Last updated: 2026-10-08
This Data Processing Addendum ("DPA") supplements the Master Services Agreement or other principal service agreement ("Agreement") entered into by and between the Customer ("Customer") and Proxylity LLC ("Proxylity").
This DPA applies to the extent Proxylity Processes Personal Data on behalf of Customer in connection with the Services.
"Applicable Data Protection Laws" means all applicable laws and regulations relating to privacy, data protection, and the Processing of Personal Data applicable to the Processing under the Agreement, including, where applicable, the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act ("CCPA"), and their applicable implementing regulations.
"Customer Data" means any network packet data, packet payloads, or electronic data submitted, routed, or transmitted through the Services by or on behalf of Customer.
"Personal Data" means personal data, personal information, or equivalent terms as defined under Applicable Data Protection Laws. For purposes of this DPA, Personal Data may be contained within Customer Data.
"Processing" has the meaning given to it under Applicable Data Protection Laws and includes accessing, transmitting, routing, manipulating, or otherwise processing data as necessary to provide the Services.
"Services" means the real-time networking, packet processing, and routing pipeline services provided by Proxylity to Customer under the Agreement.
"Operational Metadata" means information generated or collected through the operation, administration, security, billing, and performance monitoring of the Services, such as account identifiers, listener or service identifiers, connection timestamps, aggregate packet and byte counts, latency measurements, service health information, and billing records. Operational Metadata does not include Customer Data payload contents.
"Subprocessor" means a third party engaged by Proxylity to Process Personal Data on behalf of Customer in connection with the Services.
Unless the context requires otherwise, capitalized terms not defined in this DPA have the meanings given in the Agreement or Applicable Data Protection Laws.
Customer may act as a Data Controller, Data Processor, or equivalent role under Applicable Data Protection Laws with respect to Customer Data.
To the extent Customer acts as a Data Controller, Proxylity acts as a Data Processor on behalf of Customer. To the extent Customer acts as a Data Processor on behalf of another party, Proxylity acts as a subprocessor or equivalent service provider on behalf of Customer.
In all cases, Proxylity shall Process Personal Data solely on behalf of Customer and in accordance with Customer's documented instructions, subject to the terms of this DPA and the Agreement.
Customer is responsible for determining its role and obligations under Applicable Data Protection Laws and for ensuring that its instructions to Proxylity are lawful.
The subject matter of the Processing is the transient Processing and transmission of Customer Data through the Services.
Proxylity operates real-time networking infrastructure. The Processing is limited to what is necessary to provide the Services, including the transmission, routing, protocol handling, packet manipulation, and delivery of network traffic to Customer's designated destination, including resources within Customer's Amazon Web Services (AWS) account or other designated cloud environment.
Proxylity does not use Customer Data for advertising, profiling, analytics unrelated to providing the Services, or any independent commercial purpose.
Processing of Customer Data occurs dynamically and continuously as network traffic passes through the Services. Processing of an individual packet is limited to the execution and transmission window required to provide the applicable Service.
Upon termination of the Services, Proxylity shall cease Processing Customer Data except to the extent required by Applicable Data Protection Laws or otherwise expressly permitted by the Agreement.
Depending on Customer's use of the Services, Customer Data may contain any category of Personal Data that Customer chooses to transmit through the Services. Such data may include identifiers, network identifiers, device identifiers, communications, location information, authentication information, and other information contained in network traffic.
Proxylity does not intentionally determine the categories of Personal Data transmitted by Customer.
Depending on Customer's use of the Services, Personal Data may relate to Customer's employees, contractors, customers, users, end users, device operators, or other individuals whose information is transmitted through the Services.
Customer is responsible for determining the categories of Data Subjects whose Personal Data is submitted to the Services.
Proxylity maintains a Zero Data Retention (ZDR) architecture for Customer Data. Customer Data payload contents are processed transiently in volatile memory as necessary to provide the Services.
Proxylity does not intentionally write, cache, index, log, or otherwise persist Customer Data payload contents to non-volatile storage.
Customer Data payload contents are not retained by Proxylity for historical security monitoring, abuse investigation, troubleshooting, analytics, advertising, or other secondary purposes.
Customer Data payload contents cease to be available to the Proxylity processing environment after the data has been delivered to the Customer-designated destination or the applicable processing attempt has ended, subject to transient technical processing necessary to complete or terminate that operation.
Proxylity does not retain Customer Data payload contents after completion of processing.
The ZDR commitment applies to Customer Data payload contents. Proxylity may collect, process, and retain Operational Metadata as reasonably necessary to provide, secure, administer, monitor, support, and bill for the Services.
Operational Metadata does not include Customer Data payload contents. To the extent Operational Metadata constitutes Personal Data under Applicable Data Protection Laws, Proxylity shall Process it in accordance with those laws and the applicable provisions of this DPA.
Because Customer Data payload contents are not retained by Proxylity, Proxylity generally cannot retrieve, reconstruct, modify, or delete previously processed Customer Data payload contents in response to a subsequent request.
Where assistance with a Data Subject request, investigation, or other regulatory obligation would require access to previously processed Customer Data, Customer acknowledges that Proxylity's ability to provide such assistance is necessarily limited by the ZDR architecture.
Proxylity shall Process Personal Data only on documented instructions from Customer, including with respect to routing destinations and other Processing activities necessary to provide the Services, unless Processing is required by applicable law. Where legally permitted, Proxylity shall inform Customer of any such legal requirement before Processing.
If Proxylity reasonably believes that a Customer instruction violates Applicable Data Protection Laws, Proxylity shall inform Customer without undue delay.
Proxylity shall ensure that persons authorized to Process Personal Data are subject to appropriate confidentiality obligations.
Taking into account the nature and transient character of the Processing and the risks to the rights and freedoms of Data Subjects, Proxylity shall implement and maintain appropriate technical and organizational measures designed to protect Personal Data against unauthorized access, disclosure, alteration, destruction, or other unlawful Processing.
Such measures include, as applicable, access controls, authentication and authorization controls, encryption and secure communications, infrastructure security controls, monitoring and alerting, vulnerability management, change management, and incident response procedures.
Proxylity shall notify Customer without undue delay after becoming aware of a Personal Data breach affecting Personal Data Processed on behalf of Customer.
To the extent reasonably available and appropriate, the notification shall include information concerning the nature of the breach, the categories and approximate number of Data Subjects or Personal Data records affected, the likely consequences, and the measures taken or proposed to address the breach.
Proxylity shall provide reasonably available additional information as it becomes available and shall reasonably cooperate with Customer in connection with Customer's obligations under Applicable Data Protection Laws.
Taking into account the nature of the Processing, Proxylity shall provide reasonable assistance to Customer, where required by Applicable Data Protection Laws, in responding to requests from Data Subjects to exercise their applicable rights.
Because Proxylity does not retain Customer Data payload contents, such assistance will generally consist of providing information about Proxylity's Processing practices and, where applicable, taking action with respect to Personal Data contained in Operational Metadata that remains within Proxylity's control.
Taking into account the nature of the Processing and information available to Proxylity, Proxylity shall reasonably assist Customer, where required by Applicable Data Protection Laws, with Customer's obligations relating to security of Processing, Personal Data breaches, data protection impact assessments, and consultations with supervisory authorities.
Customer provides Proxylity with general authorization to engage Subprocessors in connection with the Services.
Proxylity shall:
Proxylity's current Subprocessor for infrastructure used to provide the Services is Amazon Web Services, Inc. and its applicable affiliates ("AWS").
Where Proxylity itself transfers Personal Data to a jurisdiction that does not provide an adequate level of protection under Applicable Data Protection Laws, Proxylity shall implement an appropriate lawful transfer mechanism, such as the European Commission's Standard Contractual Clauses, where required.
Customer remains responsible for the lawfulness of geographic routing configured by Customer through the Services, including transfers of Personal Data resulting from Customer's selection of ingress or destination regions.
Customer is responsible for:
Proxylity provides ingress locations in multiple geographic regions and permits Customer to configure the geographic destination for delivery of Customer Data.
Customer is solely responsible for determining whether its configuration and use of the Services, including the geographic location of ingress and destination regions and the routing of Customer Data between jurisdictions, complies with Applicable Data Protection Laws and any applicable data localization, residency, or cross-border transfer requirements.
Customer shall not configure the Services to route Personal Data across national or regional borders unless the applicable transfer is lawful and Customer has implemented any required transfer mechanism or other appropriate safeguard.
Proxylity does not determine whether a geographic routing configuration selected by Customer is legally permissible.
Customer is solely responsible for ensuring that its target cloud resources, AWS Identity and Access Management (IAM) policies, and ingress network boundaries are correctly configured to receive routed traffic securely.
Once Customer Data has been delivered to Customer's designated infrastructure, Customer is responsible for the subsequent Processing and protection of that data within Customer's environment.
To the extent Proxylity Processes Personal Information subject to the CCPA on behalf of Customer, Proxylity acts as a "service provider" or "contractor," as applicable, and shall comply with the applicable requirements governing such service providers and contractors.
Proxylity shall collect, retain, use, disclose, and otherwise Process Personal Information only as necessary to provide the Services specified in the Agreement and this DPA, or as otherwise permitted by Applicable Data Protection Laws.
Proxylity shall not sell or share Personal Information for purposes prohibited by the CCPA.
Proxylity shall not retain, use, or disclose Personal Information outside the direct business relationship with Customer or for purposes other than those specified in the Agreement and this DPA, except as permitted or required by Applicable Data Protection Laws.
Proxylity shall not use Personal Information received from or on behalf of Customer for its own independent commercial purposes except as expressly permitted by Applicable Data Protection Laws.
Customer is responsible for responding to consumer requests under the CCPA. Proxylity shall reasonably assist Customer with such requests where required by the CCPA and to the extent Proxylity has the relevant Personal Information in its possession or control.
Proxylity shall require Subprocessors that Process Personal Information on behalf of Customer to comply with applicable obligations consistent with this Section.
Proxylity shall provide information reasonably necessary for Customer to demonstrate compliance with its obligations concerning Proxylity's Processing of Personal Information and shall notify Customer if Proxylity determines that it can no longer meet its applicable obligations under this Section.
Because Proxylity operates a ZDR architecture, Customer Data payload contents are not retained following completion of Processing and therefore are not subject to a separate return or deletion process at termination.
Upon termination or expiration of the Services, Proxylity shall delete or return Personal Data contained in Operational Metadata in accordance with the Agreement and Applicable Data Protection Laws, except to the extent Proxylity is required by law to retain such information.
Where retention is legally required, Proxylity shall continue to protect the retained information and shall Process it only for the purpose and duration required by law.
Proxylity shall make available to Customer information reasonably necessary to demonstrate compliance with the obligations applicable to Proxylity under this DPA.
Such information may include security documentation, descriptions of technical and organizational measures, relevant compliance assessments, independent assessment summaries, and responses to reasonable security or privacy questionnaires.
Where required by Applicable Data Protection Laws, Customer may conduct or have conducted on its behalf an audit of Proxylity's compliance with this DPA, subject to reasonable advance notice, confidentiality obligations, and measures designed to avoid disruption to Proxylity's operations or compromise the security or confidentiality of other customers.
Customer shall first use available documentation and assessment information to satisfy its audit requirements where reasonably sufficient.
Audits shall not require Proxylity to provide access to Customer Data payload contents, which Proxylity does not retain as a consequence of its ZDR architecture.
Because Proxylity does not retain Customer Data payload contents, historical payload data, packet contents, or equivalent forensic records cannot be made available for audit or investigation after Processing has completed.
In the event of any conflict between the terms of this DPA and the Agreement, this DPA shall govern solely with respect to the Processing of Personal Data to the extent necessary to resolve the conflict.
This DPA remains in effect for so long as Proxylity Processes Personal Data on behalf of Customer under the Agreement.
Provisions that by their nature should survive termination, including confidentiality, applicable data protection obligations, and provisions concerning retained information, shall survive termination to the extent required by Applicable Data Protection Laws.
The parties shall reasonably cooperate to amend this DPA where necessary to comply with changes in Applicable Data Protection Laws.
Nothing in this DPA grants Proxylity any right to use Customer Data or Personal Data for purposes beyond those expressly permitted by the Agreement and this DPA.