Watch-IP

Data Processing Addendum

Effective September 6, 2026

This is Digitload's current draft DPA template for Watch-IP. It reflects how the Service actually processes data today, but has not yet been reviewed by outside counsel — treat it as informative rather than a final, executable legal instrument until that review is complete. Contact us at the address below for a signed copy for your account.

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Digitload Inc. ("Processor", "we") and the customer entity that has agreed to the Terms ("Controller", "you") wherever you process personal data of individuals in the EEA, UK, Switzerland, or another jurisdiction with substantially similar requirements through the Watch-IP Service. Capitalized terms not defined here have the meaning given in the Terms or our Privacy Policy.

1. Scope — Which Endpoints This DPA Covers

Watch-IP's endpoints put us in different roles depending on whose data is flowing through them:

  • GET /v1/geo — the request comes directly from your Visitor's own browser, using edge data Cloudflare already generates for that connection. Because you don't route your Visitors' personal data to us yourself (your Visitors' browsers call us directly, the same way they'd call any client-side script on your page), this endpoint does not by itself require a DPA in most interpretations, but we make this DPA available to cover it too if your legal analysis concludes otherwise.
  • GET/POST /v1/lookup, POST /v1/risk/check — you supply IP addresses and, for /v1/risk/check, a userId and location about your own end users or other third parties. This is the clearest case of us acting as your processor: this DPA applies to these endpoints whenever the data relates to individuals protected under an applicable data protection law.
  • POST /v1/email/validate — you supply an email address to check its domain. Because we don't retain the address, exposure is minimal, but this DPA applies to this endpoint as well for completeness.

2. Roles of the Parties

For Processing covered by Section 1, you are the Controller (or, if you process on behalf of your own customers, a Processor acting under their instructions) and we are your Processor / Sub-processor. We process personal data only on your documented instructions, as set out in this DPA and the Terms, unless required to do otherwise by law.

3. Subject Matter, Duration, and Nature of Processing

Subject matter: providing geolocation, IP-threat, disposable-email, and impossible-travel risk-scoring functionality via API. Duration: for as long as the Terms are in effect, plus any period needed to fulfill retention or deletion obligations. Nature and purpose: automated computation of a response to each API call you make, and — for /v1/risk/check only — storage of a single most-recent location per userId to serve as a baseline for future checks.

4. Categories of Data Subjects and Personal Data

Data subjects: your Visitors and end users (individuals whose IP address, email address, or location you submit to us). Categories of personal data: IP addresses; email addresses (transient, not stored); approximate geolocation (country, region, city, coordinates, timezone); network/threat classification (VPN, Tor, datacenter, malicious-range or sanctioned-ASN membership); and, for /v1/risk/check, a customer-assigned userId paired with a location and timestamp. We don't process special categories of data (Art. 9 GDPR) and ask that you don't submit any to us.

5. Your Obligations as Controller

You warrant that you have a valid legal basis and, where required, appropriate notice or consent, to submit personal data to the Service and to receive and act on our output — including any automated decision made using our risk or threat signals (see the Acceptable Use section of our Terms on human review of significant decisions). You're responsible for the accuracy of data you submit and for responding to data subject requests that relate to your own use of the Service, with our reasonable assistance under Section 7.

6. Our Obligations as Processor

We will: process personal data only on your instructions (as reflected in your use of the API) and as required by law; ensure personnel with access are bound by confidentiality; implement the security measures described in Section 8; not engage a new sub-processor without providing notice under Section 9; and, taking into account the nature of processing, assist you in responding to data subject requests and in meeting your obligations around security, breach notification, and data protection impact assessments.

7. Assistance With Data Subject Requests

If we receive a request directly from one of your data subjects, we'll redirect them to you and won't respond substantively ourselves, except to confirm we've forwarded it. We'll provide reasonable assistance so you can respond to verified requests within the timeframes applicable law requires, including deleting a stored /v1/risk/check baseline on your instruction.

8. Security Measures

We maintain technical and organizational measures appropriate to the risk, including:

  • encryption in transit (TLS) for all API and dashboard traffic;
  • API keys stored as salted cryptographic hashes, never in plaintext;
  • origin-locking on publishable keys and bearer-token authentication on secret-key endpoints, so a leaked key alone doesn't grant broad access;
  • per-customer rate limiting to contain abuse and reduce blast radius from a compromised key;
  • access to production data restricted to personnel who need it to operate the Service, on infrastructure operated by Cloudflare with its own SOC 2 / ISO 27001-audited controls; and
  • minimal retention by design — most endpoints compute a response and retain nothing beyond an aggregate usage count (see Privacy Policy Section 1).

9. Sub-processors

You authorize our engagement of the following sub-processors, each processing personal data solely to help us provide the Service:

  • Cloudflare, Inc. — API/dashboard hosting, storage (KV, D1, R2), Durable Objects, Analytics Engine, email delivery, and bot mitigation (Turnstile).
  • Stripe, Inc. and PayPal, Inc. — payment processing (billing/account data only, not Visitor data processed under this DPA).

We'll give at least 14 days' notice before adding or replacing a sub-processor that will process personal data covered by this DPA, by email or an in-dashboard notice. If you reasonably object on data-protection grounds, we'll work with you in good faith to address the concern; if we can't, either party may terminate the affected part of the Service as its sole remedy.

10. International Transfers

Where processing under this DPA involves a transfer of personal data out of the EEA, UK, or Switzerland, the transfer is governed by the EU Standard Contractual Clauses (Module 2: Controller-to-Processor, or Module 3 where you act as a Processor), incorporated by reference, with Digitload as "data importer." The UK International Data Transfer Addendum applies correspondingly for transfers subject to UK GDPR.

11. Personal Data Breach Notification

We'll notify you without undue delay, and in any case within 72 hours of becoming aware, of a confirmed personal data breach affecting data we process under this DPA, with the information available to us at the time so you can meet your own notification obligations.

12. Deletion or Return of Data

On termination of the Terms, or on your request, we'll delete any personal data we still hold that was processed under this DPA — in practice, primarily any /v1/risk/check baselines, since other endpoints don't retain submitted data — within 30 days, except where we're required by law to retain it longer.

13. Audit Rights

On reasonable prior notice, and no more than once per year (or following a confirmed breach), we'll make available the information reasonably necessary to demonstrate compliance with this DPA, including summaries of relevant third-party audit reports (e.g. Cloudflare's) where we're able to share them. On-site audits require a signed confidentiality agreement and reasonable advance scheduling.

14. Precedence and Liability

This DPA supplements, and does not replace, the Terms. In the event of a conflict between this DPA and the Terms as to the processing of personal data, this DPA governs. Liability arising under this DPA is subject to the limitations of liability set out in the Terms.

If you need a signed copy of this DPA for your account, contact legal@watch-ip.com and we'll countersign the current template for you.