Data Processing Agreement
Roundlabs, LLC (d/b/a Roundproxies)
Version 1 · Effective Date: July 30, 2026
This Data Processing Agreement (the “DPA”) is entered into by Roundlabs, LLC, doing business as Roundproxies, acting as the data processor (the “Data Processor”), and the natural or legal person that enters into this DPA as the data controller (the “Data Controller”). The Data Processor and the Data Controller are collectively the “Parties” and individually a “Party.”
The Data Processor provides IP proxy infrastructure solutions, including residential, ISP, datacenter, and mobile proxies (the “Services”), which the Data Controller obtains and uses under the Roundproxies Terms of Service (the “Agreement”), of which this DPA forms a part. In the course of providing the Services, the Data Processor may process Personal Data on behalf of and for the benefit of the Data Controller.
Accordingly, the Parties agree as follows:
1. Key Terms
1.1. For the purposes of this DPA, including its Annexes, the following capitalized terms have the meanings set out below, unless the context requires otherwise:
Applicable Data Protection Laws means any applicable law relating to the protection of Personal Data in force at the relevant time, including, where applicable, the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), and other US state privacy laws.
Data Controller means the person or entity that has accepted the Agreement and determines the purposes and means of the processing of Personal Data. Where the CCPA applies, references to the Data Controller include the “Business.”
Data Processor means Roundlabs, LLC, which processes Personal Data on behalf of the Data Controller pursuant to this DPA. Where the CCPA applies, references to the Data Processor include the “Service Provider.”
Personal Data means any information relating to an identified or identifiable natural person, including identifiers such as a name, address, identification number, IP address, location data, online identifiers, traffic data, or message content, or factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person. Where the CCPA applies, Personal Data includes “Personal Information” as defined therein.
Sub-processor means a third party engaged by the Data Processor to process Personal Data on behalf of the Data Controller in connection with the Services.
1.2. Terms not defined in this DPA have the meanings assigned to them in the Agreement or, failing that, in Applicable Data Protection Laws.
2. Roles and Responsibilities of the Parties
2.1. The Data Controller shall perform its responsibilities as a data controller in full compliance with Applicable Data Protection Laws, including those relating to the lawfulness of Personal Data handling and the lawfulness of instructions given to the Data Processor.
2.2. The Data Controller represents and warrants, on an ongoing basis, that it has all lawful bases, consents, notices, and rights required under Applicable Data Protection Laws to transfer, disclose, or otherwise make Personal Data available to the Data Processor and to permit its processing in accordance with the Agreement and this DPA. This includes, without limitation, any Personal Data contained in traffic the Data Controller transmits through the Data Processor’s proxy network and any Personal Data contained in content the Data Controller collects using the Services.
2.3. The Data Processor is not responsible for determining the lawfulness of the Data Controller’s instructions. Where the Data Processor reasonably considers an instruction to be unlawful, it shall promptly inform the Data Controller and may suspend performance of that instruction until it is confirmed or modified.
2.4. The Data Processor shall not knowingly engage in any activity that would directly cause the Data Controller to be in breach of Applicable Data Protection Laws.
2.5. Without limiting the foregoing, the Data Controller is responsible for: (i) complying with all transparency and lawfulness requirements under Applicable Data Protection Laws in relation to its collection and use of Personal Data in connection with the Services; (ii) the accuracy, quality, integrity, and legality of the Personal Data and the manner in which it was collected; and (iii) ensuring that its instructions to the Data Processor comply with Applicable Data Protection Laws.
2.6. Each Party shall promptly notify the other if it becomes unable to comply with its obligations under this DPA.
3. Scope of Processing and Instructions
3.1. The Data Processor shall process Personal Data only on the documented instructions of the Data Controller, including with respect to transfers of Personal Data to third countries or international organizations, unless required to do otherwise by law to which the Data Processor is subject; in that case, the Data Processor shall inform the Data Controller of the legal requirement before processing, unless the law prohibits such disclosure. The Agreement, this DPA, and the Data Controller’s configuration and use of the Services constitute the Data Controller’s complete documented instructions.
3.2. The details of the processing are as follows:
Subject matter: The Data Processor’s provision of the Services to the Data Controller.
Purpose and nature of the processing: Transmission and routing of network traffic through the Data Processor’s proxy infrastructure, and related technical processing strictly necessary to provide, secure, meter, and support the Services in accordance with the Agreement. The Data Processor does not log the content of traffic transmitted through the Services and processes connection metadata only as described in its Privacy Policy.
Categories of data subjects: Individuals whose Personal Data the Data Controller processes through or transmits via the Services, which may include the Data Controller’s own end users, customers, employees, and individuals whose publicly accessible data the Data Controller collects.
Categories of Personal Data: Personal Data determined and controlled by the Data Controller and processed through the Services, which may include online identifiers, IP addresses, traffic and connection data, and any Personal Data contained in content the Data Controller transmits or collects. The Data Controller shall not use the Services to process special categories of personal data (or “sensitive” data as defined under Applicable Data Protection Laws) except where it has established all safeguards required by law; the Data Processor does not request and does not wish to receive such data.
Duration of processing: For the duration of the Agreement and the Data Controller’s use of the Services, and until all Personal Data is deleted or returned in accordance with Section 7, unless retention is required by Applicable Data Protection Laws.
Processing by Sub-processors: Sub-processors are engaged solely to assist in providing the Services and process Personal Data only for as long as necessary for that purpose or as required by Applicable Data Protection Laws.
3.3. The Data Processor shall not process Personal Data for any purpose other than as set out in this DPA and the Agreement, and shall not sell or share Personal Data (as those terms are defined under the CCPA).
4. Sub-processors
4.1. The Data Controller grants the Data Processor a general authorization to engage Sub-processors for the performance of this DPA. The current list of Sub-processors is set out in Annex III.
4.2. The Data Processor shall: (i) ensure each Sub-processor is bound by a written contract imposing data protection obligations at least as protective as those in this DPA, including the implementation of appropriate technical and organizational measures; and (ii) remain fully responsible and liable to the Data Controller for the acts and omissions of its Sub-processors to the same extent as for its own.
4.3. The Data Processor shall maintain the Sub-processor list in Annex III (or at a designated URL) and shall notify the Data Controller of the addition or replacement of Sub-processors at least 14 days before the change takes effect, by updating the list and providing notice via the System or email. The Data Controller may, on reasonable grounds relating to the protection of Personal Data, object in writing to a new Sub-processor by contacting team@roundproxies.com within that notice period. In the event of a valid objection, the Data Processor will use reasonable efforts to make available a commercially reasonable change to the Services to avoid processing by the objected-to Sub-processor. If no such change is available within thirty (30) days, the Data Controller may, as its sole and exclusive remedy, terminate the affected Services (or, if partial provision is not technically feasible, the Agreement and this DPA in full). Fees due before the termination date remain payable; prepaid fees for periods after termination will be refunded pro rata.
5. Data Security and Confidentiality
5.1. The Data Processor shall implement appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as well as the risk to the rights and freedoms of individuals. The current measures are described in Annex IV. The Data Processor may update these measures from time to time, provided the updates do not materially reduce the overall level of protection.
5.2. Access to Personal Data shall be limited to personnel who need it to perform their work under this DPA. The Data Processor shall ensure that all persons authorized to process Personal Data are subject to an appropriate statutory or contractual duty of confidentiality.
5.3. The Data Processor shall not disclose Personal Data to any third party without the Data Controller’s prior written consent, except (i) to Sub-processors engaged in accordance with this DPA, or (ii) where disclosure is required by law, in which case the Data Processor shall (to the extent legally permitted) notify the Data Controller before disclosure.
5.4. Personal Data Breach. The Data Processor shall notify the Data Controller without undue delay after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed under this DPA. The notification shall include the information reasonably available to the Data Processor that the Data Controller requires to meet its own notification obligations, including the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. The Data Processor shall provide updates as further information becomes available.
6. Assistance, Cooperation, and Audits
6.1. Taking into account the nature of the processing and the information available to it, the Data Processor shall provide reasonable assistance to the Data Controller in fulfilling its obligations under Applicable Data Protection Laws, including with respect to: (i) security of processing and breach notifications; (ii) data protection impact assessments and prior consultations with supervisory authorities; and (iii) responding to data subjects exercising their rights.
6.2. If a data subject, supervisory or governmental authority, or other third party makes a request to the Data Processor regarding Personal Data processed under this DPA, the Data Processor shall, unless legally prohibited, promptly forward the request to the Data Controller and shall not respond on the Data Controller’s behalf except as instructed or required by law.
6.3. The Data Processor shall make available to the Data Controller information reasonably necessary to demonstrate compliance with this DPA, which may include summaries of third-party audit reports and security certifications.
6.4. The Data Processor shall allow for and reasonably contribute to audits or inspections conducted by the Data Controller or an independent auditor mandated by it and bound by confidentiality obligations reasonably acceptable to the Data Processor. Audits shall: relate solely to processing under this DPA; be subject to at least 30 days’ advance written notice; be conducted during normal business hours in a manner that does not unreasonably disrupt operations; occur no more than once in any twelve-month period, unless required by a supervisory authority or following a Personal Data Breach; and be at the Data Controller’s cost, including reasonable fees for the Data Processor’s time.
7. Return and Deletion of Personal Data
7.1. This DPA remains in effect for as long as the Data Processor processes Personal Data on behalf of the Data Controller under the Agreement.
7.2. Upon termination of the Services, the Data Processor shall, at the Data Controller’s choice, delete or return all Personal Data processed on the Data Controller’s behalf and delete existing copies, and shall confirm deletion in writing upon request, unless retention is required by Applicable Data Protection Laws, in which case the Data Processor shall protect the retained data in accordance with this DPA and process it only as required by law. Absent an election by the Data Controller within 30 days of termination, the Data Processor will delete the Personal Data in accordance with its standard retention schedules.
8. Liability and Costs
8.1. Each Party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, except to the extent such limitations are prohibited by Applicable Data Protection Laws. Nothing in this DPA limits either Party’s liability with respect to a data subject’s rights under Applicable Data Protection Laws.
8.2. The Data Processor may charge reasonable costs for: (i) requests for cooperation or assistance that are manifestly unfounded, excessive, or disproportionate; and (ii) work made necessary by instructions from the Data Controller that are inaccurate, incomplete, or unlawful.
9. General Provisions
9.1. This DPA is an integral part of the Agreement. Matters not expressly governed by this DPA are governed by the Agreement. In the event of conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA prevails; in the event of conflict between this DPA and the Standard Contractual Clauses incorporated under Annex I, the Standard Contractual Clauses prevail to the extent of the conflict.
ANNEX I — International Transfers (EEA, UK, and Switzerland)
EEA Transfers. In relation to Personal Data subject to the GDPR that is transferred from the EEA to the Data Processor in the United States or another third country without an adequacy decision: (i) the Data Controller is the “data exporter” and the Data Processor is the “data importer”; (ii) the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914 (Module Two — Controller to Processor) (the “SCCs”) are incorporated by reference into and form an integral part of this DPA; (iii) in Clause 7, the optional docking clause applies; (iv) in Clause 9, Option 2 (general written authorisation) applies, with the notice period specified in Section 4.3 of this DPA; (v) in Clause 11, the optional language is deleted; (vi) in Clauses 17 and 18, the governing law and forum are the law and courts of Ireland; (vii) Annexes I and II of the SCCs are deemed completed with the information set out in Section 3.2 and Annex IV of this DPA; and (viii) if the SCCs conflict with this DPA, the SCCs prevail to the extent of the conflict.
UK Transfers. In relation to Personal Data subject to the UK GDPR, the SCCs apply as modified by the UK International Data Transfer Addendum issued by the UK Information Commissioner (the “UK Addendum”), which is incorporated by reference: Tables 1–3 of the UK Addendum are deemed completed with the information in Section 3.2 and Annex IV of this DPA, and Table 4 is completed by selecting “neither party.”
Swiss Transfers. In relation to Personal Data subject to the Swiss Federal Act on Data Protection, the SCCs apply with the adaptations required by the Swiss Federal Data Protection and Information Commissioner, including that references to the GDPR are understood as references to the FADP and the competent supervisory authority is the FDPIC.
ANNEX II — CCPA/CPRA Service Provider Addendum
This Addendum forms part of the DPA and applies if and to the extent the Data Controller (the “Business”) engages the Data Processor (the “Service Provider”) to process Personal Information on its behalf, as those terms are defined under the CCPA.
1. Scope. This Addendum applies to the collection, retention, use, and disclosure of Personal Information by the Service Provider solely for the purpose of providing the Services or performing a Business Purpose as defined in the CCPA. Processing by the Service Provider for its own purposes independent of the Services is outside the scope of this Addendum.
2. Restrictions. The Service Provider shall not: (a) sell or share Personal Information; (b) retain, use, or disclose Personal Information for any purpose other than the specific business purpose of providing the Services, or as otherwise permitted by the CCPA; (c) retain, use, or disclose Personal Information outside the direct business relationship between the Parties; or (d) combine Personal Information received from the Business with Personal Information from other sources, except as permitted by the CCPA. The Parties acknowledge that the exchange of Personal Information between them does not form part of any monetary or other valuable consideration.
3. Compliance. The Service Provider certifies that it understands and will comply with its obligations under the CCPA and will notify the Business if it determines that it can no longer meet those obligations. The Business may, upon notice, take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Information.
4. Consumer Rights. If the Service Provider receives a request from a Consumer to exercise a CCPA right regarding Personal Information processed under this DPA, it shall promptly forward the request to the Business and shall provide reasonable assistance in facilitating compliance with verified requests. Upon written instruction from the Business, the Service Provider shall delete the relevant Personal Information within a commercially reasonable time, unless retention is required by law.
5. Verification. Upon reasonable written request, the Service Provider shall make available information necessary to demonstrate compliance with this Addendum, or a written certification of compliance.
ANNEX III — Sub-processor List
To provide the Services, the Data Processor engages the following categories of Sub-processors, which may process Personal Data on behalf of the Data Controller. The current list as of the Effective Date:
| Category | Sub-processor | Purpose of Processing | Location |
|---|---|---|---|
| Cloud Hosting & Infrastructure | To be confirmed | Hosting of the System, dashboards, and network infrastructure | To be confirmed |
| Payment Processing & Billing | To be confirmed | Payment processing and billing | To be confirmed |
| Customer Support & Communication | Intercom, Inc. | Live chat, help center, and customer support platform | United States |
| Analytics & Bot Protection | Google LLC (Google Analytics, Google Tag Manager, reCAPTCHA Enterprise) | Website analytics, tag management, and bot/fraud protection | United States / Global |
| Customer Feedback | Trustpilot A/S; G2.com, Inc. | Review invitation and feedback collection | Denmark / EU; United States |
This list is reviewed periodically and updated in accordance with Section 4.3 of the DPA. Note: providers that act as independent controllers (rather than on the Data Controller’s behalf) are described in the Roundproxies Privacy Policy rather than listed here.
ANNEX IV — Technical and Organizational Measures
The Data Processor implements and maintains, at minimum, the following measures:
- Encryption: TLS encryption of data in transit across the System and Services; encryption at rest for sensitive stored data.
- Access control: Role-based access on a need-to-know basis; unique credentials; two-factor authentication for administrative access; prompt revocation of access on role change or departure.
- Data minimization: No logging of the content of traffic transmitted through the proxy network; connection metadata processed and retained only as described in the Privacy Policy.
- Network and system security: Firewalls, network segmentation, monitoring and alerting, vulnerability management, and periodic security reviews of the technology stack.
- Resilience and recovery: Backup and restoration procedures designed to restore availability and access to Personal Data in a timely manner after an incident.
- Incident response: A documented incident-response process, including detection, escalation, containment, remediation, and the breach-notification obligations in Section 5.4.
- Personnel: Confidentiality obligations for all personnel with access to Personal Data; security awareness practices.
- Sub-processor management: Written data-protection terms with all Sub-processors and periodic review of their measures.
- Testing: Regular testing, assessment, and evaluation of the effectiveness of these measures.
