Legal

Data Processing Agreement

Last updated: 11 September 2026

1. When this applies

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and Mslm Dev, trading as VPNDetection ("Processor", "we", "us"). It applies where, and only to the extent that, we process personal data on your behalf in the course of providing the Service, and it takes effect when you begin using the Service. No signature is required. If you need a countersigned copy for your records, write to legal@vpndetection.io.

Where this DPA and the Terms of Service conflict on the subject of personal data, this DPA governs. Terms defined in the GDPR have the same meaning here.

2. What we process, and what we do not

The addresses you look up are not the subject of this DPA. An IP address submitted to the API is a query, not a record about a person we hold for you. We do not build profiles from queries, do not associate them with the people behind those addresses, and do not enrich our datasets with them. Section 2 of our Privacy Policy explains the distinction in full.

Where a look-up is nevertheless personal data in your hands, because you have linked it to an individual in your own systems, we process it only as described below.

Subject matterProviding IP classification over an API and, where licensed, as downloadable datasets
DurationFor as long as you have an account, plus the retention periods in section 6
Nature and purposeReceiving an address, answering with our classification of it, metering the request, and keeping the security and abuse records any API needs
Categories of personal dataThe addresses you submit; the address your request originates from; your account details (name, email, authentication identifiers); usage counts per API key
Categories of data subjectYour personnel who hold accounts, and the end users whose addresses you submit
Special category dataNone. The Service is not designed to receive it and you must not submit it

3. Our obligations

We will:

  • process personal data only on your documented instructions, of which your use of the Service and the Terms of Service are the primary ones, unless required otherwise by law, in which case we will tell you first unless the law forbids it;
  • ensure that everyone authorised to process it is bound by an appropriate duty of confidence;
  • take the measures described in section 5;
  • assist you, so far as is reasonable and taking into account the nature of the processing, with data subject requests, security incidents, impact assessments and prior consultation;
  • on termination, delete or return personal data as set out in section 6, except where law requires us to keep it;
  • make available the information reasonably needed to demonstrate compliance with this DPA, and allow and contribute to audits as set out in section 7.

We will tell you promptly if, in our opinion, an instruction infringes data protection law.

4. Sub-processors

You give us general authorisation to engage sub-processors. We impose data protection terms on each that are no less protective than this DPA, and we remain liable to you for their performance. The current list is:

Sub-processorWhat it doesWhere it processes
Hetzner OnlineHosts the Service and stores its dataFinland (EU)
Amazon Web Services (SES)Delivers transactional email, such as sign-in and billing noticesUnited States
PaddleProcesses payments as merchant of record, and holds billing detailsAs published by Paddle
CloudflareRuns the Turnstile challenge that protects sign-up and sign-inAs published by Cloudflare
Google, GitHubAuthenticate you, and only where a user chooses to sign in with them rather than with a passwordAs published by each provider

We will give at least 30 days' notice before adding or replacing a sub-processor, by updating this page and emailing account holders. If you reasonably object on data protection grounds within that period, tell us and we will work with you in good faith; if we cannot resolve it, you may terminate the affected part of the Service and we will refund any prepaid fees for the unused remainder of the term.

5. Security

We implement technical and organisational measures appropriate to the risk, which today include:

  • encryption in transit for all customer-facing traffic;
  • hashed passwords, first-party session cookies that scripts cannot read, and optional multi-factor authentication;
  • access to production systems limited to those who need it, over authenticated channels;
  • API keys that can be rotated and revoked by you at any time, with the raw value shown once;
  • logging of administrative actions against an account, readable by you in the console's audit log;
  • rate limiting and abuse controls on every public endpoint.

We may change these measures as the risk or the state of the art changes, provided we do not materially reduce the overall level of protection.

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide the information you reasonably need to meet your own notification obligations. Our notice is not an admission of fault.

6. Retention, deletion and return

Look-up queries are not retained as records about the addresses in them. Request logs used for metering, billing and abuse detection are kept for the period stated in section 8 of the Privacy Policy. Account information is kept for as long as you have an account, and for a limited period afterwards where we need it for legal, tax or accounting obligations or to resolve disputes.

On termination you may export your account data from the console. On your written request within 30 days of termination we will delete personal data processed on your behalf, except where law requires us to keep it, in which case we will keep it only for that purpose and for no longer than required.

7. Audits

On reasonable written notice, and no more than once in any twelve-month period unless a regulator requires otherwise or there has been a breach affecting your data, we will make available the information needed to demonstrate compliance with this DPA and respond to a reasonable written security questionnaire. Any on-site audit is at your cost, during business hours, subject to confidentiality, and must not disrupt the Service or compromise another customer's data.

8. International transfers

The Service is hosted in the European Union. Transactional email is delivered through a sub-processor in the United States, and the payment, challenge and authentication sub-processors in section 4 may process outside the EEA and the UK. Where personal data leaves the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, and the UK Addendum where the UK GDPR applies, together with any supplementary measures the transfer requires. By entering into this DPA you agree that the Standard Contractual Clauses, module two (controller to processor), are incorporated by reference, with you as data exporter and us as data importer, with the optional docking clause applying, with option 2 of clause 9 and the notice period in section 4, with clause 11 having no independent dispute resolution body, and with Irish law and the Irish courts governing.

9. Your obligations

You are the controller. You are responsible for having a lawful basis for the processing you instruct, for the accuracy and lawfulness of what you submit, for giving whatever notice your own data subjects are owed, and for not submitting special category data. You must not use the Service as the sole basis for a decision producing a legal or similarly significant effect on a person; our classifications are probabilistic, as section 2 of the Terms of Service sets out.

10. Liability, changes and law

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service.

We may update this DPA to reflect a change in law, in our sub-processors, or in how the Service works. Material changes are notified to account holders, and the "Last updated" date above shows the current version. This DPA is governed by the law stated in the Terms of Service, except that where the Standard Contractual Clauses apply they are governed as set out in section 8.

11. Contact

Data protection questions, audit requests and countersignature requests go to legal@vpndetection.io. General support is the contact form.

Mslm Dev, 195-B Jasmine Block Sector C Bahria Town, Lahore, Punjab 53720, Pakistan. support@vpndetection.io