Data Processing Addendum (DPA)
Last updated: September 1, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Shanghai Keshan Technology Co., Ltd. ("ApiSorcery", "we", "Processor") and the customer ("Customer", "Controller") that has accepted the Terms of Service or entered into a separate written agreement with us (together, the "Agreement") for the provision of the ApiSorcery service (the "Service").
It reflects the parties' agreement on the processing of Personal Data in connection with the EU General Data Protection Regulation (Regulation 2016/679, "GDPR"), the UK GDPR, and equivalent data protection laws. It is designed to satisfy the requirements of Article 28 GDPR.
If Customer requires a signed counterpart, please email support@apisorcery.com with the request. Otherwise, this DPA is deemed accepted upon acceptance of the Agreement.
1. Definitions
Terms not defined in this DPA have the meaning given in the GDPR. In particular:
- "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Supervisory Authority" have the meanings in Article 4 GDPR.
- "Sub-processor" means any Processor engaged by ApiSorcery to Process Personal Data on behalf of Customer.
2. Roles and Scope
- Customer is the Controller and ApiSorcery is the Processor of Personal Data submitted to the Service by Customer or its authorized users.
- ApiSorcery processes Personal Data only to provide, secure, support, and improve the Service, and to comply with legal obligations, in each case as documented in the Agreement and Customer's instructions.
3. Nature and Purpose of Processing
| Item | Description |
|---|---|
| Subject matter | Provision of the ApiSorcery API-client code generation service |
| Duration | For the term of the Agreement and thereafter as required by law or as stated in Section 10 |
| Purpose | Account authentication, code generation, usage metering, billing, support, security |
| Types of Personal Data | Account identifiers (email, username), authentication metadata, IP address, device fingerprint, usage logs, billing metadata (handled by Paddle) |
| Categories of Data Subjects | Customer's employees, contractors, or other authorized users of the Service |
We do not process special categories of Personal Data (Article 9 GDPR) or data relating to criminal convictions, and Customer agrees not to submit such data to the Service.
4. Customer Instructions
ApiSorcery will Process Personal Data only on documented instructions from Customer, which are set out in the Agreement, this DPA, and Customer's use of the Service's configuration options. If we believe an instruction violates data protection law, we will inform Customer.
5. Confidentiality
Personnel authorized to Process Personal Data are bound by written confidentiality obligations and receive appropriate data protection training.
6. Security Measures (Article 32 GDPR)
We implement appropriate technical and organizational measures, including:
- Encryption of data in transit (TLS 1.2+) and at rest for stored databases and backups
- Role-based access control and least-privilege principles for internal systems
- Multi-factor authentication for administrative access
- Network isolation, firewalling, and DDoS protection at the infrastructure boundary
- Application-level rate limiting (see Terms of Service)
- Logging, monitoring, and alerting for security-relevant events
- Regular patching of underlying operating systems and libraries
- Encrypted, off-site backups with periodic restore testing
- Incident response procedures with escalation to the responsible party
- Secure software development practices and code review
Measures are reviewed periodically and updated to reflect current risks and industry standards.
7. Sub-processors
Customer authorizes ApiSorcery to engage Sub-processors to help provide the Service.
Current Sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Paddle.com Market Limited | Payment processing and merchant-of-record services | Ireland (EU) / UK |
| Cloud hosting provider (primary) | Compute, storage, networking for the Service | Multiple regions |
| Email delivery provider | Transactional and account emails | EU / US |
| Error monitoring provider | Aggregated error and performance telemetry | EU / US |
An up-to-date list is maintained on this page. We will notify Customer of any new or replacement Sub-processor by updating this page or by email at least 30 days in advance for material changes. Customer may reasonably object to a proposed Sub-processor on data protection grounds by writing to support@apisorcery.com; the parties will work in good faith to resolve the objection.
We enter into written agreements with each Sub-processor imposing data protection obligations no less protective than those in this DPA, as required by Article 28(4) GDPR. ApiSorcery remains liable for Sub-processor performance.
8. Data Subject Rights
Taking into account the nature of the Processing, we will assist Customer, insofar as reasonably possible, in fulfilling requests from Data Subjects under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection).
If we receive a Data Subject request directly, we will forward it to Customer without undue delay and will not respond to the request ourselves except on Customer's documented instruction or as required by law.
9. Personal Data Breach
We will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer's Personal Data, providing all information reasonably required for Customer to meet its own notification obligations under Article 33 GDPR.
Notifications will be sent to the email address on Customer's account. Customer is responsible for keeping that address current.
10. Return or Deletion of Personal Data
Upon termination of the Agreement, we will, at Customer's choice, return or delete Personal Data within a reasonable period, unless retention is required by law. Backups are overwritten on a rolling basis and expire within 90 days.
Customer may request deletion of the account and associated Personal Data at any time by emailing support@apisorcery.com.
11. Audits
We will make available to Customer, upon written request, information reasonably necessary to demonstrate compliance with this DPA, including summaries of applicable third-party audit reports (SOC 2, ISO 27001, or equivalent) where available.
Where Customer's regulator (or Customer itself, acting reasonably) requires an audit, the parties will agree in advance on scope, timing, and reasonable cost allocation. Audits must not unreasonably interfere with our operations and must respect the confidentiality of other customers' data.
12. International Transfers
Where Personal Data is transferred outside the European Economic Area, United Kingdom, or Switzerland to a country without an adequacy decision, the transfer is safeguarded by:
- Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914), incorporated by reference into this DPA where applicable, and
- Supplementary technical, contractual, and organizational measures where necessary based on a transfer impact assessment.
The UK International Data Transfer Addendum applies for transfers subject to the UK GDPR.
13. Order of Precedence
In the event of a conflict, this DPA prevails over other terms of the Agreement with respect to the Processing of Personal Data.
14. Governing Law and Jurisdiction
This DPA is governed by the same law and subject to the same jurisdiction as the Agreement, unless otherwise required by mandatory law.
15. Contact
- Data protection / DPA inquiries: support@apisorcery.com
- Legal entity: Shanghai Keshan Technology Co., Ltd.
- Registered address: Room A-522, No.188 Yesheng Road, Lingang New Area of China (Shanghai) Pilot Free Trade Zone, P.R.China
- Unified Social Credit Code: 91310000MAKA7YETXH