Legal
Data Processing Agreement
Last updated: 31 July 2026
The Article 28 GDPR terms under which we process personal data on your behalf. It applies automatically to every account and forms part of our Terms of Service — you do not need to sign anything to rely on it. If your procurement process requires a countersigned copy, email privacy@dataswap.io.
1. Roles of the parties
This Data Processing Agreement ("DPA") applies where you (the "Customer") use the Dataswap API and dashboard (the "Service") to process personal data, and forms part of our Terms of Service.
For that data, the Customer is the controller and dataswap.io is the processor, acting only on the Customer’s documented instructions — which, in practice, are the API requests you make.
Separately, dataswap.io is the controller of the account data described in our Privacy Policy (your name, email, billing records and usage logs). This DPA does not cover that relationship.
2. Subject matter, duration and purpose
- Subject matter — provision of structured search, SEO, marketplace and AI-assisted data through the Service.
- Duration — for as long as the Customer holds an active account, plus the retention periods in section 6.
- Nature and purpose — receiving query parameters, retrieving and structuring the corresponding data, metering and billing the request.
- Categories of data subjects — determined by the Customer. The Service is designed for queries about companies, domains, products and public search results, not about identified individuals.
- Types of personal data — whatever the Customer chooses to send as query parameters, plus the technical metadata needed to serve and bill the request.
The Customer must not submit special categories of data (Article 9 GDPR) or data relating to criminal convictions through the Service.
3. Processing on instructions
We process personal data only to provide the Service and as instructed by the Customer through their use of it, except where required by law — in which case we will inform the Customer beforehand unless the law forbids it.
We do not sell personal data, and we do not use Customer query content to train models.
4. Confidentiality and personnel
Access to production systems and data is limited to the people who need it to operate the Service, and everyone with such access is bound by confidentiality obligations.
5. Security measures
We implement appropriate technical and organisational measures under Article 32 GDPR. In concrete terms:
- TLS for all traffic, with HSTS; no plaintext transport.
- API keys stored only as salted SHA-256 hashes; account passwords hashed with scrypt.
- Per-account isolation on every query; resources of other accounts return 404, not 403.
- Append-only credit ledger, with atomic commits, so billing movements remain auditable.
- Daily backups verified at the moment they are taken, replicated off-site, with a weekly restore drill performed on the off-site copy.
- A Content-Security-Policy that blocks third-party resources and restricts where the page may send data.
These are described in more detail, including what we do not yet have, on our Security page.
6. Sub-processors
The Customer authorises us to engage sub-processors to provide the Service. We remain responsible for their performance. Current categories:
- Upstream data providers — licensed sources that fulfil data requests. Query parameters are passed to them to serve your request.
- Payment processing — Stripe.
- Transactional email — Mandrill / Mailchimp.
- Hosting and infrastructure — our cloud provider.
A current list naming each sub-processor is available on request to privacy@dataswap.io. We will give the Customer reasonable notice before adding or replacing a sub-processor, and the Customer may object on reasonable data-protection grounds.
7. International transfers
Where personal data is transferred outside the EEA or the UK, we rely on an adequacy decision where one applies, and otherwise on the European Commission’s Standard Contractual Clauses (and the UK Addendum where relevant), together with any additional measures the transfer requires.
8. Assistance to the Customer
Taking into account the nature of the processing, we will assist the Customer with:
- responding to requests from data subjects exercising their rights;
- data protection impact assessments and prior consultations;
- demonstrating compliance with Article 32 security obligations.
9. Personal data breaches
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting their data, with the information needed for the Customer to meet its own notification obligations. Notice goes to the account email address, so keep it current.
10. Return and deletion
On termination, and at the Customer’s choice, we delete or return the personal data processed on their behalf, except where storage is required by law. Billing records are kept for the period required by accounting and tax law (typically up to 10 years), and cached query results expire automatically.
11. Audits
We will make available the information necessary to demonstrate compliance with this DPA and allow for audits, including inspections, conducted by the Customer or an auditor they mandate, on reasonable notice and no more than once per year unless a supervisory authority requires otherwise.
12. The processor
dataswap.io
Rua do Bairro, 4715-163 Braga, Portugal
VAT PT268119465
Data protection contact: privacy@dataswap.io