Data Processing Agreement (DPA)
Last Update: 11th September 2026
This document is an Art. 28 GDPR / Art. 28 DSGVO data processing agreement (Auftragsverarbeitungsvertrag) for use of the ipapi.is API.
Controller (Verantwortlicher): The Customer — the entity that
submits Query Data (e.g. visitor IP addresses) to the ipapi.is API and determines the
purposes and means of that processing.
Processor (Auftragsverarbeiter): Nikolai Tschacher, trading as
ipapi.is, Berlin, Germany (VAT ID DE325806975), who processes Query Data solely on
behalf of and under the documented instructions of the Controller.
1. Purpose
This Data Processing Agreement ("DPA") sets forth the terms under which ipapi.is, acting as Processor (Auftragsverarbeiter), processes Personal Data on behalf of the Customer, acting as Controller (Verantwortlicher), in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR / DSGVO), in particular Article 28. It supplements the ipapi.is Terms of Service; where the two conflict on the processing of Personal Data, this DPA prevails.
Typical Customer use covered by this DPA includes looking up visitor IP addresses via the API in order to enrich them with company / network information for the Customer's own purposes (e.g. website analytics, fraud prevention or B2B attribution).
2. Definitions
"Personal Data": Any information related to an identified or identifiable individual, processed by the Processor on behalf of the Controller.
"Processing": Any operation or set of operations performed on Personal Data.
"Query Data": Personal Data (in particular IP addresses) submitted by the Customer to the ipapi.is API for lookup and enrichment.
"Controller" (Verantwortlicher): the Customer, which determines the purposes and means of the processing of Query Data.
"Processor" (Auftragsverarbeiter): ipapi.is, which processes Query Data solely on behalf of and under the instructions of the Controller.
Allocation of roles: For Query Data submitted through the API, the Customer is always the Controller and ipapi.is is always the Processor. For account registration and billing data described in Section 3 (e.g. email address, client IP address used to access the account, optional company name), ipapi.is acts as an independent Controller for its own business and legal purposes; that processing is governed by the Privacy Policy and is outside the scope of this DPA except where expressly referred to for clarity.
3. Processing Details
Subject matter: Provision of the ipapi.is IP intelligence API.
Nature of Processing: Receiving an IP address (or related query parameters) from the Customer, looking it up against ipapi.is databases, and returning the associated enrichment result to the Customer in real time.
Purpose of Processing: To provide the contracted API service solely on the Controller's documented instructions (API calls constitute such instructions).
Duration: Processing of each query occurs in real time for as long as needed to return the API response. ipapi.is does not store, log, or retain the specific IP addresses queried by the Customer (Query Data). No persistent copy of Query Data is kept after the response has been delivered.
Type of Personal Data (Query Data): IP addresses (and any related identifiers the Customer chooses to send in the API request) submitted for lookup.
Categories of Data Subjects (Query Data): Typically visitors or users of the Customer's websites, applications, or services whose IP addresses the Customer looks up. Because Query Data is not logged or retained by ipapi.is, ipapi.is cannot identify those data subjects from its own systems after the request has completed.
Usage metadata (not Query Data): ipapi.is records usage data for billing, rate limiting and abuse prevention: API key, IP address of the calling system, request type and count, timestamps and User-Agent. This usage data does not include the addresses queried by the Customer.
Account data (ipapi.is as independent Controller): When creating an account, the following data may be stored by ipapi.is for its own purposes:
- Email address or Google/GitHub OAuth information.
- Client IP address used to access the account / website, and associated metadata.
- Company name, if provided by the user (optional).
- Billing and payment-related information as needed to provide and invoice the service.
4. Processor Obligations
Documented instructions: The Processor will process Query Data only in accordance with this DPA and the Controller's documented instructions. API requests made with a valid Customer API key are documented instructions to process the submitted Query Data for the purpose of returning the lookup result; the endpoint the Controller sends them to is its instruction on the processing location (Section 6). The Processor will inform the Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other data protection law.
No storage of Query Data: The Processor shall not store, archive, or otherwise retain specific IP addresses (or other Query Data) submitted by the Controller beyond the transient processing required to generate and return the API response, except where required by mandatory law (in which case the Processor will, where legally permitted, inform the Controller).
Data Security: The Processor implements appropriate technical and organisational measures in accordance with Art. 32 GDPR to protect Personal Data against unauthorised access, alteration, disclosure, or destruction. The measures currently in place are described in Annex 1.
Confidentiality: The Processor ensures that any person authorised to process Personal Data is bound by confidentiality obligations.
Sub-processor (Query Data): The Processor engages Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, for hosting of the API servers (server locations in Section 6). The Controller grants general authorisation for this sub-processor. The Processor has concluded an Art. 28 agreement with the sub-processor imposing the same data protection obligations as this DPA and remains fully liable to the Controller for the sub-processor's performance. The Processor will announce any intended addition or replacement of a sub-processor on this page and by email to the Customer's account address at least 30 days in advance. The Controller may object within that period on reasonable data protection grounds; if no solution is found, either party may terminate the affected service.
Other service providers (not Query Data processors): The following providers support the website, DNS, login, email or payments and never receive Query Data:
- Microsoft Azure: DNS and Traffic Manager routing for
api.ipapi.is. Sees DNS resolver addresses only, never API requests. - Google / GitHub: Optional OAuth account login.
- Google Workspace: Transactional and support email.
- Stripe / PayPal: Payment processing.
Data Breach Notification: The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Query Data processed under this DPA.
Assistance: The Processor will assist the Controller in responding to data subject requests and in meeting its obligations under Art. 32–36 GDPR (security, breach notification, data protection impact assessments, prior consultation), taking into account the nature of the processing and the information available to the Processor. Because Query Data is not retained, assistance regarding individual queries is limited to information about the processing itself.
5. Controller Obligations
Lawful Basis: The Controller warrants that it has a lawful basis for collecting and processing the Personal Data (including visitor IP addresses) that it submits to the Processor, and that its instructions are lawful.
Accuracy of instructions: The Controller is responsible for the content of the API requests it sends, for choosing an endpoint consistent with its location requirements (Section 6), and for not instructing the Processor to process Personal Data in violation of data protection law.
6. Processing Locations and Data Transfers
Locations: The API is served from data centres of Hetzner Online GmbH
in Falkenstein and Nuremberg (Germany), Ashburn (USA) and Singapore. Requests to
api.ipapi.is are answered by the location with the lowest network latency
to the calling system (DNS-based routing). A system in the EU is therefore normally
served from Germany; during an outage of a location, requests may be answered by another
location.
EEA-only processing: Controllers who require that Query Data is
processed exclusively within the EEA shall send their requests to
de.ipapi.is (Falkenstein) or go-ba-de.ipapi.is (Nuremberg).
These endpoints are served from Germany only and never fail over to another country.
By sending requests to api.ipapi.is instead, the Controller instructs the
Processor to process Query Data at the nearest location, which may be the USA or
Singapore.
Third-country locations: The US and Singapore servers are operated by Hetzner Online GmbH, a German company bound to the Processor under an Art. 28 agreement; Query Data is processed there only transiently as described in Section 3 and is never stored. Beyond this, the Processor will not transfer Query Data to a third country unless instructed by the Controller and the requirements of Chapter V GDPR are met.
7. Data Subject Rights
Because ipapi.is does not log or retain Query Data, it is not possible for ipapi.is to identify data subjects from Query Data after a request has completed, or to provide access, rectification, or erasure of those query contents from Processor systems. The Controller remains responsible for handling data subject rights in respect of Personal Data that the Controller itself stores (e.g. visitor IP addresses retained in the Controller's own systems). The Processor will forward any request it receives that identifiably concerns the Controller's processing.
For account-related data held by ipapi.is as independent Controller (email, account access IP, company name), data subjects may exercise their rights directly against ipapi.is in accordance with applicable data protection laws.
8. Data Retention and Deletion
Query Data: ipapi.is does not store Query Data. Queried IP addresses are processed transiently to produce the API response and are then discarded; they are not written to persistent logs, databases or backups.
Usage metadata: Retained solely for billing, accounting, rate limiting and abuse prevention, and deleted in accordance with accounting regulations and legal obligations. This metadata does not contain the addresses queried.
Account-related data: Retained as long as the account is active and deleted upon account termination or at the user's request, unless retention is required by law.
9. Audit and Compliance
The Processor will make available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR and this DPA, and allow for audits or inspections by the Controller or a mandated auditor, subject to reasonable notice (at least 30 days, except after a personal data breach), confidentiality, and protection of other customers' data and Processor trade secrets. Written questionnaires and remote audits are preferred where they are sufficient.
10. Term and Termination
This DPA applies for as long as the Processor processes Query Data on behalf of the Controller in connection with the ipapi.is API. Upon termination of the API service relationship, the Processor will not retain Query Data (consistent with Sections 3 and 8, Query Data is not stored). Certification of deletion of any residual Personal Data processed under this DPA will be provided upon reasonable request where applicable.
11. Liability and Governing Law
Liability is governed by the ipapi.is Terms of Service; Art. 82 GDPR remains unaffected. This DPA is governed by the laws of the Federal Republic of Germany; mandatory provisions of the GDPR remain unaffected. Place of jurisdiction is Berlin, where permitted.
12. Acceptance / Counter-signature
By creating an ipapi.is account and using the API, or by countersigning this DPA (including electronically), the Customer accepts this DPA as the Art. 28 agreement between the parties for Query Data. Upon request, ipapi.is will provide a countersigned copy (PDF or electronic) for the Customer's records. Contact: info@ipapi.is.
Processor (Auftragsverarbeiter)
Nikolai Tschacher (ipapi.is)
Berlin, Germany
VAT ID DE325806975
Email: info@ipapi.is
Website: https://ipapi.is
Date: _______________________
Signature: _______________________
Controller (Verantwortlicher)
Company: _______________________
Address: _______________________
Email: _______________________
Name / title: _______________________
Date: _______________________
Signature: _______________________
Annex 1 — Technical and Organisational Measures (Art. 32 GDPR)
- Transport encryption: All named API endpoints enforce TLS 1.2 or 1.3; plain HTTP requests to them are redirected to HTTPS.
- No persistence of Query Data: Lookups are answered from an in-memory database. Web-server access logging is disabled on the API servers, and queried addresses are not written to application logs, databases or backups.
- Access control: Server administration exclusively over SSH with key-based authentication. A default-deny firewall admits only API traffic and SSH; administrative endpoints are reachable only from the Processor's own servers.
- Separation: The API servers hold no customer account or payment data; they receive only API key validity and quota information. Account and billing data are kept on a separate server in Germany.
- Availability: Six servers in three regions with DNS-based health checks and failover, automatic operating system security updates, and a public status page at status.ipapi.is.
- Personnel: ipapi.is is operated by a single person; no third-party staff have access to the servers or account data.
- Incident handling: Breach notification to the Controller as set out in Section 4.