Certification programme
| Item | Details |
|---|---|
| SOC 2 Type II | Audit in progress · report expected 2027 · available under NDA |
| ISO/IEC 27001 | Certification in progress · scope: proxy network, scraping APIs, dashboard |
| GDPR | Compliant · EU data controller · DPA available on request |
| EU AI Act | Readiness assessment complete · data-provenance records available for AI customers |
Status lines on this page are updated when a milestone changes. Until an audit report is issued we describe controls as “in progress”, never as certified.
Ethically sourced residential and mobile IPs
Residential and mobile IPs join the network exclusively through the Datafuel SDK, embedded in partner applications. Every device owner sees a plain-language disclosure, opts in explicitly and can withdraw consent at any time from the host application.
- Consent records (timestamp, app, SDK version, disclosure text) are retained for the life of the device on the network and for 24 months after opt-out.
- Device owners are compensated by the host application; bandwidth usage is capped and traffic is paused on metered or low-battery conditions.
- The SDK relays traffic only; it cannot access the device owner's data, browsing or credentials.
- Partner applications are vetted before integration and audited annually against these rules.
GDPR
- Datafuel acts as a data controller for account, billing and usage data, and as a processor for personal data contained in customer traffic.
- Personal data is processed and stored in the EU. Transfers outside the EEA rely on Standard Contractual Clauses.
- A Data Processing Agreement (DPA) is part of every business account and can be counter-signed on request.
- Data-subject requests — access, rectification, erasure, portability, objection — are handled within 30 days via privacy@datafuel.ai.
- Our Data Protection Officer can be reached at dpo@datafuel.ai.
EU AI Act and data provenance
Customers training or grounding AI systems increasingly need to show where their data came from. Datafuel provides per-request provenance: timestamp, exit country, IP class (residential, mobile, ISP, datacenter) and consent reference for residential exits. Provenance exports are available from the dashboard and via the API.
- Consent-based sourcing documented per IP, exportable per job.
- No collection from targets that require authentication unless the customer holds the credentials and the right to use them.
- Acceptable use policy aligned with the AI Act's prohibited-practice list.
Sub-processors
We use a small number of sub-processors for hosting, payments and support tooling. The current list, with location and purpose, is available at datafuel.ai/trust/sub-processors and customers with a DPA are notified 30 days before any change.
| Item | Details |
|---|---|
| Hosting | EU data-centre providers · infrastructure |
| Payments | PCI-DSS Level 1 payment processor · card data never touches Datafuel systems |
| Support & CRM | Ticketing and messaging tooling · account and contact data |
| Transactional email delivery · account notifications |
Law-enforcement and abuse requests
We respond to valid legal requests from competent authorities under Italian and EU law, notify affected customers where legally permitted, and publish an annual transparency summary. Abuse reports can be sent to abuse@datafuel.ai and are triaged within one business day.
Need documents for a vendor review? Request our security package (pen-test summary, policies, DPA, sub-processor list) at legal@datafuel.ai.

