Understand how we process and secure personal data. This DPA supplements our Terms of Service for institutional and privacy compliance.
This Data Processing Addendum ("DPA") is entered into between Similarfy.com ("Processor") and the user or institution utilizing our services ("Controller"). It governs the processing of personal data in connection with the plagiarism similarity verification services provided via Similarfy.com. By using our platform, you acknowledge and agree to this DPA, which is incorporated into our Terms of Service.
Capitalized terms not defined herein shall have the meanings set forth in applicable privacy regulations, including GDPR and CCPA.
• "Personal Data" refers to any information relating to an identified or identifiable natural person processed through the Similarfy platform. • "Processing" means any operation performed on Personal Data, such as collection, analysis, generation, temporary storage, or deletion. • "Controller" represents the customer or institution submitting materials for scanning. • "Processor" represents Similarfy.com.
The details of personal data processing under this agreement are as follows:
• Purpose of Processing: To perform plagiarism check similarity matching, AI-content analysis, and credit order / billing processing. • Data Categories: Account details (name, email address, password hashes), payment metadata (receipt slip uploads), usage details (IP addresses, logs), and document text content uploaded for scanning. • Data Subjects: Students, teachers, university tutors, researchers, and general platform users.
We implement robust security controls to ensure data protection:
• Encryption: All data is encrypted in transit using TLS 1.3 and at rest using AES-256 cloud storage keys. • Turnitin Non-Repository Mode: Submitted files are processed through isolated API calls and compared against the Turnitin database in Non-Repository Mode. No document is index-saved or retained in Turnitin's repository, preventing self-plagiarism in future checks. • Credential Protection: Passwords are protected using bcrypt algorithms, and sessions are authorized via signed JWT tokens. • Physical Security: Core infrastructure is hosted in enterprise cloud environments complying with SOC2 and ISO 27001 standard frameworks.
Controller hereby authorizes Processor to engage third-party sub-processors to deliver infrastructure and core system services (such as Cloudflare R2 for secure temporary document caching and SMTP mail delivery systems for billing notifications). All sub-processors are contractually bound to process data in compliance with strict privacy and GDPR data processing clauses.
Processor will assist Controller in responding to data subject requests under GDPR or CCPA (such as requests for access, rectification, portability, or deletion). In the event of a confirmed personal data breach, Processor will notify Controller without undue delay, and no later than 72 hours after becoming aware of the incident, providing details of the breach and remediation measures.
For further details regarding this Data Processing Addendum or our data handling compliance, please contact our legal and privacy team.
Email: hello@similarfy.com