LEGAL

Data Processing Addendum

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between HyperProxy (“Processor”) and the customer accepting them (“Controller”) and applies whenever the managed service processes personal data on the Controller's behalf.

1. Definitions

“Personal Data”, “processing”, “controller”, “processor”, “data subject”, and “supervisory authority” have the meanings given in the GDPR (Regulation (EU) 2016/679) and the UK GDPR. “Customer Data” means data the Controller submits to the service, including request metadata and the contents of requests transited through the gateway.

2. Roles and scope

The Controller determines the purposes and means of processing Customer Data; the Processor processes it only to provide the service described in the documentation. For the Controller's own account details (email, billing contact) the Processor acts as an independent controller under the Privacy Policy.

3. Processing instructions

The Processor processes Customer Data only on the Controller's documented instructions, which are: the Terms, this DPA, the configuration the Controller sets in the dashboard, and the requests the Controller's applications send. The Processor will inform the Controller if, in its opinion, an instruction infringes applicable data protection law.

4. Nature of processing

5. Confidentiality and personnel

The Processor limits access to Customer Data to personnel who need it to operate the service and binds them to confidentiality obligations.

6. Security measures

The Processor implements the technical and organisational measures described on the Security page, including: split-key encryption of provider credentials, encryption in transit, no storage of request bodies, redaction of secrets from logs and monitoring, hashed session tokens, access controls on production systems, dependency and secret scanning, and tested database migrations. Measures evolve with the threat landscape and will not materially decrease during the term.

7. Subprocessors

The Controller authorises the subprocessors listed at hyperproxyai.com/subprocessors. The Processor will announce additions on that page at least 14 days before they process Customer Data; the Controller may object on reasonable data-protection grounds within that period, and if no resolution is found may terminate the affected service. The Processor remains responsible for its subprocessors' performance. AI providers configured by the Controller under the Controller's own credentials are the Controller's processors and are outside this clause.

8. International transfers

The service is hosted in the United States. Where Customer Data originating in the EEA, UK, or Switzerland is transferred to a country without an adequacy decision, the parties rely on the European Commission's Standard Contractual Clauses (Module Two, controller to processor), the UK International Data Transfer Addendum, and the Swiss FADP amendments, which are incorporated by reference, with the Controller as data exporter and the Processor as data importer, and the details in section 4 as the annexes.

9. Assistance and data subject rights

Taking into account the nature of processing, the Processor assists the Controller in responding to data subject requests and in meeting its obligations regarding security, breach notification, and impact assessments. The dashboard provides self-service export and deletion of account data; requests concerning end-user data in request history can be sent to [email protected].

10. Personal data breaches

The Processor notifies the Controller without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting Customer Data, with the information reasonably available to support the Controller's own notifications.

11. Deletion and return

On termination or on the Controller's request the Processor deletes Customer Data, subject to short-lived backups that expire on their own schedule and to records required by law (such as invoices held by the merchant of record). The export in Account → Security lets the Controller retrieve configuration and metering data beforehand.

12. Audit

The Processor makes available the information reasonably necessary to demonstrate compliance with this DPA and allows for audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, no more than once per year on 30 days' notice unless a supervisory authority requires otherwise, at the Controller's expense and under confidentiality.

13. Precedence

In case of conflict, this DPA prevails over the Terms of Service for matters of personal data protection, and the Standard Contractual Clauses prevail over this DPA.