Skip to content
Book a CallCreate AccountLogin
Trust · Compliance

Compliance & certifications

Datafuel is built and operated in the European Union. Consent-based sourcing, GDPR and the EU AI Act are our home ground, and we document how every IP and every byte of data is handled.

SOC 2 Type IIISO/IEC 27001
SOC 2 Type II · ISO/IEC 27001Audit in progress
Last updated Questions: legal@datafuel.aiDraft · legal review pending

Certification programme

ItemDetails
SOC 2 Type IIAudit in progress · report expected 2027 · available under NDA
ISO/IEC 27001Certification in progress · scope: proxy network, scraping APIs, dashboard
GDPRCompliant · EU data controller · DPA available on request
EU AI ActReadiness assessment complete · data-provenance records available for AI customers

Status lines on this page are updated when a milestone changes. Until an audit report is issued we describe controls as “in progress”, never as certified.

Ethically sourced residential and mobile IPs

Residential and mobile IPs join the network exclusively through the Datafuel SDK, embedded in partner applications. Every device owner sees a plain-language disclosure, opts in explicitly and can withdraw consent at any time from the host application.

  • Consent records (timestamp, app, SDK version, disclosure text) are retained for the life of the device on the network and for 24 months after opt-out.
  • Device owners are compensated by the host application; bandwidth usage is capped and traffic is paused on metered or low-battery conditions.
  • The SDK relays traffic only; it cannot access the device owner's data, browsing or credentials.
  • Partner applications are vetted before integration and audited annually against these rules.

GDPR

  • Datafuel acts as a data controller for account, billing and usage data, and as a processor for personal data contained in customer traffic.
  • Personal data is processed and stored in the EU. Transfers outside the EEA rely on Standard Contractual Clauses.
  • A Data Processing Agreement (DPA) is part of every business account and can be counter-signed on request.
  • Data-subject requests — access, rectification, erasure, portability, objection — are handled within 30 days via privacy@datafuel.ai.
  • Our Data Protection Officer can be reached at dpo@datafuel.ai.

EU AI Act and data provenance

Customers training or grounding AI systems increasingly need to show where their data came from. Datafuel provides per-request provenance: timestamp, exit country, IP class (residential, mobile, ISP, datacenter) and consent reference for residential exits. Provenance exports are available from the dashboard and via the API.

  • Consent-based sourcing documented per IP, exportable per job.
  • No collection from targets that require authentication unless the customer holds the credentials and the right to use them.
  • Acceptable use policy aligned with the AI Act's prohibited-practice list.

Sub-processors

We use a small number of sub-processors for hosting, payments and support tooling. The current list, with location and purpose, is available at datafuel.ai/trust/sub-processors and customers with a DPA are notified 30 days before any change.

ItemDetails
HostingEU data-centre providers · infrastructure
PaymentsPCI-DSS Level 1 payment processor · card data never touches Datafuel systems
Support & CRMTicketing and messaging tooling · account and contact data
EmailTransactional email delivery · account notifications

Law-enforcement and abuse requests

We respond to valid legal requests from competent authorities under Italian and EU law, notify affected customers where legally permitted, and publish an annual transparency summary. Abuse reports can be sent to abuse@datafuel.ai and are triaged within one business day.

Need documents for a vendor review? Request our security package (pen-test summary, policies, DPA, sub-processor list) at legal@datafuel.ai.