1. Roles
The customer is the controller (or a processor acting for its own controller) of personal data contained in traffic it routes through the service. Datafuel is the processor. For account, billing and usage data Datafuel is an independent controller under the Privacy policy.
2. Details of processing
| Item | Details |
|---|---|
| Subject matter | Relay of HTTP(S)/SOCKS5 requests and scraping API calls |
| Duration | Term of the account |
| Nature | Transmission, temporary buffering, metadata logging |
| Purpose | Providing proxy and web-data infrastructure |
| Data subjects | Determined by the customer's targets and requests |
| Categories | Any personal data contained in requests or responses; request metadata |
3. Processor obligations
- Process personal data only on documented instructions from the customer, including the Acceptable use policy and product configuration.
- Ensure personnel are bound by confidentiality and trained on data protection.
- Implement the technical and organisational measures described on the Security page (Annex II).
- Assist the customer with data-subject requests, DPIAs and supervisory-authority consultations.
- Notify the customer of a personal-data breach without undue delay and no later than 48 hours after confirmation.
- Delete or return personal data at the end of the service; metadata is deleted within 90 days.
4. Sub-processors
The customer authorises the sub-processors listed on the Compliance page. Datafuel gives 30 days' notice of additions; the customer may object on reasonable grounds, in which case either party may terminate the affected service.
5. International transfers
Personal data is processed in the EU. Any transfer outside the EEA relies on the European Commission's Standard Contractual Clauses (Module 2 or 3) with supplementary measures where required. Residential exits located outside the EEA relay traffic but do not store it.
6. Audits
Datafuel makes available the information necessary to demonstrate compliance — certification reports once issued, penetration-test summaries and policies. Once per year, or after a breach, the customer may audit on 30 days' notice, during business hours and under confidentiality.
7. Liability
Liability under this DPA follows the Terms of service. Each party is responsible for the fines and damages attributable to its own breach of the GDPR.