Legal

Data Processing Agreement

Last updated: 16 August 2026

This Data Processing Agreement (DPA) applies when you use APIs Platform to process personal data of other people — for example IP addresses you submit to the geolocation API. It sits next to the Privacy Policy and the Terms of Service. Creating an account or calling the APIs means you accept it.

Privacy Policy

1. Roles

For account, billing, security and site-measurement data we collect to run the service, we are the controller. That processing is described in the Privacy Policy and is not covered by this DPA.

For personal data you submit through the APIs so we can return a response, you are the controller and we are the processor. The most common case is an IP address you send to the geolocation API. We process that data only to return the lookup and do not use it to profile the person behind the IP.

2. Subject matter and duration

The subject matter is the processing needed to provide the APIs you subscribe to. Processing lasts for the life of the request and any short-lived logs required to operate quotas, diagnose errors and protect the service. It ends when you delete the account or we delete or anonymise the data we are not required to keep.

3. Data and data subjects

Depending on the product, this may include IP addresses, and any identifiers or values you place in a request. We do not ask you to send special-category data and you should not do so unless a request field requires it.

Data subjects are the people whose data you choose to submit — for example users of your application whose IP you look up. You are responsible for having a lawful basis to send that data to us.

4. Instructions

We process that data only on your documented instructions: the API call you make, the product and plan you use, and these terms. We will not sell it, use it for our own profiling, or use it to train unrelated models. If we believe an instruction breaks applicable law, we will tell you.

5. How we protect the data

We apply technical and organisational measures appropriate to a subscription API service: encryption in transit, access limited to people who need it to operate the service, hashed passwords, authenticated API keys, rate limits and abuse controls, security checks on sign-in, and isolation of customer keys and usage.

We keep processing to what the request needs. Lookup payloads are not used to build advertising profiles. Logs are retained only as long as needed for security, quotas, accounting or law, then deleted or anonymised.

No measure is perfect. You remain responsible for how you store API keys and for the data you choose to send.

6. Sub-processors

We use infrastructure, email, security and payment providers to operate the service. Card payments, when enabled, may be processed by Stripe. We do not currently run analytics or advertising tools, and none of them process API lookup payloads.

Those providers receive only what they need for their role. By using the service you authorise us to engage them for that purpose. We will remain responsible for their work as it relates to this DPA.

7. International transfers

The service is delivered from a global network. Data you submit may be processed in countries other than your own. We rely on the contractual and technical safeguards those providers offer for cross-border processing.

8. Assistance

We will help you respond to requests from data subjects and to questions from a supervisory authority, to the extent the data sits in our systems and the law requires it. Email support@apis-platform.com. We will also give you information reasonably needed to show that we meet this DPA.

9. Personal-data breaches

If we become aware of a personal-data breach that affects data we process for you, we will notify you without undue delay and give you the information we have so you can meet your own notice duties. We will also take reasonable steps to contain and remedy the incident.

10. Deletion and return

You can delete the account from Settings. That revokes API keys and removes the account. We then delete or anonymise personal data we process for you, except records we must keep for security, accounting or law. API responses are returned to you at the time of the request; we do not keep a separate archive of lookup results for you to download later.

11. Your responsibilities

You decide what to send. You must not use the APIs to process data unlawfully, and you must not send us data you are not allowed to share. You configure your application, keys and retention on your side.

12. Changes

We may update this DPA. The “Last updated” date will change when we do. Continued use after an update means you accept the revised DPA. If a change is material, we will try to notify the email on the account.

13. Contact

Questions about this DPA: support@apis-platform.com. Related: Privacy Policy · Terms of Service.