Data Processing Agreement
Last updated: 11 September 2026
1. When this applies
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and Mslm Dev, trading as VPNDetection ("Processor", "we", "us"). It applies where, and only to the extent that, we process personal data on your behalf in the course of providing the Service, and it takes effect when you begin using the Service. No signature is required. If you need a countersigned copy for your records, write to legal@vpndetection.io.
Where this DPA and the Terms of Service conflict on the subject of personal data, this DPA governs. Terms defined in the GDPR have the same meaning here.
2. What we process, and what we do not
The addresses you look up are not the subject of this DPA. An IP address submitted to the API is a query, not a record about a person we hold for you. We do not build profiles from queries, do not associate them with the people behind those addresses, and do not enrich our datasets with them. Section 2 of our Privacy Policy explains the distinction in full.
Where a look-up is nevertheless personal data in your hands, because you have linked it to an individual in your own systems, we process it only as described below.
| Subject matter | Providing IP classification over an API and, where licensed, as downloadable datasets |
|---|---|
| Duration | For as long as you have an account, plus the retention periods in section 6 |
| Nature and purpose | Receiving an address, answering with our classification of it, metering the request, and keeping the security and abuse records any API needs |
| Categories of personal data | The addresses you submit; the address your request originates from; your account details (name, email, authentication identifiers); usage counts per API key |
| Categories of data subject | Your personnel who hold accounts, and the end users whose addresses you submit |
| Special category data | None. The Service is not designed to receive it and you must not submit it |
3. Our obligations
We will:
- process personal data only on your documented instructions, of which your use of the Service and the Terms of Service are the primary ones, unless required otherwise by law, in which case we will tell you first unless the law forbids it;
- ensure that everyone authorised to process it is bound by an appropriate duty of confidence;
- take the measures described in section 5;
- assist you, so far as is reasonable and taking into account the nature of the processing, with data subject requests, security incidents, impact assessments and prior consultation;
- on termination, delete or return personal data as set out in section 6, except where law requires us to keep it;
- make available the information reasonably needed to demonstrate compliance with this DPA, and allow and contribute to audits as set out in section 7.
We will tell you promptly if, in our opinion, an instruction infringes data protection law.
4. Sub-processors
You give us general authorisation to engage sub-processors. We impose data protection terms on each that are no less protective than this DPA, and we remain liable to you for their performance. The current list is:
| Sub-processor | What it does | Where it processes |
|---|---|---|
| Hetzner Online | Hosts the Service and stores its data | Finland (EU) |
| Amazon Web Services (SES) | Delivers transactional email, such as sign-in and billing notices | United States |
| Paddle | Processes payments as merchant of record, and holds billing details | As published by Paddle |
| Cloudflare | Runs the Turnstile challenge that protects sign-up and sign-in | As published by Cloudflare |
| Google, GitHub | Authenticate you, and only where a user chooses to sign in with them rather than with a password | As published by each provider |
We will give at least 30 days' notice before adding or replacing a sub-processor, by updating this page and emailing account holders. If you reasonably object on data protection grounds within that period, tell us and we will work with you in good faith; if we cannot resolve it, you may terminate the affected part of the Service and we will refund any prepaid fees for the unused remainder of the term.
5. Security
We implement technical and organisational measures appropriate to the risk, which today include:
- encryption in transit for all customer-facing traffic;
- hashed passwords, first-party session cookies that scripts cannot read, and optional multi-factor authentication;
- access to production systems limited to those who need it, over authenticated channels;
- API keys that can be rotated and revoked by you at any time, with the raw value shown once;
- logging of administrative actions against an account, readable by you in the console's audit log;
- rate limiting and abuse controls on every public endpoint.
We may change these measures as the risk or the state of the art changes, provided we do not materially reduce the overall level of protection.
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide the information you reasonably need to meet your own notification obligations. Our notice is not an admission of fault.
6. Retention, deletion and return
Look-up queries are not retained as records about the addresses in them. Request logs used for metering, billing and abuse detection are kept for the period stated in section 8 of the Privacy Policy. Account information is kept for as long as you have an account, and for a limited period afterwards where we need it for legal, tax or accounting obligations or to resolve disputes.
On termination you may export your account data from the console. On your written request within 30 days of termination we will delete personal data processed on your behalf, except where law requires us to keep it, in which case we will keep it only for that purpose and for no longer than required.
7. Audits
On reasonable written notice, and no more than once in any twelve-month period unless a regulator requires otherwise or there has been a breach affecting your data, we will make available the information needed to demonstrate compliance with this DPA and respond to a reasonable written security questionnaire. Any on-site audit is at your cost, during business hours, subject to confidentiality, and must not disrupt the Service or compromise another customer's data.
8. International transfers
The Service is hosted in the European Union. Transactional email is delivered through a sub-processor in the United States, and the payment, challenge and authentication sub-processors in section 4 may process outside the EEA and the UK. Where personal data leaves the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, and the UK Addendum where the UK GDPR applies, together with any supplementary measures the transfer requires. By entering into this DPA you agree that the Standard Contractual Clauses, module two (controller to processor), are incorporated by reference, with you as data exporter and us as data importer, with the optional docking clause applying, with option 2 of clause 9 and the notice period in section 4, with clause 11 having no independent dispute resolution body, and with Irish law and the Irish courts governing.
9. Your obligations
You are the controller. You are responsible for having a lawful basis for the processing you instruct, for the accuracy and lawfulness of what you submit, for giving whatever notice your own data subjects are owed, and for not submitting special category data. You must not use the Service as the sole basis for a decision producing a legal or similarly significant effect on a person; our classifications are probabilistic, as section 2 of the Terms of Service sets out.
10. Liability, changes and law
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service.
We may update this DPA to reflect a change in law, in our sub-processors, or in how the Service works. Material changes are notified to account holders, and the "Last updated" date above shows the current version. This DPA is governed by the law stated in the Terms of Service, except that where the Standard Contractual Clauses apply they are governed as set out in section 8.
11. Contact
Data protection questions, audit requests and countersignature requests go to legal@vpndetection.io. General support is the contact form.