Data Processing Agreement
Last updated: June 2026
This Data Processing Agreement ("DPA") forms part of the tracenow Terms of Service between you (the "Controller") and tracenow (the "Processor"). It applies where tracenow processes personal data on your behalf in the course of providing the tracenow platform and APIs. It is incorporated by reference into the Terms of Service and takes effect on the date you accept those terms.
Where you are subject to the EU General Data Protection Regulation (GDPR), UK GDPR, or equivalent legislation, this DPA satisfies the written contract requirement under Article 28 GDPR.
1. Definitions
- Personal Data means any information relating to an identified or identifiable natural person that is submitted to the tracenow API by you or your application, including IP addresses, email addresses, and phone numbers processed through the enrichment APIs.
- Processing has the meaning given in GDPR Article 4 and includes any operation performed on Personal Data, such as collecting, storing, using, or deleting it.
- Sub-processor means any third party engaged by tracenow to process Personal Data in connection with providing the service.
2. Roles and Responsibilities
You are the Controller of Personal Data submitted to the tracenow API. You determine the purposes and means of that processing. For example, you decide which IP addresses, emails, or phone numbers to submit for enrichment, and how to act on the results.
tracenow is the Processor. We process Personal Data only as instructed by you through your use of the API and in accordance with this DPA and the Terms of Service. We do not use Personal Data submitted to the API for our own commercial purposes beyond what is strictly necessary to operate the service.
3. Details of Processing
Nature and purpose. tracenow processes Personal Data to return enriched intelligence signals (geolocation, network type, anonymity flags, validity scores, carrier data, risk signals) and to evaluate your configured rules and return a fraud decision verdict. Processing also occurs to record usage for billing, detect abuse, and maintain the security of the service.
Categories of data subjects. End users of your application whose IP addresses, email addresses, or phone numbers you submit to the API.
Categories of personal data. IP addresses, email addresses, phone numbers, and any additional data you pass in API request fields.
Duration. tracenow retains API request logs (including the personal data submitted) for 12 months for billing verification and abuse investigation, after which they are deleted. See the Privacy Policy for full retention schedules.
4. Controller Obligations
You represent and warrant that:
- You have a lawful basis under applicable data protection law to submit Personal Data to the tracenow API (for example, a legitimate interest in fraud prevention).
- Where required, you have provided appropriate notices to data subjects whose data you submit, or you are relying on an exemption from the notice requirement that applies in your jurisdiction.
- You will not submit special category data (as defined in GDPR Article 9) or data relating to children unless you have appropriate legal authority to do so.
5. Processor Obligations
tracenow will:
- Process Personal Data only on your documented instructions and not for any other purpose, except where required by law.
- Ensure that personnel authorized to process Personal Data are bound by appropriate confidentiality obligations.
- Implement and maintain technical and organizational security measures appropriate to the risk, as described in Section 6 below.
- Assist you in responding to data subject rights requests to the extent we hold data about those individuals.
- Delete or return Personal Data at your request upon termination of the service, subject to legal retention obligations.
- Make available to you the information necessary to demonstrate compliance with this DPA and allow for reasonable audits, including inspections conducted by you or an auditor mandated by you, upon reasonable notice.
- Notify you without undue delay (and in any event within 72 hours of becoming aware) of any personal data breach affecting data we process on your behalf.
6. Security Measures
tracenow implements the following technical and organizational measures to protect Personal Data:
- All data in transit encrypted via TLS 1.2 or higher.
- Data at rest encrypted using AES-256 or equivalent.
- API keys stored as hashed credentials; plaintext never persisted.
- Access to production systems restricted to authorized personnel on a need-to-know basis.
- Regular automated backups with access controls.
- Vulnerability disclosure program: report issues to hello@tracenow.io.
7. Sub-processors
You authorize tracenow to engage the following sub-processors to assist in providing the service. tracenow will ensure sub-processors are bound by data protection obligations no less protective than those in this DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Cloud infrastructure (primary) | Germany / Finland / USA |
| Stripe, Inc. | Payment processing | USA |
tracenow will notify you of any intended changes concerning the addition or replacement of sub-processors by updating this page and emailing you at least 14 days in advance. If you object to a new sub-processor on legitimate data protection grounds, contact us at hello@tracenow.io; we will work with you to find a resolution, which may include enabling you to terminate the service without penalty.
8. International Data Transfers
Where Personal Data is transferred outside the EEA or UK to a country not recognized as providing an adequate level of data protection, such transfers are made under the Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914 or any successor), or the UK International Data Transfer Agreement (IDTA), as applicable. By accepting the Terms of Service, you agree to the execution of SCCs where required by applicable law; they are incorporated by reference and take effect automatically.
9. Data Subject Rights
If a data subject exercises their rights under GDPR or other applicable law (e.g., access, erasure, restriction) with respect to Personal Data processed through the tracenow API, tracenow will assist you in fulfilling that request to the extent we hold the relevant data. Submit requests to hello@tracenow.io.
10. Term and Termination
This DPA remains in effect for as long as tracenow processes Personal Data on your behalf under the Terms of Service. Upon termination of the Terms of Service, tracenow will, at your election, delete or return all Personal Data in its possession that it processes on your behalf, and delete existing copies, unless applicable law requires continued storage.
11. Liability
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service. Nothing in this DPA is intended to limit either party's liability in respect of a personal data breach caused by that party's negligence or wilful misconduct.
12. Governing Law
This DPA is governed by the laws of the State of Delaware, consistent with the Terms of Service, except where EU or UK data protection law mandates a different governing law for specific provisions.
13. Contact
Questions about this DPA or data processing under GDPR? Email us at hello@tracenow.io.