# Data Processing Addendum

> This DPA governs TrafficWar’s processing of customer personal data.

Version 2026-08-21 · Effective August 21, 2026

## Parties and application

TrafficWar is an online service operated by Mohammed Albadri, an individual based in New Cairo, Cairo, Egypt; it is not operated by an incorporated company. This Data Processing Addendum forms part of the Terms of Service between the operator and the TrafficWar customer. It applies when TrafficWar processes personal data in customer event data on the customer’s behalf. The customer is the controller or an authorized processor; TrafficWar is the processor or subprocessor, as applicable.

## Subject matter and duration

The processing covers collection through TrafficWar ingest endpoints; validation, transmission, storage, indexing, aggregation, querying, visualization, alerting, export, support, security, suppression, and deletion. It continues for the customer’s use of the service and afterward only for applicable retention, deletion, dispute, security, or legal requirements.

## Nature, purpose, data, and people

The purpose is to provide the observability and event-analytics features selected by the customer. Personal data may include online and account identifiers, trace or event identifiers, timestamps, routes, device and user-agent data, derived fingerprint and geography, status or error details, latency, source, labels, and customer-defined properties. Data subjects may include the customer’s users, visitors, personnel, contractors, and other people represented in submitted events.

## Customer instructions and responsibilities

TrafficWar will process covered personal data only on documented instructions in the agreement, this DPA, configured service features, and authenticated customer requests, unless law requires otherwise. The customer warrants that its instructions and use comply with applicable data-protection law, that it has a lawful basis, and that it gives required notices. The customer will not submit unnecessary special-category, highly sensitive, or regulated data unless the parties expressly agree appropriate safeguards.

## Confidentiality and access

TrafficWar limits covered data access to persons and providers who need it to operate, secure, or support the service and who are bound by appropriate confidentiality obligations. Access is scoped and reviewed according to operational need.

## Security measures

TrafficWar maintains measures appropriate to the service and risk, including TLS in transit; Secure and HttpOnly session cookies; email verification; optional and administrator-required MFA; scoped credentials and service-level authorization; browser-origin controls; rate and quota enforcement; infrastructure and account access controls; operational logging and monitoring; controlled export verification; and retention, suppression, and deletion workflows. The customer is responsible for credential security, endpoint configuration, data minimization, and its own systems.

## Subprocessors

The customer gives general authorization to use the providers on the Subprocessors page. TrafficWar remains responsible for requiring subprocessors to protect covered personal data consistently with applicable obligations. We will publish material additions or replacements where reasonably practicable. A customer may object on reasonable, documented data-protection grounds; the parties will work in good faith on a commercially reasonable alternative, and either party may end the affected service if none is available.

## International transfers

Primary processing is hosted in Frankfurt, Germany, with optional secondary storage in Germany. Cloudflare’s global network and other enabled providers may process data elsewhere. Where a restricted transfer mechanism is required, TrafficWar will rely on applicable adequacy decisions, contractual safeguards made available by the provider, or another lawful mechanism and will provide reasonable information about it on request.

## Assistance and data-subject requests

Taking into account the nature of processing and information available, TrafficWar will provide reasonable assistance with authenticated requests concerning data-subject rights, security, breach notifications, impact assessments, and regulator consultations. If TrafficWar receives a request relating to customer event data, it may direct the requester to the customer and will not independently respond except on the customer’s instruction or as law requires.

## Personal-data incidents

TrafficWar will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting covered customer data. The notice will provide available information reasonably needed for the customer’s obligations and may be updated as the investigation continues. Notification is not an admission of fault or liability.

## Return and deletion

During the service, customers can access or export data according to their plan and available product features. On authenticated instruction or termination, TrafficWar will delete or suppress covered data in accordance with service deletion workflows and retention schedules, unless law requires retention. Because archive files can contain bounded shared or boundary data, physical deletion may complete asynchronously while query-time suppression prevents ordinary access.

## Information and audits

TrafficWar will make information reasonably necessary to demonstrate compliance with this DPA available on request. If that information is insufficient, a customer may request a proportionate audit no more than once annually, or after a relevant incident, subject to confidentiality, security, reasonable notice, minimal disruption, and reimbursement of reasonable costs. Audits must not expose another customer’s data or compromise service security.

## Order of precedence and law

If this DPA conflicts with the Terms of Service on processing covered personal data, this DPA controls for that subject. The liability provisions in the Terms apply to this DPA to the extent permitted by law. This DPA is governed by Egyptian law and disputes are subject to the competent courts of Cairo, Egypt, without limiting mandatory rights or data-protection authority jurisdiction.

## Contact

Data-protection questions and processor instructions may be sent to privacy@trafficwar.tech. Operator: Mohammed Albadri, New Cairo, Cairo, Egypt.
