Hugo & Friends AB · 559555-9989
ProxyAPI standard terms for processing personal data on a customer’s behalf.
1. Parties, Roles, and Scope
Hugo & Friends AB, company reg. no. 559555-9989, provides ProxyAPI and is the “Processor”. The customer is the “Controller” or, where the customer itself acts as processor, the contracting primary processor. ProxyAPI then acts as processor or subprocessor. This DPA forms part of the Terms or other main agreement governing the Service.
2. Subject Matter, Duration, Nature, and Purpose
The subject matter is processing required to provide authenticated proxy routing, connection handling, usage metering, the dashboard, control API, health validators, support, and security. Processing mainly consists of transmission, routing, temporary handling, logging, aggregation, storage, and deletion of connection and account data. The purpose is to deliver and secure the features selected by the customer. Processing lasts for the agreement term and afterward only for wind-down, deletion, security, and legal requirements.
3. Data Subjects and Personal Data
Data subjects may include the customer’s users, employees, consultants, end users, and persons whose data the customer transmits through the proxy. Personal data may include account and contact data, IP addresses, destination host and port, timestamps, byte volume, session and targeting identifiers, technical logs, and personal data inside customer traffic. For HTTPS over CONNECT, content is relayed in encrypted form and is not decrypted or stored by ProxyAPI as application content.
4. Customer Instructions and Responsibilities
The Processor processes personal data only on the customer’s documented instructions in the main agreement, this DPA, API requests, proxy connections, settings, and support matters, and where required by EU or Swedish law. If we believe an instruction infringes data protection law, we will inform the customer without undue delay. The customer is responsible for lawful instructions, a legal basis, and required information to data subjects.
5. Personnel and Confidentiality
Persons authorised to process customer personal data are bound by confidentiality commitments or statutory duties, receive access only as needed, and are instructed on secure handling.
6. Technical and Organisational Measures
- TLS for the control plane and support for TLS to the proxy endpoint; HTTPS CONNECT content is relayed without TLS termination at the gateway.
- Hashing of customer API keys and encryption of upstream secrets.
- Role- and need-based access, private administrative network access, and separated customer identities.
- Health checks, logging, metrics, backups, patching, and incident procedures.
- Data minimisation: no intentional storage of request/response bodies for HTTPS CONNECT; metadata is limited to routing, operations, security, and billing.
7. Subprocessors
The customer gives general prior written authorisation to use the subprocessors on the published list. The Processor will ensure subprocessors are subject to data-protection obligations materially equivalent to this DPA and remains responsible for their performance under Article 28(4) GDPR. Planned material additions or replacements are published and communicated by email or dashboard normally at least 30 days before they begin processing customer data. The customer may make a reasonably substantiated data-protection objection during that period. The parties will then seek a reasonable solution; if none is available, the affected feature or agreement may be terminated under the main agreement.
8. Transfers Outside the EU/EEA
Core data is hosted in Sweden. Where a subprocessor or upstream proxy processes personal data outside the EU/EEA, processing must rely on a valid adequacy decision or appropriate safeguards under Chapter V GDPR, such as the European Commission’s Standard Contractual Clauses, with supplementary measures where needed.
9. Data Subject Rights and Compliance Assistance
Taking into account the nature of processing, the Processor will assist the customer through appropriate technical and organisational measures with data subject rights. Taking into account available information, we also assist with obligations under Articles 32–36 GDPR, including security, breach assessment, impact assessments, and prior consultation. The customer bears unreasonable or extraordinary costs by agreement.
10. Personal Data Breach
The Processor will notify the customer without undue delay after becoming aware of a personal data breach affecting customer personal data. Information is provided progressively as available and will, where possible, describe the nature of the breach, affected categories, likely consequences, and measures taken or planned.
11. Deletion and Return
When the Service ends, the Processor deletes or anonymises personal data processed on the customer’s behalf, at the customer’s choice, unless law requires continued retention. Data may remain in rotating backups until the relevant backup generation expires and remains protected during that time. Aggregates that can no longer be linked to an individual may be retained.
12. Information and Audit
The Processor will provide information reasonably necessary to demonstrate compliance with Article 28 and this DPA. Audits are primarily conducted through documentation and remote review. On-site audits require reasonable notice, confidentiality, normal business hours, and must not compromise security or other customers. The customer normally bears its audit costs; the Processor bears costs where an audit identifies a material breach for which the Processor is responsible.
13. Precedence, Liability, and Contact
A separately signed DPA or main agreement takes precedence over this standard DPA in case of conflict. Liability follows the main agreement’s liability provisions to the extent permitted by GDPR. Questions should be sent to hello@proxyapi.se.