Data Processing Agreement
Last updated: 22 July 2026
This Data Processing Agreement ("DPA") forms part of the agreement between CPL TECH MB ("ScrapeFleet", the "Processor") and the customer (the "Controller") under the Terms of Service. It applies whenever personal data within the meaning of the GDPR is processed through the Service at the Controller's direction, and is entered into pursuant to Art. 28(3) GDPR.
1. Roles and scope
The Controller alone determines which websites the Service accesses and which data is extracted. The categories and volume of personal data contained in extracted content are therefore determined solely by the Controller's configuration choices. ScrapeFleet processes such data exclusively as Processor, on the Controller's documented instructions, which consist of: the Controller's scraper configurations, use of Service features, the Terms, and this DPA. Annex A describes the processing.
For account, billing and website data, ScrapeFleet is an independent controller as described in the Privacy Policy; that processing is outside this DPA.
2. Controller obligations and warranties
The Controller warrants that it: (a) has and will maintain a valid legal basis for the collection and intended use of all personal data it processes through the Service; (b) has provided any required privacy notices to, and obtained any required consents from, affected individuals; (c) has performed a data protection impact assessment where required; (d) will not use the Service to process special categories of personal data (Art. 9 GDPR) or data relating to criminal convictions (Art. 10 GDPR); and (e) will issue no instruction that would cause the Processor to violate applicable law. The Controller indemnifies the Processor against claims arising from breach of this Section.
The Processor does not intentionally process special-category data; any such data inadvertently contained in content selected by the Controller is processed on the Controller's sole responsibility.
3. Processor obligations
The Processor shall: (a) process personal data only on documented instructions, including with regard to international transfers, unless required by EU or Member State law (in which case it will inform the Controller before processing, unless prohibited); (b) ensure persons authorised to process the data are bound by confidentiality; (c) implement the technical and organisational measures in Annex C; (d) respect the subprocessor conditions in Section 4; (e) taking into account the nature of the processing, assist the Controller with data subject requests (Arts. 12–23) and with the Controller's obligations under Arts. 32–36; (f) notify the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Controller's data, providing the information required by Art. 33(3) as it becomes available; (g) at the Controller's choice, return in a machine-readable format or delete all personal data within 30 days of the end of the services, unless EU or Member State law requires storage; and (h) make available information necessary to demonstrate compliance and allow audits under Section 6.
4. Subprocessors
The Controller grants general authorisation for the subprocessors listed in Annex B. The Processor will give at least 30 days' notice of intended additions or replacements (via the Service or e-mail); the Controller may object within 15 days on reasonable data-protection grounds, in which case the parties will seek a solution and, failing one, the Controller may terminate the affected services. The Processor imposes data-protection obligations on subprocessors materially equivalent to this DPA and remains fully liable for their performance.
Transmission-only infrastructure. Internet carriers and proxy/IP-transit providers that relay encrypted traffic between the Service and target websites, without the ability to access the content of that traffic, are engaged as telecommunications infrastructure rather than as subprocessors and are not listed in Annex B. Providers that access retrieved content in order to perform their service (such as fetching/unblocking APIs) are listed.
5. International transfers
Processing and storage of extraction results occurs primarily in the EU (Annex B). Where a subprocessor processes personal data in a third country without an adequacy decision, the transfer is governed by the European Commission's Standard Contractual Clauses (2021/914), Module 2 (controller-to-processor) or Module 3 (processor-to-subprocessor) as applicable, together with supplementary measures where required. Annex B states the mechanism per subprocessor.
6. Audits
No more than once per year and on at least 30 days' notice, the Controller may audit the Processor's compliance with this DPA, at its own cost, during business hours, without disrupting operations, and not through a competitor of the Processor. The Processor may first satisfy the audit by providing recent independent audit reports or certifications and written responses.
7. Liability, term, law
Liability under this DPA is subject to the limitations of the Terms, except where mandatory data protection law provides otherwise. This DPA applies for as long as the Processor processes personal data for the Controller. It is governed by the law of the Terms, subject to mandatory provisions of the GDPR and Lithuanian data protection law.
Annex A — Description of processing
- Subject matter and nature: automated retrieval of content from websites designated by the Controller; extraction of Controller-defined fields; automated construction, verification and repair of extraction configurations (including analysis of retrieved page content by machine-learning models); storage and delivery of results.
- Duration: the term of the agreement plus the deletion period of Section 3(g).
- Purpose: providing the website-to-API service described in the Terms.
- Categories of data: any personal data appearing in content of pages selected by the Controller (typically: names, public contact details, seller/author identifiers, prices and offers connected to persons). Determined solely by the Controller. Special categories are not intended to be processed.
- Data subjects: individuals whose data appears on the websites selected by the Controller.
Annex B — Authorised subprocessors
| Subprocessor | Role | Location | Transfer mechanism |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Hosting, storage, execution (eu-north-1, Stockholm); transactional e-mail (Amazon SES) | EU (Sweden) | EU processing; AWS DPA with SCCs for support access |
| Zyte Ltd | Web page fetching / unblocking infrastructure | Ireland (EU) | EU processing |
| Google LLC (Gemini API) | ML analysis of retrieved page content during scraper build/repair | USA / EU | EU–US Data Privacy Framework / SCCs |
| Anthropic PBC | ML analysis of retrieved page content during scraper build/repair | USA | SCCs |
| Moonshot AI PTE. LTD. | ML analysis of retrieved page content during scraper build/repair | Singapore | SCCs |
| DeepInfra Inc. | ML inference (fallback/benchmark capacity) | USA | SCCs |
The current version of this list is always available at this page. Payment processing (Revolut) relates to Controller account data and is covered by the Privacy Policy, not this DPA.
Annex C — Technical and organisational measures
- Encryption in transit (TLS 1.2+) for all external interfaces; encryption at rest for object storage and databases.
- Isolation of untrusted extraction code in sandboxed execution environments without filesystem, network or process access.
- Authentication on all internal service-to-service interfaces using secrets held in a managed secrets store; no credentials in source code.
- Role-limited production access for authorised personnel only; access is logged.
- Logical separation of customer data by account identifiers; automated lifecycle deletion rules on transient processing artifacts.
- Backups and the ability to restore availability after an incident; monitoring and alerting on anomalous usage.
- Vendor due diligence and data processing agreements with all subprocessors.
- Card payment data handled exclusively by the payment provider (hosted pages); never stored on ScrapeFleet systems.