately shorter than the three years permitted by 740 ILCS 14/15(a), and matches the shorter period required by Texas CUBI. This schedule is published and forms part of this Addendum.
5.4 Destruction Means Hard Deletion. Destruction under Section 5.3 is a hard delete, not a soft delete or flag. Deletion cascades to all related records.
5.5 No Sale, Lease, Trade, or Profit. Xident shall not sell, lease, trade, or otherwise profit from a Consumer’s Biometric Data. Xident’s fees are consideration for performing verification, not for the Biometric Data.
5.6 No Disclosure. Xident shall not disclose, redisclose, or otherwise disseminate Biometric Data except: (a) with the Consumer’s consent; (b) to complete a financial transaction the Consumer requested and authorised; (c) as required by federal, state, or local law; or (d) pursuant to a valid warrant or subpoena.
5.7 Standard of Care. Xident shall store, transmit, and protect Biometric Data using a reasonable standard of care within its industry, and in a manner that is the same as or more protective than the manner in which it stores, transmits, and protects other confidential and sensitive information.
5.8 Consent Is the Customer’s Responsibility. The Customer is responsible for providing the written notice and obtaining the written release required by 740 ILCS 14/15(b) and the equivalent notice and consent required by other US State Privacy Laws, before directing a Consumer to the verification flow. Xident makes available notice text and a consent checkpoint within the verification widget to support the Customer in doing so, but the obligation and the record of consent remain the Customer’s.
5.9 Consumer Health Data. Where a verification would constitute the Processing of “consumer health data” under the Washington My Health My Data Act or a comparable statute, Xident Processes it solely as a Processor on the Customer’s instruction, applies Sections 5.1 to 5.7, and does not sell it. The Customer is responsible for obtaining any separate authorisation that statute requires.
6. SENSITIVE PERSONAL INFORMATION
6.1 Date of birth, government identity document data, and Biometric Data are Sensitive Personal Information under the CCPA and Sensitive Data under the other US State Privacy Laws.
6.2 Xident Processes Sensitive Personal Information only to perform the Services and only for the purposes listed in Annex 1 of the DPA. Xident does not use it to infer characteristics about a Consumer.
6.3 The Customer receives a pass/fail result and, where a verification does not pass, a machine-readable reason code. The Customer does not receive a Consumer’s actual date of birth, document images, or Biometric Data.
7. DEIDENTIFIED AND AGGREGATE DATA
7.1 Xident may create and use deidentified and aggregate data derived from Processing for the purposes of operating, securing, and improving the Services, and for producing aggregate statistics.
7.2 With respect to any such data, Xident shall: (a) take reasonable measures to ensure it cannot be associated with a Consumer or household; (b) publicly commit to maintaining and using it only in deidentified form and not to attempt to reidentify it; and (c) contractually obligate any recipient to the same.
7.3 Xident shall not attempt to reidentify deidentified data except to test the effectiveness of its own deidentification measures, and shall delete any reidentified data immediately upon completion of that test.
8. CONSUMER RIGHTS REQUESTS
8.1 Routing. Where a Consumer submits a rights request directly to Xident that relates to Processing performed for a Customer, Xident shall not respond substantively and shall promptly direct the Consumer to the Customer, informing the Customer of the request.
8.2 Assistance. Xident shall provide the Customer with reasonable assistance in responding to verifiable Consumer requests to know, access, correct, delete, limit the use of Sensitive Personal Information, opt out, or obtain a portable copy, taking into account the nature of the Processing.
8.3 Deletion. On the Customer’s instruction, Xident shall delete the relevant Personal Information and instruct its Subcontractors to do the same, except where retention is required by law. Deletion is a hard delete.
8.4 Timeframe. Xident shall act on a Customer instruction under this Section within ten (10) business days, so that the Customer can meet the statutory deadlines applicable to it.
8.5 No Charge. Xident does not charge for assistance under this Section for a volume of requests consistent with the Customer’s Service tier.
9. SECURITY AND BREACH NOTIFICATION
9.1 Security Measures. Xident shall implement and maintain reasonable security procedures and practices appropriate to the nature of the Personal Information, as described in Annex 2 of the DPA. Those measures apply in full under this Addendum.
9.2 Notification. Xident shall notify the Customer without unreasonable delay, and in any event within twenty-four (24) hours, of becoming aware of a Security Breach affecting the Customer’s Personal Information.
9.3 Contents. The notification shall describe the nature of the Breach, the categories and approximate number of Consumers and records affected, the likely consequences, the measures taken or proposed, and a contact point.
9.4 Cooperation. Xident shall cooperate with the Customer in the Customer’s assessment of its own notification obligations under applicable state breach-notification law. As Processor, Xident does not notify Consumers or regulators on the Customer’s behalf unless instructed in writing.
10. SUBCONTRACTORS
10.1 Xident engages the Subcontractors listed in Annex 3 of the DPA. That list applies under this Addendum.
10.2 Xident shall impose on each Subcontractor, by written contract, obligations that are at least as protective as those in this Addendum, including the restrictions in Section 4.2 and, where the Subcontractor Processes Biometric Data, those in Section 5.
10.3 Xident shall give the Customer at least thirty (30) days’ notice before engaging a new Subcontractor. The Customer may object on reasonable data-protection grounds, and where the objection cannot be resolved the Customer may terminate the affected Services without penalty.
10.4 Xident remains liable to the Customer for the performance of each Subcontractor’s obligations.
11. ASSESSMENTS AND AUDITS
11.1 Xident shall make available to the Customer the information reasonably necessary to demonstrate compliance with this Addendum, including the Subcontractor list, the security measures in Annex 2 of the DPA, and this retention schedule.
11.2 No more than once per twelve (12) months, and on thirty (30) days’ notice, the Customer may request a report of an assessment of Xident’s policies and technical and organisational measures, using an appropriate and accepted control standard, performed by a qualified and independent assessor. Xident shall provide a report of that assessment to the Customer on request.
11.3 Where the Customer is required to conduct a data protection assessment under an applicable US State Privacy Law, Xident shall provide the information within its possession that is reasonably necessary for that assessment.
12. CROSS-BORDER PROCESSING
12.1 Where Processing Occurs. Xident’s production infrastructure — application servers, database, cache, queue, and object storage — is located in the European Union. Personal Information originating in the United States is Processed in the European Union.
12.2 Effect. No US State Privacy Law restricts the transfer of Personal Information to the European Union, and the European Union provides a level of statutory data protection at least equivalent to that of any US state. Processing location therefore imposes no additional obligation on the Customer under this Addendum.
12.3 Notification of Change. Xident shall notify the Customer before any change to the location of Processing infrastructure that would move Personal Information outside the European Union.
12.4 Government Access. Xident shall notify the Customer of any binding request from a public authority for Personal Information Processed on the Customer’s behalf, unless prohibited by law, and shall challenge any request that appears unlawful or overbroad.
13. TERM, TERMINATION, AND SURVIVAL
13.1 This Addendum takes effect on acceptance and continues for as long as Xident Processes Personal Information on the Customer’s behalf.
13.2 On termination, Xident shall, at the Customer’s election, delete or return the Personal Information, and delete existing copies except where retention is required by law. Absent an election within thirty (30) days of termination, Xident shall delete.
13.3 Sections 4.2 (Restrictions), 5.5 to 5.7 (Biometric Data), 7 (Deidentified Data), and 14 (General Provisions) survive termination.
14. GENERAL PROVISIONS
14.1 Governing Law. This Addendum is governed by the laws of the State of Delaware, without regard to its conflict-of-laws rules, except that the substantive requirements of an applicable US State Privacy Law govern the interpretation of the provisions implementing that law. This Section 14.1 displaces Section 13.1 of the DPA for Processing subject to this Addendum.
14.2 Venue. The parties submit to the exclusive jurisdiction of the state and federal courts located in Delaware, without prejudice to a Consumer’s statutory rights or to any mandatory venue provision of an applicable US State Privacy Law.
14.3 Updates. Xident may update this Addendum to reflect a change in applicable law or in Xident’s Processing. Xident shall give thirty (30) days’ notice of a material change and shall not reduce the level of protection afforded to Personal Information. Continued use of the Services after the notice period constitutes acceptance; a Customer that does not accept may terminate the affected Services without penalty.
14.4 Severability. If any provision is held invalid or unenforceable, the remainder continues in effect.
14.5 Notices. Notices to Xident under this Addendum go to [email protected]. Notices to the Customer go to the contact on the Customer’s account.
14.6 No Third-Party Beneficiaries. Except as an applicable US State Privacy Law expressly provides for Consumers, this Addendum creates no third-party rights.
ANNEXES
ANNEX A: APPLICABLE US STATE PRIVACY LAWS
This Addendum is written to satisfy the processor/service-provider contracting requirements of the following. The list is descriptive; the Addendum applies to any US state privacy law that applies to the Customer, whether or not listed.
| State | Law | Relevance to the Services |
|---|---|---|
| California | CCPA as amended by CPRA | Service-provider contract terms; Sensitive Personal Information |
| Illinois | BIPA (740 ILCS 14) | Biometric Data. Private right of action with statutory damages |
| Texas | CUBI (Bus. & Com. Code § 503.001); TDPSA | Biometric Data; one-year destruction requirement |
| Washington | My Health My Data Act | Consumer health data. Private right of action |
| Virginia | VCDPA | Controller/processor contract terms; sensitive data consent |
| Colorado | CPA and Colorado Privacy Act Rules | Processor duties; data protection assessments |
| Connecticut | CTDPA | Processor duties |
| Oregon, Montana, Texas, Utah, and other states | Comprehensive privacy statutes in effect | Processor duties; sensitive data |
ANNEX B: WHAT THE CUSTOMER RECEIVES
For the avoidance of doubt, and because it is the shortest description of Xident’s data-minimisation posture:
| The Customer receives | The Customer does not receive |
|---|---|
| A pass/fail verification result | The Consumer’s date of birth |
| A reason code where a verification does not pass | Any document image |
| The age threshold that was tested | Any facial image or embedding |
| A verification token identifier, session identifier and timestamp | Any document number |
The Customer’s own user_id, echoed back |
Any data about the Consumer’s activity with another Customer |
This Addendum supplements and does not replace the Xident Data Processing Agreement. Where the Customer is subject to both EU and US privacy law, both documents apply.