This template helps you document your legitimate interest assessment for using BotCruncher. Adapt it to your specific circumstances and retain it as part of your GDPR compliance records.
1. Purpose Test
What is the legitimate interest you are pursuing?
Detecting bot traffic on paid advertising campaigns (Google Ads, Meta Ads, etc.) to prevent ad spend waste
Quantifying the financial impact of fraudulent clicks on our advertising budget
Generating IP exclusion lists to block known bot IPs from receiving our ads
Identifying AI crawlers and scrapers accessing our website content without permission
Protecting the integrity of our website analytics and business metrics
Ad fraud is a documented industry problem costing businesses billions annually. Without bot detection, we cannot distinguish genuine customers from automated scripts, leading to wasted advertising spend and skewed business decisions.
2. Necessity Test
Is this processing necessary for the purpose? Could you achieve the same result with less data?
Consent is impractical: Bots cannot and will not give consent. A consent-based approach would only apply to human visitors, defeating the entire purpose of bot detection.
Minimal data collection: BotCruncher collects only behavioural signal counts (e.g., "12 mouse movements"), not the content of interactions. No form inputs, personal names, or browsing history are captured.
IP addresses are necessary: IP addresses are essential for identifying datacenter traffic, VPN usage, and generating exclusion lists for ad platforms. There is no alternative identifier that serves this purpose.
No less intrusive alternative exists: Ad platform built-in fraud protection is insufficient — industry studies consistently show significant undetected invalid traffic. Third-party detection using behavioural signals is the industry standard approach.
No cookies: The BotCruncher snippet sets no cookies and does not track visitors across sites.
3. Balancing Test
Do the individual's rights and freedoms override the legitimate interest?
Impact on data subjects
No personal content is captured — only aggregate behavioural counts and technical metadata
No cookies are set on visitors' browsers
No cross-site tracking — each website's data is completely isolated
Data is not used for advertising, profiling, or any purpose other than fraud detection
The processing is invisible to the visitor and does not affect their experience
Reasonable expectation
Website visitors reasonably expect that websites will take measures to prevent fraud
The processing is analogous to security cameras in a shop — a proportionate response to a genuine threat
Bot detection is widely adopted across the industry (reCAPTCHA, Cloudflare Bot Management, etc.)
Data minimisation
Limited retention period tied to subscription plan (7–365 days depending on plan)
Automatic deletion via scheduled cleanup jobs
All data stored and processed exclusively within the EU (Hetzner, Germany)
No data transfers outside the European Economic Area
Conclusion: The legitimate interest in detecting ad fraud outweighs the minimal impact on data subjects, given the limited nature of the data collected, the absence of cookies and cross-site tracking, and the strong safeguards in place.
4. Safeguards
Transparency: Our privacy policy discloses BotCruncher's data collection, including what data is collected and why
IP erasure tool: Site owners can erase all data for a specific IP address via the dashboard Data Rights tool
Account deletion: Users can delete their entire account and all associated data at any time
Plan-based retention: Data is automatically deleted after the retention period for the site owner's plan
Security: TLS encryption, PostgreSQL Row-Level Security, bcrypt password hashing, Hetzner ISO 27001-certified data centres
Right to object: Visitors can contact us to exercise their GDPR rights, including objection to processing
Sample Privacy Policy Paragraph
Copy this into your website's privacy policy to disclose BotCruncher's data collection to your visitors.
We use BotCruncher (botcruncher.com), an EU-hosted bot detection service, to identify fraudulent bot traffic on our website. BotCruncher collects IP addresses, user-agent strings, and behavioural signals (mouse movement counts, scroll depth, time on page) from visitors. This processing is based on our legitimate interest in detecting ad fraud and protecting our advertising spend (GDPR Art. 6(1)(f)). No cookies are set, no personal content is captured, and data is retained for a limited period based on our plan. For more information, see BotCruncher's privacy policy at botcruncher.com/privacy.
Record-keeping
Assessment date
[Your date]
Conducted by
[Your name / role]
Data controller
[Your company name]
Data processor
Botcruncher.com (Sweden)
Review date
[Date — review annually or when processing changes]