This page summarises how Dual Login approaches legal and regulatory compliance. It is an overview and points to the detailed policies elsewhere in our Trust Center.
In plain English
A policy has to be precise, which makes it hard to read. Here is the same document answered as the questions people usually arrive with. It is a summary: where the two could be read differently, the numbered sections below govern.
What does this page cover?
The obligations that sit on us as a company rather than on you as a user: data protection, how payments are handled, sanctions and export rules, and the limits on lawful use. It is the page to send to a procurement team that has asked whether you are allowed to buy this.
How is data protection handled?
Section 1, with the detail in the Privacy Policy and, for business customers who need processor terms, the DPA. The design principle behind all three is the same: collect little, keep it briefly, never sell it. Least data is also the cheapest position to defend when somebody asks what you hold.
Is my card safe?
Card details go to a PCI-DSS compliant payment provider and are processed on their infrastructure — section 2. Full card numbers never reach our servers, which means a breach of us is not a breach of your card. That is a deliberate architectural choice, not a description of good intentions.
Are there places you will not sell to?
Yes. Section 3 covers sanctions and export controls, and they are not optional for us or negotiable by you. If your organisation sits in a restricted jurisdiction, we would rather tell you before you subscribe than after.
What does lawful use mean here?
Section 4, and it points back at the Acceptable Use Policy. The product is legal, widely used for ordinary commercial work, and the fact that it can be misused makes it like most tools. What we ask is that your use is lawful where you are and consistent with the agreements you have made with the platforms you use it on.
Can I use this document for a vendor security review?
That is what it is for. It gathers the answers procurement teams ask in the order they usually ask them, and it links to the Security Policy for controls and the DPA for processor terms. If a questionnaire needs something these three do not cover, email legal@duallogin.com rather than guessing -- we would rather answer once than have someone reverse-engineer a position from a marketing page.
Are you certified to any particular standard?
This page states what we do rather than which badges we hold, and it is worth being precise about that distinction: card handling is delegated to a PCI-DSS Level 1 provider, so that compliance is theirs and the effect on you is real, while the practices in the Security Policy are ours and described directly. Where an attestation exists we will say so; where it does not, we would rather describe the control than imply an audit that has not happened.
What happens if sanctions rules change while I am a customer?
We follow the rules as they stand, which can mean a change affects an existing account rather than only new signups. Section 3 is not a formality -- it is one of the few places where something outside both our control and yours can end a working relationship, and we would rather that be visible in advance than discovered.
Is an antidetect browser legal?
The software is legal and is used for ordinary commercial work every day -- QA across environments, agencies holding client accounts, price and market research on public data, journalists and researchers keeping work compartmentalised. Like most tools it can also be misused, which is why the Acceptable Use Policy names the misuse specifically. The question that actually matters is not whether the category is legal, but whether your particular use is lawful where you are and consistent with the agreements you have made.
Who is the contracting entity?
Keyback Systems Ltd., at the address on the contact page, with Bangladesh as the governing jurisdiction. Procurement teams ask this early and it is better answered plainly than discovered in a footer -- if your organisation has constraints on counterparty jurisdiction, that is worth knowing before an evaluation rather than after.
Can you complete our security questionnaire?
Yes. Send it to legal@duallogin.com. Most of what these ask is already answered across the Security Policy, this page and the DPA, and where a question needs an answer none of them give, we will answer it rather than pointing at a document that does not quite address it.
Do you have a point of contact for regulators?
legal@duallogin.com reaches the people who can answer, and a request that identifies itself as coming from a regulator or a data protection authority is treated as such rather than routed through ordinary support.
1. Data protection
We are GDPR- and CCPA/CPRA-aware. We minimise data collection, honour data subject rights, use Standard Contractual Clauses for international transfers, and offer a Data Processing Addendum to business customers. See our Privacy Policy and DPA.
2. Payments (PCI-DSS)
Payments are processed by Stripe, a PCI-DSS Level 1 certified provider. Card data is handled by Stripe and is not stored on our servers, which reduces risk and keeps us within scope-appropriate boundaries.
3. Sanctions and export controls
We do not knowingly provide the Services to individuals or entities on applicable sanctions lists or in embargoed regions, and you agree not to use the Services in violation of sanctions or export-control laws.
4. Lawful use
Our Acceptable Use and Anti-Abuse Policies prohibit fraud, cybercrime, money laundering and other illegal activity, and we enforce them. Dual Login is intended for legitimate business and privacy purposes.
5. Questions
Compliance, security or legal questions? Email legal@duallogin.com.