Data Processing Agreement
Last updated: June 18, 2026
-
Parties
- This Data Processing Agreement (“DPA”) forms part of the agreement entered into between UltraAPIs, a service operated by METE PRIM SRL (“Company”, “Processor”), acting as the Processor and you (“the Customer”, “Controller”), acting as the Controller. This DPA governs the processing of Personal Data by the Processor on behalf of the Customer in connection with the services provided and such Personal Data is subject to applicable Data Protection Laws including the General Data Protection Regulation (GDPR) and other applicable privacy regulations.
-
Definitions
- “Personal Data” refers to any information that identifies, or could reasonably be used to identify, a natural person, either directly or indirectly.
- “Processing” refers to any action or set of actions carried out on Personal Data, whether automated or manual, including activities such as collecting, recording, organizing, storing, modifying, retrieving, using, sharing, or deleting such information.
- “Data Subject” refers to the individual whose Personal Data is being processed.
- “Sub-processor” refers to any third-party service provider engaged by the Company to perform processing activities involving Personal Data on its behalf.
- “Data Breach” refers to any incident resulting in unauthorized access to, disclosure of, alteration of, loss of, or destruction of Personal Data.
-
Scope
- The Processor shall process Personal Data solely for the purpose of providing web data extraction services and related data infrastructure services to the Customer. Such processing may include automated web data retrieval, hosting and operation of scraping infrastructure, and the delivery of collected data through application programming interfaces (APIs) or similar technical interfaces.
-
Roles of the Parties
- The Customer acts as the Controller of Personal Data processed through the services. The Processor acts solely as a Processor and shall process Personal Data only on behalf of the Customer.
-
Processing Instructions
- The Processor acts solely as a technical infrastructure provider and processes Personal Data only on documented instructions from the Customer. Such instructions may be provided through the Customer’s use of the services, including API requests, scraping configurations, or platform settings that determine the scope and nature of the processing or other technical instructions through the services.
- The Customer is solely responsible for determining the purposes of processing, the target websites, scraping parameters, and data fields to be collected through the services. The Processor does not independently select data sources, determine the content of collected data, or assess whether such data contains Personal Data.
- The Processor has no obligation to monitor, review, or verify the legality of the Customer’s instructions or the content of the data retrieved through the services.
-
Customer Warranties and Compliance Obligations
- The Customer represents and warrants that all instructions provided to the Processor comply with applicable laws and regulations. The Customer further warrants that the collection of data is lawful, that the data sources are publicly accessible or otherwise legally accessible, and that the Customer has a valid legal basis for any processing of Personal Data conducted through the services.
- The Customer also represents that it complies with applicable website terms of service and that it will not instruct the Processor to perform any activity that violates applicable laws, infringes intellectual property rights, or bypasses authentication mechanisms or other access controls implemented by third-party systems.
- The Customer agrees to indemnify and hold the Processor harmless against any claims, damages, liabilities, or expenses arising from the Customer’s breach of these warranties or unlawful instructions.
-
Prohibited Data
- The Customer shall not instruct the Processor to collect, process, or store special categories of Personal Data or other sensitive data. This prohibition includes, but is not limited to, health data, biometric identifiers, criminal history information, and Personal Data relating to children.
-
Acceptable Use Restrictions
- The Customer shall not use the services in connection with activities that involve spam, harassment, discrimination, unlawful surveillance, identity theft, or political manipulation. The Processor reserves the right to suspend or terminate access to the services if the Customer engages in activities that violate these acceptable use requirements.
-
Technical and Organizational Measures
- The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. Such measures shall include, as appropriate, encryption of Personal Data, the implementation of access controls, and the ongoing monitoring of systems and processing activities. The Processor shall also ensure the ability to respond to incidents and to maintain the availability and resilience of processing systems through appropriate backup and recovery procedures.
-
Confidentiality
- The Processor shall ensure that any persons authorized to process Personal Data are bound by appropriate confidentiality obligations, whether contractual or statutory. Such persons shall process Personal Data only as necessary to provide the services and in accordance with the documented instructions of the Customer.
-
Subprocessors
- The Processor may engage third-party subprocessors to support the provision of the services, including providers of cloud infrastructure, content delivery networks, analytics services, and payment processing services. The Customer provides general authorization for the Processor to appoint such subprocessors as necessary for the delivery and operation of the services.
- The Processor shall ensure that any subprocessor is bound by written contractual obligations that provide a level of data protection and security equivalent to those set out in this DPA, including obligations relating to confidentiality, security measures, and the processing of Personal Data only on documented instructions.
- The Processor shall remain responsible for the subprocessor’s compliance with such obligations as required by applicable data protection laws.
-
Security Incidents
- In the event of a confirmed Personal Data breach affecting data processed on behalf of the Customer, the Processor shall notify the Customer without undue delay. Such notification shall include, to the extent reasonably available, information regarding the nature of the breach, the categories of affected data, and any measures taken or proposed to mitigate the effects of the incident.
-
Data Subject Requests
- The Processor shall provide reasonable assistance to the Customer in responding to requests from data subjects exercising their rights under applicable data protection laws. Such assistance may include support for requests for access, deletion, or restriction of processing relating to Personal Data processed through the services.
- The Processor shall provide reasonable assistance to the Customer in responding to inquiries or investigations from supervisory authorities relating to the processing of Personal Data under this Agreement, where such cooperation is required under applicable data protection laws.
-
Data Retention and Deletion
- Upon termination or expiration of the Agreement, the Customer may request that the Processor either return or delete Personal Data, unless retention of such data is required by applicable law or regulatory obligations.
-
Audit Rights
- Upon written request, the Processor shall make available reasonable documentation to demonstrate compliance with this DPA. Where required by applicable data protection law, the Customer may request an audit at their own cost and expense. In such cases, audits must be conducted with reasonable notice, during normal business hours, and in a manner that does not disrupt the Processor’s operations.
-
International Data Transfers
- If Personal Data is transferred outside the European Economic Area, such transfers will be carried out in accordance with applicable data protection laws and may rely on approved transfer mechanisms such as the Standard Contractual Clauses adopted by the European Commission where required.
-
Limitation of Liability
- The Processor shall not be responsible for determining the legality of data sources selected by the Customer, the legality of the Customer’s instructions, or the Customer’s downstream use of data obtained through the services. The Customer agrees to indemnify and hold the Processor harmless against claims arising from such matters.
-
Governing Law
- This Data Processing Agreement shall be governed by and interpreted in accordance with the laws of Moldova. Any disputes shall be resolved in the courts of Moldova.