Skip to content

Data Processing Agreement

Last updated: 22 September 2026

1. When this applies

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and Mslm Dev, trading as InternetData ("Processor", "we", "us"). It applies where, and only to the extent that, we process personal data on your behalf in the course of providing the Service, and it takes effect when you begin using the Service. No signature is required. If you need a countersigned copy for your records, write to legal@internetdata.io.

Where this DPA and the Terms of Service conflict on the subject of personal data, this DPA governs. Where you have signed a license agreement with us that deals with personal data, that agreement prevails over this DPA to the extent the two conflict. Terms defined in the GDPR have the same meaning here.

2. What we process, and what we do not

The addresses your users connect from are not the subject of this DPA, because they never reach us. We license databases and answer no lookups: you query a database you hold, inside your own infrastructure, and we see none of it. Our datasets describe network infrastructure, are built from our own measurement and from public registry and operator records, and are not processed on your behalf. Section 2 of our Privacy Policy explains the distinction in full.

What we do process on your behalf is personal data about the people in your organization who use the Service, as described below.

Subject matterProviding access to the Service and delivering the databases you license
DurationFor as long as you have an account, plus the retention described in section 6
Nature and purposeAuthenticating your personnel, issuing and checking API keys, delivering the databases you license, recording each download attempt, and keeping the security and audit records the console shows you
Categories of personal dataYour personnel's account details (name, email address, authentication identifiers); the address and user agent each sign-in and download comes from; a record of each download attempt, with the API key behind it where one was used; administrative actions taken in your organization
Categories of data subjectYour personnel who hold accounts
Special category dataNone. The Service is not designed to receive it and you must not submit it

3. Our obligations

We will:

  • process personal data only on your documented instructions, of which your use of the Service and the Terms of Service are the primary ones, unless required otherwise by law, in which case we will tell you first unless the law forbids it;
  • not use personal data processed on your behalf to train machine-learning or AI models;
  • ensure that everyone authorized to process it is bound by an appropriate duty of confidence;
  • take the measures described in section 5;
  • assist you, so far as is reasonable and taking into account the nature of the processing, with data subject requests, security incidents, impact assessments and prior consultation;
  • on termination, delete or return personal data as set out in section 6, except where law requires us to keep it;
  • make available the information reasonably needed to demonstrate compliance with this DPA, and allow and contribute to audits as set out in section 7.

We will tell you promptly if, in our opinion, an instruction infringes data protection law.

4. Sub-processors

You give us general authorization to engage sub-processors. We impose data protection terms on each that are no less protective than this DPA, and we remain liable to you for their performance. The current list is:

Sub-processorWhat it doesWhere it processes
Hetzner OnlineHosts the Service and stores its dataFinland (EU)
Amazon Web Services (SES)Delivers transactional email, such as sign-in codes and invitationsUnited States
CloudflareRuns the Turnstile challenge that protects sign-up and sign-inAs published by Cloudflare
Google, GitHubAuthenticate you, and only where a user chooses to sign in with them rather than with a passwordAs published by each provider

We will give at least 30 days' notice before adding or replacing a sub-processor, by updating this page and emailing account holders. If you reasonably object on data protection grounds within that period, tell us and we will work with you in good faith; if we cannot resolve it, you may terminate the affected part of the Service and we will refund any prepaid license fees for the unused remainder of the term.

5. Security

We implement technical and organizational measures appropriate to the risk, which today include:

  • encryption in transit for the console, the website, the API and database downloads;
  • hashed passwords, first-party session cookies that scripts cannot read, and optional multi-factor authentication;
  • access to production systems limited to those who need it, over authenticated channels;
  • API keys scoped to what each may do, which you can rotate and revoke at any time, and whose value is shown again only to a member permitted to reveal it, after re-authenticating;
  • a record of every download attempt, refusals included, readable by you in the console's download history;
  • logging of administrative actions against an account, readable by you in the console's audit log;
  • limits on repeated sign-in and second-factor attempts, and a bot challenge on sign-up and sign-in;
  • rate limiting and abuse controls on every public endpoint.

We may change these measures as the risk or the state of the art changes, provided we do not materially reduce the overall level of protection.

We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting your data, and provide the information you reasonably need to meet your own notification obligations. Our notice is not an admission of fault.

6. Retention, deletion and return

Records of download attempts are kept without a set deletion date, for support and abuse investigation, as section 8 of the Privacy Policy describes. Account information is kept for as long as you have an account, and for a limited period afterwards where we need it for legal, tax or accounting obligations or to resolve disputes.

On termination you may export your account data from the console. On your written request within 30 days of termination we will delete personal data processed on your behalf, except where law requires us to keep it, in which case we will keep it only for that purpose and for no longer than required.

7. Audits

On reasonable written notice, and no more than once in any twelve-month period unless a regulator requires otherwise or there has been a breach affecting your data, we will make available the information needed to demonstrate compliance with this DPA and respond to a reasonable written security questionnaire. Any on-site audit is at your cost, during business hours, subject to confidentiality, and must not disrupt the Service or compromise another customer's data.

8. International transfers

The Service is hosted in the European Union. Transactional email is delivered through a sub-processor in the United States, and the challenge and authentication sub-processors in section 4 may process outside the EEA and the UK. Where personal data leaves the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, and the UK Addendum where the UK GDPR applies, together with any supplementary measures the transfer requires. By entering into this DPA you agree that the Standard Contractual Clauses, module two (controller to processor), are incorporated by reference, with you as data exporter and us as data importer, with the optional docking clause applying, with option 2 of clause 9 and the notice period in section 4, with clause 11 having no independent dispute resolution body, and with Irish law and the Irish courts governing.

For the annexes to those clauses, the parties and their contact details are as set out in sections 1 and 11, the description of the transfer is section 2, and the technical and organizational measures are section 5.

9. Your obligations

You are the controller. You are responsible for having a lawful basis for the processing you instruct, for the accuracy and lawfulness of what you submit, for giving whatever notice your own data subjects are owed, and for not submitting special category data. You must not use the Service as the sole basis for a decision producing a legal or similarly significant effect on a person; our classifications are probabilistic, as section 2 of the Terms of Service sets out.

10. Liability, changes and law

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service.

We may update this DPA to reflect a change in law, in our sub-processors, or in how the Service works. Material changes are notified to account holders, and the "Last updated" date above shows the current version. This DPA is governed by the law stated in the Terms of Service, except that where the Standard Contractual Clauses apply they are governed as set out in section 8.

11. Contact

Data protection questions, audit requests and countersignature requests go to legal@internetdata.io. General support is the contact form. Our registered office is:

Mslm Dev
195-B Jasmine Block Sector C Bahria Town
Lahore, Punjab 53720, Pakistan