Data Processing Agreement
This Data Processing Agreement ("DPA") applies whenever you use scrape.land to process personal data. It forms part of our Terms of Service and takes effect when you accept them, so there is nothing to sign: it is already in force for every account. If your procurement process needs a countersigned PDF, email legal@scrape.land and we will return one.
Your contract is with ZOOMERS DATA COLLECTION SRL, CUI 55170282, J2026043628007, Șos. Bucium 55 K, Bl. C3, Sc. 3, Et. 7, Ap. 7, 700280 Iași, România ("Scrapeland", "we") — full company details. This page is written in English and the English text governs; we will supply a Romanian or Italian translation on request, for reading only.
1. Who is who
For the data you send through the Service and the content it returns — together, Customer Content — you are the controller and we are your processor. If you are yourself someone else's processor, we are your sub-processor and the same terms apply down the chain.
For your own account — your email address, password hash, API key hashes, billing records and the usage metadata we meter you on — we are the controller, and our Privacy Policy governs instead. The two roles are separate, and this page is only about the first.
2. What we process for you, and for how long
You decide what to send us; we cannot know in advance whether a page you fetch contains personal data. In practice the processing is:
- Subject matter and duration: providing the Service for as long as your account exists, plus the retention windows below.
- Nature and purpose: fetching the URLs you ask for through a proxy exit, optionally rendering them in a browser, optionally extracting fields from them, and returning the result to you — and metering that traffic so we can bill it.
- Types of personal data: whatever the destinations you choose return, plus anything you put in your requests (URLs, headers, request bodies). You control both.
- Categories of data subjects: whoever appears in that content.
What we keep is deliberately narrow, and these are the numbers the software actually enforces:
- Response bodies are not stored. A synchronous fetch or extraction passes through memory and is gone when the request ends. We record only metadata: timestamp, destination host, HTTP status, byte counts, exit country, plan and key id.
- Asynchronous job results are the exception. If you submit a job instead of a live request, its result is stored so you can poll for it, and deleted after 7 days.
- Usage metadata is deleted after 90 days.
- Backups: gzipped database dumps, kept 14 days on the server and 30 days off-site.
3. Our instructions come from you
We process Customer Content only on your documented instructions. Your API calls are those instructions; this DPA and the Terms are the rest of them. We will tell you if an instruction appears to breach data protection law, and we may refuse it. If a law requires us to process for another reason, we will tell you first unless that law forbids it.
You are responsible for having a lawful basis for what you collect, for the transparency your own data subjects are owed, and for whether fetching a given destination is lawful for you. We check none of that, and nothing in the Service should be read as advice that a particular scrape is permitted. Our Acceptable Use Policy sets the outer limit of what you may do with the Service at all.
4. Confidentiality
Everyone with access to Customer Content is bound by confidentiality. Access to production systems is limited to the people who operate the Service, and is used for support, security and keeping it running.
5. Security
Our technical and organisational measures (Art. 32), as implemented today:
- TLS for every connection to the API and the dashboard; HTTPS destinations travel through an end-to-end encrypted tunnel we cannot read.
- Passwords stored as bcrypt hashes; API keys stored as SHA-256 hashes and shown once at creation.
- The application connects to the database as a least-privilege role; schema changes use a separate credential.
- Only the dashboard and the proxy gateway are exposed; the database and internal services are unreachable from the internet.
- A bot check on sign-up and sign-in, rate limits, and per-account request budgets.
- Daily database backups, verified by an actual restore, copied off-site under a bucket-scoped credential.
- Data minimisation as a design rule: response bodies are not persisted, and operational alerts have customer email addresses stripped before they reach any chat webhook.
We hold no ISO 27001 or SOC 2 certification and do not claim one.
6. Sub-processors
You give us general authorisation to use the sub-processors in Annex III. We will announce any addition or replacement on this page and by email to your account address at least 30 days before it starts processing. If you object on reasonable data protection grounds, tell us within those 30 days; if we cannot offer an alternative, you may terminate the affected part of the Service, and unused prepaid credit is handled under our Refund & Cancellation Policy.
Each sub-processor is bound by a written contract with data protection terms no weaker than these, and we remain liable to you for what they do.
7. The free proxy pool is not for personal data
Requests on the free tier, and any request our gateway serves from the public pool, leave through third-party proxy servers we do not operate and have no contract with. We cannot give you Art. 28 guarantees for those exits. Use HTTPS destinations, which stay encrypted end to end through the tunnel, and if you are processing personal data, use a paid plan so your traffic leaves through contracted exits. This is a limitation of the free pool, stated plainly rather than buried.
8. International transfers
Our servers are in Germany. Some sub-processors are established outside the EEA, as marked in Annex III. Those transfers rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision where one covers the provider.
9. Data subject requests
Because we do not store the content we fetch for you, we usually cannot locate a particular person's data in it — you hold that. If a data subject contacts us about Customer Content, we will not answer them on the merits; we will forward the request to you without undue delay. We will help you meet your own obligations under Art. 12 to 23 by the means available to us.
10. Personal data breaches
If we become aware of a personal data breach affecting Customer Content, we will notify you without undue delay, and in any case within 48 hours, by email to your account address. The notice will describe what happened, which data and roughly how many records are involved, the likely consequences, and what we are doing about it — and we will follow up as we learn more.
11. Help with your obligations
On request we will give you the information you reasonably need for a data protection impact assessment or a prior consultation with a supervisory authority, to the extent it concerns our processing.
12. Deletion and return
You can delete your account yourself from the dashboard (Settings, Danger zone). That erases your account data, API keys, usage rows and stored job results. Backups age out on the schedule in section 2. After deletion we keep a one-way hash of your email address, so the same address cannot claim the free allowance twice; it cannot be reversed and is used for nothing else.
Results can be exported through the API at any time while your account is live, so there is no separate return step at the end of the contract.
13. Audits
We will make available the information needed to show we meet Art. 28, and answer your security questionnaires. You may audit once in any 12-month period, on 30 days' written notice, at your cost, under a confidentiality agreement, and without access to other customers' data. Where a supervisory authority requires more, we will cooperate with it.
14. Liability, term and law
This DPA runs for as long as we process Customer Content for you. The limitation of liability in the Terms applies to it, except where the GDPR does not permit that. Romanian law governs and the courts of Iași have jurisdiction, without prejudice to any right a supervisory authority or a data subject has elsewhere.
15. Changes
We will update this DPA when the processing changes. Material changes are announced by email to your account address and take effect no sooner than 30 days after that notice, except where the law requires a change sooner. The version and date are at the top of the page.
Annex I — Details of processing
Set out in section 2: the subject matter, duration, nature and purpose, the types of personal data and the categories of data subjects, together with the retention windows the software enforces.
Annex II — Technical and organisational measures
Set out in section 5.
Annex III — Sub-processors
Current as of the version date at the top of this page.
| Sub-processor | What it does for us | What it can see | Where | Transfer basis |
|---|---|---|---|---|
| netcup GmbH | Servers running the API, gateway, database and local backups | Everything the Service processes, as the hosting layer | Germany (EU) | EU — none needed |
| Sendinblue SAS (Brevo) | Transactional email: verification, password reset, receipts | Account email addresses and the text of those messages | France (EU) | EU — none needed |
| Stripe Payments Europe, Ltd. | Card payments, subscriptions and invoices | Billing identifiers and payment data (we never see full card numbers) | Ireland, with group processing in the United States | Standard Contractual Clauses |
| Cloudflare, Inc. | DNS, the bot check on sign-up and sign-in, and off-site backup storage (R2) | Connection metadata for the bot check; encrypted backup files | United States and global edge | Standard Contractual Clauses |
| Webshare Software Company | Paid proxy exits used by paid plans | Traffic it routes; HTTPS stays encrypted end to end | United States | Standard Contractual Clauses |
| OpenRouter, Inc. | Routes AI-extraction prompts to a model, only when a request asks for AI extraction | The page content and prompt sent for that extraction | United States | Standard Contractual Clauses |
| NVIDIA Corporation | Model inference endpoint behind AI extraction, on the same condition | The page content and prompt sent for that extraction | United States | Standard Contractual Clauses |
| jsDelivr (Prospect One) | Serves one JavaScript library to the dashboard in your browser | The IP address and browser of whoever loads the page | EU / global edge | EU — none needed |
| Bunny Fonts (BunnyWay d.o.o.) | Serves the web fonts used by the site | The IP address and browser of whoever loads the page | Slovenia (EU) | EU — none needed |
| Telegram FZ-LLC | Delivers operational alerts to our on-call operator | Alert text: account ids, plans, usage figures and destination domains. Email addresses are stripped before sending | United Arab Emirates | Standard Contractual Clauses |
The last three rows concern people who load our website rather than Customer Content: there we are the controller and the Privacy Policy applies. They are listed anyway, because a reader doing supplier diligence wants one complete list rather than two partial ones.
Public-pool proxy exits are not listed here because they are not sub-processors we can contract with — see section 7.
Contact
Data protection questions, sub-processor objections and audit requests: privacy@scrape.land. Contractual matters, including a countersigned copy: legal@scrape.land.