Data processing agreement

Add your company details, then download the completed agreement as a PDF.

The PDF is built in your browser; nothing you type here is sent to us. No signature is needed from either party. Latin-script names only; for other scripts, email legal@sightradar.com.

Customer legal name
Not set yet
Customer contact
Optional
Effective date
October 8, 2026

SightRadar Data Processing Agreement

Last updated: September 25, 2026

This Data Processing Agreement ("DPA") is between SightRadar and you (the "Customer"). It forms part of the SightRadar Terms of Service and governs how we handle personal data — including biometric face data — on your behalf.

1. Key terms

Controller — that's you. You decide which images to submit, whose faces to index, and why (your users, your photos, your application).

Processor — that's us, SightRadar. We process the data only to give you face detection, indexing, search, and comparison results and related services.

Subprocessor — vendors we use to help process data (for example, our cloud hosting providers).

Customer Content — the images you submit through the API or console, and the face embeddings (numeric vectors), face IDs, bounding boxes, quality scores, and metadata we derive from them.

2. Scope of processing

When you call the SightRadar API, we process the images you send to detect faces, compute face embeddings, and return results. For indexing, the embedding is stored in a collection you own. For detection, comparison, and search-by-image, the image is processed in memory to compute a result and is not retained.

Face embeddings are biometric data. You are responsible for ensuring that your application complies with GDPR, the UK GDPR, India's DPDP Act, Illinois BIPA, and any other applicable data-protection or biometric-privacy law, including obtaining explicit or written consent from the individuals whose faces you submit where the law requires it.

We also process your account data (email address, authentication identifiers, API key metadata) and usage data (timestamps, operation type, credits charged, request IDs) to run your account, secure the Service, and bill you.

We process Customer Content only to provide you with the Service. We never use your images or embeddings to train, fine-tune, or improve any model. We never build a cross-customer face database. We never sell or share your data with third parties.

3. Data retention

Customer account data is kept until you delete your account.

Customer Content retention is under your control:

  • Indexed faces stay in your collections until you delete them via the API or console.
  • Deleting a collection hides it immediately and permanently purges its face vectors after a 7-day grace window, during which you can restore it.
  • For verified erasure requests (for example, GDPR Article 17), you can choose immediate deletion, which purges the data right away and cannot be undone.
  • Detect, compare, and search-by-image requests are processed in memory; the submitted image is not stored.

Usage and billing records are kept for as long as needed to run your account and to meet legal, tax, and accounting obligations. You can request deletion at any time.

4. Subprocessors

We currently use the following trusted vendors to process data:

SubprocessorPurposeLocation
AWS (Amazon Web Services, Inc.)Cloud infrastructure for the face-recognition engine, API gateway, vector database, and storage of indexed face data.Asia Pacific (Mumbai), India — ap-south-1
Cloudflare (Cloudflare, Inc.)Edge network, DNS, TLS termination, and hosting of the sightradar.com website, developer console, and static assets.Global edge network (data in transit only)

Each subprocessor is bound by data-protection obligations no less protective than this DPA, and we remain responsible for their performance. We may add or replace subprocessors, and will update this page when we do so you can object where you have that right.

5. International data transfers

Our face-recognition engine, vector database, and stored Customer Content are hosted in India (AWS Asia Pacific, Mumbai). Our website and console are served through Cloudflare's global edge network. This means personal data of EU, EEA, and UK residents will be transferred internationally.

Where a transfer is made to a country without an applicable adequacy decision, the parties rely on the EU Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), incorporated by reference and completed with the details in Sections 1 and 2, together with our subprocessors' own compliance commitments.

6. Security measures

We implement the following security measures:

  • Encryption in transit via HTTPS (TLS) for every API and console request.
  • Encryption at rest for stored face vectors and account data.
  • Per-tenant isolation — each account's face vectors are namespaced and can never be searched by, or disclosed to, another customer.
  • Scoped API keys, shown once at creation and revocable at any time from the console.
  • Least-privilege access controls so only authorised SightRadar personnel can reach production systems, under confidentiality obligations.
  • Backups to prevent accidental loss of important data.
  • Secure hosting with reputable vendors (see Section 4).

7. Roles and responsibilities

Your responsibilities

  • Ensure you have a lawful basis to collect and process the personal data you submit, including explicit or written consent for biometric data where required.
  • Provide a privacy notice to the individuals whose faces you process, as required by law.
  • Issue only lawful instructions, and comply with our Acceptable Use Policy — no covert surveillance, no identifying people without their consent.
  • Handle access, correction, and deletion requests from the individuals in your data; we will assist you.

Our responsibilities

  • Process data only on your documented instructions (which include your use of the API and console), except where the law requires otherwise.
  • Keep data secure and confidential, and ensure our personnel are bound by confidentiality.
  • Notify you without undue delay after becoming aware of a personal-data breach affecting your data.
  • Assist you, within reason, in meeting your data-protection obligations, including data-subject requests, security, breach notification, and impact assessments.
  • Delete or return your personal data at the end of the engagement, as described in Section 3.
  • Make available the information reasonably necessary to demonstrate compliance, and allow for audits, subject to reasonable confidentiality and security conditions.

8. Data access and exports

SightRadar provides access to all Customer Content processed on your behalf via its API and console. You can list, export, and delete collections and faces at any time. Exports reflect the data as processed and stored by the platform (face IDs, metadata, and embeddings); we do not retain or export the original images you submitted.

9. Governing law

This DPA is governed by the laws of India. Any disputes will be resolved exclusively in the courts of competent jurisdiction in India. If there is a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA controls.

By using SightRadar, you agree to this DPA.

This agreement is generated digitally and takes effect without signatures from either party. If your own records need a signed copy, you may sign the downloaded PDF; SightRadar does not countersign.

Data-protection queries: privacy@sightradar.com or legal@sightradar.com.