Data Processing Agreement
Last updated: September 5, 2026
On this page 11 sections
This Data Processing Agreement ("DPA") is part of our Terms of Service and applies whenever Parse API LLC, operating as ParseAPI, processes personal data on your behalf. It applies to every plan and to Bulk jobs, including one-time purchases. No separate signature is needed for this DPA. For a countersigned copy or transfer documents, email Email.
1. Definitions
"Personal data", "processing", "controller", "processor", and "data subject" have the meanings given in the EU General Data Protection Regulation (GDPR). Terms under other applicable privacy laws have the meanings given by those laws.
2. Roles
For personal data you send through the API and Bulk tools, you determine the purpose of the processing and we act as your processor. When you are a processor acting for a client, we act as your subprocessor. You are responsible for having the authority to submit the data and instruct us.
For your own account, billing, and site data, Parse API LLC is the controller as described in the Privacy Policy. That data is not covered by this DPA.
3. What we process
- Subject matter. Operating the ParseAPI lookup and validation services, including the API, bulk file jobs, and integrations.
- Nature and purpose. Receiving values you submit, returning results, and keeping operational logs so your dashboards and billing work.
- Categories of data. Values you submit, including IP addresses, email addresses, phone numbers, postal addresses, and names. Bulk jobs also include uploaded columns, sample data, and results. Request metadata includes the endpoint, timing, status, and parameters.
- Data subjects. Your users, customers, and contacts.
- Duration. For the requested service or job, plus the retention periods below. A one-time Bulk purchase does not require an account.
4. Our obligations
- We process personal data only to provide the service and follow your documented instructions. Using the service is the instruction.
- People with access to personal data are bound by confidentiality obligations.
- We apply the technical and organizational measures described on the Security page, including HTTPS encryption in transit, passwordless authentication, API key controls, and role-based team access.
- We assist you, as reasonably needed, with data subject requests, security assessments, and your own compliance obligations.
- We notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information we have at the time.
5. Subprocessors
You authorize us to use subprocessors to run the service. They only receive what their job requires and are bound by data protection terms at least as protective as this DPA. We remain responsible for their performance. Current categories:
- Hosting and infrastructure providers
- Database and logging providers for API usage
- File storage and processing providers for Bulk jobs
- Lookup and verification providers that receive values needed to answer your request
- Email delivery providers for job notices and results links
For customers covered by this DPA, we provide the identities, roles, and processing locations of subprocessors handling personal data on their behalf. We provide and keep this information current as required by applicable data protection law, sharing it privately for data protection review.
Where applicable data protection law requires notice under this general authorization, we will notify you of intended additions or replacements before they process your data and give you an opportunity to object. This includes a change within an existing category. If we cannot resolve an objection on reasonable data protection grounds, you may cancel the affected service.
Providers handling our own account and billing records are described in the Privacy Policy.
6. Data subject requests
If a data subject contacts us directly about data we process for you, we will refer them to you and will not respond on your behalf beyond that, except where the law requires us to.
7. Audits
We make information reasonably necessary to demonstrate compliance available on request, including answers to security questionnaires and this documentation. Where the GDPR grants you an audit right that this does not satisfy, an audit may be conducted once per year, at your expense, on reasonable notice, under confidentiality, and without access to other customers' data. This limit does not restrict additional audits required by applicable law or a competent regulator.
8. International transfers
We process data in the United States and other countries where our providers operate. Where the EU Standard Contractual Clauses are the applicable transfer mechanism, the clauses adopted in Commission Implementing Decision (EU) 2021/914 are incorporated by reference, with you as data exporter and Parse API LLC as importer. Module two applies when you are a controller. Module three applies when you are a processor. For UK transfers relying on these clauses, the UK Addendum applies.
The applicable selections, party details, transfer descriptions, security measures, and UK Addendum tables must be completed for the relevant transfer. Contact Email to arrange these documents before using the service for a transfer that requires them.
9. Retention and deletion
Our retention commitments for personal data processed on your behalf are set out below. The Privacy Policy separately describes current storage and download access. Expiry of a download link is not deletion of every associated record, and storage settings do not extend the deadlines we owe under this agreement.
- Request logs are kept for a limited operational window (weeks to a few months) and then dropped or aggregated, as described in the Privacy Policy.
- Bulk job files and results delete 30 days after the job completes.
- When your account closes, we delete or anonymize personal data we process on your behalf within 90 days, except records we must keep for legal or billing reasons.
- Where applicable law requires your choice of return or deletion at the end of processing, we follow that choice, subject to required legal retention.
10. Liability and precedence
Liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms on data protection matters, this DPA wins. If it conflicts with the Standard Contractual Clauses, the Clauses win.
11. Changes
We may update this DPA to reflect new laws or service changes. The date at the top changes when we do. Material changes will not reduce the protections here.
Part of the Terms of Service. Questions or a countersigned copy: Email