GDPR Compliance
Our commitment to data protection and privacy.
Our Commitment
Crawlens is fully committed to compliance with the General Data Protection Regulation (GDPR). We have implemented technical and organizational measures to ensure the security and privacy of the personal data we process.
Data Roles
In the context of the GDPR, Crawlens acts as a Data Processor for the data uploaded by our Customers, who act as the Data Controllers. We also act as a Data Controller for the personal data of our own Customers and Visitors.
Data Processing Agreement
We have a standard Data Processing Agreement (DPA) that outlines our obligations as a Data Processor. This DPA is incorporated into our Terms of Use and applies to all customers using our Services.
Sub-processors
We use a deliberately short list of sub-processors, listed in full below. Each is bound by contract to act only on our instructions, and none of them may use your data for their own purposes. We will tell you at least 30 days before adding or replacing one, and you may object in writing within that period. A signed Data Processing Agreement is available on request and forms part of our Terms of Use.
Rows marked awaiting confirmation name a category rather than a company. We are not publishing a list we have not verified: before this page goes live, the hosting, storage and email vendors named in your order form replace them, and the list is re-checked.
| Processor | Purpose and the data it handles | Where it runs | How a transfer is safeguarded |
|---|---|---|---|
| Polar (Merchant of Record) | Taking the payment, issuing the invoice and remitting the tax | European Union (Netherlands) | EU-US Data Privacy Framework where the recipient is certified; Standard Contractual Clauses otherwise |
| Google (Gemini) | Writing the AI interpretation of a change, when AI analysis is switched on for your organization | United States | Standard Contractual Clauses; Google Data Processing Addendum |
| Google (Analytics 4 via Tag Manager) | Measuring whether our own website works, on our website only | European Union / United States | EU-US Data Privacy Framework; consent required before it runs |
| Hosting providerawaiting confirmation | Running the servers that hold the service | Named in your order form | Standard Contractual Clauses |
| Object storage (MinIO on our own server)awaiting confirmation | Holding the screenshots, page HTML and diff images that constitute the evidence | Same region as the hosting provider (named in your order form) | Not applicable — in the same place as the server, no transfer |
| Brevo (email delivery)awaiting confirmation | Delivering the transactional emails the service sends to you and your team: invitations, password resets, verification, invoices and reminders | European Union (France) | Unverified — the data processing agreement and transfer mechanism with Brevo are to be confirmed |
| Cloudflare (DNS, proxy and WAF)awaiting confirmation | Resolving your domain, routing traffic to our server and stopping unwanted requests. Infrastructure only: it does not reach our application logic. | European Union / United States (Cloudflare's global network) | Unverified — Cloudflare's data processing addenda and any regional restriction are to be confirmed |
Security Measures and Audits
Our security measures include encryption of data at rest and in transit, regular vulnerability scans, and restricted access to personal data. We conduct periodic internal audits to ensure continued compliance with our security policies.