DATA PROCESSING ADDENDUM
Data Processing Addendum
Processor-grade and privacy-ready. This addendum covers our roles, security, subprocessors, international transfers, breach notification, and audit rights when we process personal data on your behalf.
AuraCrawl is a pre-launch service. This DPA is provided in good faith and is not legal advice; have your own counsel review it before you rely on it. Each section opens with a plain-language summary — a courtesy, not the contract; the operative text controls.
01.Overview and how to execute
This sets out how we handle personal data on your behalf. On personal-data matters, it overrides the main agreement.
This Data Processing Addendum (“DPA”) forms part of the Terms of Service and governs our processing of personal data when you use AuraCrawl, under the EU GDPR, the UK GDPR, India’s Digital Personal Data Protection Act, 2023 (“DPDP”), and U.S. state privacy laws such as the CCPA. Where this DPA conflicts with the Terms on the processing of personal data, this DPA controls.
This page is our standard DPA. A countersigned PDF, with Standard Contractual Clauses and a current subprocessor schedule, is available on request at hi@auracrawl.com.
02.Definitions
- Data Protection Law
- All laws applicable to the processing of personal data under the Terms, including the EU GDPR, the UK GDPR, India’s DPDP Act, and U.S. state privacy laws such as the CCPA/CPRA.
- Controller / Processor
- As defined under the GDPR; under the CCPA, the equivalent “business” and “service provider”. Under DPDP, “Data Fiduciary” and “Data Processor”.
- Personal Data
- Any Customer Data that constitutes personal data and is processed by AuraCrawl on your behalf under the Terms.
- Subprocessor
- Any third party engaged by AuraCrawl to process Personal Data on your behalf.
- SCCs
- The Standard Contractual Clauses approved by the European Commission, together with the UK International Data Transfer Addendum where applicable.
03.Roles and scope of processing
You decide what is collected (Controller); we act on your instructions (Processor). We flag anything that looks unlawful.
For Personal Data processed under the Terms, you are the Controller and AuraCrawl is the Processor. We process Personal Data only to (a) provide the service and perform the Terms, (b) follow your documented, lawful instructions, and (c) comply with law — and where the law requires processing, we notify you unless legally prohibited. If an instruction appears to us to violate Data Protection Law, we will promptly tell you. The subject matter, duration, nature, purpose, and categories of data are described in Annex A.
04.Our obligations
- Process Personal Data only on your documented instructions, never for our own purposes.
- Bind personnel who access Personal Data to confidentiality.
- Implement the technical and organisational measures in Annex B.
- Assist you, taking account of the nature of processing, with data-subject requests and your own security and breach obligations.
- Make available information reasonably necessary to demonstrate compliance, and allow for audits as set out below.
- Delete or return Personal Data at the end of the engagement, at your choice, unless law requires retention.
Consistent with our minimal-retention posture, we do not keep Output containing Personal Data beyond the period needed to deliver it and any retention window you configure.
05.Data-subject requests
If a person contacts us directly about their data, we forward it to you rather than acting on our own.
We will assist you, so far as reasonably possible, in fulfilling requests from data subjects exercising their rights. If a data subject contacts us directly about data we process on your behalf, we will forward the request to you where legally permitted and will not respond except to confirm receipt or as you instruct.
06.Subprocessors
We use a small set of vetted providers to run the service. They are bound to protect data, and we stay responsible for them.
You give general authorisation for us to engage Subprocessors, provided that (a) each is bound by data-protection obligations no less protective than this DPA, and (b) we remain liable for their performance. Our current categories of Subprocessor are:
| Subprocessor | Purpose | Region |
|---|---|---|
| Cloud hosting & CDN (Vercel) | Website and documentation hosting, content delivery | US / EU |
| Cloud infrastructure provider | Compute, storage, and delivery queues for extraction | US / EU |
| Analytics (Google Analytics) | Aggregate website-usage analytics | US / EU |
| Email & support tooling | Transactional email, enquiry and support handling | US / EU |
| Payment processor (when billing is enabled) | Billing and payment handling | India / US |
A current list with legal entity names is provided with the signed DPA on request. We will give reasonable advance notice of any new Subprocessor and a reasonable period to object; email hi@auracrawl.com to receive change notifications.
07.International transfers
When data crosses borders we rely on the Standard Contractual Clauses and technical safeguards.
Where processing involves transferring Personal Data from the EEA, the UK, or Switzerland to a country without an adequacy decision, the SCCs are incorporated by reference, with AuraCrawl as data importer and you as data exporter; the UK Addendum and Swiss amendments apply where relevant. Supplementary measures include encryption in transit and at rest, access controls, and a policy of challenging unlawful government-access requests. Where offered, data-residency options confine processing and storage to a chosen region.
08.Security measures
We maintain the safeguards in Annex B, appropriate to the risk, and don’t weaken them during your engagement.
We maintain the technical and organisational measures set out in Annex B, appropriate to the risk and taking account of the state of the art, the cost of implementation, and the nature and scope of processing. We may update these measures during the term provided the level of protection is not materially reduced.
09.Personal-data breach notification
If there’s a breach, we tell you without undue delay and help you respond.
We will notify you without undue delay, and in any event within the timeframe required by Data Protection Law, after becoming aware of a personal-data breach affecting your Personal Data. The notification will describe the nature of the breach, its likely consequences, the measures taken or proposed, and a contact point. We will cooperate with you to mitigate and remediate it.
10.Audit and demonstration of compliance
We give you the information needed to verify compliance, and support reasonable audits.
We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or a mandated independent auditor — subject to reasonable confidentiality and security constraints, and no more than once per year absent a breach or a regulator’s requirement. Available security documentation may be provided to satisfy an audit request.
11.CCPA and U.S. state-law terms
Under U.S. state law we are a “service provider”: we don’t sell or share your data, or use it beyond running your service.
To the extent the CCPA applies, AuraCrawl is a “service provider” and certifies that it will: (a) not sell or share Personal Data; (b) not retain, use, or disclose Personal Data except to perform the service or as the CCPA permits; (c) not combine Personal Data with data from other sources except as permitted; and (d) comply with these restrictions. Equivalent terms apply under other U.S. state privacy laws where relevant.
12.Term, deletion, and return
The DPA lasts as long as we process your data. At the end, we delete or return it at your choice.
This DPA takes effect when the Terms do and remains in force for as long as we process Personal Data on your behalf. On termination or expiry, and at your choice, we will delete or return all Personal Data and delete existing copies, unless law requires retention — in which case we will protect it and limit further processing.
13.Annex A — Details of processing
| Subject matter | Provision of the AuraCrawl web-data service and managed extraction engagements. |
|---|---|
| Duration | The term of the Terms plus any agreed wind-down period. |
| Nature & purpose | Retrieval, structuring, transformation, and delivery of publicly accessible web data per your instructions. |
| Categories of data subjects | As determined by your instructions; you are responsible for the lawful basis. |
| Categories of personal data | As determined by your instructions; no special-category data without prior written agreement and safeguards. |
| Frequency | Continuous or batch, per your configuration. |
14.Annex B — Security measures
- Encryption. TLS 1.3 in transit and AES-256 at rest.
- Access control. Least-privilege, role-based access with unique credentials and multi-factor authentication for administrative access.
- Network security. Segmentation, firewalls, and restricted ingress and egress.
- Logging & monitoring. Centralised logging with alerting and anomaly detection.
- Resilience. Redundancy, backups, and tested recovery procedures.
- Vulnerability management. Patching, dependency scanning, and periodic testing.
- Personnel. Confidentiality obligations and security awareness for anyone with access.
- Incident response. A documented detection, escalation, and notification process.
Legal, privacy, or compliance questions go to a person, not a ticket queue — write to hi@auracrawl.com.