Approximated.app Data Processing Agreement
Last updated: September 1, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Use (the “Agreement”) between Approximated, Inc. (“Approximated”) and the customer identified in the applicable Approximated account (“Customer”). It applies to the extent Approximated processes Personal Data on behalf of Customer in providing the Services and Data Protection Laws apply to that processing. Customer and Approximated are each a “party” and together the “parties”.
Signed copies. This DPA applies automatically and does not need to be signed to take effect. If Customer requires a countersigned copy for its records, email support@approximated.app with Customer’s legal entity name, registered address, and the name and title of its signatory, and Approximated will return a countersigned PDF of the then-current version. If the parties have executed a separate data processing agreement, that agreement prevails over this DPA.
Related documents: Sub-Processors and Processing Locations, Data Retention Policy, Privacy Policy, and the Trust Center.
1. Definitions
Capitalized terms not defined here have the meaning given in the Agreement.
- “Customer Personal Data” means Personal Data that Approximated processes on behalf of Customer in providing the Services, as described in Annex I.
- “Data Protection Laws” means all laws applicable to the processing of Personal Data under the Agreement, including, where applicable, the GDPR, the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection (“FADP”), and United States state privacy laws such as the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”).
- “GDPR” means Regulation (EU) 2016/679. “UK GDPR” means the GDPR as it forms part of the law of the United Kingdom by virtue of the European Union (Withdrawal) Act 2018.
- “Personal Data”, “Controller”, “Processor”, “Data Subject”, “Processing”, “Personal Data Breach” and “Supervisory Authority” have the meanings given in the GDPR. Under the CCPA, “Controller” includes a “business” and “Processor” includes a “service provider”.
- “Restricted Transfer” means a transfer of Customer Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country that is not recognized by the relevant authority as providing an adequate level of protection, where the transfer would be prohibited by Data Protection Laws without an appropriate safeguard.
- “SCCs” means the standard contractual clauses for the transfer of personal data to third countries annexed to Commission Implementing Decision (EU) 2021/914.
- “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, version B1.0, in force 21 March 2022.
- “Services” means the services Approximated provides to Customer under the Agreement.
- “Sub-processor” means a third party engaged by Approximated to process Customer Personal Data.
- “Security Incident” means a Personal Data Breach affecting Customer Personal Data in the possession or control of Approximated or a Sub-processor.
2. Roles and Scope
2.1 Customer is the Controller of Customer Personal Data or, where Customer processes Customer Personal Data on behalf of its own customers, a Processor. Approximated is a Processor or, where Customer is a Processor, a Sub-processor, and processes Customer Personal Data only on Customer’s behalf.
2.2 Where Customer is a Processor, Customer warrants that its instructions to Approximated and its engagement of Approximated as a Sub-processor have been authorized by the relevant Controller, and Customer is responsible for exercising the Controller’s rights under this DPA on the Controller’s behalf.
2.3 Annex I describes the subject matter, duration, nature, and purpose of the processing, the types of Personal Data, and the categories of Data Subjects.
2.4 This DPA does not apply to Personal Data that Approximated processes as a Controller, such as the contact details of Customer’s account holders processed for account administration, billing, and communications. That processing is described in the Privacy Policy.
3. Customer Instructions
3.1 Approximated will process Customer Personal Data only on Customer’s documented instructions, including with regard to transfers to a third country, unless required to do otherwise by law to which Approximated is subject. In that case Approximated will inform Customer of the legal requirement before processing, unless the law prohibits doing so on important grounds of public interest.
3.2 Customer’s instructions are: (a) the Agreement and this DPA; (b) Customer’s configuration and use of the Services through the dashboard and API, including the virtual hosts, target addresses, regions, routing rules, and security features Customer chooses; and (c) any further written instructions agreed by the parties.
3.3 Approximated will inform Customer if, in its opinion, an instruction infringes Data Protection Laws. Approximated is not obliged to perform a legal review of Customer’s instructions.
3.4 Customer is responsible for the lawfulness of the Customer Personal Data it causes to be processed, including providing any notices and obtaining any consents that Data Protection Laws require, and for determining whether the Services are appropriate for the data Customer routes through them.
4. Approximated’s Obligations
4.1 Confidentiality. Approximated will limit access to Customer Personal Data to personnel who need it to provide the Services, and will ensure that those personnel are bound by written confidentiality obligations and receive appropriate data protection training.
4.2 Security. Approximated will implement and maintain the technical and organizational measures described in Annex II. Approximated may update those measures from time to time, provided the updates do not materially reduce the overall level of protection.
4.3 Assistance. Taking into account the nature of the processing and the information available to it, Approximated will assist Customer, by appropriate technical and organizational measures, in responding to Data Subject requests (Section 6) and in meeting Customer’s obligations relating to security, Security Incident notification, data protection impact assessments, and prior consultation with Supervisory Authorities.
4.4 Records and cooperation. Approximated will maintain the records of processing required of it by Data Protection Laws and will cooperate with Supervisory Authorities as Data Protection Laws require.
5. Sub-processors
5.1 Customer gives Approximated general written authorization to engage Sub-processors. The current list, with each Sub-processor’s purpose and location, is published at approximated.app/sub-processors and forms Annex III of this DPA.
5.2 Approximated will give at least 30 days’ notice before authorizing a new Sub-processor to process Customer Personal Data by updating that page. Customer is responsible for checking that page for changes.
5.3 Customer may object to a new Sub-processor on reasonable data protection grounds within the notice period. The parties will discuss the objection in good faith. If it is not resolved within 30 days of the objection, Customer may terminate the affected Services on written notice, and Approximated will refund any prepaid fees for the remainder of the affected subscription term.
5.4 Approximated will impose on each Sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA, and remains responsible to Customer for the performance of each Sub-processor’s obligations.
6. Data Subject Requests
6.1 If Approximated receives a request from a Data Subject relating to Customer Personal Data and can identify the Customer concerned, it will forward the request to Customer without undue delay and will not respond to the Data Subject except to direct them to Customer, unless required by law.
6.2 Approximated will assist Customer in responding to such requests through the self-service features of the Services, including the ability to delete virtual hosts and other configuration, and, where those features are insufficient, by providing reasonable additional assistance on request.
7. Security Incidents
7.1 Approximated will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident.
7.2 To the extent the information is available to Approximated, the notification will describe the nature of the Security Incident, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. Approximated may provide this information in phases as it becomes available.
7.3 Approximated will take reasonable steps to contain, investigate, and mitigate the Security Incident, and will provide Customer with the information it reasonably requires to meet its own notification obligations. Notification of a Security Incident is not an acknowledgement of fault or liability.
8. Audits
8.1 On written request, Approximated will make available the information reasonably necessary to demonstrate compliance with this DPA, including descriptions of its security measures and any third-party assessment reports it holds.
8.2 Where that information is not sufficient to demonstrate compliance, Customer, or an independent auditor appointed by Customer and bound by confidentiality, may audit Approximated’s compliance with this DPA no more than once in any 12-month period, and additionally following a Security Incident affecting Customer Personal Data or where required by a Supervisory Authority. Audits are conducted remotely, by review of documentation and written responses to Customer’s questions. An on-site inspection may be required only where a remote audit cannot reasonably resolve the matter, where a Supervisory Authority requires it, or following a Security Incident affecting Customer Personal Data. Audits require at least 30 days’ written notice, take place during normal business hours, must not unreasonably disrupt Approximated’s operations, and are subject to Approximated’s reasonable security and confidentiality requirements.
8.3 Customer bears its own audit costs. Approximated may charge reasonable fees, at its then-current rates, for personnel time spent supporting an audit beyond providing the information described in Section 8.1.
8.4 Audit findings are confidential information of both parties, and Customer will share them with Approximated.
9. Deletion and Return
9.1 Customer may export its configuration through the API and may delete virtual hosts and other configuration at any time during the term of the Agreement.
9.2 On termination or expiry of the Agreement, Approximated will delete Customer Personal Data in accordance with the Data Retention Policy: it is removed from active systems within 30 days and ages out of backups within 60 days, unless Approximated is required by law to retain specific records. On written request received before deletion, Approximated will make Customer’s configuration available for export.
9.3 TLS certificates and private keys issued for Customer’s domains are removed within 30 days of the domain being deleted from the Services or the account being closed.
10. International Transfers
10.1 Approximated is established in the United States. Customer Personal Data is processed in the locations published under Processing Locations on the Sub-Processors page. Customer may restrict the regions in which its proxy nodes run to any subset of the available regions, at no additional cost, by contacting support@approximated.app.
10.2 To the extent the processing involves a Restricted Transfer from the European Economic Area, the SCCs are incorporated into this DPA by reference and apply as follows:
- Module Two (controller to processor) applies where Customer is a Controller, and Module Three (processor to processor) applies where Customer is a Processor. Customer is the “data exporter” and Approximated is the “data importer”.
- Clause 7 (docking clause) is not included.
- In Clause 9, Option 2 (general written authorization) applies, with the notice period in Section 5.
- In Clause 11, the optional language is not included.
- In Clause 13, the competent Supervisory Authority is determined in accordance with Annex I, Part C.
- In Clause 17, Option 1 applies and the SCCs are governed by the law of Ireland. In Clause 18, disputes are resolved by the courts of Ireland.
- Annex I and Annex II of the SCCs are completed by Annex I and Annex II of this DPA. Annex III of the SCCs is completed by the Sub-Processors page.
10.3 To the extent the processing involves a Restricted Transfer from the United Kingdom, the UK Addendum applies to the SCCs as completed above. Tables 1 to 3 of the UK Addendum are completed with the information in this DPA and its Annexes, and for Table 4 either party may end the UK Addendum as set out in Section 19 of the UK Addendum.
10.4 To the extent the processing involves a Restricted Transfer from Switzerland, the SCCs apply with the following adaptations: references to the GDPR are read as references to the FADP; the Federal Data Protection and Information Commissioner is the competent Supervisory Authority; the term “member state” is not interpreted to exclude Data Subjects in Switzerland from bringing claims in their place of habitual residence; and the SCCs also protect the data of legal entities for as long as the FADP does.
10.5 If a transfer mechanism relied on under this Section ceases to be valid, the parties will cooperate in good faith to implement an alternative lawful mechanism without undue delay. Approximated may, on notice to Customer, replace the SCCs or UK Addendum with a successor mechanism approved by the relevant authority.
10.6 For Restricted Transfers, the SCCs (as supplemented by the UK Addendum or the Swiss adaptations where applicable) prevail over this DPA and the Agreement in the event of conflict.
11. United States State Privacy Laws
Where the CCPA or a similar United States state privacy law applies to Customer Personal Data, Approximated acts as a service provider or processor and: (a) will not sell or share Customer Personal Data; (b) will not retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement, or outside the direct business relationship between the parties; (c) will not combine Customer Personal Data with Personal Data it receives from other sources, except as permitted by the applicable law; (d) will comply with the obligations applicable to service providers and provide the same level of privacy protection as the applicable law requires of Customer; (e) will notify Customer if it determines it can no longer meet these obligations; and (f) grants Customer the right to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data. Approximated certifies that it understands these restrictions and will comply with them.
12. Liability
Each party’s liability arising out of or relating to this DPA, including the SCCs and the UK Addendum, is subject to the exclusions and limitations of liability in the Agreement, and each party’s aggregate liability under the Agreement and this DPA combined is subject to the limitation set out in the Agreement. Nothing in this Section limits either party’s liability to Data Subjects under Clause 12 of the SCCs, or any liability that cannot be limited under Data Protection Laws.
13. Term, Changes, and Precedence
13.1 This DPA takes effect when the Agreement takes effect or, for existing Customers, on the “Last updated” date above, and continues until Approximated has deleted all Customer Personal Data in accordance with Section 9.
13.2 Approximated may update this DPA to reflect changes in Data Protection Laws, the Services, or Sub-processors. Material changes will be notified to account holders by email at least 30 days before they take effect, and the current version is always published on this page.
13.3 With respect to Customer Personal Data, in the event of conflict the order of precedence is: the SCCs (where applicable), then this DPA, then the Agreement.
13.4 Except for the SCCs, which are governed as set out in Section 10, this DPA is governed by the governing law and jurisdiction provisions of the Agreement.
13.5 Questions about this DPA may be sent to support@approximated.app.
Annex I: Description of the Processing
A. List of parties
Data exporter: Customer, as identified by the legal name, address, and contact details provided in its Approximated account. Role: Controller or, where Section 2.2 applies, Processor. Activities relevant to the transfer: use of the Services to route custom-domain traffic to Customer’s application and manage TLS certificates for those domains. Signature and date: by accepting the Agreement.
Data importer: Approximated, Inc., 2810 N Church St PMB 81017, Wilmington, Delaware 19802, United States. Contact: support@approximated.app. Role: Processor or, where Section 2.2 applies, Sub-processor. Activities relevant to the transfer: providing the Services. Signature and date: by publishing this DPA.
B. Description of the processing
| Categories of Data Subjects | (1) Customer’s personnel and other users authorized to access Customer’s Approximated account. (2) Customer’s own customers, where Customer configures domains on their behalf. (3) End users and other parties who send requests to, or receive responses from, domains configured on the Services. |
| Categories of Personal Data | (1) Account data: names, email addresses, authentication credentials, and billing details of Customer’s authorized users. (2) Configuration data: domain names, target addresses, DNS records, routing and security rules, and any Personal Data Customer includes in them. (3) Traffic metadata: client IP address, user agent, request timestamp, hostname, path, method, status code, request and response sizes, duration, and derived country and network (ASN) information. (4) TLS certificates and private keys issued for Customer’s domains. (5) Request and response content: the content of HTTP requests and responses passes through Approximated’s proxy nodes in memory for the purpose of routing and, where Customer enables it, security filtering. It is not written to logs or storage. Where Customer enables the optional web application firewall, the fragment of a request that matched a security rule is recorded as a security event. |
| Sensitive data | None intended. The Services are not designed for the storage of special categories of Personal Data, and any such data contained in traffic routed through the Services is not stored by Approximated. Customer determines whether the Services are appropriate for the data it routes through them. |
| Frequency | Continuous, for the duration of the Agreement. |
| Nature of the processing | Receiving, transmitting, and routing network traffic; terminating TLS and re-encrypting connections to Customer’s origin where Customer configures an HTTPS target; storing configuration and certificates; security filtering; aggregating traffic statistics; and providing support. |
| Purpose | Providing the Services: routing traffic for Customer’s custom domains to Customer’s application, issuing and renewing TLS certificates, checking DNS configuration, producing traffic statistics, protecting against abusive traffic, and providing customer support. |
| Retention | As set out in the Data Retention Policy: request-level records up to 14 days; security events up to 90 days; aggregated statistics that do not identify individuals up to 24 months; configuration and certificates within 30 days of deletion or account closure; backups within 60 days. |
| Transfers to Sub-processors | As set out on the Sub-Processors page, for the purposes listed there and for the same duration. |
C. Competent Supervisory Authority
Where Customer is established in an EU member state, the Supervisory Authority of that member state. Where Customer is not established in an EU member state but is subject to the GDPR under Article 3(2) and has appointed a representative, the Supervisory Authority of the member state in which the representative is established. Otherwise, the Supervisory Authority of the member state in which the Data Subjects whose Personal Data is transferred are located.
Annex II: Technical and Organizational Measures
Approximated maintains the following measures to protect Customer Personal Data.
- Encryption in transit. All dashboard and API traffic uses TLS. Traffic between end users and proxy nodes uses TLS for every domain with an issued certificate, and traffic from proxy nodes to Customer’s origin uses TLS whenever Customer configures an HTTPS target.
- Protection of stored data. Passwords are stored as salted hashes. API keys and other credentials are encrypted at the application level before storage. Backups are encrypted.
- Data minimization. Request and response bodies are not written to logs or storage. Request-level records contain metadata only and are retained for the limited periods in the Data Retention Policy, after which only aggregated statistics that do not identify individuals remain.
- Access control. Access to production systems is limited to authorized Approximated personnel on a least-privilege basis and is revoked when no longer needed. Administrative access to the platform requires multi-factor authentication. Customers can enable multi-factor authentication on their accounts and use API keys scoped to individual clusters.
- Infrastructure isolation. Each cloud cluster runs as a separate set of machines dedicated to one Customer. Customers choose the regions in which their proxy nodes run and may restrict them at any time.
- Traffic protection. Customers may enable a web application firewall, rate limiting, and IP-based allow and block rules on their clusters. Approximated uses threat intelligence to identify abusive sources.
- Monitoring and logging. Approximated monitors the health of clusters and the platform, records application errors, and keeps an audit log of configuration changes to each cluster.
- Availability and resilience. Cloud clusters run multiple machines, across multiple regions where selected, with automatic scaling. Production data is backed up on a regular schedule with a documented restore procedure.
- Change and vulnerability management. Changes to the platform go through code review and automated tests before deployment. Dependencies and base images are updated regularly, and security patches are prioritized.
- Incident response. Approximated maintains a process for detecting, containing, and investigating Security Incidents, and notifies affected Customers as set out in Section 7.
- Sub-processor management. Sub-processors are bound by written agreements with data protection obligations, and the list of Sub-processors is published and updated with notice.
- Personnel. Personnel with access to Customer Personal Data are bound by confidentiality obligations and receive data protection training. Access is removed when personnel leave or change roles.
- Deletion. Customer Personal Data is deleted in accordance with the Data Retention Policy and Section 9.
Annex III: Sub-processors
The current list of Sub-processors, with each one’s purpose and location, and the locations in which Customer Personal Data is processed, is published at approximated.app/sub-processors.