1.Parties
This Data Processing Agreement (“DPA”) forms part of the Bullion API Terms of Service between you (the Controller) and Bullion API(the Processor, “we”, “us”). It applies whenever you use Bullion API under a paid plan that includes this DPA (currently the Enterprise tier) or when you have otherwise agreed to it. Where this DPA conflicts with the Terms, this DPA prevails for the processing of personal data.
2.Definitions
Capitalised terms have the meaning given in the UK GDPR, except:
- “Personal Data”, “Processing”, “Controller”, “Processor”, “Sub-processor” and “Data Subject” have the meanings given in Article 4 UK GDPR.
- “UK GDPR” means the United Kingdom General Data Protection Regulation as defined in section 3(10) (and supplemented by section 205(4)) of the Data Protection Act 2018.
- “Services” means the Bullion API platform, API endpoints, and associated dashboard, provided to you under the Terms.
3.Scope and roles
You are the Controller of Personal Data you submit to the Services (account details, support correspondence, billing metadata). We are the Processor, processing that Personal Data on your documented instructions to provide, secure and bill the Services. This DPA covers all processing carried out by us under the Terms. The duration of processing, the nature and purpose, the types of Personal Data, and the categories of Data Subjects are described in the sections below.
4.Categories of Personal Data and Data Subjects
- Categories of Personal Data: name, email address, hashed password, hashed API keys, request metadata (timestamp, endpoint, response size, IP, user agent), billing address country as returned by Stripe, support correspondence.
- Categories of Data Subjects: your end-users who sign up to your account or contact support, and your named billing and technical contacts.
5.Purposes and instructions
We process Personal Data only for the purposes of (a) providing and authenticating the Services; (b) billing, invoicing and tax accounting; (c) enforcing per-plan quotas and detecting abuse; (d) diagnosing outages; (e) responding to support requests you send us; and (f) complying with legal obligations. We will not process Personal Data for our own purposes, train third-party models on it, or use it for advertising. You give us documented instructions by using the Services; any additional instruction must be agreed in writing.
6.Authorised sub-processors
We engage the following sub-processors. Each operates under a written agreement that imposes data-protection obligations no less protective than those in this DPA.
| Sub-processor | Purpose | Region |
|---|---|---|
| Cloudflare | Edge hosting and Workers compute for the API and website. | Global edge network; data may transit any region. |
| Neon | Serverless Postgres for accounts, API keys and request logs. | EU (Frankfurt) primary; US fallback. |
| Stripe | Payment processing and subscription management. Card data never touches our servers. | US and EU processing regions per Stripe configuration. |
| Twelve Data | Upstream gold and exchange-rate pricing. Receives symbols and time ranges, not account data. | US. |
| Plausible | Cookie-free aggregate website analytics. Receives page-view metadata, not account data. | EU. |
| Cloudflare Workers Email Service | Transactional email (verification, password reset, billing receipts, support replies). Sent through Cloudflare’s network as an integrated Worker binding. | Cloudflare’s email delivery infrastructure. |
7.Security measures (Article 32 UK GDPR)
- TLS 1.2+ in transit on every endpoint.
- At-rest encryption on Neon-managed Postgres volumes.
- API keys stored as SHA-256 hashes; plaintext shown once at creation only.
- Worker secrets for third-party credentials, never committed to source.
- Least-privilege access for personnel, logged and reviewed.
- Regular backup verification and recovery testing of the production database.
- An up-to-date vulnerability-management process for runtime dependencies.
8.Changes to sub-processors
We will give you at least 30 days’ notice by email before adding or replacing a sub-processor that handles Personal Data. You may object on reasonable data-protection grounds within that period; we will work with you in good faith to address the objection and, if we cannot, you may terminate the affected Services for termination-for-cause and receive a pro-rated refund.
9.Data Subject requests
We will assist you, by appropriate technical and organisational measures, in fulfilling Data Subject rights requests (access, rectification, erasure, restriction, portability, objection). If we receive a request directly from a Data Subject relating to Personal Data we process on your behalf, we will forward it to you without undue delay and not respond directly except to confirm receipt and identify you as the Controller.
10.Personal-data breaches
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting your Personal Data. The notification will describe the nature of the breach, categories and approximate number of Data Subjects and records affected, likely consequences, and the measures taken or proposed. We will assist you in meeting your obligations under Articles 33 and 34 UK GDPR.
11.Retention
We retain Personal Data only for as long as needed to provide the Services or to comply with legal obligations. Account rows, API keys and request logs are retained while your account is active. On account deletion, account data is erased within 30 days; billing records are retained for the statutory accounting period (six years in the UK). Support correspondence is retained for as long as we reasonably need it for the purpose for which it was sent.
12.Return and deletion at end of Services
On termination of the Services, we will, at your choice, delete or return all Personal Data processed under this DPA within 30 days, and delete any existing copies unless retention is required by law. Deletion is logged and a confirmation is provided on request.
13.Liability
Liability arising under or in connection with this DPA (including any non-contractual liability arising from it) is subject to the limitations and exclusions of liability set out in the Terms. Nothing in this DPA limits any liability that cannot be excluded by applicable data-protection law.
14.Governing law
This DPA is governed by the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales in relation to any dispute arising out of or in connection with it, without prejudice to either party’s right to seek interim or injunctive relief in any competent jurisdiction.