Data Processing Agreement

Global DPA pursuant to GDPR art. 28, UK GDPR, LGPD art. 39 (Brazil) and the CCPA "service provider" requirements (California), governed by the laws of the Netherlands.

When Rainproxy processes personal data on behalf of a business customer (the "Controller" / "Business" / "Controladora"), Rainproxy acts as Processor / Service Provider / Operador within the meaning of GDPR art. 4(8), CCPA §1798.140 and LGPD art. 5(VII). This DPA forms an integral part of our Terms of Service and is executed automatically upon acceptance of those Terms — no signature required for it to be binding worldwide.

Key terms

  • Subject matter: provision of proxy infrastructure services.
  • Duration: the term of the underlying subscription.
  • Nature & purpose: routing Controller's HTTP/HTTPS/SOCKS5 requests through the Rainproxy network.
  • Categories of data subjects: Controller's own end-users where Controller chooses to process their data.
  • Types of data: as determined by Controller; Rainproxy has no access to request/response bodies.
  • Sub-processors: see Annex II (provided on request); 30-day prior notice for changes, with right to object.
  • International transfers: EU Standard Contractual Clauses (Module 2/3, Commission Decision 2021/914), the UK IDTA / UK Addendum, the EU-US Data Privacy Framework where the recipient is certified, LGPD art. 33 mechanisms, and PIPEDA / APP 8 contractual safeguards — all incorporated by reference, plus a transfer impact assessment per Schrems II.
  • Security: the technical and organisational measures listed in Annex III meet GDPR art. 32 and align with ISO/IEC 27001 and SOC 2 control families (TLS, encryption at rest, MFA, audit logs).
  • Breach notification: within 48 hours of discovery, enabling Controller to meet its own statutory deadlines (72 h GDPR/UK GDPR; "without unreasonable delay" under CCPA, LGPD, PIPEDA and the Australian NDB scheme).
  • Audit rights: third-party audit reports made available annually; on-site audits by prior arrangement and at Controller's cost.
  • CCPA-specific: Rainproxy will not "sell" or "share" personal information, will not combine it with data from other sources except as permitted by §1798.140(ag)(2), and will notify Controller if it can no longer meet its CCPA obligations.
  • Return / deletion: at the end of services, personal data is returned or deleted within 30 days unless retention is required by applicable law.
  • Governing law: Dutch law; competent court: Rechtbank Midden-Nederland (Utrecht). Mandatory rights of data subjects under their local law are not affected.

Need a counter-signed copy, a regional addendum (e.g. UK IDTA standalone, LGPD Portuguese version, CCPA addendum) or a custom DPA for procurement? Email legal@rainproxy.io and we'll return it within one business day.