BotCruncher
ProductDetectionROIPricingFAQ
Sign inStart free
Legal · GDPR Art. 6(1)(f)

Legitimate Interest Assessment Template

This template helps you document your legitimate interest assessment for using BotCruncher. Adapt it to your specific circumstances and retain it as part of your GDPR compliance records.

1. Purpose Test

What is the legitimate interest you are pursuing?

  • Detecting bot traffic on paid advertising campaigns (Google Ads, Meta Ads, etc.) to prevent ad spend waste
  • Quantifying the financial impact of fraudulent clicks on our advertising budget
  • Generating IP exclusion lists to block known bot IPs from receiving our ads
  • Identifying AI crawlers and scrapers accessing our website content without permission
  • Protecting the integrity of our website analytics and business metrics

Ad fraud is a documented industry problem costing businesses billions annually. Without bot detection, we cannot distinguish genuine customers from automated scripts, leading to wasted advertising spend and skewed business decisions.

2. Necessity Test

Is this processing necessary for the purpose? Could you achieve the same result with less data?

  • Consent is impractical: Bots cannot and will not give consent. A consent-based approach would only apply to human visitors, defeating the entire purpose of bot detection.
  • Minimal data collection: BotCruncher collects only behavioural signal counts (e.g., "12 mouse movements"), not the content of interactions. No form inputs, personal names, or browsing history are captured.
  • IP addresses are necessary: IP addresses are essential for identifying datacenter traffic, VPN usage, and generating exclusion lists for ad platforms. There is no alternative identifier that serves this purpose.
  • No less intrusive alternative exists: Ad platform built-in fraud protection is insufficient — industry studies consistently show significant undetected invalid traffic. Third-party detection using behavioural signals is the industry standard approach.
  • No cookies: The BotCruncher snippet sets no cookies and does not track visitors across sites.

3. Balancing Test

Do the individual's rights and freedoms override the legitimate interest?

Impact on data subjects

  • No personal content is captured — only aggregate behavioural counts and technical metadata
  • No cookies are set on visitors' browsers
  • No cross-site tracking — each website's data is completely isolated
  • Data is not used for advertising, profiling, or any purpose other than fraud detection
  • The processing is invisible to the visitor and does not affect their experience

Reasonable expectation

  • Website visitors reasonably expect that websites will take measures to prevent fraud
  • The processing is analogous to security cameras in a shop — a proportionate response to a genuine threat
  • Bot detection is widely adopted across the industry (reCAPTCHA, Cloudflare Bot Management, etc.)

Data minimisation

  • Limited retention period tied to subscription plan (7–365 days depending on plan)
  • Automatic deletion via scheduled cleanup jobs
  • All data stored and processed exclusively within the EU (Hetzner, Germany)
  • No data transfers outside the European Economic Area
Conclusion: The legitimate interest in detecting ad fraud outweighs the minimal impact on data subjects, given the limited nature of the data collected, the absence of cookies and cross-site tracking, and the strong safeguards in place.

4. Safeguards

  • Transparency: Our privacy policy discloses BotCruncher's data collection, including what data is collected and why
  • IP erasure tool: Site owners can erase all data for a specific IP address via the dashboard Data Rights tool
  • Account deletion: Users can delete their entire account and all associated data at any time
  • Plan-based retention: Data is automatically deleted after the retention period for the site owner's plan
  • Data Processing Agreement: A DPA is available at botcruncher.com/dpa
  • Security: TLS encryption, PostgreSQL Row-Level Security, bcrypt password hashing, Hetzner ISO 27001-certified data centres
  • Right to object: Visitors can contact us to exercise their GDPR rights, including objection to processing

Sample Privacy Policy Paragraph

Copy this into your website's privacy policy to disclose BotCruncher's data collection to your visitors.

We use BotCruncher (botcruncher.com), an EU-hosted bot detection service, to identify fraudulent bot traffic on our website. BotCruncher collects IP addresses, user-agent strings, and behavioural signals (mouse movement counts, scroll depth, time on page) from visitors. This processing is based on our legitimate interest in detecting ad fraud and protecting our advertising spend (GDPR Art. 6(1)(f)). No cookies are set, no personal content is captured, and data is retained for a limited period based on our plan. For more information, see BotCruncher's privacy policy at botcruncher.com/privacy.

Record-keeping

Assessment date[Your date]
Conducted by[Your name / role]
Data controller[Your company name]
Data processorBotcruncher.com (Sweden)
Review date[Date — review annually or when processing changes]
© 2026 BotCruncher · Copenhagen
PrivacyTermsDPALIAStatus · all systems go