Layer7 Technologies Inc.
Layer7 Data Processing Addendum
Last updated 2 September 2026
This Data Processing Addendum ("DPA") is part of the Terms of Service between you ("Customer") and Layer7 Technologies Inc. ("Layer7"). It applies whenever Layer7 processes personal data on your behalf as part of providing the Service, and it sets out how that processing is handled.
If anything in this DPA conflicts with the rest of the Terms of Service on the subject of processing personal data, this DPA wins.
1. How to read this
When you route a domain through Layer7, the traffic that reaches your site passes through us first. That traffic carries information about your visitors, such as their IP addresses. For that visitor data, you are the controller (you decide why it is collected and what happens to it) and Layer7 is your processor (we handle it to give you the filtering you asked for).
This DPA covers only that processor relationship: the visitor and traffic data we handle on your behalf. It does not cover your own account data, such as your email address and billing details. We are the controller of that account data, and how we handle it is described in our Privacy Policy, not here.
2. Definitions
"Controller", "processor", "data subject", "personal data", "processing", and "personal data breach" have the meanings given to them in applicable data protection law, including the EU and UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended (CCPA/CPRA).
"Applicable data protection law" means the privacy and data protection laws that apply to the processing under this DPA.
"Customer personal data" means the personal data contained in traffic that you route through the Service and that Layer7 processes on your behalf.
3. Roles and scope of processing
You are the controller of Customer personal data, and Layer7 is the processor. If you are yourself a processor acting for another controller, you confirm you have the authority to engage Layer7 as a subprocessor, and this DPA applies as though you were the controller.
Layer7 will process Customer personal data only:
- to provide, maintain, secure, and improve the Service for you, which is what "on your documented instructions" means here, with your instructions being the Terms of Service, this DPA, and your configuration and use of the Service; and
- as otherwise required by law, in which case we will tell you first unless the law forbids it.
Layer7 will not sell Customer personal data, will not share it for cross-context behavioural advertising, and will not use it for our own unrelated purposes. We process it for the purpose you engaged us for, which is filtering hostile traffic away from your sites.
4. Details of the processing
The specifics of what is processed are set out in Annex 1. In summary, the subject matter is the operation of a traffic-filtering reverse proxy, the data subjects are your website visitors and end users, and the personal data is mainly technical information carried by their requests, such as IP addresses and request metadata. Processing lasts for as long as you use the Service for the relevant domain.
5. Confidentiality
Layer7 makes sure that the people who are authorized to process Customer personal data are bound by appropriate confidentiality obligations and only access the data as needed to do their jobs.
6. Security
Layer7 keeps appropriate technical and organizational measures to protect Customer personal data against loss and against unauthorized access, disclosure, or alteration, taking into account the risk. A description of those measures is in Annex 2. Because attacks and defences change, we may update our measures over time, but we will not weaken the overall level of protection.
7. Subprocessors
You give Layer7 general authorization to use subprocessors to help provide the Service. Our current subprocessors are listed at our subprocessors page, which is part of this DPA by reference. Each subprocessor is bound by data protection terms no less protective than those in this DPA, to the extent relevant to what it does for us.
If we plan to add or replace a subprocessor that processes Customer personal data, we will update the subprocessors page. Where our agreement with you calls for advance notice, we will give it, and if you have a reasonable, data-protection-based objection to a new subprocessor, contact us and we will work with you in good faith to address it.
8. Assisting you with data subject requests
The Service is a pass-through filter, so we usually hold very little visitor data, and most of it is short-lived. If a data subject contacts us directly about data we process on your behalf, we will forward the request to you rather than respond ourselves, unless the law requires otherwise. Taking into account the nature of the processing, we will give you reasonable help to respond to requests from data subjects who want to exercise their rights.
9. Personal data breach
If Layer7 becomes aware of a personal data breach affecting Customer personal data, we will notify you without undue delay and give you the information you reasonably need to meet your own obligations, including what we know about the nature of the breach and the steps we are taking. We will not present a routine attack that our filtering handled as a breach; this is about actual compromise of Customer personal data in our care.
10. Data protection impact assessments
Taking into account the information available to us, we will give you reasonable help with data protection impact assessments and any prior consultation with a regulator, where applicable data protection law requires it and where it relates to the processing under this DPA.
11. Return and deletion
When you stop using the Service for a domain, traffic for that domain stops flowing through us. Most Customer personal data is transient and is not retained after the request that carried it: clearance tokens expire within 30 minutes, short-lived anti-replay records expire on their own, and block-list entries created during an attack expire after about 15 minutes. Sampled request records held in analytics, which can include visitor IP addresses, user-agents, and paths, are retained for up to 90 days and then cycle out; aggregated statistics are not tied to an individual visitor. Encrypted backups are overwritten on their normal rotation. On your written request after termination, we will delete or return any Customer personal data that remains, unless the law requires us to keep it.
12. Audits
On reasonable written request, and no more than once a year unless a regulator or a real incident calls for more, Layer7 will make available the information reasonably necessary to show it is meeting this DPA. Because the Service is multi-tenant and shared, we will satisfy audit rights primarily by providing documentation and answering your questions, rather than by giving direct access to systems that hold other customers' data.
13. International transfers
The Service currently runs on infrastructure located mainly in the United States, and Customer personal data may be processed there and in other countries where our subprocessors operate. Where a transfer of personal data is restricted by applicable data protection law, we rely on a lawful transfer mechanism, such as the European Commission's Standard Contractual Clauses and the UK Addendum, which are incorporated into this DPA by reference where they apply.
14. Relationship to the Terms
This DPA is subject to the Terms of Service, including their limitations of liability. Except as changed here, the Terms of Service stay in full effect.
Annex 1: Details of processing
Subject matter: Layer7's provision of a reverse-proxy traffic-filtering (DDoS mitigation) service to the Customer.
Duration: For as long as the Customer routes the relevant domain through the Service. Most data is transient; sampled request records in analytics are retained for up to 90 days, and the other short residual periods are described in section 11.
Nature and purpose: Receiving requests addressed to the Customer's protected domains, scoring and filtering them to separate legitimate traffic from hostile or automated traffic, issuing and verifying challenges where needed, maintaining short-lived clearance so real visitors are not repeatedly challenged, and producing aggregated analytics about traffic and attacks for the Customer.
Categories of data subjects: The Customer's website and application visitors and end users.
Categories of personal data:
- IP address of the visitor, including a truncated IP-prefix form used inside the clearance token.
- Request metadata: the requested URL and path, HTTP method, and request headers.
- Device and client signals: user-agent string and client hint headers.
- Connection fingerprint: a TLS or JA4-style fingerprint prefix used to tell clients apart.
- Approximate location: the country or region derived from the connection by the underlying network.
- The contents of the Layer7 clearance token described in Annex 2, which binds a cleared visitor to a network prefix and a protected service for a short time.
Special categories of personal data: None are intentionally processed. Layer7 does not ask for or target sensitive data. If the Customer's own URLs or payloads happen to carry such data, that is within the Customer's control, not something Layer7 seeks.
Annex 2: Technical and organizational measures
- Encryption in transit. Traffic to the edge and cookies set on visitors are served over HTTPS, and the clearance cookie is marked Secure and HttpOnly.
- Authenticated, tamper-evident tokens. The clearance token is signed with an HMAC using a per-tenant derived key, so a token issued for one customer cannot be reused against another and cannot be forged or altered without detection. Anti-replay records prevent a single proof from being reused.
- Data minimization at the edge. Filtering decisions are made from request signals in memory. The challenge pages shown to visitors load nothing from any third party, so visitor browsers are not exposed to outside trackers or scripts during a challenge.
- Secrets management. Signing keys and service credentials are held as platform secrets, not in source code, and internal service endpoints require an authenticated secret and refuse to start without one.
- Access controls and account security. Access to systems is limited to authorized personnel. Customer accounts support two-factor authentication, and sensitive account actions require re-authentication.
- Encrypted backups. Off-site backups are encrypted before they leave our systems and are rotated on a schedule.
- Availability by design. The Service is built to let legitimate traffic through rather than block it when our own systems are degraded, so a failure on our side does not turn into an outage for the Customer's visitors.
Annex 3: Subprocessors
The current list of subprocessors is maintained at Layer7's subprocessors page and is incorporated into this DPA by reference.
Contact
Data protection and privacy questions: support@l7.gg
Layer7 Technologies Inc. 1500 North Grant Street, Suite 429 Denver, CO 80302, USA