Skip to content

Data Processing Agreement

Version 1.0 — 16 September 2026

This Data Processing Agreement ("DPA") applies whenever you use scrape.land to process personal data. It forms part of our Terms of Service and takes effect when you accept them, so there is nothing to sign: it is already in force for every account. If your procurement process needs a countersigned PDF, email legal@scrape.land and we will return one.

Your contract is with ZOOMERS DATA COLLECTION SRL, CUI 55170282, J2026043628007, Șos. Bucium 55 K, Bl. C3, Sc. 3, Et. 7, Ap. 7, 700280 Iași, România ("Scrapeland", "we") — full company details. This page is written in English and the English text governs; we will supply a Romanian or Italian translation on request, for reading only.

1. Who is who

For the data you send through the Service and the content it returns — together, Customer Contentyou are the controller and we are your processor. If you are yourself someone else's processor, we are your sub-processor and the same terms apply down the chain.

For your own account — your email address, password hash, API key hashes, billing records and the usage metadata we meter you on — we are the controller, and our Privacy Policy governs instead. The two roles are separate, and this page is only about the first.

2. What we process for you, and for how long

You decide what to send us; we cannot know in advance whether a page you fetch contains personal data. In practice the processing is:

What we keep is deliberately narrow, and these are the numbers the software actually enforces:

3. Our instructions come from you

We process Customer Content only on your documented instructions. Your API calls are those instructions; this DPA and the Terms are the rest of them. We will tell you if an instruction appears to breach data protection law, and we may refuse it. If a law requires us to process for another reason, we will tell you first unless that law forbids it.

You are responsible for having a lawful basis for what you collect, for the transparency your own data subjects are owed, and for whether fetching a given destination is lawful for you. We check none of that, and nothing in the Service should be read as advice that a particular scrape is permitted. Our Acceptable Use Policy sets the outer limit of what you may do with the Service at all.

4. Confidentiality

Everyone with access to Customer Content is bound by confidentiality. Access to production systems is limited to the people who operate the Service, and is used for support, security and keeping it running.

5. Security

Our technical and organisational measures (Art. 32), as implemented today:

We hold no ISO 27001 or SOC 2 certification and do not claim one.

6. Sub-processors

You give us general authorisation to use the sub-processors in Annex III. We will announce any addition or replacement on this page and by email to your account address at least 30 days before it starts processing. If you object on reasonable data protection grounds, tell us within those 30 days; if we cannot offer an alternative, you may terminate the affected part of the Service, and unused prepaid credit is handled under our Refund & Cancellation Policy.

Each sub-processor is bound by a written contract with data protection terms no weaker than these, and we remain liable to you for what they do.

7. The free proxy pool is not for personal data

Requests on the free tier, and any request our gateway serves from the public pool, leave through third-party proxy servers we do not operate and have no contract with. We cannot give you Art. 28 guarantees for those exits. Use HTTPS destinations, which stay encrypted end to end through the tunnel, and if you are processing personal data, use a paid plan so your traffic leaves through contracted exits. This is a limitation of the free pool, stated plainly rather than buried.

8. International transfers

Our servers are in Germany. Some sub-processors are established outside the EEA, as marked in Annex III. Those transfers rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision where one covers the provider.

9. Data subject requests

Because we do not store the content we fetch for you, we usually cannot locate a particular person's data in it — you hold that. If a data subject contacts us about Customer Content, we will not answer them on the merits; we will forward the request to you without undue delay. We will help you meet your own obligations under Art. 12 to 23 by the means available to us.

10. Personal data breaches

If we become aware of a personal data breach affecting Customer Content, we will notify you without undue delay, and in any case within 48 hours, by email to your account address. The notice will describe what happened, which data and roughly how many records are involved, the likely consequences, and what we are doing about it — and we will follow up as we learn more.

11. Help with your obligations

On request we will give you the information you reasonably need for a data protection impact assessment or a prior consultation with a supervisory authority, to the extent it concerns our processing.

12. Deletion and return

You can delete your account yourself from the dashboard (Settings, Danger zone). That erases your account data, API keys, usage rows and stored job results. Backups age out on the schedule in section 2. After deletion we keep a one-way hash of your email address, so the same address cannot claim the free allowance twice; it cannot be reversed and is used for nothing else.

Results can be exported through the API at any time while your account is live, so there is no separate return step at the end of the contract.

13. Audits

We will make available the information needed to show we meet Art. 28, and answer your security questionnaires. You may audit once in any 12-month period, on 30 days' written notice, at your cost, under a confidentiality agreement, and without access to other customers' data. Where a supervisory authority requires more, we will cooperate with it.

14. Liability, term and law

This DPA runs for as long as we process Customer Content for you. The limitation of liability in the Terms applies to it, except where the GDPR does not permit that. Romanian law governs and the courts of Iași have jurisdiction, without prejudice to any right a supervisory authority or a data subject has elsewhere.

15. Changes

We will update this DPA when the processing changes. Material changes are announced by email to your account address and take effect no sooner than 30 days after that notice, except where the law requires a change sooner. The version and date are at the top of the page.

Annex I — Details of processing

Set out in section 2: the subject matter, duration, nature and purpose, the types of personal data and the categories of data subjects, together with the retention windows the software enforces.

Annex II — Technical and organisational measures

Set out in section 5.

Annex III — Sub-processors

Current as of the version date at the top of this page.

Sub-processorWhat it does for usWhat it can seeWhereTransfer basis
netcup GmbHServers running the API, gateway, database and local backupsEverything the Service processes, as the hosting layerGermany (EU)EU — none needed
Sendinblue SAS (Brevo)Transactional email: verification, password reset, receiptsAccount email addresses and the text of those messagesFrance (EU)EU — none needed
Stripe Payments Europe, Ltd.Card payments, subscriptions and invoicesBilling identifiers and payment data (we never see full card numbers)Ireland, with group processing in the United StatesStandard Contractual Clauses
Cloudflare, Inc.DNS, the bot check on sign-up and sign-in, and off-site backup storage (R2)Connection metadata for the bot check; encrypted backup filesUnited States and global edgeStandard Contractual Clauses
Webshare Software CompanyPaid proxy exits used by paid plansTraffic it routes; HTTPS stays encrypted end to endUnited StatesStandard Contractual Clauses
OpenRouter, Inc.Routes AI-extraction prompts to a model, only when a request asks for AI extractionThe page content and prompt sent for that extractionUnited StatesStandard Contractual Clauses
NVIDIA CorporationModel inference endpoint behind AI extraction, on the same conditionThe page content and prompt sent for that extractionUnited StatesStandard Contractual Clauses
jsDelivr (Prospect One)Serves one JavaScript library to the dashboard in your browserThe IP address and browser of whoever loads the pageEU / global edgeEU — none needed
Bunny Fonts (BunnyWay d.o.o.)Serves the web fonts used by the siteThe IP address and browser of whoever loads the pageSlovenia (EU)EU — none needed
Telegram FZ-LLCDelivers operational alerts to our on-call operatorAlert text: account ids, plans, usage figures and destination domains. Email addresses are stripped before sendingUnited Arab EmiratesStandard Contractual Clauses

The last three rows concern people who load our website rather than Customer Content: there we are the controller and the Privacy Policy applies. They are listed anyway, because a reader doing supplier diligence wants one complete list rather than two partial ones.

Public-pool proxy exits are not listed here because they are not sub-processors we can contract with — see section 7.

Contact

Data protection questions, sub-processor objections and audit requests: privacy@scrape.land. Contractual matters, including a countersigned copy: legal@scrape.land.