BusinessProxy
1. Introduction and Acceptance
1.1. These BusinessProxy International Master Terms of Service, together with all schedules, addenda, policies, order forms, checkout terms, invoices and service-specific terms that expressly incorporate them, form a legally binding agreement between the applicable BusinessProxy contracting entity and the Customer.
1.2. The Agreement governs access to and use of the BusinessProxy controlled browser access service, browser extension, web dashboard, proxy gateway, policy engine, filtering functionality, audit logs, support channels, documentation, APIs, Private App Access functionality, beta features and related services.
1.3. These Terms are drafted for business-to-business and professional use. The Global Service is not intended for personal, household or consumer use unless a country-specific consumer addendum is expressly published and accepted for the relevant country. If a person uses the Service on behalf of an organization, that person represents that he or she has authority to bind that organization.
1.4. A Customer accepts these Terms by clicking to accept, registering an account, creating a workspace, installing or authorizing the BusinessProxy extension, creating a session, inviting users, signing or accepting an order form, paying for a plan, using a free or paid plan, requesting support, accessing Private App Access, or otherwise using the Service.
1.5. If Customer does not agree to these Terms, Customer must not register, install the extension, create sessions, invite users, pay for a plan, connect internal applications or otherwise access or use the Service.
1.6. BusinessProxy may offer separate regional terms for specific countries. Where a regional site, checkout page, order form or invoice identifies a separate regional operator, the agreement is with that regional operator for that regional service only. No other BusinessProxy entity is responsible for that regional service except to the extent expressly stated in writing.
1.7. The Agreement is not a legal opinion, compliance certification or permission to access any third-party website, platform, market, content, cloud service, payment service or regulated resource. Customer remains responsible for determining whether its intended use is lawful in all relevant jurisdictions.
1.8. For clarity, the Service is not offered for sanctions circumvention, unlawful bypass of blocking measures, anonymous public proxy use, scraping abuse, bot activity, payment evasion, credential attacks, piracy, cyber abuse or any other prohibited use described in these Terms.
2. Contracting Entity, Regional Operators and Order of Precedence
2.1. The term "BusinessProxy" means the contracting entity identified in the applicable order form, checkout page, invoice, regional terms, regional schedule or other written contracting document. If no entity is identified, Customer must not assume that any specific affiliate, licensor, developer, trademark owner, payment processor, domain owner or regional operator is the contracting party.
2.2. BusinessProxy may operate the Service through regional operators, affiliates, independent distributors, resellers, technology licensees or other entities. A regional operator may provide local contracting, billing, support, tax documentation, data processing, filtering, legal request handling and compliance with local law.
2.3. Regional operators are not automatically agents, partners, franchisees, representatives or joint venturers of any other BusinessProxy entity. A regional operator may bind only itself unless the relevant entity has expressly authorized that operator in writing.
2.4. Regional domains and subdomains are not a guarantee that all features, countries, egress regions, payment methods or legal regimes are available. Service availability depends on the applicable contracting entity, customer location, end-user location, target resources, payment provider rules, sanctions, export controls, infrastructure provider requirements and local law.
2.5. BusinessProxy may maintain a clean global service for jurisdictions where the global operator can lawfully provide the Service and separate local services for jurisdictions requiring local contracting, local data processing, local filtering or local law compliance. A local service must not be used to access or procure the global service where the global service is unavailable.
2.6. The following order of precedence applies in case of conflict, unless a mandatory law requires otherwise: (a) signed enterprise order form; (b) data protection addendum and applicable SCCs/UK Addendum to the extent required by data protection law; (c) regional addendum; (d) service-specific addendum; (e) these main Terms; (f) Acceptable Use Policy; (g) other online policies; (h) documentation.
2.7. No purchase order, procurement term, vendor portal term, invoice note, email footer, click-through customer term or other customer-provided term modifies the Agreement unless BusinessProxy expressly signs it as an amendment.
2.8. Where a reseller, distributor or marketplace sells access to the Service, Customer remains bound by these Terms in relation to use of the Service. Payment and procurement terms between Customer and the reseller apply only between those parties unless BusinessProxy expressly agrees otherwise.
2.9. BusinessProxy may refuse to contract through a requested regional entity or domain if doing so would create legal, sanctions, export-control, tax, telecom, platform, payment, data protection, security or reputational risk.
3. Definitions
3.1. "Account Data" means data provided by or collected from Customer or Authorized Users to create, administer, verify, secure, bill, support or communicate about an account, including name, business email, company name, role, login identifiers, authentication events, billing identifiers, plan data, support requests, administrative settings and legal notices.
3.2. "Affiliate" means an entity that directly or indirectly controls, is controlled by or is under common control with a party, where control means ownership of more than 50% of voting interests or the legal power to direct management.
3.3. "Agreement" means these Terms together with the schedules, addenda, policies, order forms, invoices and other documents incorporated by reference.
3.4. "Authorized User" means an employee, contractor, consultant, agent, administrator, tester, support person or other individual authorized by Customer to access the Service through Customer's account or workspace.
3.5. "Browser Extension" or "Extension" means the BusinessProxy browser extension for Chrome, Chromium or compatible browsers, including updates, permissions, configuration files and authentication flows used to operate the Service.
3.6. "BusinessProxy Materials" means the Service, software, source code, object code, interfaces, dashboards, APIs, documentation, trademarks, logos, designs, domain names, technology, data models, configuration templates, security mechanisms, filtering rules, reports and other materials made available by BusinessProxy.
3.7. "Customer" means the legal entity or individual acting for business or professional purposes that accepts the Agreement, signs an order form, pays for a plan or uses the Service.
3.8. "Customer Data" means electronic data, settings, logs, user records, policies, allow/block lists, internal application configuration, support materials and other content submitted to or generated through the Service by or for Customer, excluding BusinessProxy Materials and Usage Data.
3.9. "Customer Content" means any data, files, payloads, request bodies, response bodies, URLs, headers, application content, user-generated content or other materials that Customer or Authorized Users transmit, route, make available or expose through the Service, including through Private App Access.
3.10. "Data Protection Laws" means all privacy, data protection, cybersecurity breach notification, electronic communications and similar laws applicable to the processing of Personal Data under the Agreement, including GDPR, UK GDPR, Swiss FADP, CCPA/CPRA, PIPEDA, LGPD, PDPA, APPI, APPs and other applicable regional laws as they may apply.
3.11. "Documentation" means user guides, technical requirements, security disclosures, integration instructions, API documentation, release notes, administrator instructions and other written materials made available by BusinessProxy for the Service.
3.12. "Egress Region" means a region, country, data center, IP range or network location from which a session may appear to connect to a target resource, subject to plan, policy, availability and legal restrictions.
3.13. "High-Risk Jurisdiction" means a country, territory or region where BusinessProxy determines that the Service may be subject to heightened sanctions, export-control, telecom, proxy/VPN, content blocking, local storage, law enforcement, privacy, payment, security, tax or infrastructure risk.
3.14. "Personal Data" means information relating to an identified or identifiable natural person, or any equivalent term under applicable Data Protection Laws.
3.15. "Plan" means the subscription, trial, free tier, paid tier, enterprise package, usage allocation, order, traffic quota, feature bundle, support level and other commercial terms applicable to Customer's access to the Service.
3.16. "Policy" or "Filtering Policy" means rules applied by BusinessProxy or Customer to allow, block, restrict or log access by domain, category, port, destination, egress region, workspace, user, device, time, traffic volume, internal application, connector or other technical signals.
3.17. "Private App Access" means the BusinessProxy functionality, if enabled, that allows Customer to publish a controlled HTTPS alias or access path for an internal web application through a connector, reverse proxy, application proxy or similar L7 routing model.
3.18. "Restricted Person" means any person, entity, vessel, aircraft, organization, group, government, public body, owner, beneficial owner or controller that is sanctioned, blocked, denied, debarred, restricted, subject to asset freezes or otherwise prohibited from receiving the Service under applicable sanctions, export-control, trade-control, anti-terrorism, anti-money laundering, payment, infrastructure or platform rules.
3.19. "Restricted Territory" means any country, region or territory subject to comprehensive sanctions, embargoes, trade restrictions, export restrictions, service bans, provider restrictions or BusinessProxy regional unavailability rules, including territories that are restricted under U.S., EU, UK, UN or other applicable sanctions or provider policies.
3.20. "Service" means BusinessProxy's controlled browser access SaaS service, including the website, dashboard, Extension, proxy gateway, policy engine, filtering features, session management, authentication, usage controls, logs, support, APIs, documentation, Private App Access and related features.
3.21. "Session" means a time-limited, policy-controlled access session created for an Authorized User, device, workspace or application using credentials, tokens, keys, gateway rules, quotas and limits.
3.22. "Subprocessor" means a third party engaged by BusinessProxy to process Personal Data on behalf of Customer in connection with the Service.
3.23. "Usage Data" means technical, diagnostic, operational, security, billing and analytical data about use, performance, configuration, policies, logs, failures, blocks, traffic volume, errors and abuse signals of the Service. Usage Data does not include Customer Content except where required for troubleshooting, security, legal compliance or as expressly described in the Service-specific terms.
3.24. "Workspace" means a logical environment within the Service where Customer manages Authorized Users, devices, policies, sessions, applications, quotas, logs, roles and settings.
4. Service Description and Technical Model
4.1. BusinessProxy provides a controlled browser access path for business teams. Unless a service-specific term states otherwise, the current package is designed for Chrome, Chromium or compatible browser environments and does not route all traffic of the operating system or all traffic of the device.
4.2. The Service is designed for scoped, accountable and policy-controlled browser work: managed work domains, approved egress regions, session limits, allow/block policies, category filtering, contractor access, BYOD support, QA testing, support tasks and controlled access to internal web applications where Private App Access is enabled.
4.3. BusinessProxy is not a general-purpose consumer VPN, anonymity service, public unblocker, device-wide tunnel, traffic laundering service, bot platform, scraping infrastructure, payment circumvention tool or means of bypassing legal, platform, employer, school, copyright, licensing, sanctions or export restrictions.
4.4. In the standard browser proxy path, the Service routes only traffic configured to pass through BusinessProxy in the supported browser profile or extension path. Other browsers, local applications, operating system traffic, voice/video calls, messaging apps, banking apps, background services and local tools may remain outside the BusinessProxy path unless separately configured and expressly supported.
4.5. In the standard browser proxy path, BusinessProxy does not generally inspect the content of HTTPS pages. Filtering may use domain, port, SNI where available, DNS/network metadata, category results, local lists, policy rules, workspace settings and abuse signals. Customer acknowledges that this model may not detect all prohibited resources, mirrors, alternate domains, hidden paths or newly created threats.
4.6. Private App Access, if enabled, is a different technical model. It may involve TLS termination, aliasing, connector routing, reverse proxying or application-layer relay. In that model, BusinessProxy may process HTTP method, path, headers and request/response bodies in transit to route, secure, authenticate, apply policy, audit or troubleshoot the internal application. Additional restrictions apply in Schedule 7.
4.7. The Service may create short-lived proxy credentials, device keys, tokens, gateway credentials or session identifiers. Such credentials may be bound to a user, device, workspace, time period, policy, plan or security status and may be revoked automatically or manually.
4.8. BusinessProxy may change, rotate, withdraw, limit or block egress regions, proxy gateways, IP ranges, ports, protocols, categories, APIs, browser versions, extensions, connectors or features for security, capacity, legal, provider, sanctions, export-control, payment, regional or abuse reasons.
4.9. BusinessProxy does not guarantee that a target website, application, platform or provider will accept traffic routed through the Service. Target resources may block, rate-limit, challenge, flag, suspend, terminate or treat traffic according to their own rules.
4.10. On unmanaged devices, Customer may need browser management, MDM, Chrome Enterprise policies or similar controls to ensure that users use the managed browser profile and do not bypass Customer policies by using a different browser, device or network path.
4.11. Customer is responsible for configuring the Service according to its risk profile, including allowed domains, blocked categories, internal application access, user roles, administrator privileges, egress regions, retention settings and device control expectations.
5. Business Use, Eligibility and Authority
5.1. The Service is offered for business, professional and organizational use only, unless a specific consumer addendum is published for a country and expressly accepted. Customer represents that it is using the Service for business or professional purposes and not for personal, family or household purposes.
5.2. Individuals under 18 years of age may not create an account or use the Service unless a higher local age threshold applies, in which case the higher threshold applies. Customer must not knowingly authorize minors to use the Service.
5.3. Customer must have full legal capacity and all internal approvals necessary to enter into the Agreement, bind the relevant organization and authorize the use of the Service by its Authorized Users.
5.4. If an individual accepts the Agreement on behalf of a company, public body, partnership, client, employer or other organization without authority, that individual is personally responsible for the obligations arising from the account and for any losses caused to BusinessProxy.
5.5. Customer must not create accounts using false identities, disposable identities, fake companies, misleading business purposes, stolen payment methods, masked locations or inaccurate beneficial ownership information.
5.6. BusinessProxy may require KYB, KYC, sanctions screening, beneficial ownership information, business registration documents, tax information, trade license, proof of authority, local compliance declarations, use-case descriptions or end-user/end-use certifications before or during service provision.
5.7. BusinessProxy may refuse or terminate any registration or order if BusinessProxy reasonably believes that Customer is not eligible, lacks authority, presents unacceptable risk or seeks to use the Service in a country, region, industry, transaction or use case that BusinessProxy does not support.
6. Accounts, Workspaces, Administrators and Authorized Users
6.1. Customer is responsible for all activity under its accounts, workspaces, administrator accounts, Authorized User accounts, devices, connectors, API keys, tokens, session credentials and payment credentials.
6.2. Customer must ensure that each Authorized User receives access only through the official functionality of the Service and only for permitted business purposes. Shared accounts are prohibited unless a feature expressly permits shared service accounts for a specific use case.
6.3. Customer must keep credentials confidential, use strong authentication, promptly rotate compromised credentials, remove users who no longer need access and notify BusinessProxy promptly of suspected compromise, unauthorized access, security incident or misuse.
6.4. Administrators may configure policies, invite users, manage devices, create allow/block lists, set quotas, review logs, approve internal applications and request support. Customer is responsible for administrator actions and omissions.
6.5. BusinessProxy may rely on instructions from administrators and other authorized contacts unless BusinessProxy has reason to believe that an instruction is unauthorized, unlawful, abusive or creates material risk.
6.6. Customer must maintain accurate account, billing, tax, security and support contact information. Notices sent to the account email, administrator email, dashboard, support portal or order form contact are deemed received according to Section 25.
6.7. BusinessProxy may disable, lock, reset or require re-verification of accounts, sessions, devices, connectors or credentials when necessary for security, legal compliance, sanctions screening, billing, abuse prevention or platform integrity.
7. License, Intellectual Property and Feedback
7.1. Subject to Customer compliance with the Agreement and payment of applicable fees, BusinessProxy grants Customer a limited, revocable, non-exclusive, non-transferable, non-sublicensable license during the term to access and use the Service for Customer's internal business purposes within the applicable plan, documentation and regional availability.
7.2. The license includes the right to install and use the official BusinessProxy Extension solely to use the Service. Customer may not distribute modified versions, sideload unapproved builds, remove security controls, reverse engineer the Extension or use permissions for any purpose outside the Service.
7.3. BusinessProxy and its licensors retain all right, title and interest in BusinessProxy Materials. No rights are granted by implication, exhaustion or estoppel.
7.4. Customer may not copy, modify, translate, adapt, create derivative works from, decompile, disassemble, reverse engineer, scrape, benchmark for competitive purposes, train competing models on, or otherwise attempt to discover source code, underlying ideas, algorithms, data structures, security controls or non-public interfaces of the Service, except to the extent such restriction is prohibited by mandatory law.
7.5. Customer may not rent, lease, sell, resell, sublicense, provide, outsource, operate as a managed service for third parties, make available on a public network, use as downstream proxy infrastructure, or otherwise commercialize the Service except under a signed reseller, marketplace, MSP or regional operator agreement.
7.6. Customer must not use BusinessProxy trademarks, logos, screenshots, domain names or marketing claims without prior written permission, except to identify BusinessProxy as a vendor in ordinary business records.
7.7. Customer grants BusinessProxy a limited license to process Customer Data and Customer Content solely as necessary to provide, secure, support, improve, enforce, bill and comply with legal obligations relating to the Service, subject to the Data Processing Addendum where applicable.
7.8. Feedback is voluntary. Customer grants BusinessProxy a perpetual, irrevocable, worldwide, royalty-free license to use, reproduce, disclose, distribute, modify and exploit feedback, suggestions, ideas, bug reports and recommendations without restriction or compensation, provided BusinessProxy does not publicly disclose Customer confidential information in doing so.
7.9. BusinessProxy may use Customer's name and logo in customer lists only if Customer consents in writing or if such use is permitted by the order form. Customer may revoke marketing use by written notice unless a separate publicity obligation applies.
8. Plans, Fees, Taxes, Trials, Renewals and Refunds
8.1. Plans, fees, quotas, included traffic, egress regions, user limits, device limits, support levels, retention periods, usage overages, beta features and other commercial terms are stated in the applicable order form, checkout page, pricing page, invoice or dashboard.
8.2. Fees are due in the currency, amount, billing cycle and payment method stated at checkout or in the order form. Customer authorizes BusinessProxy and its payment providers to charge the payment method for fees, taxes, overages and renewals according to the applicable plan.
8.3. Unless the order form states otherwise, fees are non-cancelable and non-refundable except where required by mandatory law, where BusinessProxy materially fails to provide paid access and does not cure within a reasonable period, or where BusinessProxy expressly approves a refund.
8.4. Free trials, beta access, credits, promotional offers and free tiers are provided at BusinessProxy's discretion, may be modified or withdrawn at any time, may have reduced features or support, and may be subject to additional restrictions. Trial abuse is prohibited.
8.5. If a plan renews automatically, BusinessProxy or its payment provider will disclose the renewal period and charging process in the checkout, order form or dashboard. Customer is responsible for cancelling renewals before the renewal date according to the applicable cancellation process.
8.6. Customer is responsible for all taxes, levies, duties, VAT, GST, sales tax, withholding tax, digital services tax and similar charges, except taxes based on BusinessProxy's net income. If Customer is required to withhold taxes, Customer must gross up payments unless a valid exemption applies and is provided before payment.
8.7. BusinessProxy may suspend or downgrade access for non-payment, failed payment authorization, expired payment method, chargeback, suspected fraud, sanctions risk, payment provider refusal or breach of payment terms.
8.8. Chargebacks and payment disputes must be raised in good faith. BusinessProxy may treat abusive chargebacks, stolen payment methods, payment laundering or use of payment instruments to mask location or identity as a material breach.
8.9. BusinessProxy may change prices for future periods by notice through the website, dashboard, email or order form. Price changes do not affect prepaid periods unless required for legal, tax, sanctions, provider or security reasons, or unless the order form states otherwise.
8.10. If Customer purchases through a reseller, marketplace or regional operator, payment, refund, invoicing and tax terms may be handled by that party, but use of the Service remains subject to these Terms.
9. Customer Responsibilities and Compliance Duties
9.1. Customer is solely responsible for its use case, target resources, business purpose, internal approvals, employee notices, end-user instructions, customer policies, legal bases for processing, authorization to access websites and applications, and compliance with laws applicable to Customer.
9.2. Customer must ensure that Authorized Users use the Service only for permitted business purposes and comply with the Agreement, Customer policies, target-resource terms, employer obligations, data protection notices, sanctions/export controls and applicable law.
9.3. Customer must not use the Service to obtain access that Customer would not be allowed to obtain directly. The fact that a resource is technically reachable through the Service does not mean that the access is legal, authorized, compliant with platform rules or permitted by BusinessProxy.
9.4. Customer must obtain all consents, notices, approvals and lawful bases required to monitor employee or contractor activity, log browser access, process device identifiers, route traffic through BusinessProxy, configure allow/block policies and connect internal applications.
9.5. Customer must not use the Service in regulated contexts such as health care, payment card processing, children's data, financial market infrastructure, defense, classified information, critical infrastructure, law enforcement, biometric identification or special-category data processing unless BusinessProxy expressly agrees in a signed written addendum that addresses the required compliance regime.
9.6. Customer must maintain its own security measures, including endpoint security, browser management where required, access control, least privilege, user offboarding, internal application hardening, connector security, network segmentation, monitoring, backup and incident response.
9.7. Customer must promptly investigate and remediate any misuse, abuse report, security event, unauthorized access, infected device, compromised credential, suspicious automation or internal policy breach involving Customer's account.
9.8. Customer must not rely on the Service as its only means of compliance with local blocking, sanctions, data protection, employment monitoring, regulated-sector, recordkeeping or lawful access obligations. BusinessProxy filtering and logging are tools, not legal guarantees.
9.9. Customer is responsible for all conduct of Authorized Users, administrators, contractors, invitees, integrated applications, connected networks and persons who gain access through Customer's credentials or configuration.
10. Service Availability, Regional Restrictions and High-Risk Jurisdictions
10.1. The Service is not available in every country, territory, sector, egress region or use case. BusinessProxy may restrict registration, access, payments, egress, features, internal application access, support, data processing, downloads, extension distribution or renewals by country, region, person, industry, payment method, IP address, device, domain or use case.
10.2. Customer may not access or use the Global Service from, in, through, for the benefit of, or to facilitate activity involving Restricted Territories or Restricted Persons, unless BusinessProxy has expressly approved the specific scenario in writing after sanctions and export-control review and the approval is lawful under all applicable regimes.
10.3. Customer may not use a regional domain, local operator, reseller, VPN, proxy, remote desktop, corporate address, payment method, user identity, affiliate entity or business partner to circumvent a country restriction, sanctions rule, export-control rule, payment rule, provider rule or BusinessProxy availability decision.
10.4. BusinessProxy may require Customer to contract with a local or regional operator for certain countries. Conversely, BusinessProxy may prohibit self-service registration, require enterprise review, or completely exclude certain countries or territories.
10.5. High-Risk Jurisdictions may require written enterprise contracting, local legal review, local data storage, local filtering, telecom/proxy classification, KYC/KYB, trade license verification, local law enforcement process, local tax treatment or a separate product configuration.
10.6. BusinessProxy may geoblock, payment-block, feature-block, or require re-verification if a user's apparent location, billing country, IP address, business registration, beneficial ownership, usage pattern, egress selection or support request conflicts with the applicable regional availability rules.
10.7. BusinessProxy may discontinue service in a country or region without liability if continuing would create legal, sanctions, export-control, provider, security, payment, telecom, privacy, tax or reputational risk. Where feasible and lawful, BusinessProxy will provide reasonable notice for non-emergency discontinuance.
10.8. Customer must not represent to its users, customers, affiliates, regulators or third parties that BusinessProxy is approved, licensed, registered, legal or available in a country unless BusinessProxy has expressly confirmed that representation in writing.
10.9. Regional addenda in Schedule 9 describe baseline terms for certain regions. They are not exhaustive legal advice. If Customer's use is materially regulated, Customer must obtain local legal advice before using the Service.
11. Acceptable Use, Prohibited Conduct and Abuse Controls
11.1. Customer and Authorized Users must use the Service responsibly, lawfully and only for permitted business purposes. The Acceptable Use Policy in Schedule 2 is incorporated into the Agreement.
11.2. Customer must not use the Service for illegal, harmful, fraudulent, abusive, deceptive, infringing, privacy-invasive, high-risk or unauthorized activities.
11.3. Prohibited activities include phishing, spam, malware, credential attacks, account takeover, bot traffic, click fraud, fake accounts, unauthorized scraping, bypass of access controls, DDoS/DoS, vulnerability probing without authorization, port scanning, fraud, payment abuse, impersonation, evasion of platform rules, circumvention of copyright or geolocation controls, unlawful data collection, child exploitation, terrorism, extremist activity, human trafficking, sanctions evasion and any other activity listed in Schedule 2.
11.4. BusinessProxy has the right, but not the obligation, to monitor usage, logs, metadata, abuse reports, payment signals, support information and security events to enforce the Agreement, protect the Service, prevent abuse, comply with law, verify billing and maintain platform integrity.
11.5. BusinessProxy may act on actual or suspected abuse by warning Customer, blocking destinations, revoking sessions, limiting egress, disabling users, suspending accounts, preserving logs, requesting information, rejecting allow-list entries, removing tokens, terminating the Agreement, notifying affected parties or reporting to authorities when appropriate and lawful.
11.6. Customer must cooperate with abuse investigations, provide accurate information, promptly remediate misuse and preserve relevant records. Failure to cooperate is a material breach.
11.7. BusinessProxy is not required to pre-screen all Customer activity or content. Enforcement discretion does not waive BusinessProxy's rights and does not create any obligation to enforce against all similar conduct in the same way.
11.8. BusinessProxy may apply abuse measures narrowly where feasible, but may suspend an entire workspace, account or regional feature if narrower measures are insufficient to prevent harm, legal risk, provider risk or platform damage.
12. Sanctions, Export Control and Anti-Circumvention
12.1. Customer must comply with all sanctions, export-control, import-control, anti-boycott, trade-control, anti-money laundering and counter-terrorism laws applicable to Customer, BusinessProxy, the Service, software, technology, support, payments, infrastructure, egress regions, target resources and transactions.
12.2. Customer represents that Customer, its beneficial owners, directors, officers, administrators, Authorized Users, affiliates, end users and any person for whose benefit the Service is used are not Restricted Persons and are not located in, organized under the laws of, ordinarily resident in, or acting for the benefit of a Restricted Territory where receipt of the Service is prohibited.
12.3. Customer must not use the Service to directly or indirectly export, re-export, transfer, provide, enable, approve, finance, facilitate, support, maintain, update or make available software, technology, services, cloud access, connectivity, data, technical assistance, support or other benefits to Restricted Persons, Restricted Territories or prohibited end uses.
12.4. Customer must not use the Service to access websites, cloud services, software, payment services, app stores, developer tools, financial services, media services, marketplaces, communications services or other resources that Customer could not lawfully access directly because of sanctions, export controls, provider restrictions, platform rules, contractual restrictions or legal blocking.
12.5. Customer must not structure transactions, route traffic, use regional operators, split orders, mask IP address or location, use aliases, use third-party payments, use intermediaries, conceal beneficial ownership, or provide false end-user/end-use information to avoid sanctions, export-control, payment or provider restrictions.
12.6. BusinessProxy may screen Customer and users against sanctions lists, restricted party lists, denied party lists, high-risk geography signals, payment signals, infrastructure-provider restrictions and internal risk rules. BusinessProxy may request additional documents or certifications and may deny service if risk is not resolved.
12.7. BusinessProxy may immediately suspend, terminate, block payments, reject renewals, disable features, geoblock access, preserve logs or refuse refunds where BusinessProxy determines that sanctions, export-control, payment, provider or legal restrictions require or justify such action.
12.8. Customer must notify BusinessProxy immediately if Customer becomes a Restricted Person, becomes owned or controlled by a Restricted Person, changes beneficial ownership, begins operating in a Restricted Territory, learns that an Authorized User is restricted, or intends to use the Service for a high-risk end use.
12.9. BusinessProxy may treat sanctions and export-control compliance as a continuing condition of service. If an applicable rule changes, BusinessProxy may modify or terminate access even if access was previously allowed.
12.10. Customer acknowledges that software and cryptographic functionality may be subject to export classification, license exceptions, reporting, notices or restrictions. Customer must not export or re-export BusinessProxy software or technology in violation of applicable law.
12.11. Nothing in the Agreement requires BusinessProxy to provide any service, support, refund, update, data transfer, export, disclosure or performance if BusinessProxy reasonably believes doing so would violate or create risk under sanctions, export controls or provider restrictions.
13. Filtering, Restricted Resources and No Circumvention
13.1. BusinessProxy may apply filtering and blocking rules based on domains, categories, ports, IP ranges, egress regions, local lists, provider requirements, legal restrictions, sanctions, security signals, Customer policies, BusinessProxy policies and abuse patterns.
13.2. Customer must not attempt to bypass filtering, blocking, session limits, device binding, egress restrictions, rate limits, quotas, region restrictions, category restrictions, allow-list controls, private network blocks or other technical measures.
13.3. Circumvention techniques are prohibited, including use of chained proxies or VPNs, mirrors, alternative domains, IP-address access, non-standard DNS, URL shorteners, obfuscation, tunneling, modified extensions, browser automation, alternate ports, credential sharing, fake accounts, remote desktop relays or other means to defeat restrictions.
13.4. Customer acknowledges that filtering in the standard browser proxy path may not inspect HTTPS content and may be imperfect. BusinessProxy does not guarantee detection of every illegal, restricted, sanctioned, harmful or unauthorized resource.
13.5. A successful connection does not mean that the access is permitted. Customer must independently ensure that access is lawful and authorized.
13.6. BusinessProxy may override Customer allow-lists, block internal application aliases, disable connectors, restrict egress regions or reject policy settings that BusinessProxy believes may enable unlawful access, sanctions evasion, provider violations, abuse, security risk or access to restricted resources.
13.7. If Customer discovers that a resource that should be restricted is reachable through the Service, Customer must not exploit that reachability and must promptly notify BusinessProxy.
13.8. BusinessProxy may log and retain filtering events, block decisions, allow-list changes, administrator actions, session metadata and related technical data for security, compliance, billing, support and abuse prevention.
14. Data, Privacy, Logs and Cookies
14.1. BusinessProxy will process Personal Data in accordance with Data Protection Laws applicable to BusinessProxy in connection with the Service and the Privacy Notice published for the applicable region or contracting entity.
14.2. The Agreement distinguishes between Account Data, Customer Data, Customer Content, Usage Data and support/legal/compliance data. The applicable role of BusinessProxy may differ by data category.
14.3. BusinessProxy acts as an independent controller or business for Account Data, billing, payments, anti-fraud, service administration, security, abuse prevention, analytics, product improvement, legal compliance and communications that BusinessProxy determines independently.
14.4. BusinessProxy acts as processor or service provider for Customer Personal Data that it processes on Customer's documented instructions in the workspace, policy, session log, user-management and Private App Access contexts, except where BusinessProxy must process such data as an independent controller for security, abuse, legal or compliance purposes.
14.5. Customer is the controller or business responsible for Customer's Authorized Users, employee/contractor monitoring, internal notices, lawful bases, data subject requests, workspace policies, internal applications, Customer Content, allow/block lists, Customer-directed retention and compliance with employment, privacy and sector-specific laws.
14.6. The Data Processing Addendum in Schedule 4 applies where BusinessProxy processes Customer Personal Data as a processor, service provider or equivalent role. If the DPA conflicts with these Terms on data processing, the DPA controls for that processing.
14.7. BusinessProxy may process technical data including email, name, company, role, account identifiers, workspace identifiers, device identifiers, session IDs, source IP, login events, traffic volume, quota data, plan information, payment identifiers, destination domain, port, category, policy outcome, block events, administrative events, support tickets, cookies and similar technologies.
14.8. In the standard browser proxy path, BusinessProxy does not generally collect content of HTTPS pages. In Private App Access, BusinessProxy may process application-layer data in transit as described in Schedule 7.
14.9. BusinessProxy does not sell Customer browsing activity logs for advertising resale. BusinessProxy may use Usage Data to operate, secure, support, analyze, improve and enforce the Service, subject to confidentiality and privacy obligations.
14.10. Cookies and similar technologies may be used for authentication, security, session management, preferences, fraud prevention, analytics, support and product improvement. Where required by law, BusinessProxy will provide consent or preference mechanisms for non-essential cookies.
14.11. BusinessProxy may transfer Personal Data to subprocessors, affiliates, regional operators, payment providers, hosting providers, email providers, security providers, support vendors, analytics providers and professional advisers as described in the Privacy Notice, DPA and subprocessor list.
14.12. BusinessProxy may retain logs and data according to the Log Retention Schedule in Schedule 6, the applicable plan, legal requirements, security needs, abuse investigations, legal holds, payment/tax records, backup cycles and regional addenda.
14.13. Customer must not upload, route or expose sensitive regulated data through the Service unless the applicable plan and written addendum expressly authorize that data type. Sensitive regulated data includes payment card data, protected health information, children's data, biometric data, special-category data, classified data, government secrets and data subject to sector-specific restrictions.
14.14. If Customer receives a data subject request involving data processed through the Service, Customer is responsible for responding where Customer is the controller. BusinessProxy will provide reasonable assistance according to the DPA and available functionality.
14.15. If BusinessProxy receives a request directly from a data subject concerning Customer-controlled data, BusinessProxy may redirect the person to Customer unless required by law to respond directly.
15. Security, Credentials and Incident Response
15.1. BusinessProxy will implement commercially reasonable technical and organizational measures designed to protect the Service and Customer Personal Data against unauthorized access, loss, alteration, disclosure and misuse, taking into account the nature of the Service, risks and available technology.
15.2. Customer is responsible for endpoint security, browser policy enforcement, MDM or Chrome Enterprise controls where needed, identity provider security, administrator permissions, device management, Authorized User training, internal application hardening, connector placement and secure configuration.
15.3. Customer must promptly notify BusinessProxy of suspected compromise of credentials, tokens, devices, connectors, accounts, administrator privileges, API keys, payment methods or internal applications connected to the Service.
15.4. BusinessProxy may revoke credentials, force password reset, rotate tokens, disable connectors, pause sessions, restrict egress, disable accounts or require additional authentication if BusinessProxy detects or suspects a security issue.
15.5. BusinessProxy may conduct security monitoring, logging, rate limiting, abuse detection, anomaly detection, vulnerability management, penetration testing of its own systems, patching, threat intelligence and other security activities.
15.6. Customer may not conduct vulnerability testing, penetration testing, automated scanning, load testing, fuzzing or security research against the Service, BusinessProxy infrastructure or shared third-party infrastructure without prior written approval. Security reports should be sent to the security contact listed in Schedule 10.
15.7. BusinessProxy will notify Customer of a confirmed security incident affecting Customer Personal Data as required by the DPA and applicable law. Notification does not constitute admission of fault or liability.
15.8. Customer must not publicly disclose security vulnerabilities before BusinessProxy has had a reasonable opportunity to investigate and remediate, unless mandatory law requires disclosure.
16. Support, Maintenance, Beta Features and Changes
16.1. Support is provided according to the applicable plan, order form, documentation or support policy. Unless a signed SLA states otherwise, BusinessProxy does not guarantee response or resolution times.
16.2. BusinessProxy may provide maintenance, updates, patches, configuration changes, category updates, browser extension updates, connector updates, API changes, security hotfixes and infrastructure changes. Customer must use supported versions and may be required to update to continue service.
16.3. Beta, preview, experimental, free, trial, early-access and evaluation features are provided as-is, may be changed or withdrawn at any time, may be subject to additional terms, may have reduced support and should not be used for production-critical workloads unless BusinessProxy expressly agrees.
16.4. BusinessProxy may change or discontinue features, egress regions, plans, integrations, APIs, support channels, payment methods, retention options and documentation. Where feasible, BusinessProxy will provide reasonable notice of material adverse changes to paid production features, except where changes are required for security, legal, provider, sanctions, payment or abuse reasons.
16.5. BusinessProxy may use remote support tools, diagnostic data, logs, screenshots, configuration data and support materials provided by Customer to troubleshoot issues. Customer must not provide sensitive or regulated data in support tickets unless requested through a secure channel and authorized by a written addendum.
16.6. Customer acknowledges that third-party browser changes, operating system changes, target website changes, provider changes, app store policies, network conditions and legal restrictions may affect the Service and may require updates or temporary limitations.
17. Confidentiality
17.1. "Confidential Information" means non-public information disclosed by one party to the other that is marked confidential or should reasonably be understood to be confidential, including business plans, technical information, security information, pricing, product roadmaps, customer lists, workspace settings, logs, support communications, internal application details, credentials and legal requests.
17.2. The receiving party will use Confidential Information only to perform or exercise rights under the Agreement and will protect it using reasonable care, at least the care it uses to protect its own similar information.
17.3. The receiving party may disclose Confidential Information to employees, contractors, affiliates, advisers, subprocessors, payment providers, infrastructure providers and regional operators who need to know and are bound by confidentiality obligations, and to authorities or third parties where permitted or required by Section 19.
17.4. Confidential Information does not include information that is public without breach, independently developed without use of Confidential Information, lawfully received from a third party without confidentiality duty, or approved for release by the disclosing party.
17.5. If disclosure is required by law, court order, regulator, subpoena, legal process or mandatory provider rule, the receiving party may disclose the minimum required information and, where legally permitted, will provide notice to the disclosing party.
17.6. Confidentiality obligations continue for five years after termination, and for trade secrets, Personal Data, security information, credentials and highly sensitive information, for so long as the information remains protected by law or retains its confidential nature.
18. Third-Party Services, Payment Providers and Infrastructure Providers
18.1. The Service may depend on third-party providers for hosting, DNS, CDN, email, payment processing, tax, fraud prevention, analytics, monitoring, security, support, browser distribution, app stores, identity providers, cloud services, data centers and connectivity.
18.2. BusinessProxy is not responsible for third-party services, target websites, Customer identity providers, Customer networks, Customer devices, browsers, app stores, payment providers, banks, local ISPs or infrastructure outside BusinessProxy's reasonable control.
18.3. Third-party providers may impose their own terms, restrictions, sanctions controls, export controls, abuse rules, content rules, rate limits, data processing terms, payment rules or regional limitations. BusinessProxy may enforce or pass through such restrictions.
18.4. If a third-party provider suspends, blocks, terminates or restricts a component necessary for the Service, BusinessProxy may suspend or modify affected features without liability while it seeks reasonable alternatives, if any.
18.5. Customer's use of third-party websites and applications through the Service is governed by the terms, privacy policies and rules of those third parties. BusinessProxy does not grant Customer any right to access third-party resources.
18.6. Customer must not use the Service in a way that causes BusinessProxy to breach the terms, acceptable-use policies, sanctions policies, security requirements or abuse rules of BusinessProxy providers.
19. Lawful Requests, Abuse Reports, Preservation and Disclosure
19.1. BusinessProxy may receive legal process, court orders, subpoenas, warrants, regulatory requests, law enforcement requests, national security requests, sanctions inquiries, payment provider inquiries, infrastructure provider inquiries, abuse reports, copyright notices, emergency requests or complaints from third parties.
19.2. BusinessProxy will review requests according to its applicable law enforcement and legal request policy, regional law, provider obligations and available records. BusinessProxy may reject, narrow, challenge or request clarification where appropriate and legally available.
19.3. BusinessProxy may disclose Account Data, Usage Data, logs, Customer Data, payment data, contact data, security records, preservation records or other information where BusinessProxy believes disclosure is required or permitted by law, legal process, emergency, safety risk, sanctions/export-control compliance, provider rule, abuse investigation, payment dispute, fraud prevention or protection of rights.
19.4. Where legally permitted and practicable, BusinessProxy may notify Customer of a request seeking Customer data. BusinessProxy may delay or omit notice where prohibited by law, where notice would create risk, where the request is confidential, where emergency disclosure is required, or where the account is involved in abuse or fraud.
19.5. BusinessProxy may preserve records, logs, account data or other information where required or permitted by law, legal hold, litigation, investigation, abuse report, security incident, payment dispute or provider request, even if ordinary retention would have expired.
19.6. BusinessProxy is not a host or publisher of content merely because traffic to third-party content passes through the Service. For third-party content abuse, BusinessProxy may be unable to remove the content from the Internet but may restrict Customer's access or use of the Service.
19.7. Customer must not use the Service to interfere with investigations, hide evidence, evade lawful requests or obstruct compliance with legal process.
19.8. Emergency disclosure may occur where BusinessProxy in good faith believes there is an imminent risk of death, serious physical harm, child exploitation, terrorism, major cyber harm, compromise of critical infrastructure or similar emergency.
20. Warranties, Disclaimers and Service Limitations
20.1. Each party represents that it has authority to enter into the Agreement and perform its obligations.
20.2. Customer represents that its use of the Service, Customer Data, Customer Content, internal applications, target resources and instructions will comply with the Agreement, applicable law, third-party rights, platform terms, sanctions/export controls and data protection obligations.
20.3. Except for any express warranties in a signed order form, the Service is provided "as is" and "as available." To the maximum extent permitted by law, BusinessProxy disclaims all implied warranties, including merchantability, fitness for a particular purpose, non-infringement, quiet enjoyment, availability, accuracy, uninterrupted operation, error-free operation and compatibility.
20.4. BusinessProxy does not warrant that the Service will prevent every misuse, detect every prohibited resource, satisfy every legal requirement, provide anonymity, bypass restrictions, maintain access to a target website, avoid target-site blocking, produce business results, meet Customer's internal policies or operate without downtime, errors or security incidents.
20.5. BusinessProxy does not provide legal, sanctions, export-control, telecom, tax, employment, privacy, regulated-sector or compliance advice. Customer must obtain its own advice before using the Service for regulated or cross-border scenarios.
20.6. BusinessProxy does not warrant that filtering decisions will be correct. False positives, false negatives, delays in category updates, region-specific differences and manual review limitations may occur.
20.7. No oral or written information provided by BusinessProxy creates a warranty unless expressly stated in a signed written agreement.
21. Indemnification
21.1. Customer will defend, indemnify and hold harmless BusinessProxy, its affiliates, regional operators, officers, directors, employees, contractors, licensors, providers and agents from and against claims, damages, losses, liabilities, penalties, fines, costs and expenses, including reasonable legal fees, arising from: (a) Customer's or Authorized Users' use of the Service; (b) breach of the Agreement; (c) illegal or prohibited use; (d) Customer Data or Customer Content; (e) internal applications; (f) violation of third-party rights; (g) privacy or employment monitoring violations; (h) sanctions/export-control violations; (i) payment fraud or chargebacks; (j) abuse reports caused by Customer activity; or (k) acts or omissions of Authorized Users.
21.2. BusinessProxy will defend Customer against a third-party claim alleging that the Service, as provided by BusinessProxy and used according to the Agreement, infringes that third party's intellectual property rights, and will pay damages finally awarded or amounts approved in settlement, subject to this Section.
21.3. BusinessProxy's IP indemnity does not apply to claims arising from Customer Data, Customer Content, Customer instructions, combination with non-BusinessProxy products, modifications not made by BusinessProxy, use after BusinessProxy provides a non-infringing alternative, use outside the Agreement, open-source components governed by separate licenses, beta features, free features or alleged infringement caused by target resources or internal applications.
21.4. If the Service becomes or is likely to become subject to an infringement claim, BusinessProxy may procure the right to continue, modify the Service, replace the affected feature or terminate the affected feature and refund prepaid unused fees for that feature.
21.5. Indemnification obligations require prompt notice of the claim, reasonable cooperation, and control of defense by the indemnifying party. The indemnified party may participate with its own counsel at its own expense. Settlement may not admit fault or impose non-monetary obligations on the indemnified party without consent.
22. Limitation of Liability
22.1. To the maximum extent permitted by law, neither party will be liable for indirect, incidental, special, consequential, exemplary or punitive damages, or for loss of profits, revenue, goodwill, business, anticipated savings, data, use, reputation, opportunities, contracts, or business interruption, even if advised of the possibility.
22.2. To the maximum extent permitted by law, BusinessProxy's aggregate liability arising out of or relating to the Agreement will not exceed the greater of USD 100 or the fees paid by Customer for the Service giving rise to the claim during the 12 months before the event giving rise to liability.
22.3. For free, trial, beta or evaluation services, BusinessProxy's aggregate liability will not exceed USD 100 to the maximum extent permitted by law.
22.4. The limitations apply to all theories of liability, including contract, tort, negligence, strict liability, statute, restitution and otherwise, even if a remedy fails of its essential purpose.
22.5. The limitations do not apply to liability that cannot be limited by law, including death or personal injury caused by negligence where applicable, fraud, fraudulent misrepresentation, willful misconduct, or other non-excludable liability.
22.6. Customer's payment obligations, misuse indemnity, confidentiality obligations, sanctions/export-control obligations and liabilities arising from prohibited use may be excluded from the liability cap where permitted by law and as stated in an order form.
22.7. The parties acknowledge that the fees reflect the risk allocation in this Section and that BusinessProxy would not provide the Service on the same terms without these limitations.
23. Suspension, Termination and Data Return/Deletion
23.1. The Agreement begins when accepted and continues until terminated or until all plans expire, unless an order form states a fixed term.
23.2. Customer may stop using the Service at any time. Termination does not entitle Customer to a refund except as expressly stated in the Agreement or required by law.
23.3. BusinessProxy may suspend or terminate access immediately if Customer breaches the Agreement, fails to pay, presents security risk, violates the AUP, creates sanctions/export-control risk, creates provider or payment risk, attempts circumvention, abuses a trial, provides false information, becomes insolvent or uses the Service in a way that may harm BusinessProxy, third parties or the Service.
23.4. BusinessProxy may terminate for convenience with reasonable notice for paid plans and immediately for free, trial, beta or discontinued features, unless an order form states otherwise.
23.5. Upon termination, Customer's license ends, active sessions may be revoked, accounts may be disabled, access to paid features ceases and Customer must stop using BusinessProxy Materials.
23.6. BusinessProxy will delete or return Customer Personal Data processed as processor according to the DPA, available functionality, retention schedule, backup cycles and legal hold requirements.
23.7. BusinessProxy may retain Account Data, payment records, invoices, tax records, security logs, abuse records, legal request records, compliance records, aggregated usage data and other information as required or permitted for legal, tax, accounting, security, audit, dispute, enforcement, backup and legitimate business purposes.
23.8. Sections that by their nature should survive termination survive, including payment obligations, confidentiality, data protection, restrictions, ownership, indemnification, limitations of liability, dispute resolution, legal request provisions and general terms.
24. Governing Law, Dispute Resolution and Regional Mandatory Rights
24.1. Unless the applicable regional addendum or order form states otherwise, the Agreement is governed by the laws of England and Wales, without regard to conflict-of-law rules, and the United Nations Convention on Contracts for the International Sale of Goods does not apply.
24.2. Unless the applicable regional addendum or order form states otherwise, any dispute arising out of or relating to the Agreement will be finally resolved by arbitration under the LCIA Rules by one arbitrator, seated in London, England, in the English language. Judgment on the award may be entered in any court of competent jurisdiction.
24.3. BusinessProxy may seek injunctive, equitable, protective or interim relief in any court of competent jurisdiction to protect intellectual property, confidential information, security, infrastructure, data, payments, sanctions/export-control compliance or to prevent abuse.
24.4. If Customer is located in the United States and the applicable order form selects U.S. law, the U.S. Addendum may provide Delaware law, courts, jury waiver and class-action waiver. Such terms apply only to the extent permitted by law and only to business users.
24.5. If mandatory law gives a party non-waivable rights or imposes mandatory venue, regulator, consumer, data protection, employment, tax, sanctions, telecom or cybersecurity obligations, those mandatory rules apply only to the extent they cannot be excluded by contract.
24.6. Customer and BusinessProxy will first attempt to resolve disputes through good-faith negotiations. A party must provide written notice describing the dispute and allow 30 days for negotiation before commencing arbitration or litigation, except for urgent injunctions, non-payment, abuse, security incidents, sanctions/export-control issues or legal compliance matters.
24.7. To the extent permitted by law, disputes must be brought individually, not as a class, collective, representative or private attorney general action. This waiver does not apply where prohibited by mandatory law.
24.8. The English language version of the Agreement controls unless a regional addendum expressly states that a local-language version controls for that regional service.
25. Notices, Electronic Records and Changes to these Terms
25.1. BusinessProxy may provide notices through the dashboard, website, email, support portal, payment interface, order form, status page, regional site or other electronic means. Customer may provide notices to the legal notice address listed in Schedule 10 or the applicable order form.
25.2. Electronic records, logs, click acceptance records, account events, email delivery records, payment confirmations, support tickets, API records and dashboard records are admissible to evidence acceptance, performance, notices, instructions and breach, subject to applicable law.
25.3. BusinessProxy may update these Terms by posting a revised version or providing notice. Updates apply on the effective date stated. Continued use after the effective date constitutes acceptance.
25.4. For material adverse changes to paid production use, BusinessProxy will use reasonable efforts to provide advance notice unless the change is required by law, security, sanctions/export controls, provider requirements, payment requirements, abuse prevention or urgent operational needs.
25.5. Customer must keep contact information current. Notices sent to the last account email, administrator email, billing email, order form contact or dashboard are deemed delivered even if Customer failed to update contact details.
25.6. If Customer does not agree to updated Terms, Customer must stop using the Service before the effective date. Continued use means acceptance of the updated Terms.
26. General Legal Terms
26.1. The Agreement is the entire agreement between the parties regarding the Service and supersedes prior or contemporaneous understandings on that subject.
26.2. If any provision is unenforceable, it will be modified to the minimum extent necessary to make it enforceable, or severed if modification is not possible, and the remaining provisions will remain in effect.
26.3. No waiver is effective unless in writing and signed by the waiving party. Failure to enforce a provision is not a waiver.
26.4. Customer may not assign or transfer the Agreement without BusinessProxy's prior written consent, except to a successor in connection with merger, reorganization or sale of substantially all assets, provided the successor is not a Restricted Person, is not located in a Restricted Territory and agrees to be bound. BusinessProxy may assign to an affiliate, successor, regional operator or acquirer.
26.5. The parties are independent contractors. The Agreement does not create an agency, partnership, joint venture, employment, fiduciary or franchise relationship.
26.6. Except for indemnified parties and affiliates expressly protected by the Agreement, there are no third-party beneficiaries.
26.7. Neither party is liable for failure or delay caused by events beyond reasonable control, including acts of God, war, terrorism, civil unrest, labor disputes, epidemics, natural disasters, government action, sanctions, embargoes, export restrictions, provider outages, power failures, internet failures, DNS/CDN failures, data center incidents, payment network failures and other force majeure events.
26.8. Headings are for convenience only. "Including" means "including without limitation." "Will" and "shall" indicate obligations. Singular includes plural and vice versa. References to laws include amendments and replacements.
26.9. BusinessProxy may use affiliates, contractors, subprocessors and regional operators to perform obligations but remains responsible to Customer according to the Agreement for acts and omissions within the scope of its responsibility.
26.10. Nothing in the Agreement requires either party to violate law or provider rules. If performance becomes unlawful or commercially unreasonable due to legal or provider changes, BusinessProxy may modify, suspend or terminate the affected service.
Schedule 1. Contracting Entity and Regional Service Matrix
This Schedule is designed so BusinessProxy can operate a single global legal framework while using different contracting entities and regional operators where required. The matrix must be completed before publication or checkout launch.
Region / Service
Contracting Entity
Domain / Checkout
Baseline Position
Required Local Controls
Global Service
[Insert global contracting entity]
business-proxy.com and approved global checkout
B2B-only global SaaS. Restricted Territories excluded. English Terms apply.
Sanctions/export screening, provider flow-down, privacy notice, DPA, AUP, abuse/legal contacts.
United States
[Insert US entity or global entity]
us.business-proxy.com or US checkout
B2B service. US Addendum applies where Customer is in the U.S. or U.S. law applies.
OFAC/EAR screening, DMCA/abuse process, state privacy review, tax/sales tax setup.
EU/EEA
[Insert EU entity or global entity + EU representative if required]
eu.business-proxy.com or EU checkout
B2B service. EU/EEA Addendum and DPA/SCC apply.
GDPR DPA, SCC/TIA, subprocessor list, DSA contact/representative analysis, cookie/ePrivacy controls.
United Kingdom
[Insert UK entity or global entity + UK representative if required]
uk.business-proxy.com or UK checkout
B2B service. UK Addendum and UK GDPR terms apply.
UK IDTA/Addendum, UK transfer risk assessment, UK representative analysis.
Russia / Local Russian Service
OOO UpravTreb or designated Russian operator
ru domain or Russian checkout
Separate Russian offer should govern Russian local service. Global Terms do not authorize restricted global access.
152-FZ localization, Russian filtering, local payments, local data policy, local legal request process.
UAE
[Insert UAE operator or approved partner]
ae.business-proxy.com only after review
Controlled enterprise launch only. No consumer unblock/proxy positioning.
TDRA/local telecom review, UAE PDPL, trade-license KYB, UAE filtering, local legal request workflow.
India
[Insert approved Indian operator or enterprise contracting entity]
in.business-proxy.com only after review
No self-service unless CERT-In and DPDP controls are implemented.
CERT-In incident and retention workflow, local log obligations if applicable, KYB, India privacy terms.
Mainland China
[No global self-service]
No China-targeted global checkout
No service unless local licensing/partner and China legal review approve.
MIIT/telecom, PIPL, cross-border transfer, local partner/licensing, no cross-border proxy positioning.
Restricted Territories / Restricted Persons
None under Global Service
No global or regional checkout unless legally cleared
Global Service unavailable.
Geoblocking, payment blocking, sanctions screening, no support/facilitation.
S1.1. The checkout, order form or invoice must clearly identify the contracting entity. If a regional operator contracts with Customer, that regional operator is solely responsible for local billing, tax, support and legal compliance unless another entity expressly assumes responsibility in writing.
S1.2. A regional domain should not be used to imply that the global operator provides service in a restricted country. Regional services must be operationally separated where required by sanctions, export-control, privacy, payment, telecom or provider rules.
S1.3. Customer must not move accounts, workspaces, sessions, payments or users between regional services to avoid local law, sanctions, export controls, taxes, KYC/KYB, filtering or provider restrictions.
S1.4. BusinessProxy may require separate regional terms, DPA, order form, local invoice, local payment method, local data storage, local support channel or local legal representative before providing service in a country.
Schedule 2. Acceptable Use Policy
This Acceptable Use Policy (AUP) applies to Customer, Authorized Users, administrators, contractors, affiliates and anyone who accesses the Service through Customer. It applies in addition to Sections 11-13 of the main Terms.
S2.1 Lawful and authorized use only
Customer may use the Service only for lawful, authorized, business purposes. Customer must have permission to access every target website, application, system, dataset, account and network.
S2.2 No public proxy, VPN or anonymity service
Customer must not operate the Service as a public proxy, consumer VPN, anonymity service, unblocker, downstream proxy, resale gateway, shared proxy pool, traffic laundering path or general Internet access service for third parties.
S2.3 No cyber abuse
Customer must not use the Service for malware, botnets, phishing, credential attacks, account takeover, brute force, password spraying, credential stuffing, exploit delivery, command-and-control, scanning, unauthorized testing, DDoS/DoS, vulnerability probing without written authorization, port scanning or unauthorized access.
S2.4 No platform abuse
Customer must not use the Service for fake accounts, mass registrations, spam, social media manipulation, fake engagement, reviews fraud, click fraud, ad fraud, CAPTCHA bypass, anti-bot bypass, rate-limit evasion, ticketing abuse, sneaker bots, scraping of prohibited data or circumvention of platform rules.
S2.5 No unlawful content or commerce
Customer must not use the Service for child sexual abuse material, sexual exploitation, human trafficking, terrorism, violent extremism, weapons trafficking, illegal drugs, stolen goods, counterfeit goods, regulated goods without authorization, illegal gambling, fraud, identity theft, doxxing, harassment, non-consensual intimate content or other unlawful content or commerce.
S2.6 No IP or data rights violations
Customer must not infringe copyright, trademarks, trade secrets, database rights, privacy rights, publicity rights, contractual access restrictions, digital rights management, paywalls, robots restrictions where legally binding, or other third-party rights.
S2.7 No sanctions or export violations
Customer must not use the Service for Restricted Persons, Restricted Territories, prohibited end uses, military/intelligence end uses where restricted, nuclear/chemical/biological/weapons end uses, export-control evasion or sanctions circumvention.
S2.8 No harmful traffic patterns
Customer must not generate traffic that disrupts BusinessProxy, target resources, networks, ISPs, payment providers, infrastructure providers or other customers, including excessive requests, automated traffic, scraping bursts, connection flooding, abusive retries or traffic inconsistent with the plan.
S2.9 No bypass of BusinessProxy controls
Customer must not bypass filters, region blocks, quotas, device binding, session limits, credential expiry, pricing limits, billing controls, security controls, logging, detection systems or support restrictions.
S2.10 Conditional use cases
Security research, QA testing, brand protection, ad verification, price intelligence, market research, fraud prevention, SEO monitoring and automated testing may require written approval, documented authorization from target resources, rate limits, data minimization and additional safeguards.
S2.11 Enforcement
BusinessProxy may investigate suspected violations, request information, suspend or terminate accounts, block traffic, preserve logs, refuse refunds, notify providers or authorities and take other measures permitted by law and the Agreement.
Schedule 3. Sanctions and Export Control Policy
S3.1. This policy applies to all accounts, trials, payments, support, updates, downloads, APIs, browser extensions, regional operators, resellers, affiliates and users of the Service.
S3.2. The Global Service excludes Restricted Persons and Restricted Territories. A region may be restricted because of sanctions, export controls, provider terms, payment rules, infrastructure restrictions, local law, BusinessProxy policy or operational risk.
S3.3. Customer must not provide access to the Service to any person or entity that is sanctioned, blocked, denied, owned or controlled by a blocked party, or otherwise prohibited from receiving the Service.
S3.4. Customer must not use the Service to facilitate transactions, access, support, software updates, cloud services, technical assistance, development tools, communications services or payments for prohibited countries, regions, persons, sectors, industries, entities or end uses.
S3.5. BusinessProxy may perform risk-based screening at onboarding, renewal, payment, support request, region change, unusual activity, KYB/KYC review or abuse investigation.
S3.6. Customer must provide accurate end-user, end-use, ownership, country, payment, business-purpose and location information on request. Refusal or delay may result in suspension or denial of service.
S3.7. BusinessProxy may decline any transaction, suspend access, geoblock, payment-block, revoke updates or terminate accounts when risk is unacceptable or cannot be resolved.
S3.8. If an existing customer becomes restricted or a legal change makes service unavailable, BusinessProxy may terminate immediately and may be unable to provide refunds, data export, support or transition assistance where prohibited.
S3.9. Regional operators must not use BusinessProxy trademarks, software, updates, support, infrastructure or payments to serve Restricted Territories or Restricted Persons unless the specific operation is legally cleared in writing and does not create risk for the global service, providers or other BusinessProxy entities.
S3.10. This policy is risk-based and may be stricter than law. BusinessProxy may restrict service based on provider rules, bank rules, payment rules, app store rules, risk appetite or contractual obligations even where a transaction might otherwise be lawful for Customer.
Schedule 4. Data Processing Addendum
This Data Processing Addendum (DPA) applies where BusinessProxy processes Customer Personal Data on behalf of Customer as processor, service provider or equivalent role. It forms part of the Agreement.
Part A. DPA Definitions and Scope
DPA 1.1. "Customer Personal Data" means Personal Data processed by BusinessProxy on behalf of Customer through the Service, including Authorized User account information, workspace logs, policy results, device/session identifiers and Private App Access routing data to the extent processed on Customer instructions.
DPA 1.2. "Controller", "processor", "personal data breach", "processing", "subprocessor" and similar terms have the meanings under applicable Data Protection Laws.
DPA 1.3. Customer is the controller or business for Customer Personal Data. BusinessProxy is the processor or service provider for Customer Personal Data except where it acts as an independent controller for Account Data, billing, security, abuse, legal compliance, product analytics or other independent purposes.
DPA 1.4. The subject matter, duration, nature, purpose, categories of Personal Data and categories of data subjects are described in Part H of this DPA.
Part B. Processing Instructions
DPA 2.1. BusinessProxy will process Customer Personal Data only to provide, secure, support, maintain, improve, enforce and comply with legal obligations relating to the Service, and in accordance with Customer's documented instructions in the Agreement, order form, dashboard settings, policies, support requests and written instructions.
DPA 2.2. BusinessProxy may process Customer Personal Data where required by law, legal process, sanctions/export-control compliance, provider obligations or protection of rights, and will notify Customer where legally permitted.
DPA 2.3. Customer must ensure that instructions are lawful. BusinessProxy may refuse instructions that it believes violate law, the Agreement, provider rules, sanctions/export controls, data protection requirements or security obligations.
DPA 2.4. Customer must not provide sensitive regulated data unless expressly authorized by a written addendum. If Customer does so without authorization, Customer remains responsible and BusinessProxy may delete, block or restrict processing.
Part C. Confidentiality and Personnel
DPA 3.1. BusinessProxy will ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations or are under an appropriate statutory obligation of confidentiality.
DPA 3.2. BusinessProxy will limit access to Customer Personal Data to personnel and subprocessors who need access for service delivery, support, security, compliance or other permitted purposes.
Part D. Security Measures
DPA 4.1. BusinessProxy will maintain technical and organizational measures appropriate to the risk of processing, including measures described in Schedule 5.
DPA 4.2. Customer acknowledges that security is a shared responsibility. Customer is responsible for secure configuration, user management, endpoint security, identity provider controls, connector security, internal application security, notices and lawful basis.
Part E. Subprocessors
DPA 5.1. Customer provides general authorization for BusinessProxy to engage subprocessors to provide the Service. BusinessProxy will maintain a subprocessor list or make it available through a trust center, support request or other reasonable mechanism.
DPA 5.2. BusinessProxy will impose data protection obligations on subprocessors that are materially equivalent to those in this DPA for the services they perform.
DPA 5.3. BusinessProxy remains responsible for subprocessors' performance of data protection obligations to the extent required by Data Protection Laws.
DPA 5.4. Where required by Data Protection Laws, BusinessProxy will provide notice of new subprocessors and allow Customer to object on reasonable data protection grounds. If the parties cannot resolve the objection, Customer may terminate the affected Service and receive a pro-rata refund of prepaid unused fees for the affected Service, unless the subprocessor is necessary for the core service or required by law/provider.
Part F. Data Subject Requests, DPIA and Assistance
DPA 6.1. BusinessProxy will provide reasonable assistance for data subject requests to the extent Customer cannot fulfill the request through the Service and the request relates to Customer Personal Data processed by BusinessProxy as processor.
DPA 6.2. BusinessProxy will provide reasonable assistance with data protection impact assessments, consultations and compliance documentation where required by law, taking into account the nature of processing and information available to BusinessProxy. Additional professional services may be charged at standard rates.
DPA 6.3. If BusinessProxy receives a request directly from a data subject relating to Customer Personal Data, BusinessProxy may direct the data subject to Customer unless required by law to respond.
Part G. Personal Data Breaches
DPA 7.1. BusinessProxy will notify Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data processed by BusinessProxy as processor.
DPA 7.2. Where feasible, BusinessProxy will include available information about the nature of the breach, affected data, likely consequences, measures taken or proposed, and contact point for follow-up. Notifications may be provided in phases as information becomes available.
DPA 7.3. Customer is responsible for notifying regulators, data subjects and other persons where Customer is the controller, unless Data Protection Laws require BusinessProxy to notify directly.
DPA 7.4. BusinessProxy's notification is not an admission of fault, liability or breach of the Agreement.
Part H. Processing Details
Element
Description
Subject matter
Provision of controlled browser access, workspace management, filtering, session management, audit logs, support, billing, security and Private App Access if enabled.
Duration
Term of the Agreement plus retention periods required for logs, backups, legal holds, security, accounting, tax, abuse and legal compliance.
Nature and purpose
Hosting, storage, transmission, routing, authentication, authorization, filtering, logging, support, troubleshooting, security monitoring, abuse prevention, billing and compliance.
Data subjects
Customer employees, contractors, administrators, end users, support contacts, billing contacts, invited users, internal app users and other persons whose data Customer routes through the Service.
Personal Data categories
Name, email, company, role, account identifiers, workspace identifiers, device identifiers, IP address, session identifiers, timestamps, traffic volume, destination domain/port/category, policy result, block events, admin audit events, support content, Private App Access metadata and data in transit.
Sensitive data
Not permitted by default. Special-category, health, payment card, children, biometric, criminal, classified, national ID and similar regulated data require written authorization.
Frequency
Continuous during use of the Service.
Subprocessors
Hosting, email, security, monitoring, payment, support, analytics, data center and other providers listed by BusinessProxy or disclosed on request.
Part I. International Transfers
DPA 8.1. Where GDPR applies and Customer Personal Data is transferred to a country without an adequacy decision, the EU Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 are incorporated by reference. The applicable module is Module Two (controller to processor) unless another module better reflects the transfer.
DPA 8.2. For onward transfers from BusinessProxy to subprocessors outside the EEA, the relevant SCC module applies as appropriate, including Module Three (processor to processor) where required.
DPA 8.3. For transfers subject to UK GDPR, the UK International Data Transfer Addendum to the EU SCCs, or the UK IDTA where applicable, is incorporated by reference to the extent required.
DPA 8.4. For Swiss transfers, references to GDPR supervisory authorities and EU Member States are interpreted as references to the Swiss Federal Data Protection and Information Commissioner and Swiss law where required.
DPA 8.5. Customer acknowledges that transfer impact assessments and supplementary measures may depend on Customer's configuration, data categories, region, subprocessor choices, encryption, access controls and legal requirements. The parties will cooperate reasonably where required.
Part J. Deletion, Return and Audit
DPA 9.1. Upon termination, BusinessProxy will delete or return Customer Personal Data processed as processor according to available functionality, the retention schedule, backup deletion cycles and legal holds.
DPA 9.2. BusinessProxy may retain data where required or permitted for legal, tax, accounting, security, fraud prevention, abuse investigations, sanctions/export-control compliance, dispute resolution or backup purposes.
DPA 9.3. BusinessProxy will provide information reasonably necessary to demonstrate compliance with this DPA through documentation, security summaries, third-party audit reports, questionnaires or certifications where available. On-site audits are allowed only where required by Data Protection Laws, on reasonable notice, during business hours, without disrupting operations, and subject to confidentiality and security restrictions.
Schedule 5. Technical and Organizational Measures
Control Area
Baseline Measures
Access control
Role-based access, least privilege, administrator controls, account authentication, access review practices, session controls, token rotation where supported.
Credential security
Password and token protection, short-lived session credentials where supported, revocation of sessions, device/session binding where supported.
Encryption
Transport encryption for supported interfaces; encryption or provider-managed protection for stored data where supported by infrastructure; no intentional plaintext disclosure outside service needs.
Network and application security
Gateway controls, firewall/security groups where applicable, vulnerability management, patching, monitoring, abuse detection, rate limiting and segmentation where feasible.
Logging and monitoring
Operational logs, security logs, usage/block events, administrator events, support records and legal request records according to retention schedule and plan.
Private App Access controls
Connector model, alias controls, application access policies, audit events, TLS/application-layer processing disclosure and customer responsibility matrix.
Personnel and confidentiality
Confidentiality obligations for personnel with access to relevant data; internal access on need-to-know basis.
Subprocessor controls
Contractual data protection obligations, service provider due diligence proportionate to risk, subprocessor list or disclosure.
Incident response
Security event triage, containment, investigation, customer notification where required, log preservation and remediation.
Business continuity
Commercially reasonable backup, infrastructure resilience and recovery measures appropriate to plan and provider availability.
Data minimization
Collection of operational, security, billing, filtering and support data reasonably necessary for the Service; HTTPS content not inspected in standard browser path by default.
Customer responsibilities
Endpoint security, MDM/browser enforcement, identity provider security, user training, internal application security, data classification and lawful basis.
S5.1. Measures may vary by plan, feature, beta status, regional operator and infrastructure provider. Enterprise plans may include additional security commitments in an order form or security addendum.
Schedule 6. Log Retention Schedule
The following retention periods are default operational targets unless the plan, order form, regional law, legal hold, security incident, abuse investigation, payment dispute or tax/accounting obligation requires a different period.
Data Category
Default Retention Target
Purpose / Notes
Usage events
30 days by default
Quota enforcement, support, performance, billing verification, abuse prevention.
Blocked events / policy outcomes
30 days by default
Filtering, troubleshooting, security analytics, abuse investigation.
Workspace and administrator audit logs
180 days by default
Accountability, internal investigations, administrator actions, enterprise audit.
Raw gateway/API logs
7-14 days by default
Short-term operational troubleshooting, error analysis, security triage.
Session identifiers, device identifiers, source IP
30-90 days depending on feature and incident needs
Session creation, revocation, security, abuse prevention, compliance.
Account and billing records
Account term plus legal/tax/accounting period
Contracting, invoices, taxes, payments, fraud prevention, disputes.
Support tickets
Account term plus reasonable support history period
Support continuity, troubleshooting, evidence of instructions and communications.
Security incident records
As long as required for investigation and defense
Incident response, forensics, legal holds, regulator/provider obligations.
Legal request and abuse records
As long as required or reasonably necessary
Compliance, evidence, repeat abuse prevention, legal defense.
Backups
Rotating backup cycles according to infrastructure practice
Resilience; deletion from backups may occur through ordinary backup rotation.
Aggregated/anonymized data
May be retained longer
Product analytics, security trends, capacity planning, provided it is not Personal Data under applicable law.
S6.1. BusinessProxy may offer shorter or longer retention as a paid feature. Customer is responsible for exporting logs before expiration if Customer needs them for its own compliance.
S6.2. Retention periods may be extended for legal holds, investigations, suspected abuse, chargebacks, sanctions/export-control inquiries, regulator requests, provider requests, security incidents, tax/accounting obligations and disputes.
S6.3. Retention periods may be shortened where required by law, provider rules, storage limits, security reasons or product changes.
Schedule 7. Private App Access Addendum
This Addendum applies if Customer uses Private App Access, connectors, aliases, reverse proxy, application proxy or similar functionality to expose an internal web application through BusinessProxy.
PAA 1.1. Private App Access is a service-specific feature and may be beta, enterprise-only, region-limited or subject to additional review. It is not a device VPN and does not provide full network access unless expressly stated.
PAA 1.2. Customer is solely responsible for the internal application, upstream host, connector deployment, network placement, identity controls, authorization model, application security, user permissions, logs, notices and legal basis for exposing the application.
PAA 1.3. The Private App Access path may terminate TLS at a BusinessProxy-controlled endpoint or otherwise process application-layer data to relay requests. BusinessProxy may process HTTP method, path, query string, headers, cookies, authentication metadata and request/response bodies in transit as necessary to route, secure, authenticate, authorize, audit, troubleshoot and enforce policies.
PAA 1.4. BusinessProxy does not log request/response bodies by default unless required for troubleshooting, security, legal compliance or a separately enabled feature. Customer must not provide secrets, regulated data or sensitive content in support tickets or logs unless expressly requested through an approved secure process.
PAA 1.5. Customer must not use Private App Access for applications involving payment card processing, protected health information, children's data, biometric data, special-category data, national secrets, classified information, criminal records, financial trading systems, critical infrastructure, emergency services, high-risk government systems or regulated workloads unless a signed addendum authorizes that use.
PAA 1.6. Customer must configure authentication, authorization and least privilege for each internal application. BusinessProxy routing does not replace application-level authorization or security controls.
PAA 1.7. Customer must secure connectors, rotate secrets, restrict connector network access, monitor connector health, patch internal applications, maintain backups and ensure that exposing an alias does not violate internal policies, customer contracts or local law.
PAA 1.8. BusinessProxy may disable an alias, connector, internal application or workspace if it presents security risk, abuse risk, legal risk, sanctions risk, privacy risk, provider risk or instability.
PAA 1.9. Customer must not use Private App Access to publish unlawful content, evade local licensing, expose third-party applications without authorization or provide access to Restricted Persons or Restricted Territories.
PAA 1.10. If Customer requires service levels, penetration testing, audit rights, specific encryption, dedicated infrastructure, log retention, data residency or regulated-data terms for Private App Access, those requirements must be stated in a signed enterprise order form or security addendum.
Schedule 8. Law Enforcement, Abuse and DSA Addendum
S8.1. BusinessProxy will maintain designated contacts for legal requests, abuse reports, security reports and privacy requests. Current contacts must be published in Schedule 10 or the applicable regional site.
S8.2. Legal requests must identify the requesting authority, legal basis, account identifiers, requested data, time period, urgency and confidentiality requirements. BusinessProxy may require formal legal process, translation, authentication, MLAT or local counsel review.
S8.3. Abuse reports should include the target resource, timestamps, source/destination information, account identifiers if known, logs, screenshots, impact, legal basis and requested action. BusinessProxy may be unable to act on incomplete reports.
S8.4. BusinessProxy may disclose information without prior notice to Customer in emergencies involving imminent risk of death, serious physical harm, child exploitation, terrorism, major cyber harm, critical infrastructure compromise, major fraud or comparable emergency.
S8.5. BusinessProxy may preserve data upon valid preservation request, legal hold, abuse report, security incident, payment dispute or internal investigation. Preservation does not guarantee that data exists or that data will be disclosed without valid process.
S8.6. For EU DSA purposes, if BusinessProxy is classified as a provider of intermediary services and offers services in the EU, BusinessProxy will designate points of contact for authorities and recipients and, if required, an EU legal representative. These obligations apply only to the extent the DSA applies to the relevant service.
S8.7. BusinessProxy is not the host of third-party websites merely because Customer accesses them through the Service. BusinessProxy may restrict Customer access or suspend accounts but may not have the ability to remove third-party content from the Internet.
S8.8. BusinessProxy may publish transparency reports or statistics about legal requests, abuse reports, enforcement actions and regional availability, subject to law and confidentiality obligations.
Schedule 9. Regional Addenda
These Regional Addenda supplement the main Terms. They are designed to allow a single global agreement with targeted regional adjustments. They do not replace local legal review for regulated or high-risk deployments.
9A. United States Addendum
US 1.1. This Addendum applies if Customer is located in the United States, the contracting entity is a U.S. entity, U.S. law applies by order form, U.S. persons are involved, U.S. payments or infrastructure are used, or the Service is otherwise subject to U.S. law.
US 1.2. Customer must comply with U.S. export controls, sanctions, anti-boycott laws, anti-money laundering laws and trade restrictions, including restrictions administered by OFAC and BIS where applicable.
US 1.3. Customer may not use the Service if Customer is on a U.S. restricted party list, located in a comprehensively sanctioned jurisdiction, or using the Service for a prohibited end use, unless authorized by applicable law and expressly approved by BusinessProxy.
US 1.4. If the CCPA/CPRA or other U.S. state privacy laws apply, BusinessProxy will act as a service provider/processor for Customer Personal Data processed on Customer's behalf and will not sell or share such Customer Personal Data except as permitted by applicable law and the Agreement.
US 1.5. BusinessProxy may provide mechanisms for privacy requests where required by applicable state privacy laws. Customer remains responsible for responding to requests where Customer determines purposes and means of processing.
US 1.6. BusinessProxy may maintain a DMCA or copyright abuse process if required for the applicable service. BusinessProxy is generally not the host of third-party content accessed by Customer through the Service.
US 1.7. If a U.S. order form selects U.S. law, unless stated otherwise the law of Delaware applies, courts in Delaware have exclusive jurisdiction for non-arbitrable claims, and each party waives jury trial and class action rights to the extent permitted by law.
US 1.8. The Service is not intended for children under 13 or for collecting children's data. Customer must not use the Service in a way that triggers COPPA or student privacy obligations without a signed written addendum.
9B. EU/EEA, Switzerland and United Kingdom Addendum
EUUK 1.1. This Addendum applies where GDPR, UK GDPR, Swiss FADP, ePrivacy rules, DSA or similar European laws apply to the Service.
EUUK 1.2. For Customer Personal Data processed by BusinessProxy as processor, the DPA in Schedule 4 applies and includes Article 28-style processing terms, subprocessor authorization, security obligations, assistance, breach notification, deletion/return and audit support.
EUUK 1.3. For transfers from the EEA to non-adequate countries, the EU SCCs adopted by Commission Implementing Decision (EU) 2021/914 are incorporated by reference where required. For UK transfers, the UK Addendum or IDTA applies where required. For Swiss transfers, Swiss modifications apply.
EUUK 1.4. Customer is responsible for lawful bases, employee/contractor monitoring notices, works council or employee representative consultation where required, internal policies, DPIA assessment and informing Authorized Users about browser access logging.
EUUK 1.5. BusinessProxy will provide a privacy notice and cookie controls for non-essential cookies where required. Customer must not use the Service to evade ePrivacy or consent requirements.
EUUK 1.6. If DSA applies to BusinessProxy as an intermediary service, BusinessProxy will maintain points of contact and legal representative arrangements where required. Classification of the Service may vary by feature and country.
EUUK 1.7. Nothing in the Agreement limits non-waivable rights under EU, EEA, Swiss or UK law. For B2B customers, limitation of liability and dispute terms apply to the extent permitted by applicable law.
EUUK 1.8. Customer must not use the Service for workplace monitoring in a way that violates labor, employment, privacy, data protection, secrecy of communications or employee consultation requirements.
9C. Canada Addendum
CA 1.1. This Addendum applies where Canadian privacy or commercial laws apply, including PIPEDA or substantially similar provincial laws.
CA 1.2. Customer is responsible for consent or other lawful authority, transparency and accountability for Personal Data that Customer collects or routes through the Service.
CA 1.3. BusinessProxy will use contractual and security safeguards for cross-border processing of Customer Personal Data and will provide information reasonably necessary for Customer to describe foreign processing in its privacy materials.
CA 1.4. If a breach of security safeguards creates a real risk of significant harm and BusinessProxy is responsible for notifying Customer, BusinessProxy will provide information reasonably available to support Customer's reporting and notification obligations.
CA 1.5. For Quebec or other provincial requirements, Customer must ensure that language, transfer, privacy impact assessment and transparency requirements are met before using the Service.
9D. Australia Addendum
AU 1.1. This Addendum applies where the Australian Privacy Act and Australian Privacy Principles apply.
AU 1.2. Customer is responsible for determining whether disclosure to BusinessProxy or its overseas recipients is permitted and for taking reasonable steps required under APP 8.
AU 1.3. BusinessProxy will maintain contractual and security safeguards for Customer Personal Data and provide information about subprocessors or regions reasonably necessary for Customer's APP 8 assessment.
AU 1.4. Customer must not use the Service for employee monitoring, sensitive information, health information, government identifiers or regulated data without ensuring compliance with Australian law and obtaining a signed addendum where required.
9E. Singapore Addendum
SG 1.1. This Addendum applies where Singapore PDPA applies.
SG 1.2. Customer is responsible for consent, notification of purposes, data subject rights and transfer limitation obligations for Personal Data disclosed or made available to BusinessProxy.
SG 1.3. BusinessProxy will provide contractual protections designed to ensure a comparable standard of protection for transferred Personal Data where required by Singapore law.
SG 1.4. Customer must not use the Service for regulated telecommunications, cybersecurity or sector-specific workloads in Singapore without confirming licensing and compliance requirements.
9F. Brazil Addendum
BR 1.1. This Addendum applies where Brazil LGPD applies.
BR 1.2. The parties will treat BusinessProxy as operator for Customer Personal Data processed on Customer's instructions and as controller for Account Data and independent compliance/security purposes.
BR 1.3. International transfers will be made under contractual safeguards, standard clauses or other valid transfer mechanisms where required.
BR 1.4. Customer is responsible for lawful basis, transparency, data subject rights, sensitive data restrictions and notices to Authorized Users in Brazil.
9G. Japan Addendum
JP 1.1. This Addendum applies where Japan APPI applies.
JP 1.2. Customer is responsible for proper handling of personal information, notices, consent or other transfer basis, supervision of entrusted processing and restrictions on providing personal data to third parties in foreign countries.
JP 1.3. BusinessProxy will process Customer Personal Data according to Customer instructions, provide reasonable information about foreign processing where required and maintain safeguards described in Schedule 5.
JP 1.4. Customer must not route special-care required personal information or regulated data without confirming APPI requirements and obtaining a written addendum where necessary.
9H. UAE Addendum - Controlled Enterprise Launch Only
UAE 1.1. The Service must not be marketed or used in the UAE as a consumer unblocker, unauthorized VPN, public proxy, VoIP bypass tool, content-blocking bypass tool or means to evade ISP filtering or local law.
UAE 1.2. UAE use should be limited to verified business customers, internal corporate access and documented lawful purposes, subject to local legal review and, where required, local operator or partner arrangements.
UAE 1.3. BusinessProxy may require trade license verification, KYB, UAE-specific filtering, local support/legal process, PDPL terms, regional data handling, and written enterprise order before enabling UAE customers, UAE users or UAE egress.
UAE 1.4. Customer must comply with UAE cybercrime, telecom, content, privacy and data protection rules and must not use the Service to access blocked content, unauthorized VoIP services, prohibited categories, gambling, adult content, illegal financial services or other restricted resources.
UAE 1.5. BusinessProxy may disable UAE access or egress immediately if local law, provider rules or risk assessment requires it.
9I. India Addendum - No Self-Service Until Compliance Approval
IN 1.1. India self-service, India egress or India-targeted marketing should not be enabled unless BusinessProxy has confirmed whether CERT-In Directions, DPDP Act, telecom/intermediary rules, local log retention, incident reporting and customer validation obligations apply.
IN 1.2. If enabled, Customer must provide accurate validated customer information, business purpose, IP allocation/use information and other details required by applicable Indian law or BusinessProxy compliance processes.
IN 1.3. BusinessProxy may implement India-specific retention, logging, incident reporting, time synchronization, customer validation, data localization or government request procedures if required.
IN 1.4. Customer must not use the Service in India to bypass government blocking orders, legal restrictions, platform rules, sanctions, cybercrime laws or telecom licensing requirements.
IN 1.5. BusinessProxy may block India users, India egress or India contracting until local compliance is operationally ready.
9J. Mainland China Addendum - No Global Service Unless Licensed
CN 1.1. The Global Service is not offered as a Mainland China cross-border proxy, VPN, dedicated line, telecom service or Great Firewall bypass tool.
CN 1.2. Mainland China egress, China-targeted sales, China-based users, China internal applications or China cross-border connectivity require local licensing and legal review before launch.
CN 1.3. Customer must not use the Service in or for Mainland China to bypass network controls, provide unauthorized cross-border access, evade telecom rules, violate PIPL, circumvent content restrictions or provide service to persons who cannot lawfully receive it.
CN 1.4. BusinessProxy may geoblock Mainland China access, reject China-related orders and disable China-related configurations unless a licensed local structure is approved.
9K. Russia and CIS Note
RU 1.1. The Russian local service should be governed by a separate Russian-language offer, Russian privacy policy and Russian regional operator terms. These Global Terms do not authorize use of the Global Service to evade Russian law, sanctions, blocking, provider restrictions or regional availability rules.
RU 1.2. If a Customer contracts with a Russian regional operator, that operator is responsible for Russian local contracting, payment, tax, personal data, filtering and lawful request handling, subject to separate local documents.
RU 1.3. Global BusinessProxy may exclude or restrict Russia-related transactions, users, egress, payments, support or software access where required by sanctions, export controls, provider rules, payment rules or risk policy.
Schedule 10. Contact Details and Contract Variables
The following fields identify the contracting, support, privacy, security and regional variables for the applicable Service. The applicable Contracting Entity, regional website, checkout flow or Order Form must display the final values before Customer accepts the Service.
Global contracting entity — UPRAVTREB LLC (OOO «UpravTreb»), OGRN 1247700140973, INN 9709106589, Nizhny Susalny lane 5, bld. 19, Basmanny District, 105064 Moscow, Russia
Main website — https://business-proxy.com
Global legal notices — office@upravtreb.ru
Privacy requests — pd@upravtreb.ru
Security reports — office@upravtreb.ru
Abuse reports — office@upravtreb.ru
Law enforcement requests — office@upravtreb.ru
Support — support@business-proxy.com
Subprocessor list URL — https://business-proxy.com/trust#subprocessors
Privacy Notice URL — https://business-proxy.com/legal/privacy
Cookie Notice URL — https://business-proxy.com/legal/cookies
AUP URL — https://business-proxy.com/legal/acceptable-use
DPA URL — Available on request via office@upravtreb.ru
Log retention URL — https://business-proxy.com/legal/log-retention
Payment provider disclosures — YooKassa — one-time payment; manual renewal, refund and tax handling per YooKassa rules, checkout terms and applicable law.