data processing agreement
effective 2026-08-03 · version 1.0.0
This data processing agreement ("DPA") is part of the crawlbrulee terms and conditions and applies automatically to every customer — no signature is needed. If your procurement process requires a countersigned copy, write to contact@crawlbrulee.com and we will execute this same version as a pdf.
It is concluded between the customer ("you") and SC YLEMBYTES SRL, trade register no. J12/4422/2018, VAT RO39940193, Cluj-Napoca, Romania ("we", "us"), and governs the processing of personal data protected by the GDPR (Regulation (EU) 2016/679) or the UK GDPR that is contained in content you process through the crawlbrulee service.
1. roles
"Customer content" means information you submit to the service or direct it to fetch or process, together with content-bearing outputs the service produces on your behalf, regardless of format, including any personal data it contains. It also includes the personal data you supply to direct that processing: target urls and their query strings, request options and payloads, webhook configuration and, where the service supports them, customer-supplied target request headers and cookies. Changing the format, cleaning the content, or otherwise transforming it does not by itself stop it being customer content. You are the controller (or, where you act for your own customers, a processor) of the personal data in customer content. We are your processor (or subprocessor) for that data.
Separately, we are an independent controller — not your processor — for: account and organization data, billing and usage metering, security logging and abuse prevention, service performance and capacity planning, any personal-data processing involved in creating and using qualifying service data for analysis and product improvement, aggregated service statistics, and compliance with our own legal obligations.
"Service data" has the meaning given in section 10 of the terms. Information derived from customer content qualifies as service data only where it does not contain or reproduce customer content, cannot reasonably be used to reconstruct it, and does not identify you, a person, or a specific target. A specific target url remains customer content; only aggregated or de-identified information derived from it can qualify as service data. The roles described here apply per processing operation and do not change any role imposed by data protection law. Our controller-side processing is described in our privacy policy.
2. instructions
When acting as your processor, we process customer content only on your documented instructions. Your api requests and your dashboard configuration are your documented instructions: the target url, the requested formats and options, and cache settings define what we fetch, render, return, and retain for you. The terms and this DPA are also part of your documented instructions.
In that capacity, we process customer content only on those instructions, including as regards transfers to a third country, unless EU or Romanian law to which we are subject requires us to process it otherwise. In that case we inform you of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
The limited controller-side processing described in section 1 is separate from our processing on your instructions. We can process raw request-level records, including specific target urls, for the security, reliability, abuse-prevention, and troubleshooting purposes described in the privacy policy. We can also transform customer content into qualifying service data under section 1. Where we have the reasonable grounds described in section 8 of the terms, we can also inspect the content of the specific requests concerned, to the extent necessary to investigate a suspected material breach of the terms or the acceptable use policy. We do not use customer content for independent purposes except for that limited raw-record processing, that grounds-based inspection, and transformation into qualifying service data.
Some request options route target traffic through third-party proxy network operators. By submitting a request with those options, you instruct us to use that network service as described on our provider page. Those operators provide standardized raw proxy connectivity under their own terms. For connection metadata they process for their own service delivery, billing, security, and abuse-prevention purposes, they act as independent controllers rather than as our subprocessors. The provider page explains what they can see on HTTPS and plaintext HTTP connections.
If we consider that an instruction infringes the GDPR or other EU or Member State data protection law, we inform you immediately and may pause executing it until it is clarified. We are not obliged to verify the lawfulness of your targets; section 8 of the terms allocates that responsibility to you.
3. your commitments
You warrant that, for the personal data you direct us to process, you — or the controller on whose behalf you act — have a lawful basis, have provided any required notices, and have obtained any required consents or authorizations. You will not use the service to process special categories of personal data (GDPR art. 9), data relating to criminal convictions (art. 10), or data subject to sector-specific secrecy regimes (such as health, banking, or telecommunications secrecy) as a systematic purpose of your scraping, unless we have agreed to it with you in writing first. Incidental presence of such data in ordinary web content is not a breach of this clause — but its systematic, targeted collection is.
4. confidentiality
Persons we authorize to process customer content are bound by contractual or statutory confidentiality obligations. Access is limited to what is needed to operate the service and to resolve issues you raise.
5. security
We implement and maintain the technical and organizational measures described in Annex 2. They are appropriate to the risk, taking into account the state of the art, implementation costs, the nature, scope, context, and purposes of the processing, and the varying likelihood and severity of risks to individuals' rights and freedoms. We may change or improve individual measures, but will not materially weaken the overall protection they provide during your subscription.
6. subprocessors
You give us general authorization to engage subprocessors. The current list — who they are, what they process, and where — is published at /subprocessors.
- We will announce any new subprocessor that will process customer content — and any material change to an existing one — at least 14 days before it takes effect, on that page and by email to your account owners. If a replacement is reasonably necessary sooner for security, law, or to avoid a material service interruption, we may shorten that period to the advance notice reasonably available, but we will still notify you before the new subprocessor first processes customer content.
- Each subprocessor is bound to us by written data protection terms (GDPR art. 28(4)) — typically the subprocessor's standard data processing agreement, concluded electronically as part of our service agreement with it — imposing data protection obligations substantially the same as those set out in this DPA, in particular sufficient guarantees of appropriate technical and organizational measures.
- You may object in writing within the notice period on reasonable data-protection grounds relating to the announced change. For a shortened emergency period, an objection is timely if we receive it before the announced first-processing time. We respond to objections without undue delay. If we cannot offer you a way to avoid the new subprocessor, you may terminate the affected subscription; section 5 of the terms governs the unused-period refund.
- We are responsible to you for our subprocessors as article 28(4) GDPR provides.
7. assistance
Taking into account the nature of the processing, we will assist you with reasonable technical and organizational measures in fulfilling your obligations regarding:
- data subject requests. If a data subject contacts us directly about processing you control, we will refer them to you and tell you, unless the law forbids it. Our cache is short-lived (Annex 1). If you need identifiable cached content removed before automatic expiry, write to contact@crawlbrulee.com with the exact urls and any result or job identifiers you have. We use reasonable efforts to locate and remove responsive copies with the information available to us. Because the shared content cache is not attributed to an organization, we cannot promise to identify every item produced by one customer's requests or during a given period; content we cannot reliably identify expires on the ordinary schedule.
- security of processing, breach notification, impact assessments, and prior consultation (GDPR arts. 32–36). This means providing reasonable information available to us about our measures, processing, and a relevant incident. It does not transfer your controller responsibilities to us or include legal advice.
Assistance is free in the ordinary course; for requests that are excessive or unrelated to our processing we may charge our reasonable costs, telling you before we incur them.
8. personal data breaches
We notify you without undue delay after becoming aware of a personal data breach affecting customer content, with the information available to us that you reasonably need for GDPR art. 33(3), supplemented as our investigation progresses. The GDPR's 72-hour supervisory-authority deadline applies to a controller where its conditions are met; it is not a separate deadline for this processor notice. Unsuccessful attempts (blocked attacks, scans, failed logins) are not breaches. Our notification is not an acknowledgment of fault or liability. We also inform you about a personal data breach affecting account data where applicable data protection law requires us to do so.
9. deletion and return
Customer content is deleted automatically no later than 90 days after creation, and may be deleted earlier. That maximum covers every copy we hold, including backup and content-delivery copies. Retrieval of your results through the api while they remain available is the ordinary means of "return"; we do not provide a separate custom export at closure.
At the end of the provision of services, you choose whether to retrieve customer content still available through the api or have it deleted. Tell us before your account closes; if you tell us nothing, deletion is the default. Early deletion is a manual, request-based process and is subject to the identification limits in section 7. In every case, remaining customer content expires under the 90-day maximum above. We confirm the action taken or applicable expiry schedule in writing on request, except where EU or Romanian law requires us to retain specific data — in which case we keep protecting it under this DPA for as long as we hold it.
Backup copies exist only for disaster recovery and expire within the same 90-day maximum. If a restore brings back content we previously deleted in response to your request, we delete it again without undue delay.
10. audits
We demonstrate compliance first through documentation: this DPA, the subprocessor list, Annex 2, and written answers to your reasonable questions. Before requesting an audit, you must review that material and identify the GDPR article 28 obligation you reasonably believe it does not demonstrate. Where additional verification is reasonably necessary, you or an independent auditor that is not our competitor may conduct a proportionate audit limited to the processing covered by this DPA. We use remote review where it is sufficient.
Unless a personal data breach, a request from a supervisory authority, or documented reasonable indications of non-compliance require otherwise, audits are limited to once per 12 months, on at least 30 days' notice, during business hours (Romania time) and under confidentiality. An audit never permits access to other customers' data, credentials or encryption keys, and does not create a right to source code, unrestricted production systems, or information whose disclosure would create a material security or confidentiality risk. Where evidence about those matters is reasonably necessary, we may provide alternative evidence, relevant extracts, or supervised and redacted access sufficient to demonstrate compliance. You bear the audit's costs and reimburse our reasonable, documented time and out-of-pocket expenses, unless the audit establishes our material breach of this DPA.
We make available to you all information necessary to demonstrate compliance with GDPR art. 28 and allow for and contribute to audits and inspections conducted by you or an auditor you mandate. Nothing in this section limits your rights, or our obligations, under GDPR art. 28(3)(h); the arrangements above are the practical means of exercising them, not a restriction on them.
11. international transfers
We are an EU company and process customer content on infrastructure in the EU. For customers in the EU/EEA, our processing of customer content takes place in the EU — except where your request options route traffic through non-EU/EEA proxy exits, or where a listed subprocessor processes it outside the EU/EEA, as described on the provider page.
That page identifies each subprocessor and its data locations. It also describes our independent proxy network operators as a category: their contracting entities are each established in the EU/EEA, the United Kingdom or Switzerland, while gateway and exit processing can take place worldwide according to your request options. A customer-directed non-EU/EEA exit is part of your documented routing instruction, but that does not turn the exit into a non-processing location or remove any transfer rule that applies. We remain responsible for safeguards required for transfers we make; each independent network operator is responsible for transfers it makes for the processing it controls. The precise safeguard depends on the parties, roles, and route involved. For a new subprocessor arrangement that requires a transfer mechanism, we put the appropriate safeguard in place before that processing begins, using an adequacy decision or standard contractual clauses as applicable.
If a transfer from us to you outside the EU/EEA is a restricted transfer under GDPR Chapter V, we and you will use the safeguard appropriate to the actual roles and transfer — for example, the European Commission's standard contractual clauses (normally module four where you receive data as a controller, or module three where you act as a processor) or the UK International Data Transfer Addendum for UK-protected data. This is conditional: it does not require separate transfer paperwork where Chapter V does not require a safeguard. Contact contact@crawlbrulee.com where it applies.
12. liability and precedence
Liability under this DPA is subject to the limitations in section 17 of the terms, to the extent permitted by data protection law. In case of conflict between this DPA and the terms on a data-protection matter, this DPA prevails. This DPA is governed by the same law and jurisdiction as the terms.
13. changes
We update this DPA the same way as the terms (section 19 of the terms): materially adverse changes are announced at least 14 days in advance, except where section 19's immediate-change route applies, with the same termination and refund rights. Each version carries its effective date, and previous versions are archived and available on request. Section 6 governs subprocessor changes, including its shortened emergency-notice route.
annex 1 — description of processing
| subject matter | web data extraction: fetching, rendering, converting, and returning web content you designate, with optional short-term caching, link discovery, and screenshots |
| duration | for as long as you use the service; content retention at most 90 days per item, covering every copy we hold (see section 9) |
| nature and purpose | processing needed to execute your api requests: retrieval of target pages (directly or through network operators), rendering, format conversion, temporary storage for delivery and caching, webhook delivery of results |
| categories of data subjects | determined by your choice of targets: any individuals whose personal data appears on the web pages you designate (for example site owners, authors, reviewers, people mentioned in content) |
| categories of personal data | determined by your choice of targets and request inputs: personal data present in those inputs and in publicly accessible or otherwise lawfully accessible web content (for example names, contact details, identifiers, user-generated content) |
| special categories | not intended; systematic targeted collection is prohibited without prior written agreement (section 3) |
annex 2 — technical and organizational measures
- EU hosting. Core processing and storage run on cloud infrastructure in the European Union.
- Encryption in transit. TLS protects traffic between customers and the service and each connection to an HTTPS target. We do not automatically upgrade plaintext HTTP target connections: where you direct the service to such a connection, the corresponding target traffic is relayed without target-side TLS and may be visible to a network operator. For HTTPS connections, request and response content remains protected by the target TLS connection while passing through those operators. Internal connections to data stores are encrypted with pinned certificates.
- Encryption at rest. Managed storage encryption for databases and object storage.
- Credential protection. Api tokens are stored only as cryptographic hashes; secrets are kept in encrypted secret management, never in code.
- Tenant isolation. Your account data, organization data, api credentials, usage records, and job history are scoped to your organization; cross-organization access to them is treated as a security defect. The shared content cache is deliberately outside this boundary — see the next measure.
- Shared content cache. To avoid re-fetching pages that were recently
retrieved, the service keeps a short-lived cache of fetched public web content
and screenshots that is shared across customers: if you request a url that
another customer requested recently, you may receive the cached copy, and a
copy produced for your request may be served to another customer within the
retention window. The cache is intended for publicly accessible,
non-personalized content and is not designed to store crawlbrulee account
data, credentials, or request history. Setting the documented
max_agevalue to0bypasses existing cached results for your request, but does not prevent the newly fetched result from being stored or later served from the shared cache. If you access non-public or personalized content, you must be authorized to permit that shared-cache use; otherwise, do not submit the request. The cache expires automatically (Annex 1); section 7 explains the limits of early removal requests. - Access control. Production access restricted to authorized personnel on a need-to-know basis, with individual accounts.
- Workload isolation. Services run in isolated containers on a managed Kubernetes platform with segregated responsibilities.
- Automatic data expiry. Customer content is deleted automatically no later than 90 days after creation; the maximum covers every copy we hold, including backup and content-delivery copies.
- Monitoring and logging. Continuous monitoring, alerting, and audit logging of the production platform.
- Screenshot delivery. Screenshots are served from a content delivery network at unguessable urls that we do not publish in an index or sitemap. They are not individually access-controlled: anyone holding the url can retrieve the image until it expires. Treat screenshot urls as you would any other unguessable link; section 7 explains how to request early removal where the image can be identified.
- Backups. Regular encrypted backups of operational databases; backup restoration is tested. Backup copies expire within the 90-day maximum (section 9).
- Incident response. A documented internal process for detecting, assessing, containing, and notifying security incidents (section 8).
- Personnel. Confidentiality obligations and security awareness for everyone with production access.
annex 3 — authorized subprocessors
The authorized subprocessors, their roles, and their locations are published and maintained at /subprocessors; its subprocessor table is part of this DPA.
SC YLEMBYTES SRL · Cluj-Napoca, Romania · contact@crawlbrulee.com