subprocessors and data recipients
effective 2026-09-07 · version 1.2.0
The first table on this page is part of our data processing agreement. It lists the subprocessors that process customer content (the pages you scrape and the results we return) on your behalf. The other tables provide transparency about independent network operators that receive target traffic and the service providers we use for our own controller-side processing.
How changes are announced: we add a new subprocessor — or a material change to an existing one — to this page and notify account owners by email at least 14 days before the change takes effect. An immediate replacement reasonably needed for security, law, or service continuity may use the shorter advance notice reasonably available, but we still notify you before it first processes customer content. The dpa gives you an objection right and, if we can't resolve an objection, a termination right with a pro-rata refund. This authorization and change process applies to subprocessors in the first table, not to independent recipients in the later tables.
How to read these tables. We list the provider's entity location (where the company is established) separately from its data location (where the data actually sits) — because the two often differ, in both directions. The personal data column states what we send, and the retention column what the provider keeps it for. A dash (–) in the retention column means the provider publishes no retention period for that data. For processors acting on our behalf, binding standard online terms or a provider DPA are sufficient; we do not promise separately negotiated paper. We require deletion under the applicable agreement. An independent controller determines its own retention under its applicable terms; the periods in our privacy policy do not bind that controller.
subprocessors (process customer content)
| provider | purpose | entity location | data location | personal data we send | retention |
|---|---|---|---|---|---|
| Scaleway SAS | core infrastructure: fetching, rendering, caching and delivery of your results; operational databases and object storage | France (EU) | France (EU) | account and organization data, hashed api tokens, usage records, and any personal data present in the pages you scrape | scrape, map and screenshot results at most 90 days; everything else per section 9 of the privacy policy |
| Bunny.net (BunnyWay d.o.o.) | content delivery network for screenshot results | Slovenia (EU) | edge locations worldwide | screenshot content, the requesting ip address with the final octet set to zero, and request metadata in edge logs | screenshot copies and request logs within 90 days |
| Grafana Labs | diagnostic logs and metrics | United States | European Union | requested urls (which may contain personal data in query strings), ip addresses and technical request metadata — never page content | up to 90 days |
| AppSignal B.V. | application performance monitoring | Netherlands (EU) | European Union | performance traces and errors, which can include a requested url or limited diagnostic metadata; our agent is configured not to send request bodies or structured parameters, session data, authorization credentials, cookies, or page content | within 90 days |
independent network operators (receive target traffic)
| recipient category | purpose | entity location | data location | personal data we send | retention |
|---|---|---|---|---|---|
| third-party proxy network operators | standardized raw-proxy connectivity for target-website traffic when your request options call for it | each established in the EU/EEA, the United Kingdom or Switzerland | gateway and exit locations worldwide, as selected by your request options | for HTTPS connections: target hostname, port, exit selection, timing, byte volume, and other connection metadata, while request and response content remains protected by target TLS; for plaintext HTTP connections: the full target url and transmitted headers, request body, and response data can be visible while relayed. We do not send crawlbrulee account details or account identifiers as part of proxy requests | connection metadata according to the applicable operator's terms; crawlbrulee does not use operator-side result caching |
These operators determine the purposes and means of the connection metadata they process to deliver, bill, secure, and protect their networks. They act as independent controllers for that processing, not as our subprocessors. We keep the public entry at category level because our agreements restrict naming the operators publicly.
We use these operators as raw relays, not for their managed scraping, parsing, or unblocker products, and not to cache or warehouse results. The distinction above applies to each target connection, including redirects and browser subresources: HTTPS content remains inside the target TLS connection, while plaintext HTTP traffic can be read in transit. We do not automatically upgrade an HTTP target to HTTPS. Operators may retain connection metadata under their applicable terms; we do not claim that they retain nothing.
We keep the current operators' identities and role assessments in our internal records. Where an operator's identity is reasonably necessary to answer a data subject request, investigate an incident, respond to a competent authority, or otherwise help a customer meet an applicable data-protection obligation, write to contact@crawlbrulee.com.
service providers for our controller-side processing
| provider | purpose | entity location | data location | personal data we send | retention |
|---|---|---|---|---|---|
| Creem (Armitage Labs OÜ, reg. 16977866) | merchant of record: payments, subscriptions, invoicing (independent controller) | Estonia (EU) | fixed hosting locations are not specified publicly; its own service providers, including its payment providers, may process data outside the EU/EEA, for which its privacy policy states that it uses safeguards such as the European Commission's standard contractual clauses | name, email address, billing address and transaction records; we never receive your full card details | under its privacy policy: contractual data 3.5 years from termination, customer due-diligence data 5 years from termination, accounting data 7 years |
| Crisp IM SAS | support chat | France (EU) | European Union (Netherlands and Germany; encrypted backups in Ireland) | your name, email address, organization name, account identifiers, ip address, and the content of your support conversations | – |
| Mailjet SAS (Sinch group) | transactional email and newsletter contact management | France (EU) | Germany and Belgium (EU) | email address, name, plan and subscription status | – |
| Google Cloud EMEA Limited (Google Workspace) | business email for our contact addresses | Ireland (EU) | United States and other locations worldwide | the contents of email you send to our contact addresses and the contact details you include | support conversations, per section 9 of the privacy policy |
| Slack Technologies Limited (Salesforce) | internal team communication and operational notifications | Ireland (EU) | United States and other locations worldwide | organization names, account identifiers, operational & customer support notifications & communications | 1 year |
| Cloudflare, Inc. | pass-through layer for internal team notifications; not used to host, serve, or store the service or customer content | United States | processed at the edge location nearest the sender, worldwide | the contents of operational notifications and support communications, in transit only | no content; technical logs for up to 7 days |
| Bunny.net (BunnyWay d.o.o.) | content delivery network for public website assets | Slovenia (EU) | edge locations worldwide | ip address with the final octet set to zero, plus request metadata in edge logs | cached copies and request logs within 90 days |
| Google Ireland Limited (Google Analytics) | website analytics — cookies only with your consent | Ireland (EU) | United States and other locations worldwide | online identifiers, ip address, device and usage data | user- and event-level data for up to 14 months; standard aggregate reports under Google's retention policies |
| Intuition Machines, Inc. (hCaptcha) | anti-abuse verification on the dashboard sign-in, sign-up, and password-reset forms | United States | regional servers near the visitor; limited metadata is processed in Europe and, where applicable, the United States | ip address, browser and device characteristics | – |
Questions about any provider on this page — including transfer safeguards for a specific one — are answered at contact@crawlbrulee.com.