Data processing agreement · v1 · 2026-09
Data processing agreement
Accepted by every account at checkout, before the first purchase is provisioned. A countersigned copy is available on request.
1. Roles and subject matter
The customer is the controller of personal data contained in traffic routed through its proxy credentials and ports; Portproof is the processor. Portproof is an independent controller for account, billing, verification and abuse-prevention data.
2. Nature and purpose of processing
Transit of customer-originated traffic through the proxy gateway (mobile and residential pools) and, where purchased, dedicated ports; storage of the metadata described in the privacy notice (subscriber-port-IP-time, per-minute aggregates, rotation log entries, probe results, per-destination-ASN five-minute aggregates for 30 days). No payload, URLs or per-flow records are stored.
3. Duration and retention
For the term of the subscription plus the retention period: 90 days by default, up to the statutory maximum in the country of the egress SIM where the service is classified as an electronic communications service, 12 months for Attested customers who opt in.
4. Sub-processors
| Sub-processor | Purpose | Location and transfer mechanism |
|---|---|---|
| Hosting provider | Servers and database of the control plane | EU |
| Transactional email provider | Account, order and usage mails | Named on request; SCCs where outside the EU |
| Network partner | Carries proxy traffic on the mobile and residential pools | Country of the exit; flow-down of this DPA |
| Identity-verification vendor | Signatory identity at tier T2 | EU; named in the dashboard before verification starts |
| Payment processor | cryptocurrency payments | Named at checkout before you pay |
Changes are notified 30 days ahead with a right to object and terminate the affected service.
5. Security measures
Proxy credentials encrypted at rest, API keys and passwords stored hashed, TLS on every public endpoint, access to production limited to the operator, incident notification within 72 hours.
6. Assistance, audits, deletion
Assistance with data-subject requests and DPIAs within 10 business days; one audit per year on 30 days' notice or a current third-party report; deletion or return of metadata at the end of retention, except where statutory retention applies.