This Data Processing Agreement ("DPA") is entered into between:
This DPA forms part of and is incorporated into the Terms of Service. It applies to all processing of personal data by BotCruncher on behalf of the Controller.
BotCruncher processes personal data for the purpose of bot detection, ad fraud analysis, and AI crawler identification on the Controller's website(s). Processing begins when the Controller installs the BotCruncher JavaScript snippet and continues for the duration of the subscription. Upon termination, data is deleted according to the retention schedule for the Controller's plan.
| Data type | Purpose |
|---|---|
| IP addresses | Geolocation, datacenter/residential classification, exclusion list generation |
| User-agent strings | Browser identification, known bot signature matching |
| Behavioural signal counts | Mouse movements, scroll depth, click count, time on page (aggregate counts only) |
| Browser capability flags | WebGL, WebRTC, canvas fingerprint hash, screen resolution, timezone |
| Page URL and referrer | Ad click parameter detection (gclid, fbclid, etc.) |
No special category data (Art. 9 GDPR) is processed. No form inputs, personal names, email addresses, or payment details of website visitors are collected.
Visitors to the Controller's website(s) where the BotCruncher JavaScript snippet is installed. This includes both human visitors and automated bots/crawlers.
BotCruncher shall:
BotCruncher uses the following sub-processors:
| Sub-processor | Location | Purpose | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH | Germany, EU | Server infrastructure and data storage | EU/EEA — no transfer |
| Cloudflare, Inc. | Global (transient edge processing) | Reverse proxy (CDN, DDoS protection). HTTP requests are transiently processed at Cloudflare edge locations worldwide. No personal data is stored beyond transient request processing. Origin data storage remains exclusively in the EU (Hetzner, Germany). | |
| Stripe, Inc. / Stripe Payments Europe Ltd | US (contracted via Stripe Payments Europe Ltd, Ireland) | Payment processing | Under review |
| Resend, Inc. | US | Transactional email delivery | Under review |
| Instantly.ai, Inc. | US | Outbound sales email | Under review |
| Fastmail Pty Ltd | AU | Operator mailbox | Under review |
| Google LLC (Google Ads API) | US | Ad-account integration for exclusion lists | Under review |
We will notify the Controller of any intended changes to sub-processors by email at least 30 days before the change takes effect, giving the Controller the opportunity to object.
All personal data is stored exclusively within the European Union. Our servers are located at Hetzner data centres in Germany. No personal data is stored outside the EU/EEA. Transient request processing occurs at Cloudflare edge locations worldwide (see Section 6).
Cloudflare acts as a reverse proxy (CDN, DDoS). HTTP requests are transiently processed at Cloudflare edge locations worldwide. No personal data is stored by Cloudflare beyond transient request processing. Origin data storage remains exclusively in the EU (Hetzner, Germany). Stripe processes payment data under their own controller-to-controller relationship with the account holder.
BotCruncher implements the following technical and organisational security measures:
BotCruncher provides the following tools to assist Controllers in fulfilling data subject requests:
BotCruncher will make available to the Controller, on reasonable written request, evidence of compliance with the obligations set out in this DPA. This may include security documentation, compliance certifications, or answers to a reasonable data protection questionnaire. On-site audits may be conducted at the Controller's expense with at least 30 days' prior written notice, subject to confidentiality obligations.
In the event of a personal data breach, BotCruncher will notify the Controller without undue delay and in any case within 72 hours of becoming aware of the breach. The notification will include the nature of the breach, the categories and approximate number of data subjects affected, and the measures taken or proposed to address the breach.
This DPA is governed by Swedish law. Any disputes shall be resolved in accordance with the dispute resolution provisions of the Terms of Service.
For questions about this DPA or to exercise any rights under it, contact:
Botcruncher.com
Email: [email protected]
Sweden, EU