Data Processing Agreement
Last updated June 30, 2026
This DPA forms part of the Terms of Service between Obol ("Processor") and a business customer ("Controller") where Obol processes personal data on the Controller's behalf. Enterprise customers can countersign a copy — email obolmcp@gmail.com.
1. Roles
For data the Controller submits to Obol (e.g. their team's accounts), Obol acts as Processor and the customer as Controller. For Obol's own account data, Obol is the Controller (see our Privacy Policy). Where a seller's service processes its buyers' personal data, the seller is the controller for that processing — Obol does not process the content of seller services.
2. Scope & purpose
Obol processes personal data only to provide the marketplace: authentication, listing, payment routing/metering, security, and support. Obol processes data per the Controller's documented instructions (these terms and use of the product) and will not process it for any other purpose.
3. Categories of data & subjects
- Subjects: the Controller's authorized users / agents.
- Data: account identifiers (email), public wallet addresses, API-key metadata (hashed), listings, transaction records. No special-category data is required by Obol.
4. Sub-processors
The Controller authorizes these sub-processors; Obol remains responsible for their compliance and will give notice of changes:
- Google Cloud / Firebase — hosting, auth, database (SOC 2, ISO 27001, GDPR).
- Circle — USDC settlement and on-chain rails (regulated money-services provider).
5. Security
Obol maintains appropriate technical and organizational measures: encryption in transit (TLS) and at rest, least-privilege access controls, secret management, audit logging, and monitoring on Google Cloud's audited platform. Secrets (API-key hashes, 2FA seeds) are encrypted and never exposed.
6. Data-subject rights & assistance
Obol provides self-service export and deletion in-product and will assist the Controller in responding to data-subject requests (access, rectification, erasure, portability, restriction) without undue delay.
7. Breach notification
Obol will notify the Controller without undue delay (and within 72 hours where feasible) after becoming aware of a personal-data breach affecting the Controller's data, with the information needed to meet the Controller's own notification duties.
8. International transfers
Where personal data is transferred outside the EEA/UK, transfers rely on Standard Contractual Clauses and the sub-processors' transfer mechanisms.
9. Deletion & return
On termination or request, Obol deletes or returns the Controller's personal data, except where retention is legally required. In-product deletion erases the user's records and authentication identity.
10. Audit
Obol will make available the information necessary to demonstrate compliance, including third-party audit reports of its sub-processors (e.g. Google Cloud SOC 2) and, for enterprise customers, completed security questionnaires.
11. Compliance status
Obol inherits SOC 2 / ISO 27001 / GDPR-compliant infrastructure from Google Cloud and Circle, and operates a minimal-data design. Obol's own SOC 2 Type II is available to enterprise customers on request or in progress; contact obolmcp@gmail.com for current status and a countersigned DPA.