Skip to content

Data processing agreement · v1 · 2026-09

Data processing agreement

Accepted by every account at checkout, before the first purchase is provisioned. A countersigned copy is available on request.

1. Roles and subject matter

The customer is the controller of personal data contained in traffic routed through its proxy credentials and ports; Portproof is the processor. Portproof is an independent controller for account, billing, verification and abuse-prevention data.

2. Nature and purpose of processing

Transit of customer-originated traffic through the proxy gateway (mobile and residential pools) and, where purchased, dedicated ports; storage of the metadata described in the privacy notice (subscriber-port-IP-time, per-minute aggregates, rotation log entries, probe results, per-destination-ASN five-minute aggregates for 30 days). No payload, URLs or per-flow records are stored.

3. Duration and retention

For the term of the subscription plus the retention period: 90 days by default, up to the statutory maximum in the country of the egress SIM where the service is classified as an electronic communications service, 12 months for Attested customers who opt in.

4. Sub-processors

Sub-processorPurposeLocation and transfer mechanism
Hosting providerServers and database of the control planeEU
Transactional email providerAccount, order and usage mailsNamed on request; SCCs where outside the EU
Network partnerCarries proxy traffic on the mobile and residential poolsCountry of the exit; flow-down of this DPA
Identity-verification vendorSignatory identity at tier T2EU; named in the dashboard before verification starts
Payment processorcryptocurrency paymentsNamed at checkout before you pay

Changes are notified 30 days ahead with a right to object and terminate the affected service.

5. Security measures

Proxy credentials encrypted at rest, API keys and passwords stored hashed, TLS on every public endpoint, access to production limited to the operator, incident notification within 72 hours.

6. Assistance, audits, deletion

Assistance with data-subject requests and DPIAs within 10 business days; one audit per year on 30 days' notice or a current third-party report; deletion or return of metadata at the end of retention, except where statutory retention applies.