Ethically-sourced proxies: Learn More External link arrow

Data Protection Addendum (DPA)

Last updated on 02.06.2026

1. Purpose and scope

This Data Protection Addendum (“DPA”) forms part of the applicable reseller agreement, customer agreement, partner agreement, online terms, order, or other written agreement governing access to or use of the Services between the applicable Infatica contracting entity and the Customer, Reseller, Partner, or other counterparty identified in that agreement (the “Agreement”).

This DPA applies to the processing of Personal Data in connection with residential proxies, mobile proxies, datacenter proxies, ISP/static proxies, SDK-enabled peer network functionality, dashboard access, API access, technical support, account administration, billing, compliance, fraud prevention, abuse prevention, security, and related services.

This DPA is designed for use with existing Infatica agreements. It does not replace commercial terms, pricing, service descriptions, support commitments, warranty disclaimers, liability limitations, governing law, dispute resolution, payment terms, suspension rights, or termination rights in the Agreement unless expressly stated otherwise.

2. Definitions

TermMeaning
AgreementThe applicable agreement between the Company and Customer governing access to or use of the Services.
CompanyThe Infatica contracting entity identified in the Agreement, including INFATICA LTD, Infatica Pte. Ltd., or another Infatica entity expressly identified in the Agreement.
CustomerThe counterparty to the Agreement, including a customer, reseller, partner, or other entity accessing or using the Services.
ServicesInfatica residential proxies, mobile proxies, datacenter proxies, ISP/static proxies, SDK-enabled peer network functionality, dashboards, APIs, technical support, connectivity, routing, access management, account administration, compliance, and related services.
Data Protection LawsAll applicable laws and regulations relating to privacy, data protection, data security, electronic communications, and the processing of Personal Data, including where applicable the GDPR, UK GDPR, Data Protection Act 2018, Singapore Personal Data Protection Act, CCPA/CPRA, and other applicable privacy laws.
Personal DataAny information relating to an identified or identifiable natural person, or any equivalent term under applicable Data Protection Laws.
Company-Controlled Personal DataPersonal Data processed by the Company as an independent controller for its own purposes, including billing, account administration, fraud prevention, abuse prevention, compliance, security, service integrity, marketing, legal claims, and SDK / peer network governance.
Customer-Provided InformationInformation provided by Customer to the Company in connection with the Services, including business contact information, account information, support communications, compliance review information, use-case information, reseller or end-client information, and other information submitted through Company-approved channels.
Processor ModuleThe optional processor terms in Schedule 4, which apply only where the Parties expressly agree in writing that the Company processes specific Personal Data on behalf of Customer as a processor.

3. Relationship between the Parties

Unless expressly agreed otherwise in writing, each Party acts as an independent controller with respect to Personal Data it processes in connection with the Agreement and the Services.

The Company processes Company-Controlled Personal Data for its own business, legal, compliance, security, fraud prevention, abuse prevention, network integrity, billing, account administration, marketing, service analytics, support, and SDK / peer network governance purposes.

Customer processes Personal Data for its own purposes and is solely responsible for determining the lawfulness of its use of the Services, including the lawfulness of any target websites, requests, data collection activities, end-user activities, instructions, traffic, resale, or downstream processing carried out by Customer, its users, its customers, or its end clients.

Nothing in this DPA creates a joint controller relationship between the Parties. The Parties do not jointly determine the purposes and means of processing unless expressly agreed in a separate written joint-controller arrangement.

The Company does not act as Customer’s processor in connection with Customer’s general use of the Services unless the Agreement, an order, or a separate written schedule expressly states that the Company processes specific Personal Data on behalf of Customer as a processor.

4. No processor relationship unless expressly agreed

The Parties acknowledge that the Company provides neutral connectivity, proxy, network, dashboard, API, SDK, support, security, and compliance infrastructure and does not determine Customer’s target websites, Customer’s data collection objectives, Customer’s lawful bases, Customer’s end users, Customer’s downstream processing purposes, or Customer’s legal permissions.

Customer shall not provide or make available to the Company any Personal Data for processing on behalf of Customer as a processor unless the Parties have first entered into a written processor schedule or other written agreement expressly identifying: (a) the subject matter and duration of processing; (b) the nature and purpose of processing; (c) the categories of Personal Data; (d) the categories of data subjects; (e) the applicable controller instructions; (f) applicable security measures; and (g) any required service-provider, transfer, deletion, audit, and assistance terms.

If the Parties later agree that the Company will act as a processor for specific processing activities, such processing will be governed only by the Processor Module in Schedule 4 or another written data processing schedule signed or otherwise accepted by the Parties.

5. Company processing purposes

The Company may process Company-Controlled Personal Data for the following purposes:

  • creating, administering, securing, and managing accounts
  • providing access to the dashboard, API, support channels, and Services
  • authenticating users, API requests, credentials, sessions, and access rights
  • billing, invoicing, payments, refunds, tax, accounting, and financial administration
  • fraud prevention, abuse prevention, sanctions screening, KYC/KYB, compliance checks, and risk management
  • monitoring, detecting, investigating, preventing, and responding to misuse, prohibited activities, security threats, complaints, legal notices, government requests, and policy violations
  • maintaining, protecting, troubleshooting, testing, improving, and securing the Services and Company infrastructure
  • enforcing the Agreement, Acceptable Use Policy, Website Access Policy, blacklist, whitelist, access restrictions, and other applicable policies
  • managing SDK / peer network participation, consent, withdrawal, network integrity, routing governance, partner compliance, and peer network operations
  • communicating with Customer regarding the Services, support, legal notices, security notices, policy updates, and service-related matters
  • marketing, sales, relationship management, and business development, subject to applicable law
  • complying with legal obligations and establishing, exercising, or defending legal claims

6. Customer responsibilities

Customer is solely responsible for:

  • ensuring that Customer’s use of the Services complies with applicable laws, third-party rights, platform terms, contractual restrictions, privacy laws, electronic communications laws, sanctions, export controls, and acceptable use requirements
  • providing all notices and obtaining all consents, permissions, rights, authorizations, and lawful bases required for Customer’s own collection, use, processing, transfer, resale, disclosure, storage, or other handling of data
  • ensuring that Customer’s users, customers, end clients, contractors, agents, and resellers comply with the Agreement, this DPA, the Acceptable Use Policy, and applicable laws
  • determining whether Customer may lawfully access, scrape, crawl, monitor, collect, extract, use, store, transfer, or otherwise process data from any third-party website, platform, application, service, database, search engine, marketplace, social network, account, system, or online property
  • not using the Services to process special category data, children’s data, sensitive personal data, protected health information, financial account credentials, payment authentication data, government identifiers, biometric data, or other highly sensitive data unless expressly authorized in writing by the Company

7. Sensitive data and children’s data

The Services are not designed for the processing of special categories of Personal Data, children’s Personal Data, protected health information, payment authentication data, financial account credentials, government identifiers, biometric data, or other sensitive data unless expressly agreed in writing.

Customer shall not use the Services to bypass, circumvent, disable, interfere with, or evade age-verification, age-assurance, parental-control, child-safety, minor-protection, app-store, platform safety, or similar mechanisms.

8. Acceptable use and compliance review

Customer acknowledges that the Company may restrict, block, suspend, throttle, review, or refuse access to certain websites, domains, platforms, categories, geographies, traffic patterns, or use cases for safety, compliance, fraud prevention, abuse prevention, child-safety, sanctions, legal, platform-risk, infrastructure protection, or reputational-risk reasons.

The Company may request use-case information, business purpose information, end-client information, target domain or website category, expected traffic type, expected duration of access, and related compliance information where reasonably necessary to assess access requests, restricted domains, blacklist exceptions, misuse risks, or compliance with the Agreement and applicable policies.

Any such information is requested and processed by the Company as an independent controller for compliance, fraud prevention, abuse prevention, access-control, legal, security, and risk-management purposes.

9. Data subject requests

Each Party is responsible for responding to data subject requests it receives in relation to Personal Data for which that Party acts as controller.

Where a Party receives a request that appears to relate to Personal Data controlled by the other Party, the receiving Party may, where legally permitted and reasonably practicable, redirect the requester to the other Party or notify the other Party of the request.

The Company will handle data subject requests relating to Company-Controlled Personal Data in accordance with applicable Data Protection Laws and the Company’s applicable privacy notices.

Operational item
DSAR intake channelRequests may be submitted through the Company’s applicable privacy request form or other privacy request channel published by the Company.
DSAR ownerThe Company’s privacy, legal, or compliance function is responsible for coordinating review and response to data subject requests relating to Company-Controlled Personal Data.
Identity verification processThe Company may request information reasonably necessary to verify the requester’s identity, authority, relationship to the Company, and the Personal Data covered by the request. If the request is submitted by an authorized agent, the Company may require proof of authorization and may also require the individual to verify their identity directly.
Target response timelineThe Company will respond within the timeframe required by applicable Data Protection Laws. Where GDPR / UK GDPR applies, the Company will respond without undue delay and in any event within one month, subject to permitted extensions. Where California privacy law applies, the Company will confirm receipt and respond within the applicable statutory periods. Where Singapore PDPA applies, the Company will respond as soon as reasonably possible and provide required notices if additional time is needed.
Deletion workflowThe Company will review the request, verify identity where required, identify relevant Company-Controlled Personal Data, assess applicable exceptions, delete, de-identify, restrict, or retain the relevant data as required or permitted by law, and record the outcome of the request.
Exceptions / legal retentionThe Company may refuse, limit, or defer a request where permitted by law, including where retention is necessary for legal, tax, accounting, compliance, security, fraud prevention, abuse prevention, dispute resolution, contractual, audit, backup, or legitimate business purposes.

10. Security measures

The Company will implement and maintain appropriate technical and organizational measures designed to protect Company-Controlled Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure, taking into account the nature, scope, context, and purposes of processing and the risks to individuals.

Security areaCurrent position
Access controlsAccess to relevant systems and data is limited to authorized personnel based on business need, role, and responsibility.
AuthenticationThe Company uses authentication controls designed to prevent unauthorized access to Company systems, accounts, and administrative environments.
Encryption in transitThe Company uses encryption in transit where appropriate to protect data transmitted through websites, dashboards, APIs, and online services.
Encryption at restThe Company uses storage and infrastructure safeguards designed to protect stored data against unauthorized access, alteration, or disclosure.
Network securityThe Company maintains network security controls designed to protect service infrastructure against unauthorized access, misuse, disruption, and abuse.
Logging and monitoringThe Company uses logging and monitoring to support security, abuse prevention, troubleshooting, service integrity, and incident investigation.
Vulnerability managementThe Company uses vulnerability management practices designed to identify, assess, prioritize, and remediate security issues.
Secure developmentThe Company applies secure development and change-management practices designed to reduce security risks in its services, applications, and infrastructure.
Incident responseThe Company maintains incident response processes designed to assess, contain, investigate, remediate, and communicate security incidents where required.
Backups and recoveryThe Company maintains backup and recovery practices designed to support service continuity and restoration in the event of technical or operational incidents.
Employee controlsPersonnel with access to relevant systems or data are subject to confidentiality, access-control, and internal policy requirements.
Vendor managementThe Company assesses and manages vendors and service providers based on the nature of the service, data involved, operational role, and applicable legal or security requirements.

11. Personal data incidents

The Company will assess suspected security incidents involving Company-Controlled Personal Data in accordance with its internal incident response procedures and applicable Data Protection Laws.

Where the Company determines that a personal data breach affecting Company-Controlled Personal Data requires notification to Customer under applicable law or the Agreement, the Company will notify Customer without undue delay after such determination.

Incident item
Incident contactThe Company’s designated incident response, privacy, legal, or compliance channel.
Internal incident ownerThe Company’s incident response function, with involvement from security, engineering, legal, compliance, and relevant business owners as appropriate.
Customer notification timelineWithout undue delay after the Company determines that a personal data breach affecting Company-Controlled Personal Data requires notification to Customer under applicable law or the Agreement.
Notification contentsWhere available and appropriate: the nature of the incident, categories of Personal Data affected, approximate scope, likely consequences, measures taken or proposed, mitigation steps, and contact point for follow-up.
Regulatory notification responsibilityThe Company is responsible for assessing and making regulatory notifications where required for Company-Controlled Personal Data. Where GDPR / UK GDPR applies, notification to the supervisory authority is generally required without undue delay and, where feasible, within 72 hours after becoming aware of the breach, unless the breach is unlikely to result in risk to individuals.
Government / law enforcement handlingGovernment, regulator, or law enforcement requests will be reviewed for legal validity and handled in accordance with applicable law, the Agreement, and the Company’s internal procedures. Where legally permitted and appropriate, the Company may notify affected customers or individuals.

12. Retention and deletion

The Company will retain Company-Controlled Personal Data only for as long as reasonably necessary for the purposes described in this DPA, the Agreement, applicable privacy notices, and applicable retention schedules, unless a longer retention period is required or permitted by law.

Data categoryRetention
Dashboard account dataRetained for the duration of the account or customer relationship, and thereafter for as long as reasonably necessary for legal, contractual, compliance, security, audit, and dispute-resolution purposes.
API credentials / tokensRetained while the relevant account, integration, or API access remains active, and thereafter for as long as reasonably necessary for security, troubleshooting, audit, abuse-prevention, and dispute-resolution purposes.
API logsRetained for as long as reasonably necessary to provide, secure, monitor, troubleshoot, and improve the Services, and to investigate misuse, security incidents, or policy violations.
Proxy/session metadataRetained for as long as reasonably necessary for service operation, usage calculation, troubleshooting, abuse prevention, fraud prevention, security, compliance, and dispute-resolution purposes.
Abuse/security logsRetained for as long as reasonably necessary to detect, investigate, prevent, and respond to security threats, abuse, fraud, unlawful activity, policy violations, complaints, and legal requests.
Support ticketsRetained for the period necessary to handle the support request and maintain a record of the interaction, and thereafter as reasonably necessary for service quality, compliance, legal, and dispute-resolution purposes.
Billing recordsRetained for the period required by applicable tax, accounting, and company law, and thereafter where retention is required or permitted for audit, legal, compliance, or dispute-resolution purposes.
KYC/KYB recordsRetained for the duration of the customer relationship and thereafter for as long as reasonably necessary for compliance, sanctions screening, fraud prevention, abuse prevention, audit, legal, and dispute-resolution purposes.
Compliance review / blacklist request recordsRetained for as long as reasonably necessary to evidence review decisions, enforce access restrictions, investigate misuse, support compliance monitoring, respond to complaints, and protect the Company’s legal and security interests.
SDK consent logsRetained for as long as reasonably necessary to evidence consent, participation status, partner compliance, network governance, legal compliance, and dispute resolution.
SDK withdrawal logsRetained for as long as reasonably necessary to evidence withdrawal, opt-out handling, exclusion from participation, partner compliance, legal compliance, and dispute resolution.
SDK connection / DAU logsRetained for as long as reasonably necessary for network operation, DAU calculation, partner reporting, billing/payment reconciliation, abuse prevention, security, compliance, and audit purposes.
BackupsBackup copies are retained in accordance with the Company’s backup and disaster-recovery procedures and are overwritten or deleted in the ordinary backup cycle, unless preservation is required for security, legal, compliance, or dispute-resolution purposes.

13. International transfers

Each Party is responsible for ensuring that its own processing and transfers of Personal Data comply with applicable Data Protection Laws.

Where the Company transfers Personal Data internationally, the Company will use a valid transfer mechanism where required by applicable Data Protection Laws, which may include adequacy decisions, standard contractual clauses, international data transfer agreements, transfer addenda, or other lawful mechanisms.

Transfer categoryMechanism
EU personal dataAdequacy decisions where available; otherwise European Commission Standard Contractual Clauses and supplementary contractual, technical, and organizational safeguards where required.
UK personal dataUK adequacy regulations where available; otherwise the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, and supplementary safeguards where required.
Swiss personal dataSwiss adequacy decisions where available; otherwise Standard Contractual Clauses with Swiss-specific adaptations and supplementary safeguards where required.
Singapore / APAC transfersContractual, technical, and organizational safeguards designed to ensure protection comparable to applicable local data protection laws, including vendor contracts, intra-group safeguards, and recognized model clauses where appropriate.
US transfersApplicable adequacy frameworks where available, including the EU-U.S. Data Privacy Framework for eligible certified recipients; otherwise SCCs, UK transfer mechanisms, Swiss-specific terms, contractual safeguards, and supplementary measures where required.
OtherAny other lawful transfer mechanism available under applicable Data Protection Laws, including consent, contractual necessity, legal claims, important public interest, or other statutory derogations where applicable.

14. Vendors and service providers

The Company may engage vendors, service providers, infrastructure providers, hosting providers, payment providers, analytics providers, CRM providers, support providers, KYC/KYB providers, security providers, and other third parties to support the Company’s processing of Company-Controlled Personal Data.

The Company will remain responsible for selecting such providers in accordance with applicable Data Protection Laws and will use appropriate contractual, technical, and organizational measures where required by law.

Vendor category
Hosting / infrastructureUsed to host, operate, maintain, secure, and scale the Company’s websites, dashboard, APIs, databases, service infrastructure, and related systems.
CDN / WAF / DDoS protectionUsed to improve performance, availability, traffic routing, network security, abuse prevention, and protection against malicious or disruptive traffic.
Email providerUsed to send service, account, security, billing, support, legal, and operational communications.
Support toolUsed to receive, manage, investigate, and respond to customer, reseller, partner, technical, abuse, and privacy-related requests.
CRMUsed to manage customer, reseller, partner, prospect, sales, procurement, compliance, and relationship-management information.
AnalyticsUsed to understand website, dashboard, Trust Center, product, service, and campaign performance, subject to applicable cookie and consent requirements.
Payment providerUsed to process payments, invoices, billing status, payment verification, refunds, chargebacks, and related financial administration.
KYC/KYB providerUsed where required to verify customer, reseller, partner, business, beneficial ownership, sanctions, fraud, abuse-prevention, and compliance information.
Logging / monitoringUsed to monitor service availability, performance, security, errors, abuse indicators, incidents, troubleshooting, and operational integrity.
Cloud storageUsed to store business, operational, support, compliance, security, backup, and documentation records.
OtherUsed where reasonably necessary to provide, secure, support, monitor, improve, administer, and protect the Services, or to comply with legal, contractual, security, accounting, tax, audit, and compliance obligations.

15. SDK / peer network processing

The Company acts as an independent controller in relation to Personal Data processed for SDK / peer network governance, network integrity, peer participation, consent management, withdrawal management, routing governance, abuse prevention, security, compliance, and related operational purposes.

Where the Services involve the SDK-enabled peer network, participation of peer devices must be based on user consent or another valid legal basis required by applicable law and applicable partner documentation.

The Company may process IP addresses, device/network metadata, connection metadata, consent status, withdrawal status, country or region information, activity status, DAU-related records, and related technical or operational data for SDK / peer network purposes.

16. CCPA / US state privacy terms

The Company’s default role under this DPA is independent controller. The Company does not act as a CCPA service provider or contractor for Customer unless the Parties expressly agree in writing that the Company processes specific personal information for a specified business purpose on Customer’s behalf under service-provider or contractor terms.

If the Parties expressly agree that the Company acts as a service provider or contractor under the CCPA or similar US state privacy laws for a specific processing activity, the Parties will complete the applicable service-provider / contractor schedule, including restrictions on sale or sharing, use for specified business purposes, retention, disclosure, combining of personal information, assistance with consumer requests, reasonable security, and other mandatory terms required by applicable law.

17. Governing law and order of precedence

This DPA is governed by the same law and dispute resolution provisions as the Agreement, unless expressly stated otherwise in this DPA.

If there is a conflict between this DPA and the Agreement regarding data protection matters, this DPA controls to the extent of the conflict. Commercial terms, service terms, payment, suspension, termination, governing law, dispute resolution, warranty disclaimers, indemnities, and liability limitations remain governed by the Agreement unless expressly modified in this DPA.

Schedule 1. Details of Company-controlled processing

ItemDescription
Subject matterProvision, operation, support, security, billing, compliance, abuse prevention, access control, and governance of the Services.
DurationTerm of the Agreement plus applicable retention, backup expiry, legal retention, security, billing, tax, accounting, compliance, and dispute-resolution periods.
Nature of processingCollection, recording, organization, structuring, storage, retrieval, consultation, use, transmission, disclosure to vendors, restriction, deletion, and other operations necessary for Company-controlled purposes.
PurposesAccount administration, service access, authentication, billing, support, compliance, fraud prevention, abuse prevention, security, network integrity, SDK/peer governance, marketing, and legal claims.
Data subjectsCustomer representatives, customer users, reseller representatives, end-client business contacts, support contacts, website visitors, prospects, SDK peers/app users, and other individuals interacting with the Company.
Data categoriesBusiness contact data, account data, credentials/identifiers, IP addresses, device/network metadata, usage logs, session/traffic metadata, support content, billing/admin data, KYC/KYB data, consent/withdrawal records, compliance review data.
Special categoriesNot intended; prohibited unless expressly agreed in writing.
Children’s dataNot intended; Services must not be used for child-safety-sensitive abuse or age-verification bypass.

Schedule 2. Technical and organizational measures

Control familyCurrent statement
Access controlThe Company limits access to relevant systems, services, and data to authorized personnel based on business need, role, and responsibility. Access rights are managed to support least-privilege and accountability principles.
Data protectionThe Company applies technical and organizational safeguards designed to protect Personal Data against unauthorized access, loss, alteration, disclosure, or misuse, taking into account the nature of the data and the relevant processing risks.
Infrastructure securityThe Company maintains infrastructure security controls designed to protect service environments, networks, systems, and supporting infrastructure against unauthorized access, misuse, disruption, and abuse.
Application securityThe Company applies security-aware development, deployment, and change-management practices designed to reduce risks in its websites, dashboard, APIs, SDK-related components, and service applications.
Vulnerability managementThe Company uses vulnerability management practices designed to identify, assess, prioritize, and remediate security issues affecting relevant systems, applications, infrastructure, and service components.
Incident responseThe Company maintains incident response processes designed to assess, contain, investigate, remediate, and communicate security incidents where required by applicable law or contractual commitments.
Business continuityThe Company maintains backup, recovery, and continuity practices designed to support service restoration and operational resilience in the event of technical, security, or operational incidents.
CertificationsCertification status, audit reports, and detailed security documentation may be made available through the Trust Center or upon reasonable request, where applicable and subject to confidentiality, security, and commercial restrictions.

Schedule 3. Vendor / service provider list

The Company does not publish a vendor-by-vendor list in this document. Vendor and service provider information may be made available through the Trust Center, the applicable agreement, or upon reasonable request, where appropriate and subject to confidentiality, security, and commercial restrictions.Where the Company engages vendors or service providers, it uses appropriate contractual, technical, and organizational safeguards taking into account the nature of the service, the data involved, the provider’s role, and applicable Data Protection Laws.

Schedule 4. Processor Module

Status: Not applicable unless expressly agreed in writing by the Parties.

The Company does not act as Customer’s processor under this DPA unless this Schedule is expressly completed, agreed, and incorporated into the Agreement.If the Parties agree that the Company will process specific Personal Data on behalf of Customer as a processor, the Parties will complete a separate processor schedule covering the mandatory processor terms required by applicable Data Protection Laws, including: subject matter and duration of processing, nature and purpose of processing, categories of Personal Data, categories of data subjects, documented instructions, confidentiality, security measures, subprocessors, international transfers, data subject request assistance, breach assistance, deletion or return of Personal Data, and audit or information rights.Until such processor schedule is completed and agreed, this Schedule does not apply.