Data Processing Agreement (DPA)

Last Update: 18th July 2026

This document is an Art. 28 GDPR / Art. 28 DSGVO data processing agreement (Auftragsverarbeitungsvertrag) for use of the ipapi.is API.


Controller (Verantwortlicher): The Customer — the entity that submits Query Data (e.g. visitor IP addresses) to the ipapi.is API and determines the purposes and means of that processing.
Processor (Auftragsverarbeiter): ipapi.is (Nikolai Tschacher), which processes Query Data solely on behalf of and under the documented instructions of the Controller.

Important: For API Query Data, the roles are not reversed. The Customer is always the Controller. ipapi.is is always the Processor. This DPA replaces any earlier public draft that incorrectly listed ipapi.is as Controller for Query Data.

1. Purpose

This Data Processing Agreement ("DPA") sets forth the terms under which ipapi.is, acting as Processor (Auftragsverarbeiter), processes Personal Data on behalf of the Customer, acting as Controller (Verantwortlicher), in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR / DSGVO), in particular Article 28.

Typical Customer use covered by this DPA includes looking up visitor IP addresses via the API in order to enrich them with company / network information for the Customer's own purposes (e.g. website analytics or B2B attribution).

2. Definitions

"Personal Data": Any information related to an identified or identifiable individual, processed by the Processor on behalf of the Controller.

"Processing": Any operation or set of operations performed on Personal Data.

"Query Data": Personal Data (in particular IP addresses) submitted by the Customer to the ipapi.is API for lookup and enrichment.

"Controller" or "Data Controller" (Verantwortlicher): means the Customer, which determines the purposes and means of the processing of Personal Data, specifically including all data submitted via API requests ("Query Data").

"Processor" or "Data Processor" (Auftragsverarbeiter): means ipapi.is, which processes Query Data solely on behalf of and under the instructions of the Controller.

Allocation of roles: With respect to Query Data submitted through the API, the Customer is the Controller and ipapi.is is the Processor. With respect to account registration and billing data described in Section 3 (e.g. email address, client IP address used to access the account, and optional company name), ipapi.is acts as an independent Controller for its own business and legal purposes. Those account / billing processing activities are outside the scope of this Art. 28 processing on behalf of the Customer, except where this DPA expressly refers to them for clarity.

3. Processing Details

Subject matter: Provision of the ipapi.is IP intelligence API.

Nature of Processing: Receiving an IP address (or related query parameters) from the Customer, looking it up against ipapi.is databases, and returning the associated enrichment result to the Customer in real time.

Purpose of Processing: To provide the contracted API service solely on the Controller's documented instructions (API calls constitute such instructions).

Duration: Processing of each query occurs in real time for as long as needed to return the API response. ipapi.is does not store, log, or retain the specific IP addresses queried by the Customer (Query Data). No persistent copy of Query Data is kept after the response has been delivered.

Type of Personal Data (Query Data): IP addresses (and any related identifiers the Customer chooses to send in the API request) submitted for lookup.

Categories of Data Subjects (Query Data): Typically visitors or users of the Customer's websites, applications, or services whose IP addresses the Customer looks up. Because Query Data is not logged or retained by ipapi.is, ipapi.is cannot identify those data subjects from its own systems after the request has completed.

Usage / billing metadata (not Query Data): ipapi.is logs aggregated usage data for billing and abuse prevention (e.g. API key, request counts, timestamps). That usage data does not include the specific IP addresses queried by the Customer.

Account data (ipapi.is as independent Controller): When creating an account, the following data may be stored by ipapi.is for its own purposes:

  • Email address or Google/GitHub OAuth information.
  • Client IP address used to access the account / website, and associated metadata.
  • Company name, if provided by the user (optional).
  • Billing and payment-related information as needed to provide and invoice the service.

4. Processor Obligations

Documented instructions: The Processor will process Query Data only in accordance with this DPA and the Controller's documented instructions. API requests made with a valid Customer API key are documented instructions to process the submitted Query Data for the purpose of returning the lookup result.

No storage of Query Data: The Processor shall not store, archive, or otherwise retain specific IP addresses (or other Query Data) submitted by the Controller beyond the transient processing required to generate and return the API response, except where required by mandatory law (in which case the Processor will, where legally permitted, inform the Controller).

Data Security: Processor will implement appropriate technical and organizational measures to protect Personal Data against unauthorized access, alteration, disclosure, or destruction.

Confidentiality: Processor ensures that personnel authorized to process the data are bound by confidentiality obligations.

Sub-processors (Query Data): For hosting and operation of the API infrastructure that may process Query Data in transit, Processor engages:

  • Hetzner Online GmbH (Germany / EU) — server hosting.
  • OVHcloud (EU) — server hosting.
Customers who require processing exclusively in Germany may use the de.ipapi.is endpoint, which is operated on infrastructure located in Germany.

Other service providers (not Query Data processors): The following providers support the website, DNS, authentication, or analytics and are not engaged to process Customer Query Data for API lookups:

  • Microsoft Azure: DNS services.
  • Google Analytics: Website traffic analysis only.
  • Google / GitHub OAuth: Optional account authentication.

Data Breach Notification: Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Query Data processed under this DPA.

Assistance: Processor will assist the Controller, taking into account the nature of the processing (real-time lookup without retention of Query Data), in responding to data subject requests and fulfilling Controller obligations under applicable data protection law, insofar as this is possible given that Query Data is not retained.

5. Controller Obligations

Lawful Basis: The Controller warrants that it has a lawful basis for collecting and processing the Personal Data (including visitor IP addresses) that it submits to the Processor, and that its instructions are lawful.

Accuracy of instructions: The Controller is responsible for the content of the API requests it sends and for not instructing the Processor to process Personal Data in violation of data protection law.

6. Data Transfers

No transfers of Query Data outside the EEA: The Processor shall not transfer Query Data (including queried IP addresses) outside the European Economic Area (EEA). API Query Data is processed on infrastructure located in the EEA. Where the Customer uses the de.ipapi.is endpoint, processing takes place on infrastructure located in Germany.

If a future change would require a transfer of Query Data outside the EEA, the Processor will not carry out such a transfer unless authorized by the Controller and the transfer complies with Chapter V GDPR (e.g. adequacy decision or appropriate safeguards).

7. Data Subject Rights

Because ipapi.is does not log or retain specific IP address Query Data, it is not possible for ipapi.is to identify data subjects from Query Data after a request has completed, or to provide access, rectification, or erasure of those query contents from Processor systems. The Controller remains responsible for handling data subject rights in respect of Personal Data that the Controller itself stores (e.g. truncated visitor IPs retained in the Controller's own systems).

For account-related data held by ipapi.is as independent Controller (email, account access IP, company name), data subjects may exercise their rights directly against ipapi.is in accordance with applicable data protection laws.

8. Data Retention and Deletion

Query Data: ipapi.is does not store specific IP address query data. Queried IP addresses are processed transiently to produce the API response and are then discarded; they are not written to persistent logs or databases.

Usage / billing metadata: Retained solely for billing, accounting, and abuse prevention, and deleted in accordance with accounting regulations and legal obligations. This metadata does not contain the specific IP addresses queried.

Account-related data: Retained as long as the account is active and deleted upon account termination or at the user's request, unless retention is required by law.

9. Audit and Compliance

Processor will provide reasonable assistance to the Controller in demonstrating compliance with this DPA and allow for audits or inspections by the Controller or a mandated auditor, subject to reasonable notice, confidentiality, and protection of other customers' data and Processor trade secrets. Remote audits / written questionnaires are preferred where they are sufficient.

10. Term and Termination

This DPA applies for as long as the Processor processes Query Data on behalf of the Controller in connection with the ipapi.is API. Upon termination of the API service relationship, the Processor will not retain Query Data (consistent with Sections 3 and 8, Query Data is not stored). Certification of deletion of any residual Personal Data processed under this DPA will be provided upon reasonable request where applicable.

11. Governing Law

This DPA is governed by and shall be construed in accordance with the laws of the Federal Republic of Germany. Mandatory provisions of the GDPR remain unaffected.

12. Acceptance / Counter-signature

By creating an ipapi.is account and using the API, or by countersigning this DPA (including electronically), the Customer accepts this DPA as the Art. 28 agreement between the parties for Query Data. Upon request, ipapi.is will provide a countersigned copy (PDF or electronic) for the Customer's records. Contact: info@ipapi.is.

Processor (Auftragsverarbeiter)
ipapi.is / Nikolai Tschacher
Email: info@ipapi.is
Website: https://ipapi.is

Date: _______________________

Signature: _______________________

Controller (Verantwortlicher)
Customer / contracting entity
Company: _______________________
Address: _______________________
Email: _______________________

Date: _______________________

Signature: _______________________