How it works Features Pricing Scrapers
Terms of Service Privacy Policy GDPR Compliance Data Processing Agreement Cookie Policy Acceptable Use Policy Legal Notices

On this page

    GDPR Compliance

    Last updated: 22 July 2026

    This page is a plain-language overview. The legally binding documents are the Privacy Policy (for your account and our website) and the Data Processing Agreement (for data processed through the Service on your behalf).

    Who processes what

    Two distinct processing situations exist when you use ScrapeFleet:

    • Your account, billing and website visits. ScrapeFleet is the data controller. What we collect and why is described in the Privacy Policy.
    • Data extracted from websites you target. You choose the targets and the fields; if the extracted content includes personal data (for example names appearing on public pages), you are the controller of that data and ScrapeFleet processes it strictly on your instructions as a processor, under the Data Processing Agreement. You are responsible for having a lawful basis for that collection and use.

    Where data lives

    Our core infrastructure — databases, storage of extraction results and analysis artifacts, and execution workloads — runs on Amazon Web Services in the EU (Stockholm, eu-north-1). Advanced page-fetching is provided by Zyte Ltd (Ireland).

    Machine-learning providers

    Building and repairing scrapers uses machine-learning models. During those build and repair steps, content of the pages being analysed (which can include any personal data visible on those pages) is submitted to model providers acting as subprocessors. The current provider list, locations, and the transfer safeguards applied are maintained in the DPA. We use provider configurations under which submitted content is not used to train the providers' models; where a provider's standard terms would otherwise permit such use, we put contractual restrictions in place before routing content to that provider.

    Security in brief

    • Encryption in transit (TLS) for all external interfaces.
    • Untrusted extraction code executes in isolated sandboxes with no filesystem or network access.
    • Access to production systems is restricted and logged; secrets are stored in a managed secrets service, not in code.
    • Payment card data never touches our systems (hosted payment pages).

    The full list of technical and organisational measures is Annex C of the DPA.

    Deleting your data

    You can delete individual scrapers and their stored results from the dashboard. To delete your account and associated personal data, contact team@scrapefleet.ai; deletion is completed within 30 days except where retention is legally required (e.g. invoices).

    Data subject requests concerning scraped data

    If an individual contacts us about personal data that a customer collected through the Service, we will refer the request to the customer as controller and assist as required by Art. 28 GDPR. Individuals may contact us at team@scrapefleet.ai.

    © 2026 ScrapeFleet AI. · Scrapers · Pricing

    Terms of Service · Privacy Policy · GDPR Compliance · Data Processing Agreement · Cookie Policy · Acceptable Use Policy · Legal Notices · Cookie Settings

    We use one strictly necessary cookie to keep you signed in, and — only with your consent — Google Analytics cookies to understand how the site is used. See the Cookie Policy.