Data Processing Agreement
Last updated: September 21, 2026
This Data Processing Agreement ("DPA") applies when WebDecoy LLC processes personal data on your behalf. It forms part of our Terms of Service.
To execute it: email [email protected] with your legal entity name and the address for notices. We countersign and return a PDF. If your procurement process requires your own DPA template, send it and we will review it.
1. Roles
For personal data about visitors to your websites and applications, you are the controller and WebDecoy LLC is the processor. You decide to deploy WebDecoy, which pages it runs on and what happens to a detection.
For personal data about your account, meaning the people who sign in to the dashboard and the billing contact, WebDecoy LLC is a controller in its own right, and our Privacy Policy governs it.
2. What we process, and for whom
Data subjects: visitors to your sites, human and automated.
Categories of personal data:
- IP address, and the network operator and approximate location derived from it
- User agent, request headers, requested URL and referring page
- TLS handshake characteristics, recorded as a fingerprint
- Browser and device characteristics, including rendering behaviour, screen properties, timezone and language, recorded as a fingerprint
- Interaction signals such as mouse movement, scrolling, typing rhythm and timing, collected to tell automation from a person. We do not record the characters typed
- A persistent identifier that links repeat visits from the same automated client across IP addresses
Special category data: none is requested and none is required. Do not deploy WebDecoy on pages where the URL itself reveals special category data, such as a path naming a medical condition.
Purpose: detecting and classifying automated traffic, and applying the responses you configure.
3. What we store, and what we discard
The distinction below is the most important thing in this document, and it is how the product is built rather than a policy we apply afterwards.
- Requests are evaluated in memory. Every request to a protected page is assessed using the signals in section 2.
- Only automated traffic is stored. When a request is judged to be a legitimate human visitor, no detection record, no identity record and no enrichment is written. The verdict is returned and the signals are discarded.
- Human traffic leaves only a counter. Sites report an aggregate count so you can see the sensor is alive. It contains no personal data.
Service logs at our hosting providers record IP addresses in the ordinary course, as with any web service, and are retained under those providers' log retention.
4. Retention
| Data | Retention |
|---|---|
| Detection detail on Free plans, and on expired or cancelled subscriptions | Deleted 8 days after collection, leaving only daily counts |
| Detection detail on paid plans | Retained for the life of the subscription, then deleted under section 10 |
| Daily counts, which contain no personal data | Retained indefinitely |
| IP reputation lookups | Cached 24 hours |
You can request deletion of anything above at any time under section 8, without waiting for the end of your subscription.
5. Our commitments
- We process personal data only to provide the service and on your documented instructions, which include your configuration choices in the product.
- We do not sell personal data, do not share it for advertising, and do not use your visitors' data to build products for other customers.
- Anyone with access to personal data is bound by confidentiality.
- We tell you if an instruction appears to breach applicable data protection law.
6. Security
The measures we actually apply:
- Encryption in transit everywhere, with TLS required on every endpoint that receives detection data.
- Storage encrypted at rest by our infrastructure providers.
- Access to production systems and data limited to the personnel who need it.
- Customer data separated by organization, with every request checked against the organization that owns the record.
- Secrets held in the deployment platform rather than in source control.
- Dependency and code scanning in continuous integration, and a test suite that must pass before a deploy.
What we do not claim: WebDecoy LLC does not hold SOC 2 or ISO 27001 certification and has not been independently audited. We would rather say so than imply otherwise in a procurement questionnaire.
7. Subprocessors
Our current subprocessors are listed at webdecoy.com/subprocessors, with what each one does and what data reaches it.
You authorise the use of those subprocessors. Ask to join the notification list and we will tell you at least 30 days before adding a new one that processes visitor personal data, so you have time to object. If you object on reasonable data protection grounds and we cannot offer an alternative, you may terminate the affected service and receive a refund of prepaid fees for the unused term.
Each subprocessor is bound by terms no less protective than this DPA, and we remain responsible for their performance.
8. Helping you answer your users
If one of your visitors exercises a right of access, deletion or objection, we help you answer it:
- Access and portability. Export detection records as CSV or JSON, filtered by IP address or by actor, from the dashboard or the API.
- Deletion. Email [email protected] with the identifier. We delete the matching records and confirm within 30 days, at no charge.
- Objection and restriction. We can stop collection for a property immediately on request.
If a visitor contacts us directly, we refer them to you and tell you, rather than acting on our own.
9. Security incidents
If we become aware of a breach of security leading to accidental or unlawful destruction, loss, alteration or unauthorised disclosure of personal data we process for you, we notify you without undue delay and in any case within 48 hours of confirming it. The notice describes what we know, which data and roughly how many records are affected, what we have done, and what we recommend you do. We do not wait for a complete picture before telling you.
10. Deletion at the end
When your subscription ends, your account moves to the Free plan and detection detail is deleted after 8 days, as in section 4.
If you ask us to delete everything, we delete your organization and all personal data associated with it within 30 days, and confirm in writing. Aggregate counts that contain no personal data may be retained. We may also retain what law requires us to keep, such as billing records.
11. Audits
On request, once a year, we provide the information reasonably needed to demonstrate compliance with this DPA, including a completed security questionnaire and a description of our measures. Given the size of the company we do not host on-site audits, and we will tell you that up front rather than agreeing to something we cannot deliver.
12. International transfers
WebDecoy LLC is based in the United States and processes data there. Our edge components run on content delivery networks with points of presence worldwide, so a visitor's request may be evaluated in the region closest to them before any record reaches the United States.
For personal data transferred from the European Economic Area, the United Kingdom or Switzerland, the European Commission's Standard Contractual Clauses (Module Two, controller to processor) are incorporated into this DPA by reference, with the UK International Data Transfer Addendum applying to UK transfers. For the purposes of the Clauses: you are the data exporter, WebDecoy LLC is the data importer, sections 2 and 4 of this DPA describe the processing, section 6 describes the technical and organisational measures, and the governing law and forum are those in the Clauses.
13. California and other US state laws
Where the CCPA applies, WebDecoy LLC acts as a service provider. We do not sell or share personal information as those terms are defined, do not retain, use or disclose it for any purpose other than performing the service, and do not combine it with personal information from other sources except as permitted. The same commitments apply under comparable state laws.
14. Order of precedence
If this DPA conflicts with the Terms of Service on the processing of personal data, this DPA governs. If the Standard Contractual Clauses conflict with this DPA, the Clauses govern.
15. Contact
- Privacy and data subject requests: [email protected]
- Signing and contract questions: [email protected]
- WebDecoy LLC, a Texas limited liability company, Austin, Texas, United States