Legal
Data Processing Addendum
How Crawle processes personal data on your instructions under Article 28 GDPR, including the security measures, the sub-processor list, and deletion.
Version 1.1 - Last updated August 23, 2026
This Data Processing Addendum forms part of the Terms of Service between Crawle AB, Swedish company registration number 559595-6862 ("Crawle", the processor), and the Customer that holds a Crawle account (the controller). It applies whenever Crawle processes personal data on the Customer's behalf and gives effect to Article 28 of Regulation (EU) 2016/679 (GDPR).
Terms defined in the GDPR carry their GDPR meaning here. Where this Addendum and the Terms of Service disagree about the processing of personal data, this Addendum governs.
1. Roles of the parties
The Customer is the controller of the personal data it submits to Crawle or has Crawle collect: content and metadata from the websites the Customer verifies, Google Search Console data for connected properties, integration tokens, the contact details of report and alert recipients, and access log files the Customer uploads. Crawle is the processor of that data and processes it only on the Customer's documented instructions.
Crawle is a separate controller for the account and billing data it needs to run its own business, including account holder identity, subscription and invoice records, and security logs. That processing is described in the Privacy Policy and is outside this Addendum.
Where the Customer is itself a processor for its own client, the Customer acts as that client's processor and Crawle acts as sub-processor. The Customer confirms it has the client's authority to appoint Crawle on these terms.
2. Subject matter, duration, nature and purpose
Subject matter and purpose: providing technical SEO monitoring, change detection, alerting, reporting, exports, API and MCP access, and optional access log analysis, as configured by the Customer.
Nature of processing: automated crawling of the Customer's verified websites, storage of crawl results as continuous history, comparison between crawls, generation of issues, alerts, reports and exports, transmission of alerts to the destinations the Customer connects, and parsing and aggregation of access logs the Customer uploads.
Duration: for the term of the Terms of Service, plus the retention and deletion periods in section 9.
3. Categories of data subjects and personal data
Data subjects: the Customer's workspace users and invited team members; the Customer's own end users and website visitors, where their personal data appears in crawled page content or in uploaded access logs; recipients of alerts and reports the Customer configures; and, for white-label agencies, the agency's clients and their users.
Categories of personal data: account identifiers such as name, email address and role; authentication data including session and two-factor state; any personal data that happens to appear in crawled page content, page metadata, or structured data on the Customer's websites; Search Console query, page and property data for connected properties; access tokens and integration identifiers; alert and report recipient addresses; and, in uploaded access logs, IP addresses, user agents, requested URLs, timestamps, and status codes.
Crawle does not require special categories of personal data under Article 9 GDPR and asks the Customer not to submit them. The Customer decides which websites are crawled and which logs are uploaded, and therefore controls what personal data reaches Crawle.
4. Crawle's obligations
Crawle processes personal data only on the Customer's documented instructions, which consist of this Addendum, the Terms of Service, and the configuration the Customer applies in the product, unless EU or Member State law requires otherwise; in that case Crawle informs the Customer before processing, unless that law prohibits it. Crawle tells the Customer if, in its opinion, an instruction infringes data protection law.
Crawle ensures that people authorized to process the personal data are bound by confidentiality obligations, receive access only where their role requires it, and are subject to access reviews.
Crawle assists the Customer, by appropriate technical and organizational measures and taking into account the nature of the processing, in responding to requests to exercise data subject rights, and in meeting the Customer's obligations under Articles 32 to 36 GDPR.
Crawle notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, with the information available at the time, and provides further detail as the investigation progresses.
5. Security measures
Crawle applies technical and organizational measures appropriate to the risk, including: encryption in transit for traffic between customers, the app, and Crawle services; encryption of integration access tokens at rest; per-workspace data isolation, so a request is scoped to the workspace it authenticates against; role-based access control with two-factor authentication available on accounts; restricted operator access to production secrets; separation of production from validation environments; and monitoring and error tracking for availability and integrity.
Crawle may change individual measures as the service evolves, provided the level of security is not reduced. Crawle does not hold an external security audit report, and this Addendum does not claim one.
6. Sub-processors
The Customer gives general authorization for Crawle to appoint the sub-processors listed in the annex below. Crawle imposes data protection obligations on each sub-processor that are no less protective than this Addendum, and remains liable to the Customer for their performance.
Crawle gives at least 30 days' notice by email to the account's billing contact before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period; if the parties cannot agree on a resolution, the Customer may terminate the affected service and receive a pro rata refund of prepaid fees for the unused remainder of the term.
Annex — current sub-processors
Hetzner Online GmbH (Germany and Finland) — hosting of the Crawle application, databases, and crawler infrastructure, and object storage for backup generations.
HostUp AB (Sweden) — hosting of the dedicated data plane used for access log analysis, for workspaces that use it.
Cloudflare, Inc. — DNS, content delivery, TLS termination, web application firewall, and bot protection for Crawle's domains.
Amazon Web Services, Inc. — Amazon SES in the eu-north-1 region for transactional and authentication email, and S3 and SQS for the access log analysis pipeline.
Stripe, Inc. — subscription billing and payment processing. Card details are entered on Stripe-hosted pages; Crawle stores billing status and invoices, not card numbers.
Google LLC — Google sign-in for accounts that use it, and Google Search Console API access for properties the Customer connects.
Slack Technologies, LLC — delivery of alerts to Slack workspaces the Customer connects.
Microsoft Corporation — delivery of alerts to Microsoft Teams channels the Customer connects.
Functional Software, Inc. (Sentry) — application error and performance monitoring. Session replay is disabled; an error event from a signed-in session may include the account id and email address.
7. International transfers
Crawle hosts the service in the EU and EEA. Where a sub-processor above processes personal data outside the EEA, the transfer relies on that provider's own transfer mechanism, which is the European Commission's Standard Contractual Clauses under its published data processing agreement, together with the supplementary measures that provider documents. Crawle makes the relevant provider terms available on request.
8. Audit
Crawle makes available the information necessary to demonstrate compliance with Article 28 GDPR, in the form of written responses to a reasonable security and data protection questionnaire and the documentation described in this Addendum, no more than once in any 12-month period unless a personal data breach or a supervisory authority requires otherwise.
On-site inspection of Crawle's providers is not available, because Crawle does not operate their facilities. Where a Customer's mandatory audit right cannot be satisfied by the information above, the parties will agree a proportionate alternative before an inspection is arranged, at the Customer's cost.
9. Deletion and return
The Customer can export workspace data from the product at any time during the term. On termination, or on the Customer's written request, Crawle deletes the personal data it processes on the Customer's behalf, except where EU or Member State law requires it to be retained.
An account deletion request is recorded with a 30-day grace period, during which the Customer can withdraw it. At the end of that period the deletion workflow begins across the active services that hold workspace data. Backup copies cannot be erased individually and age out under the applicable retention schedule. Crawle provides a completion record on request and does not promise a fixed completion window without that record.
Historical crawl records are otherwise retained for up to 2 years as described in the Terms of Service, and billing records for as long as Swedish accounting law requires.
10. Contact
Send data protection questions, sub-processor objections, audit requests, and breach queries to [email protected].