Legal

Data Processing Agreement

Last updated: August 1, 2026  ·  Effective: August 1, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Proxya (proxya.co) (the "Provider") and the user of the Service (the "Client"). It applies where, and to the extent that, the Provider processes Personal Data on behalf of the Client in connection with the Service.

Acceptance of the Service constitutes acceptance of this DPA.

1. Definitions

  • Personal Data: any information relating to an identified or identifiable individual (the "data subject").
  • Data Controller: the party that determines the purposes and means of processing Personal Data.
  • Data Processor: the party that processes Personal Data on behalf of the Controller.
  • Processing: any operation performed on Personal Data, including collection, recording, storage, use, disclosure, restriction, erasure or destruction.
  • Data Breach: any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

2. Scope and purpose

The Provider shall process Personal Data only to deliver the Service described in the agreement with the Client, and strictly in accordance with the Client's documented instructions, unless otherwise required by applicable law. The subject matter, duration, nature and purpose of the processing are defined by the Client's use of the Service.

3. Roles of the parties

In relation to Personal Data processed on the Client's behalf, the Client acts as the Data Controller and the Provider acts as the Data Processor. Each party is responsible for complying with the data-protection obligations applicable to its role.

4. Provider's obligations

  • Process Personal Data only on the Client's documented instructions.
  • Ensure that personnel authorized to process Personal Data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational measures to protect Personal Data against unauthorized processing and accidental loss.
  • Notify the Client without undue delay after becoming aware of a Data Breach affecting the Client's Personal Data.
  • Assist the Client, taking into account the nature of processing, in fulfilling its obligations, including data-protection impact assessments and responding to data-subject requests and supervisory authorities.
  • Maintain records of the processing activities carried out on the Client's behalf.
  • Inform the Client without delay if, in the Provider's opinion, an instruction infringes applicable data-protection law, and pause the processing concerned until the instruction is confirmed or corrected.

5. Client's obligations

  • Ensure that all Personal Data provided to the Provider is collected and processed lawfully, fairly and transparently.
  • Provide clear and lawful documented instructions for the processing of Personal Data.
  • Promptly inform the Provider of any change in processing requirements or circumstances affecting the Personal Data processed.

6. Sub-processors

The Client gives the Provider general authorization to engage sub-processors to support delivery of the Service. The Provider engages sub-processors in the following categories: hosting and data-centre operators; network, connectivity and proxy infrastructure partners; payment processors; email delivery providers; and support, monitoring and analytics tooling. On written request to [email protected], and subject to a confidentiality undertaking, the Provider will identify the sub-processors engaged for the Client's processing.

Each sub-processor is bound by data-protection obligations substantially equivalent to those in this DPA, and the Provider remains fully liable to the Client for every sub-processor's performance of those obligations.

The Provider will give the Client at least thirty (30) days' notice before adding or replacing a sub-processor, or such shorter notice as is necessary where the change is required for security, service continuity or legal compliance. The Client may object on reasonable data-protection grounds within that period; if the parties cannot agree on a workable alternative, the Client may terminate the affected part of the Service and receive a pro-rata refund of any prepaid, unused fees for it.

7. International data transfers

Any transfer of Personal Data to a country that has not been recognized as providing an adequate level of protection is carried out under appropriate safeguards — the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an equivalent mechanism — which are incorporated into this DPA by reference and prevail over it in the event of conflict.

On request, the Provider will tell the Client which safeguard applies to a given transfer and provide a copy of the relevant clauses, redacted only as far as confidentiality requires.

8. Security measures

Taking into account the state of the art, the cost of implementation and the risks to data subjects, the Provider maintains technical and organizational measures appropriate to the risk, including at least the following:

  • Encryption of data in transit (TLS), with account passwords stored only as salted hashes.
  • Administrative access limited to authorized personnel, protected by authentication and automatic lockout after repeated failed attempts.
  • Short-lived authentication tokens, rate limiting and protection against automated credential attacks.
  • Network segregation between the public Service, the administration interface and the databases, which are not exposed to the public internet.
  • Logging of security-relevant events and alerting on anomalies such as sign-ins from unrecognized devices.
  • Access to Personal Data limited to the persons who need it to operate the Service, who are bound by confidentiality.
  • A process for reviewing and improving these measures as the Service and the threat landscape change.

9. Data breach notification

If the Provider becomes aware of a Data Breach affecting the Client's Personal Data, it will notify the Client without undue delay and in any event within seventy-two (72) hours of becoming aware of it.

The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it and mitigate its effects. Where that information is not all available at once, the Provider will supply it in phases rather than delay the first notification, and will assist the Client in meeting its own obligations towards supervisory authorities and data subjects.

10. Duration, return and deletion

This DPA remains in effect for as long as the Provider processes Personal Data on the Client's behalf. On termination or expiry of the Service, the Provider will, at the Client's choice, delete or return the Personal Data processed on the Client's behalf, and will complete deletion within ninety (90) days, unless retention is required by applicable law — in which case the Provider retains only what the law requires, for only as long as it requires, and continues to protect it under this DPA.

11. Audit rights

The Provider will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to reasonable audits, subject to reasonable prior notice, confidentiality, and mutual agreement on timing and scope so as not to disrupt the Provider's operations or other clients.

12. Liability

Liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service, except to the extent that applicable data-protection law provides otherwise.

13. Governing law

This DPA is governed by, and disputes are resolved in accordance with, the governing-law and dispute-resolution provisions of the Terms of Service.

14. Amendments

Any amendment to this DPA must be made in writing. Where changes are required to reflect updated legal requirements, the Provider will notify the Client and the updated DPA will apply to ongoing processing.

Annex 1 — Details of the processing

This Annex sets out the particulars that data-protection law requires a processing agreement to record.

  • Subject matter: provision of the Service — proxy connectivity, the dashboard and API through which it is managed, billing and support.
  • Duration: for the term of the agreement between the parties, plus the deletion period in section 10.
  • Nature and purpose: hosting and administering the Client's Account; routing network traffic initiated by the Client through the proxy network; processing payments; providing support; and preventing fraud and abuse.
  • Types of Personal Data: account identifiers (name or username, email address), authentication data, billing and transaction records, IP addresses and connection metadata, support correspondence, and any Personal Data contained in the traffic the Client chooses to route through the Service — which the Provider transmits as a conduit and does not inspect, log or store.
  • Categories of data subjects: the Client, the Client's personnel and authorized users of the Client's Account, and any individuals whose data the Client transmits through the Service.
  • Special categories of data: none are requested or required by the Service; the Client must not route special-category data through it without first agreeing additional safeguards in writing.
  • Frequency of processing: continuous, for as long as the Client uses the Service.

Questions about this document?

If anything here is unclear, we are happy to explain it in plain language. Contact us or email [email protected].