Data Processing Agreement
Version 2.0. Effective date: 20 September 2026 (replaces the version dated 20 December 2025)
This Data Processing Agreement ("DPA") forms part of the ScrapeBadger Terms of Service (the "Terms") between MB "Reikalita", a small partnership registered in the Republic of Lithuania, legal entity code 306684138, registered office Ramioji g. 12, Bajorų k., Vilniaus raj., Lithuania, trading as ScrapeBadger ("ScrapeBadger", "we"), and the customer that has accepted the Terms ("Customer", "you"). Capitalised terms not defined in this DPA have the meaning given in the Terms.
1. How this DPA applies
1.1 Automatic incorporation. This DPA applies automatically, without signature, whenever you use the Services to retrieve Output that contains Personal Data protected by Data Protection Law. By accepting the Terms you accept this DPA on behalf of yourself and, where clause 3.3 applies, on behalf of the controllers for which you act.
1.2 Signed copy. If your procurement or compliance process requires a signed document, email legal@scrapebadger.com with the subject line "DPA Signature" and we will provide a countersigned PDF of this DPA, without changes to its content.
1.3 Precedence. This DPA is the specific provision of the Agreement for the processing of Customer Personal Data and applies subject to clause 1.3 of the Terms, save that nothing in the Terms reduces the protections required by Article 28 GDPR. Where Standard Contractual Clauses apply under clause 10, they prevail over this DPA to the extent of any conflict.
1.4 What this DPA does not cover. Personal data that we process as an independent controller (your Account data, billing data, communications, and Usage Data, meaning the metadata of your Requests) is covered by our Privacy Policy, not by this DPA. You acknowledge that Request parameters, such as Source URLs and search queries, may occasionally contain personal data, and that ScrapeBadger retains them as controller for ninety (90) days for security, billing and legal purposes under clause 5.4 of the Terms.
2. Definitions
"Customer Personal Data" means Personal Data contained in Output that ScrapeBadger processes on your behalf in the course of executing your Requests.
"Data Protection Law" means Regulation (EU) 2016/679 (the "GDPR"), the GDPR as it forms part of the law of the United Kingdom by virtue of the European Union (Withdrawal) Act 2018 (the "UK GDPR") and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, the Lithuanian Law on the Legal Protection of Personal Data, and any other law that applies to the processing of Customer Personal Data under this DPA.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision (EU) 2021/914, as amended or replaced from time to time.
"Sub-processor" means a third party engaged by ScrapeBadger to process Customer Personal Data.
"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
"Controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in the GDPR.
3. Roles and scope
3.1 Roles. For Customer Personal Data, you are the controller and ScrapeBadger is your processor. You determine the Sources to be queried, the content to be requested and the purposes for which Output is used; ScrapeBadger retrieves and delivers the content on your instructions.
3.2 Nature of the processing. The processing performed by ScrapeBadger consists of receiving your Request, retrieving the publicly available content you have specified from the Source, parsing and formatting it, and returning it to you in the response. Output is processed in memory only for the duration of the Request, typically seconds, and is not written to ScrapeBadger's databases, logs or backups. Once the response has been delivered, ScrapeBadger has no copy of the Output and no technical means to retrieve, restore or reproduce it. Annex I describes the processing in detail.
3.3 Customer acting as processor. If you use the Services on behalf of another controller (for example your own client), you are a processor and ScrapeBadger is your sub-processor. In that case you warrant that your controller has authorised the engagement of ScrapeBadger and the Sub-processors listed in Annex III, that your instructions to ScrapeBadger reflect your controller's instructions, and that you will pass on to your controller any information ScrapeBadger provides under this DPA.
3.4 Your instructions. Your complete and final instructions to ScrapeBadger are: (a) the Agreement, including this DPA and the transfers to Sub-processors described in Annex III; (b) each Request you make, including its parameters; and (c) any further written instruction agreed between the parties. ScrapeBadger will process Customer Personal Data only on those instructions, unless required to do otherwise by Union or Member State law to which it is subject, in which case it will inform you before processing unless the law prohibits this. ScrapeBadger will immediately inform you if, in its opinion, an instruction infringes Data Protection Law, and may suspend the instruction until it is clarified.
4. Your obligations as controller
4.1 You are responsible for the lawfulness of the Customer Personal Data you obtain through the Services and of your instructions. In particular you must: (a) have a valid legal basis for collecting and using Customer Personal Data; (b) give data subjects the information required by Articles 13 and 14 GDPR, or document why an exemption applies; (c) carry out any data protection impact assessment required by Article 35 GDPR before making the relevant Requests; (d) comply with the personal-data rules of the Acceptable Use Policy, including the prohibitions on targeting special categories of data, data relating to criminal offences and data about children, and on surveillance, facial recognition and unlawful profiling; (e) honour data-subject rights; and (f) keep your own records of processing.
4.2 You acknowledge that ScrapeBadger does not review Output and cannot know which Requests will return Personal Data. Only you can assess whether a particular Request is lawful.
4.3 You will not instruct ScrapeBadger to process Customer Personal Data in a way that would cause ScrapeBadger to breach Data Protection Law.
5. ScrapeBadger's obligations as processor
5.1 Confidentiality. ScrapeBadger ensures that every person authorised to process Customer Personal Data is bound by a contractual or statutory obligation of confidentiality and has received appropriate training.
5.2 Security. ScrapeBadger implements the technical and organisational measures described in Annex II, and keeps them under review, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing and the risks to data subjects. ScrapeBadger may update Annex II provided that the overall level of protection is not reduced.
5.3 Assistance with data-subject requests. If ScrapeBadger receives a request from a data subject that concerns Customer Personal Data and can identify you as the customer concerned, it will forward the request to you promptly, normally within five (5) Business Days, and will not respond on the merits unless required by law, without prejudice to ScrapeBadger's own rights under the Terms to restrict or suspend use of the Services. Because ScrapeBadger holds no Output, it cannot provide access to, rectify or erase Customer Personal Data on your behalf; it will, however, give you the Usage Data relevant to the request so that you can respond.
5.4 Assistance with compliance. Taking into account the nature of the processing and the information available to it, ScrapeBadger will assist you in complying with Articles 32 to 36 GDPR (security, breach notification, impact assessments and prior consultation), including by providing the information in this DPA and its Annexes and by answering reasonable written questions. Assistance that goes beyond that, or that is required because of your own breach of this DPA, may be charged at ScrapeBadger's then-current professional rates.
5.5 Personal Data Breach. ScrapeBadger will notify you without undue delay and, where feasible, within forty-eight (48) hours after becoming aware of a Personal Data Breach, so that you can meet your own seventy-two-hour deadline under Article 33 GDPR. The notice will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact; information may be provided in phases as it becomes available. ScrapeBadger will cooperate with you in investigating and remedying the breach. Notification is not an admission of fault or liability.
5.6 Records and cooperation with authorities. ScrapeBadger keeps the records required by Article 30(2) GDPR and will cooperate, on request, with the supervisory authority in the performance of its tasks.
5.7 Location of processing. ScrapeBadger's own infrastructure is located in the European Union. Transfers to Sub-processors outside the European Economic Area are governed by clause 10.
6. Sub-processors
6.1 General authorisation. You authorise ScrapeBadger to engage the Sub-processors listed in Annex III, and any Sub-processors added in accordance with this clause 6, for the purposes described there.
6.2 Notice of changes. ScrapeBadger will give you at least thirty (30) days' notice before adding a new Sub-processor or replacing an existing one, by email to the address registered on your Account, and additionally by a notice in the dashboard. The current list is maintained at scrapebadger.com/legal/subprocessors, where you can also subscribe to change notifications.
6.3 Objection. You may object to a new Sub-processor on reasonable, documented data-protection grounds by writing to legal@scrapebadger.com within fourteen (14) days of the notice. The parties will discuss the objection in good faith. If ScrapeBadger cannot reasonably accommodate the objection, the change is treated as a material amendment under clause 17.1 of the Terms: you may terminate the Agreement, or the affected Services, on written notice before the change takes effect, with the refund provided in that clause. This is your sole remedy for an objection. If you do not object within fourteen (14) days, the change is deemed accepted.
6.4 Emergency replacement. Where a Sub-processor must be replaced urgently to maintain security or availability, ScrapeBadger may do so without prior notice, will inform you as soon as reasonably possible, and the objection right in clause 6.3 then applies from the date of that notice.
6.5 Flow-down and responsibility. ScrapeBadger will impose on each Sub-processor, by written contract, data-protection obligations that provide substantially the same level of protection as this DPA, and remains fully liable to you for the performance of the Sub-processor's obligations.
7. Deletion and return
7.1 Because Output is not stored, there is no Customer Personal Data to return or delete at the end of the Agreement. On termination of the Agreement, or on your written request at any time, ScrapeBadger will confirm in writing that it holds no Output.
7.2 Usage Data is ScrapeBadger's own record of your Requests, retained for ninety (90) days for the purposes described in the Privacy Policy and the Terms (clause 5.4). It is not Customer Personal Data and is not subject to this clause 7.
8. Audits
8.1 ScrapeBadger will make available to you all information necessary to demonstrate compliance with Article 28 GDPR and this DPA, and will allow for and contribute to audits, including inspections, conducted by you or an independent auditor mandated by you, in accordance with this clause 8.
8.2 You will first exercise your audit right by written questions and by reviewing the documentation, policies and any third-party assessments or certifications that ScrapeBadger makes available. ScrapeBadger will answer reasonable written questions within a reasonable time, normally within twenty (20) Business Days.
8.3 If the information provided under clause 8.2 is not sufficient to demonstrate compliance, or if a supervisory authority requires it, or following a Personal Data Breach affecting your Customer Personal Data, you may carry out an on-site or remote inspection, no more than once in any twelve (12) month period, on at least thirty (30) days' written notice, during normal business hours, without unreasonable disruption to ScrapeBadger's operations. The auditor must be bound by confidentiality, must not be a competitor of ScrapeBadger, and will not be given access to the data of other customers. You bear the costs of the audit, including ScrapeBadger's reasonable time, unless the audit reveals a material breach of this DPA by ScrapeBadger.
8.4 Audit findings are Confidential Information of both parties. You will share the findings with ScrapeBadger and give it a reasonable opportunity to remedy any issue.
9. Liability
9.1 Each party's liability arising out of or relating to this DPA, whether in contract, tort or otherwise, is subject to the exclusions and limitations of liability in the Terms, which apply in aggregate across the Terms and this DPA. Nothing in this DPA limits either party's liability towards data subjects or supervisory authorities under Article 82 or Article 83 GDPR.
9.2 You will indemnify ScrapeBadger in accordance with clause 14 of the Terms for claims arising from your instructions, your Requests and your use of Output.
10. International transfers
10.1 ScrapeBadger processes Customer Personal Data in the European Union and does not transfer it to a third country except to the Sub-processors and in the circumstances identified in Annex III.
10.2 Where ScrapeBadger transfers Customer Personal Data to a Sub-processor in a third country that is not covered by an adequacy decision of the European Commission, ScrapeBadger does so under the SCCs (Module Three, processor to processor) concluded between ScrapeBadger and the Sub-processor, under the EU-US Data Privacy Framework where the Sub-processor is certified, or under another transfer mechanism permitted by Data Protection Law, together with any supplementary measures required. ScrapeBadger will provide a summary of the applicable mechanism on request.
10.3 If you are established in the United Kingdom or Switzerland, your disclosure of Customer Personal Data to ScrapeBadger in the European Union is covered by the UK adequacy regulations for the European Economic Area and by the Swiss recognition of the European Union as providing adequate protection respectively; onward transfers by ScrapeBadger to Sub-processors are governed by clause 10.2. Where the UK GDPR or Swiss law nevertheless requires additional safeguards for an onward transfer, ScrapeBadger will apply the UK Addendum or the Swiss adaptations to the relevant SCCs.
10.4 If Data Protection Law applicable to you treats your own disclosure of Customer Personal Data to ScrapeBadger as a restricted transfer (for example because you are established outside the European Economic Area and the law of your country requires safeguards for transfers to the European Union), the parties will conclude the transfer mechanism required by that law on request.
11. Term and termination
11.1 This DPA takes effect when the Terms are accepted and remains in force for as long as ScrapeBadger processes Customer Personal Data on your behalf. Clauses 7, 8, 9 and 12 survive termination.
11.2 Either party may terminate the Agreement in accordance with the Terms if the other party materially breaches this DPA and does not remedy the breach within fourteen (14) days of written notice.
12. General
12.1 This DPA is governed by the law of the Republic of Lithuania and the courts of Vilnius have jurisdiction, as set out in clause 19 of the Terms, except where the SCCs, mandatory Data Protection Law or mandatory consumer-protection law require otherwise.
12.2 ScrapeBadger may update this DPA in accordance with clause 17 of the Terms. Changes that are required by Data Protection Law, by a supervisory authority or by a new version of the SCCs may take effect on shorter notice; ScrapeBadger will not reduce the level of protection provided to Customer Personal Data without your agreement.
12.3 Notices under this DPA are given in accordance with clause 20.4 of the Terms. Notices to ScrapeBadger are sent to legal@scrapebadger.com with the subject line "Legal Notice" and, in addition, "DPA" or, for breach-related communications, "URGENT: Data Breach". Notices to you are sent to the email address registered on your Account.
12.4 If any provision of this DPA is invalid or unenforceable, the remainder continues in force and the parties will replace the invalid provision with a valid one that achieves the same purpose.
Annex I: Description of the processing
| Controller | The Customer identified in the Account, acting as controller, or as processor on behalf of its own controllers under clause 3.3 |
| Processor | MB "Reikalita" (ScrapeBadger), Ramioji g. 12, Bajorų k., Vilniaus raj., Lithuania, legal@scrapebadger.com |
| Subject matter | Retrieval, parsing and delivery of publicly available web content at the Customer's Request through the ScrapeBadger APIs and related Access Channels |
| Duration | The term of the Agreement; each processing operation lasts for the duration of the individual Request (typically seconds) |
| Nature of the processing | Receiving Request parameters; sending HTTP requests to the specified Source through ScrapeBadger's infrastructure and network providers; receiving the response; rendering, parsing, structuring and, for AI-assisted endpoints, extracting content; transmitting the result to the Customer. No storage, indexing, analysis for ScrapeBadger's own purposes, or onward disclosure |
| Purpose of the processing | Execution of the Customer's Requests for the Customer's own purposes as determined by the Customer (for example market research, price and brand monitoring, academic research, lead qualification, analytics), subject to the Acceptable Use Policy |
| Categories of data subjects | Users of, and persons mentioned in, publicly available content on the Sources selected by the Customer: for example authors of public posts, comments and reviews; holders of public profiles; sellers and agents named in public listings; individuals named in public web pages |
| Categories of personal data | As determined by the Customer's Requests: names and usernames; public profile information; content of public posts, comments and reviews; public contact details; references (URLs) to publicly posted images and media; engagement metrics; metadata such as post dates and locations shown publicly |
| Special categories of data | Not intended. The Customer must not target special categories of personal data, data relating to criminal convictions and offences, or data about children (Acceptable Use Policy, section 4). ScrapeBadger does not review Output and relies on the Customer's obligations under the Acceptable Use Policy and on its own rights under the Terms to block Sources and suspend Accounts |
| Frequency | Continuous, on demand, at each Request |
| Retention by the processor | None. Output is held in memory only for the duration of the Request and is not stored |
| Sub-processors and transfers | As listed in Annex III |
Annex II: Technical and organisational measures
ScrapeBadger implements the following measures.
1. No persistence of Output. The Services are designed so that content retrieved from Sources is processed in memory and returned in the response. Response bodies are not written to application logs, databases, message queues or backups. Application logging is configured to record request metadata only.
2. Encryption in transit. Connections between the Customer and the Services use TLS 1.2 or higher. Connections to Sources use TLS where the Source supports it. Connections between ScrapeBadger components and to Sub-processors are encrypted wherever they cross public networks.
3. Encryption at rest. Databases, disks and backups holding Account data and Usage Data are encrypted at rest.
4. Access control. Access to production systems is limited to named personnel with a need to know, uses individual accounts, requires multi-factor authentication and SSH keys, and is reviewed whenever personnel or roles change. Customer API keys are stored in a form that does not allow them to be read back by personnel.
5. Secrets management. Credentials for infrastructure and Sub-processors are stored in a secrets manager or encrypted environment configuration, never in source code, and are rotated on personnel change or suspected compromise.
6. Network security. Production systems sit behind firewalls that expose only required ports; the public edge is protected by Cloudflare (DDoS mitigation, web application firewall, bot management); internal services are not exposed to the public internet.
7. Logging and monitoring. Administrative access and authentication events are logged, infrastructure availability is monitored continuously, and automated alerts are raised for service failures and abnormal request volumes. Logs are retained for ninety (90) days and contain request metadata only.
8. Vulnerability and patch management. Operating systems, runtimes and dependencies are updated regularly; automated dependency scanning is enabled on code repositories; critical security patches are applied promptly.
9. Secure development. Changes are made through version control, reviewed before deployment, and tested in a separate staging environment before reaching production.
10. Backup and recovery. Account data and Usage Data are backed up regularly to encrypted storage within the European Union; backups are overwritten in the ordinary course and kept for no longer than ninety (90) days. Output is never included in backups because it is never stored.
11. Incident response. A documented incident-response procedure covers detection, containment, assessment, notification (including the 48-hour notice in clause 5.5), remediation and post-incident review.
12. Sub-processor management. Sub-processors are selected for their security posture, bound by written data-processing terms, and listed in Annex III. Proxy and network providers are used for transmission only; ScrapeBadger does not authorise them to store or inspect content beyond what is technically necessary to relay it.
13. Personnel. All personnel with access to production systems are bound by confidentiality obligations and receive security and data-protection guidance on joining and when procedures change.
14. Data minimisation and retention. Only the metadata needed to operate, secure and bill the Services is recorded; it is retained for ninety (90) days. Account data is deleted or anonymised from live systems within thirty (30) days of Account closure and disappears from backups as they are overwritten, within ninety (90) days at most.
15. Business continuity. Infrastructure is monitored for availability; a public status page reports incidents; the architecture allows redeployment from version-controlled configuration.
Annex III: Sub-processors for Customer Personal Data
The following Sub-processors may process Customer Personal Data on ScrapeBadger's behalf. Providers that process only Account data, billing data or website analytics (for example Stripe, CoinGate, PostHog, Google Analytics, our email providers) are not Sub-processors of Customer Personal Data; they are listed in the Privacy Policy.
| Sub-processor | Processing activity | Location | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH, Gunzenhausen, Germany | Hosting of the servers on which Requests are executed and Output is processed in memory | Germany and Finland (EU) | Not applicable (EU) |
| Cloudflare, Inc. | Edge network, DDoS protection and web application firewall in front of the API; Output transits Cloudflare's network in encrypted form | Global network, headquartered in the United States | EU-US Data Privacy Framework; SCCs |
| Proxy and network infrastructure providers (datacenter, residential and mobile networks; several providers, EU and worldwide) | Routing Requests to Sources; the Source URL and the returned content transit through the provider's network and are not stored | EU and worldwide | Adequacy decision or SCCs where required for a provider outside the EEA. On written request ScrapeBadger will confirm the countries in which its current providers are established and the safeguard applied to each |
| AI model providers used for AI-assisted extraction endpoints (the current provider is named at scrapebadger.com/legal/subprocessors) | Structured extraction from Output when the Customer uses an AI-assisted endpoint; content is sent to the provider to process the Request; the provider may retain it for up to thirty (30) days for abuse monitoring under its API terms and does not use it to train models | European Union or United States, as stated on the sub-processors page | Adequacy decision or SCCs where the provider processes data outside the EEA |
Last updated: 20 September 2026. Changes are notified in accordance with clause 6.