Parties, scope and precedence
The customer identified by its CrawlPanel account or order is the “Customer”; WORDPRESS CODE SRL, Str. Grigore Cobălcescu nr. 3, corp C2, Sector 1, București 010191, România, is the “Processor”. This DPA applies to personal data submitted to monitoring, evidence, incident, reporting and notification features where Customer acts as controller or processor and CrawlPanel acts as processor or subprocessor.
This DPA is incorporated into the Terms and accepted electronically with them. If it conflicts with the Terms regarding processing of Customer Personal Data, this DPA prevails. GDPR terms have the meanings given in Regulation (EU) 2016/679.
Instructions and obligations
Processor will process Customer Personal Data only on documented instructions in the agreement, account configuration, support requests and applicable orders, including transfers, unless Union or Member State law requires otherwise. Processor will inform Customer of that requirement unless prohibited.
Processor will promptly inform Customer if, in its opinion, an instruction infringes applicable data-protection law and may suspend the affected processing. Customer is responsible for lawful instructions, notices, legal bases, target authorization and data minimization.
Confidentiality and security
Processor ensures that persons authorized to process Customer Personal Data are bound by confidentiality and access it only where operationally necessary.
Measures include tenant- and project-scoped authorization, least-privilege administration, TLS in transit, encryption of stored journey secrets, credential redaction, SSRF and private-network protections, controlled evidence access, security logging, dependency and CI checks, retention jobs and incident-response controls. Production backup and restoration controls apply only once enabled and documented for the deployed infrastructure. Measures may evolve without materially reducing overall protection.
Subprocessors
Customer gives general authorization to use subprocessors needed to provide the service. Current core subprocessors are DigitalOcean, using the FRA1 region in Frankfurt, Germany, for infrastructure, and Simplenet for transactional email. Stripe acts for payment processing under its applicable role. Google acts under its applicable role for consent-based public-site analytics and optional Google sign-in; GitHub does so only when a user chooses GitHub sign-in. Social sign-in does not disclose Customer monitoring data to either provider.
Slack, Microsoft Teams, Discord, Telegram, PagerDuty, additional email recipients and generic webhook endpoints are customer-selected destinations. Processor transmits configured notification content to them on Customer's documented instruction. Customer is responsible for the destination account, recipient authorization and its own agreement or data-protection arrangement with that destination provider.
Processor will impose Article 28-equivalent obligations where required and remains responsible for subprocessor performance to the extent required by law. Material new subprocessors will be notified through the service or account email with a reasonable objection period. If a substantiated objection cannot be resolved, Customer may stop the affected feature or terminate it.
International transfers
Processor will use a lawful transfer mechanism for restricted transfers, including an adequacy decision or the European Commission Standard Contractual Clauses, as applicable. The parties incorporate the relevant controller-to-processor or processor-to-processor module where needed, with Romanian law and the competent Romanian supervisory authority unless the Clauses require another selection.
Processor will assess supplementary safeguards where required and provide reasonably available transfer information without compromising security or other customers.
Data-subject and compliance assistance
Taking into account the nature of processing, Processor will provide reasonable technical and organizational assistance for data-subject requests. If Processor receives a request concerning Customer Personal Data, it will refer the requester to Customer unless legally required to respond.
Processor will provide reasonable assistance with security obligations, breach notifications, data-protection impact assessments and prior consultation, taking into account the information available and the nature of processing.
Personal-data breaches
Processor will notify Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Personal Data. The notice will include available information about the nature, likely consequences, affected data and subjects, mitigation and a contact point, and may be supplied in phases.
Customer remains responsible for notifications it must make as controller. A notice is not an admission of fault or liability.
Deletion, return and audits
During the term, Customer may use available export and deletion controls. At termination, Processor will delete or return Customer Personal Data as selected or instructed, unless law requires retention. If production backups are maintained, deleted data is isolated from ordinary use and expires through the documented overwrite cycle.
Processor will provide information reasonably necessary to demonstrate Article 28 compliance. Audits should first use current documentation and responses; a further audit requires reasonable notice, must protect other customers and security, occur no more than annually unless a breach or authority requires otherwise, and is at Customer’s cost unless it identifies a material breach by Processor.
Processing schedule
Subject matter and purpose: scheduled website, keyword, API and browser monitoring; run evidence; incidents; alerts; reports; support and service security. Duration: the service term plus plan retention, deletion processing, backup expiry and legally required periods.
Data subjects: Customer users and invitees, Customer personnel and clients, test-account users, and individuals whose data appears in authorized monitored targets. Data types: names, emails, account and online identifiers, IP/request metadata, configuration, encrypted secrets, page content, form values, screenshots, traces, console/network evidence, incidents and support communications.
Processing operations: collection, recording, organization, storage, retrieval, consultation, transmission, comparison, restriction, redaction, deletion and backup. Customer should use synthetic data and dedicated test accounts wherever practical and must not intentionally submit special-category or criminal-offence data unless specifically agreed with adequate safeguards.
Contact
Data-processing notices and requests: hello@crawlpanel.com. Legal entity: WORDPRESS CODE SRL, VAT RO41034515, J40/5716/2019, Str. Grigore Cobălcescu nr. 3, corp C2, Sector 1, București 010191, România.