Data Processing Agreement
Last updated 29 July 2026
01 — When this applies
If your engagement involves us processing personal data on your behalf — for example, within a system we build or maintain for you — a signed Data Processing Agreement is available on request. This page summarizes what it covers; the signed document takes precedence for any client engagement.
02 — Roles
For work covered by a DPA, you act as the data controller and Oxlabs acts as the data processor, processing personal data only on your documented instructions and only for the purposes of delivering the agreed engagement.
03 — Data we may process
Only the categories of personal data necessary for the specific system we're building or maintaining — as defined in your engagement's scope of work. We do not use client-controlled personal data for any purpose outside that engagement, including model training or evaluation.
04 — Subprocessors
Where a subprocessor (such as a hosting or infrastructure provider) is required, it will be named in your signed DPA along with its role. We will notify you of any change in subprocessors with reasonable advance notice.
05 — Security measures
Processing is governed by the access controls and practices described on our Security page, including scoped access, encrypted credential storage, and time-boxed permissions tied to the engagement.
06 — International transfers
Where personal data is transferred outside your jurisdiction as part of an engagement, the signed DPA will specify the safeguards in place, consistent with applicable data protection law.
07 — Requesting a signed DPA
To request a signed Data Processing Agreement for your engagement, write to [email protected]. We'll typically return a draft within two business days.
08 — Contact
Oxlabs, Bay Square, Business Bay, Dubai, United Arab Emirates. Written enquiries to [email protected].