Data Processing Agreement

Effective: July 30, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between CRWLR Ltd. ("CRWLR", "we") and the customer using the CRWLR service ("Customer", "you"). It sets out how we process personal data on your behalf under Article 28 of the EU General Data Protection Regulation (GDPR) and the equivalent UK provisions.

1. Roles

For personal data processed through the Service, you are the controller and CRWLR is the processor. You decide what configurations to upload and who in your organisation may access the results. We process that data only to provide the Service.

For our own business records (billing, support correspondence, marketing to prospective customers) CRWLR acts as an independent controller, and our Privacy Policy governs that processing rather than this DPA.

2. Subject matter, duration, nature and purpose

Subject matter and purpose: automated security analysis of firewall configuration files, and delivery of the resulting findings, scores and reports to you.

Nature of processing: parsing uploaded configuration files in memory, evaluating them against a catalogue of security checks, storing the normalised result and findings, and making them available in the application and in exports.

Duration: for the term of your subscription, plus the retention period in section 9.

3. Categories of data subjects and personal data

Data subjects: your personnel who hold CRWLR accounts, and any individuals who happen to be identifiable from the device configurations you upload.

Categories of personal data:

  • Account data: name, work email address, role, authentication metadata, sign-in IP address
  • Usage data: actions recorded in the account audit log, with actor and timestamp
  • Billing data: subscription and invoice records (card details are handled by Stripe; we never receive or store them)
  • Incidental configuration content: firewall configurations are network engineering artefacts rather than personal data, but they can incidentally contain administrator usernames, contact addresses in comments, VPN user identifiers, or IP addresses attributable to individuals

We do not knowingly process special categories of personal data under Article 9, and the Service is not designed to receive them. If your configurations would routinely expose such data, sanitise them before upload using our client-side sanitiser, which strips secrets and identifiers in your browser before anything is transmitted.

4. Your instructions

We process personal data only on your documented instructions, which comprise this DPA, the Terms of Service, and the actions you take in the application. We will tell you if an instruction appears to infringe applicable data protection law. We do not sell personal data, and we do not use your configurations or findings to train machine learning models.

5. Confidentiality and personnel

Access to production systems is limited to personnel who need it to operate or support the Service, is subject to confidentiality obligations that survive the engagement, and is granted on a least-privilege basis.

6. Security measures

We implement appropriate technical and organisational measures under Article 32. The measures that most directly protect the data you entrust to us:

  • Raw configuration files are never persisted. An uploaded file is parsed in memory and discarded; only the normalised analysis result is stored. The most sensitive artefact you send us therefore has no copy at rest.
  • Tenant isolation: every stored record carries a tenant identifier, and every query is scoped to it
  • Encryption: TLS in transit; encryption at rest for databases and object storage
  • Access control: role-based permissions (owner, admin, analyst, read-only), optional multi-factor authentication, and an account audit log you can read and export
  • Isolation of processing: configuration parsing runs in a resource-limited worker with execution timeouts, so a malformed or hostile file cannot affect other customers
  • Monitoring: error monitoring and external uptime checks, with alerting on failure
  • Backups: managed database backups with point-in-time recovery

Our security page describes these controls in more detail, including which certifications we hold today and which are planned.

7. Sub-processors

You authorise the following sub-processors:

Sub-processorPurposeLocation
SupabaseDatabase, authentication, file storageEU (Frankfurt)
RenderAPI hosting and scan executionEU (Frankfurt)
VercelWeb application hostingGlobal CDN
StripePayment processingEU / US
ResendTransactional and notification emailUS
AnthropicAI summaries and finding explanations (opt-in)US

AI features are opt-in and off by default. When enabled, only finding metadata and summary statistics are sent to Anthropic. Raw configuration data, IP addresses and network topology are not. Anthropic does not retain inputs for model training under our API agreement.

We will give you at least 30 days’ notice before adding or replacing a sub-processor, by email to your account owner. If you reasonably object on data protection grounds within that period, you may terminate the affected subscription and receive a pro-rata refund of prepaid fees. Each sub-processor is bound by obligations no less protective than those in this DPA.

8. International transfers

Scan data, findings and account records are stored in the European Union (Frankfurt). Where a sub-processor listed above processes personal data outside the EEA or the UK, that transfer relies on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary measures appropriate to the data involved. The data reaching US sub-processors is limited: billing records to Stripe, email addresses and message content to Resend, and finding metadata to Anthropic only where you have enabled AI features.

9. Deletion and return

You can delete firewalls, scans and findings yourself at any time from the application, and you can export your data before doing so. On termination we delete scan results and account data within 30 days, except where retention is required by law (for example, invoices kept for tax purposes). Backups age out on their own retention cycle. We process a written deletion request within 30 days.

10. Assisting you

Taking into account the nature of the processing, we will assist you with:

  • responding to data subject requests for access, correction, deletion, portability or objection
  • data protection impact assessments and prior consultation with a supervisory authority
  • demonstrating compliance with Article 28, including by providing the information in this DPA and on our security page

Much of this is self-serve: account owners can export scan data, read the audit log, and delete records directly, which usually satisfies an access or erasure request without involving us.

11. Personal data breaches

We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting your data. The notification will describe what happened, the categories and approximate volume of data involved, the likely consequences, and the measures taken or proposed. We will provide the information you reasonably need for your own notification obligations to a supervisory authority or to data subjects.

12. Audits

On reasonable written request, and no more than once in any twelve-month period unless required by a supervisory authority, we will provide the information necessary to demonstrate compliance with this DPA. Where available, third-party reports and questionnaire responses satisfy this obligation. Any on-site or hands-on audit is at your cost, scheduled to avoid disruption to the Service, and subject to confidentiality.

13. Precedence and execution

This DPA is incorporated into the Terms of Service and applies automatically when you use the Service to process personal data. In the event of a conflict on data protection matters, this DPA prevails over the Terms of Service. Liability is subject to the limitations in the Terms of Service.

If your procurement process requires a counter-signed copy, or your own DPA template, email contact@crwlr.io and we will arrange it.

14. Contact

Data protection enquiries: contact@crwlr.io. See also our Privacy Policy and Data Handling page.

Data Processing Agreement | CRWLR