CrawlVolt
GDPR

Data Processing Addendum

Processor commitments for customer personal data handled by CrawlVolt.

Version 1.0 - 11 August 2026

1. Application

This DPA forms part of the Terms or a commercial order when CrawlVolt processes personal data on behalf of a customer. The customer is controller and CrawlVolt is processor, unless the parties agree otherwise. GDPR terms have the meanings given in Regulation (EU) 2016/679.

2. Instructions and purpose

CrawlVolt processes customer personal data only to provide, secure and support the subscribed service, according to documented customer API requests, configuration and instructions. CrawlVolt will inform the customer if an instruction appears to violate applicable data-protection law, unless prohibited from doing so.

3. Processing details

Subject matter
Web retrieval, browser automation, extraction, search, crawl storage, sessions and related support.
Duration
The account or order term plus the documented deletion and backup periods.
Data subjects
Customer users and individuals whose data appears in customer-selected web content.
Data
Account identifiers, URLs, search queries, page content, browser-session data, request metadata and extracted output.

4. Security and confidentiality

CrawlVolt restricts access to authorised personnel bound by confidentiality. Measures include TLS in transit, scoped credentials, HttpOnly session cookies, rate and concurrency controls, encrypted persistent browser sessions, request tracing and restricted production secrets.

5. Subprocessors

The customer authorises subprocessors needed to provide the service. Current material providers are Stripe for payment processing and Microsoft Bing for Search queries. Internal Bastos services and publisher-operated French infrastructure support delivery. CrawlVolt will publish material changes before they take effect where practicable.

6. Assistance

CrawlVolt will provide reasonable assistance with data-subject requests, security incidents, impact assessments and regulator consultations. The customer remains responsible for responding to requests as controller.

7. Incidents

CrawlVolt will notify the customer without undue delay after confirming a personal-data breach affecting customer data and provide available information needed for customer assessment and notification duties.

8. Return, deletion and audit

At termination, CrawlVolt will delete or return customer personal data on request, except for data required by law or retained temporarily in protected backups. CrawlVolt will provide information reasonably necessary to demonstrate compliance.

9. Transfers and execution

Where a restricted international transfer occurs, the parties will use an applicable lawful transfer mechanism. Customers needing a countersigned copy or tailored annexes should contact privacy@crawlvolt.com.