Approximated.app Data Processing Agreement

Last updated: September 1, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Use (the “Agreement”) between Approximated, Inc. (“Approximated”) and the customer identified in the applicable Approximated account (“Customer”). It applies to the extent Approximated processes Personal Data on behalf of Customer in providing the Services and Data Protection Laws apply to that processing. Customer and Approximated are each a “party” and together the “parties”.

Signed copies. This DPA applies automatically and does not need to be signed to take effect. If Customer requires a countersigned copy for its records, email support@approximated.app with Customer’s legal entity name, registered address, and the name and title of its signatory, and Approximated will return a countersigned PDF of the then-current version. If the parties have executed a separate data processing agreement, that agreement prevails over this DPA.

Related documents: Sub-Processors and Processing Locations, Data Retention Policy, Privacy Policy, and the Trust Center.

1. Definitions

Capitalized terms not defined here have the meaning given in the Agreement.

2. Roles and Scope

2.1 Customer is the Controller of Customer Personal Data or, where Customer processes Customer Personal Data on behalf of its own customers, a Processor. Approximated is a Processor or, where Customer is a Processor, a Sub-processor, and processes Customer Personal Data only on Customer’s behalf.

2.2 Where Customer is a Processor, Customer warrants that its instructions to Approximated and its engagement of Approximated as a Sub-processor have been authorized by the relevant Controller, and Customer is responsible for exercising the Controller’s rights under this DPA on the Controller’s behalf.

2.3 Annex I describes the subject matter, duration, nature, and purpose of the processing, the types of Personal Data, and the categories of Data Subjects.

2.4 This DPA does not apply to Personal Data that Approximated processes as a Controller, such as the contact details of Customer’s account holders processed for account administration, billing, and communications. That processing is described in the Privacy Policy.

3. Customer Instructions

3.1 Approximated will process Customer Personal Data only on Customer’s documented instructions, including with regard to transfers to a third country, unless required to do otherwise by law to which Approximated is subject. In that case Approximated will inform Customer of the legal requirement before processing, unless the law prohibits doing so on important grounds of public interest.

3.2 Customer’s instructions are: (a) the Agreement and this DPA; (b) Customer’s configuration and use of the Services through the dashboard and API, including the virtual hosts, target addresses, regions, routing rules, and security features Customer chooses; and (c) any further written instructions agreed by the parties.

3.3 Approximated will inform Customer if, in its opinion, an instruction infringes Data Protection Laws. Approximated is not obliged to perform a legal review of Customer’s instructions.

3.4 Customer is responsible for the lawfulness of the Customer Personal Data it causes to be processed, including providing any notices and obtaining any consents that Data Protection Laws require, and for determining whether the Services are appropriate for the data Customer routes through them.

4. Approximated’s Obligations

4.1 Confidentiality. Approximated will limit access to Customer Personal Data to personnel who need it to provide the Services, and will ensure that those personnel are bound by written confidentiality obligations and receive appropriate data protection training.

4.2 Security. Approximated will implement and maintain the technical and organizational measures described in Annex II. Approximated may update those measures from time to time, provided the updates do not materially reduce the overall level of protection.

4.3 Assistance. Taking into account the nature of the processing and the information available to it, Approximated will assist Customer, by appropriate technical and organizational measures, in responding to Data Subject requests (Section 6) and in meeting Customer’s obligations relating to security, Security Incident notification, data protection impact assessments, and prior consultation with Supervisory Authorities.

4.4 Records and cooperation. Approximated will maintain the records of processing required of it by Data Protection Laws and will cooperate with Supervisory Authorities as Data Protection Laws require.

5. Sub-processors

5.1 Customer gives Approximated general written authorization to engage Sub-processors. The current list, with each Sub-processor’s purpose and location, is published at approximated.app/sub-processors and forms Annex III of this DPA.

5.2 Approximated will give at least 30 days’ notice before authorizing a new Sub-processor to process Customer Personal Data by updating that page. Customer is responsible for checking that page for changes.

5.3 Customer may object to a new Sub-processor on reasonable data protection grounds within the notice period. The parties will discuss the objection in good faith. If it is not resolved within 30 days of the objection, Customer may terminate the affected Services on written notice, and Approximated will refund any prepaid fees for the remainder of the affected subscription term.

5.4 Approximated will impose on each Sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA, and remains responsible to Customer for the performance of each Sub-processor’s obligations.

6. Data Subject Requests

6.1 If Approximated receives a request from a Data Subject relating to Customer Personal Data and can identify the Customer concerned, it will forward the request to Customer without undue delay and will not respond to the Data Subject except to direct them to Customer, unless required by law.

6.2 Approximated will assist Customer in responding to such requests through the self-service features of the Services, including the ability to delete virtual hosts and other configuration, and, where those features are insufficient, by providing reasonable additional assistance on request.

7. Security Incidents

7.1 Approximated will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident.

7.2 To the extent the information is available to Approximated, the notification will describe the nature of the Security Incident, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. Approximated may provide this information in phases as it becomes available.

7.3 Approximated will take reasonable steps to contain, investigate, and mitigate the Security Incident, and will provide Customer with the information it reasonably requires to meet its own notification obligations. Notification of a Security Incident is not an acknowledgement of fault or liability.

8. Audits

8.1 On written request, Approximated will make available the information reasonably necessary to demonstrate compliance with this DPA, including descriptions of its security measures and any third-party assessment reports it holds.

8.2 Where that information is not sufficient to demonstrate compliance, Customer, or an independent auditor appointed by Customer and bound by confidentiality, may audit Approximated’s compliance with this DPA no more than once in any 12-month period, and additionally following a Security Incident affecting Customer Personal Data or where required by a Supervisory Authority. Audits are conducted remotely, by review of documentation and written responses to Customer’s questions. An on-site inspection may be required only where a remote audit cannot reasonably resolve the matter, where a Supervisory Authority requires it, or following a Security Incident affecting Customer Personal Data. Audits require at least 30 days’ written notice, take place during normal business hours, must not unreasonably disrupt Approximated’s operations, and are subject to Approximated’s reasonable security and confidentiality requirements.

8.3 Customer bears its own audit costs. Approximated may charge reasonable fees, at its then-current rates, for personnel time spent supporting an audit beyond providing the information described in Section 8.1.

8.4 Audit findings are confidential information of both parties, and Customer will share them with Approximated.

9. Deletion and Return

9.1 Customer may export its configuration through the API and may delete virtual hosts and other configuration at any time during the term of the Agreement.

9.2 On termination or expiry of the Agreement, Approximated will delete Customer Personal Data in accordance with the Data Retention Policy: it is removed from active systems within 30 days and ages out of backups within 60 days, unless Approximated is required by law to retain specific records. On written request received before deletion, Approximated will make Customer’s configuration available for export.

9.3 TLS certificates and private keys issued for Customer’s domains are removed within 30 days of the domain being deleted from the Services or the account being closed.

10. International Transfers

10.1 Approximated is established in the United States. Customer Personal Data is processed in the locations published under Processing Locations on the Sub-Processors page. Customer may restrict the regions in which its proxy nodes run to any subset of the available regions, at no additional cost, by contacting support@approximated.app.

10.2 To the extent the processing involves a Restricted Transfer from the European Economic Area, the SCCs are incorporated into this DPA by reference and apply as follows:

10.3 To the extent the processing involves a Restricted Transfer from the United Kingdom, the UK Addendum applies to the SCCs as completed above. Tables 1 to 3 of the UK Addendum are completed with the information in this DPA and its Annexes, and for Table 4 either party may end the UK Addendum as set out in Section 19 of the UK Addendum.

10.4 To the extent the processing involves a Restricted Transfer from Switzerland, the SCCs apply with the following adaptations: references to the GDPR are read as references to the FADP; the Federal Data Protection and Information Commissioner is the competent Supervisory Authority; the term “member state” is not interpreted to exclude Data Subjects in Switzerland from bringing claims in their place of habitual residence; and the SCCs also protect the data of legal entities for as long as the FADP does.

10.5 If a transfer mechanism relied on under this Section ceases to be valid, the parties will cooperate in good faith to implement an alternative lawful mechanism without undue delay. Approximated may, on notice to Customer, replace the SCCs or UK Addendum with a successor mechanism approved by the relevant authority.

10.6 For Restricted Transfers, the SCCs (as supplemented by the UK Addendum or the Swiss adaptations where applicable) prevail over this DPA and the Agreement in the event of conflict.

11. United States State Privacy Laws

Where the CCPA or a similar United States state privacy law applies to Customer Personal Data, Approximated acts as a service provider or processor and: (a) will not sell or share Customer Personal Data; (b) will not retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement, or outside the direct business relationship between the parties; (c) will not combine Customer Personal Data with Personal Data it receives from other sources, except as permitted by the applicable law; (d) will comply with the obligations applicable to service providers and provide the same level of privacy protection as the applicable law requires of Customer; (e) will notify Customer if it determines it can no longer meet these obligations; and (f) grants Customer the right to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data. Approximated certifies that it understands these restrictions and will comply with them.

12. Liability

Each party’s liability arising out of or relating to this DPA, including the SCCs and the UK Addendum, is subject to the exclusions and limitations of liability in the Agreement, and each party’s aggregate liability under the Agreement and this DPA combined is subject to the limitation set out in the Agreement. Nothing in this Section limits either party’s liability to Data Subjects under Clause 12 of the SCCs, or any liability that cannot be limited under Data Protection Laws.

13. Term, Changes, and Precedence

13.1 This DPA takes effect when the Agreement takes effect or, for existing Customers, on the “Last updated” date above, and continues until Approximated has deleted all Customer Personal Data in accordance with Section 9.

13.2 Approximated may update this DPA to reflect changes in Data Protection Laws, the Services, or Sub-processors. Material changes will be notified to account holders by email at least 30 days before they take effect, and the current version is always published on this page.

13.3 With respect to Customer Personal Data, in the event of conflict the order of precedence is: the SCCs (where applicable), then this DPA, then the Agreement.

13.4 Except for the SCCs, which are governed as set out in Section 10, this DPA is governed by the governing law and jurisdiction provisions of the Agreement.

13.5 Questions about this DPA may be sent to support@approximated.app.

Annex I: Description of the Processing

A. List of parties

Data exporter: Customer, as identified by the legal name, address, and contact details provided in its Approximated account. Role: Controller or, where Section 2.2 applies, Processor. Activities relevant to the transfer: use of the Services to route custom-domain traffic to Customer’s application and manage TLS certificates for those domains. Signature and date: by accepting the Agreement.

Data importer: Approximated, Inc., 2810 N Church St PMB 81017, Wilmington, Delaware 19802, United States. Contact: support@approximated.app. Role: Processor or, where Section 2.2 applies, Sub-processor. Activities relevant to the transfer: providing the Services. Signature and date: by publishing this DPA.

B. Description of the processing

Categories of Data Subjects (1) Customer’s personnel and other users authorized to access Customer’s Approximated account. (2) Customer’s own customers, where Customer configures domains on their behalf. (3) End users and other parties who send requests to, or receive responses from, domains configured on the Services.
Categories of Personal Data (1) Account data: names, email addresses, authentication credentials, and billing details of Customer’s authorized users. (2) Configuration data: domain names, target addresses, DNS records, routing and security rules, and any Personal Data Customer includes in them. (3) Traffic metadata: client IP address, user agent, request timestamp, hostname, path, method, status code, request and response sizes, duration, and derived country and network (ASN) information. (4) TLS certificates and private keys issued for Customer’s domains. (5) Request and response content: the content of HTTP requests and responses passes through Approximated’s proxy nodes in memory for the purpose of routing and, where Customer enables it, security filtering. It is not written to logs or storage. Where Customer enables the optional web application firewall, the fragment of a request that matched a security rule is recorded as a security event.
Sensitive data None intended. The Services are not designed for the storage of special categories of Personal Data, and any such data contained in traffic routed through the Services is not stored by Approximated. Customer determines whether the Services are appropriate for the data it routes through them.
Frequency Continuous, for the duration of the Agreement.
Nature of the processing Receiving, transmitting, and routing network traffic; terminating TLS and re-encrypting connections to Customer’s origin where Customer configures an HTTPS target; storing configuration and certificates; security filtering; aggregating traffic statistics; and providing support.
Purpose Providing the Services: routing traffic for Customer’s custom domains to Customer’s application, issuing and renewing TLS certificates, checking DNS configuration, producing traffic statistics, protecting against abusive traffic, and providing customer support.
Retention As set out in the Data Retention Policy: request-level records up to 14 days; security events up to 90 days; aggregated statistics that do not identify individuals up to 24 months; configuration and certificates within 30 days of deletion or account closure; backups within 60 days.
Transfers to Sub-processors As set out on the Sub-Processors page, for the purposes listed there and for the same duration.

C. Competent Supervisory Authority

Where Customer is established in an EU member state, the Supervisory Authority of that member state. Where Customer is not established in an EU member state but is subject to the GDPR under Article 3(2) and has appointed a representative, the Supervisory Authority of the member state in which the representative is established. Otherwise, the Supervisory Authority of the member state in which the Data Subjects whose Personal Data is transferred are located.

Annex II: Technical and Organizational Measures

Approximated maintains the following measures to protect Customer Personal Data.

Annex III: Sub-processors

The current list of Sub-processors, with each one’s purpose and location, and the locations in which Customer Personal Data is processed, is published at approximated.app/sub-processors.