BotCruncher
ProductDetectionROIPricingFAQ
Sign inStart free
Legal

Data Processing Agreement

Effective: 12 March 2026

1. Parties

This Data Processing Agreement ("DPA") is entered into between:

  • Controller: The customer ("you") who has registered for a BotCruncher account and installed the JavaScript snippet on their website(s).
  • Processor: Botcruncher.com, a sole trader (enskild firma) registered in Sweden ("BotCruncher", "we", "us").

This DPA forms part of and is incorporated into the Terms of Service. It applies to all processing of personal data by BotCruncher on behalf of the Controller.

2. Subject matter and duration

BotCruncher processes personal data for the purpose of bot detection, ad fraud analysis, and AI crawler identification on the Controller's website(s). Processing begins when the Controller installs the BotCruncher JavaScript snippet and continues for the duration of the subscription. Upon termination, data is deleted according to the retention schedule for the Controller's plan.

3. Types of personal data processed

Data typePurpose
IP addressesGeolocation, datacenter/residential classification, exclusion list generation
User-agent stringsBrowser identification, known bot signature matching
Behavioural signal countsMouse movements, scroll depth, click count, time on page (aggregate counts only)
Browser capability flagsWebGL, WebRTC, canvas fingerprint hash, screen resolution, timezone
Page URL and referrerAd click parameter detection (gclid, fbclid, etc.)

No special category data (Art. 9 GDPR) is processed. No form inputs, personal names, email addresses, or payment details of website visitors are collected.

4. Categories of data subjects

Visitors to the Controller's website(s) where the BotCruncher JavaScript snippet is installed. This includes both human visitors and automated bots/crawlers.

5. Processor obligations

BotCruncher shall:

  • Process on documented instructions: Process personal data only for the purposes of bot detection and ad fraud analysis as described in this DPA and the Terms of Service. We will not process data for any other purpose.
  • Confidentiality: Ensure that all persons authorised to process personal data are bound by confidentiality obligations.
  • Security: Implement appropriate technical and organisational measures to protect personal data (see Section 8).
  • Sub-processors: Only engage sub-processors with the Controller's prior knowledge and under written contracts imposing equivalent data protection obligations (see Section 6).
  • Assist with data subject rights: Assist the Controller in responding to data subject requests. The IP erasure tool in the dashboard enables Controllers to delete all data for a specific IP address without contacting BotCruncher.
  • Assist with compliance: Assist the Controller with data protection impact assessments and prior consultation with supervisory authorities where required.
  • Deletion on termination: Delete all personal data upon termination of the subscription, subject to the retention schedule for the Controller's plan. Aggregated, non-personal daily reports may be retained.
  • Audit: Make available evidence of compliance with this DPA on reasonable request (see Section 9).

6. Sub-processors

BotCruncher uses the following sub-processors:

Sub-processorLocationPurposeTransfer mechanism
Hetzner Online GmbHGermany, EUServer infrastructure and data storageEU/EEA — no transfer
Cloudflare, Inc.Global (transient edge processing)Reverse proxy (CDN, DDoS protection). HTTP requests are transiently processed at Cloudflare edge locations worldwide. No personal data is stored beyond transient request processing. Origin data storage remains exclusively in the EU (Hetzner, Germany).
Stripe, Inc. / Stripe Payments Europe LtdUS (contracted via Stripe Payments Europe Ltd, Ireland)Payment processingUnder review
Resend, Inc.USTransactional email deliveryUnder review
Instantly.ai, Inc.USOutbound sales emailUnder review
Fastmail Pty LtdAUOperator mailboxUnder review
Google LLC (Google Ads API)USAd-account integration for exclusion listsUnder review

We will notify the Controller of any intended changes to sub-processors by email at least 30 days before the change takes effect, giving the Controller the opportunity to object.

7. International transfers

All personal data is stored exclusively within the European Union. Our servers are located at Hetzner data centres in Germany. No personal data is stored outside the EU/EEA. Transient request processing occurs at Cloudflare edge locations worldwide (see Section 6).

Cloudflare acts as a reverse proxy (CDN, DDoS). HTTP requests are transiently processed at Cloudflare edge locations worldwide. No personal data is stored by Cloudflare beyond transient request processing. Origin data storage remains exclusively in the EU (Hetzner, Germany). Stripe processes payment data under their own controller-to-controller relationship with the account holder.

8. Security measures

BotCruncher implements the following technical and organisational security measures:

  • Encryption in transit: All data transmitted over TLS (HTTPS). Internal service communication encrypted.
  • Data isolation: PostgreSQL Row-Level Security (RLS) ensures each customer's data is logically isolated at the database level.
  • Authentication: bcrypt password hashing (cost factor 12), JWT-based session tokens with 7-day expiry.
  • Access control: API key authentication for data collection, JWT authentication for dashboard access.
  • Intrusion prevention: fail2ban SSH protection, UFW firewall with minimal open ports.
  • DDoS protection: Cloudflare proxy with rate limiting.
  • Automatic data cleanup: Scheduled retention jobs delete visitor data beyond the plan's retention period.
  • Physical security: Hetzner ISO 27001-certified data centres with 24/7 security, biometric access controls.

9. Data subject rights

BotCruncher provides the following tools to assist Controllers in fulfilling data subject requests:

  • IP erasure tool: Controllers can delete all visits, fingerprints, bot scores, and conversions associated with a specific IP address via Settings > Data Rights in the dashboard.
  • Account deletion: Controllers can delete their entire account and all associated site data at any time.
  • Manual requests: For requests that cannot be fulfilled via self-service tools, Controllers can contact [email protected] and we will respond within 72 hours.

10. Audit

BotCruncher will make available to the Controller, on reasonable written request, evidence of compliance with the obligations set out in this DPA. This may include security documentation, compliance certifications, or answers to a reasonable data protection questionnaire. On-site audits may be conducted at the Controller's expense with at least 30 days' prior written notice, subject to confidentiality obligations.

11. Breach notification

In the event of a personal data breach, BotCruncher will notify the Controller without undue delay and in any case within 72 hours of becoming aware of the breach. The notification will include the nature of the breach, the categories and approximate number of data subjects affected, and the measures taken or proposed to address the breach.

12. Governing law

This DPA is governed by Swedish law. Any disputes shall be resolved in accordance with the dispute resolution provisions of the Terms of Service.

13. Contact

For questions about this DPA or to exercise any rights under it, contact:

Botcruncher.com
Email: [email protected]
Sweden, EU

© 2026 BotCruncher · Copenhagen
PrivacyTermsDPALIAStatus · all systems go