Skip to content
flatbrowser

Art. 28(3) GDPR

Data Processing Agreement

You are the controller, we are the processor. Published in full, because you should not have to ask a vendor for this.

draft 2026-10-04 · unreviewed

1. Roles and precedence

This agreement (“DPA”) forms part of the Terms of Service between you (“Controller”) and [PLACEHOLDER: registered legal name incl. legal form (GmbH / UG (haftungsbeschränkt))] (“Processor”) and is accepted together with them. It governs personal data the Processor processes on the Controller’s behalf. Where this DPA conflicts with the Terms, this DPA prevails for that processing.

2. Subject matter, duration, nature and purpose

  • Subject matter: provision of browser-automation infrastructure — dedicated Chromium workers, a CDP gateway and a REST API.
  • Nature and purpose: executing the Controller’s automated browser instructions. Results of REST calls (screenshots, PDFs, HTML) are streamed back to the Controller and not stored.
  • Duration: for as long as the Controller holds an account, plus the retrieval period of at least 30 days after the service ends and the erasure that follows it (§12).
  • The Processor determines neither what the Controller collects nor from where. Those are the Controller’s instructions in the sense of Art. 29 GDPR.

3. Categories of data and data subjects

The Controller determines what its browsers process. Structurally:

  • Content data: whatever personal data appears in pages the Controller’s automation loads, held only in the memory and temporary profile of the browser session and deleted when the session ends. The Processor does not inspect it and keeps no copy.
  • Session data for the Controller: the session history shown in the dashboard (session and worker IDs, API-key ID, start and end times, close reason, the IP address of the connecting client and the outbound IP address), kept for 90 days.

Data subjects are the Controller’s staff and users who connect to the Service, plus any person whose data appears in pages the Controller’s automation visits.

Not covered by this DPA, because the Processor acts as controller for it: account and billing data, and the connection log the Processor keeps for security and abuse handling (session and REST metadata, traffic volumes; kept 3 years). Both are described in the privacy policy.

4. Processor obligations (Art. 28(3)(a)–(h))

  1. Process personal data only on the Controller’s documented instructions, including for transfers, unless Union or Member State law requires otherwise — in which case the Processor informs the Controller before processing, unless that law forbids it.
  2. Bind every person authorised to process the data to confidentiality.
  3. Take the technical and organisational measures required by Art. 32 (Annex B).
  4. Engage subprocessors only under §7, and impose the same data-protection obligations on them.
  5. Assist the Controller with data-subject requests (Art. 12–23) — see §9.
  6. Assist the Controller with Art. 32–36 obligations, including breach notification (§10) and data protection impact assessments.
  7. Delete or return the data on termination — see §12.
  8. Make available the information needed to demonstrate compliance and allow audits — see §11.

5. Security measures (Art. 32)

Summarised here; the full list is Annex B.

  • Encryption in transit for every external connection (TLS/WSS); no plaintext control-plane or gateway traffic on public networks.
  • Worker containers dedicated to one customer — no shared browser pools, no shared browser profiles; one Chromium process and one temporary profile directory per session, deleted with the session.
  • Browser containers cannot reach the cloud metadata service or our private network; every host re-checks this regularly and is taken out of service if the check fails.
  • API keys stored as SHA-256 hashes only; keys are displayed once and cannot be recovered from our systems.
  • Internal traffic between the control plane, the gateway and the hosts confined to a private network; worker endpoints are not publicly reachable.
  • Metadata-only logging (never page content or response bodies), least-privilege access to production, and an audit log of administrative actions.
  • Hard session duration and idle timeouts.
  • Nightly database backups, encrypted before they leave the server, expiring after 14 days.

6. Named subprocessors

subprocessorpurposelocations
Hetzner Online GmbHServer hosting and network for the control plane and all browser workersFalkenstein and Nuremberg (Germany), Helsinki (Finland)
[PLACEHOLDER: offsite backup storage provider — name, seat and location (a separate account from Hetzner)]Offsite copy of the nightly control-plane database backup, encrypted before upload with a key the provider does not holdEU

That is the complete list for customer data today. Stripe Payments Europe Ltd., our email provider and the other recipients named in the privacy policy process account and billing data under our own controllership, not under this DPA. Any proxy you configure is your own provider, not ours. Any future residential-egress vendor or language-model provider will be added here before a feature that uses it ships.

7. Changes to subprocessors

We notify account holders by email at least [PLACEHOLDER: notice period for new subprocessors, e.g. 30 days] before a new subprocessor starts processing. You may object on reasonable data-protection grounds; if we cannot offer an alternative, you may terminate the affected service without penalty for the remainder of the term.

8. Data residency and international transfers

All processing under this DPA happens in the EU/EEA: Falkenstein and Nuremberg (Germany), Helsinki (Finland). Our provisioning software refuses to order servers in any other location. We make no transfer of personal data processed under this DPA to a third country. If that ever has to change, it happens under §7 with an Art. 46 transfer mechanism in place first. The jurisdiction the infrastructure is subject to, and our measures against third-country government access, are described on the switching page (Art. 28 Data Act).

9. Data-subject requests

Requests that reach us and concern the Controller’s data are forwarded to the Controller without undue delay; we do not answer them ourselves. On instruction we assist with access, rectification, erasure and portability. The self-serve export (§12) covers the session data in §3.

The Service stores no session artifacts: screenshots, PDFs and HTML are returned in the response, and browser profiles are deleted when a session ends. Data that no longer exists cannot be lost — German case law prices mere loss of control over personal data, so this is a liability control for both sides.

10. Personal data breaches (Art. 33(2))

We notify the Controller without undue delay after becoming aware of a personal data breach affecting data processed under this DPA — target [PLACEHOLDER: internal breach-notification deadline, e.g. 48 hours] — with the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, and the measures taken or proposed. Notification to a supervisory authority or to data subjects remains the Controller’s obligation; we provide the information needed for it.

11. Records, information and audits

We keep the processor records required by Art. 30(2) and make them available on request. Once a year, and after any breach affecting your data, you may request information on our technical and organisational measures, or audit them — remotely and against reasonable notice, or on site where a supervisory authority requires it. Audits may not compromise other customers’ confidentiality.

12. Return and deletion on termination

  1. Return: the Controller can download all data covered by this DPA at any time, before and after termination, as one machine-readable JSON export from the dashboard (format on the switching page).
  2. Workers, and with them every browser profile, are destroyed when the service ends.
  3. The data stays retrievable for at least 30 days after the service ends — and after any transitional period under the Terms §12a — and is then erased, unless Union or Member State law requires the Processor to keep it.
  4. Backups expire within 15 days of the erasure. On request we confirm the erasure in writing.

Data the Processor keeps as controller (§3, last paragraph) follows the retention periods in the privacy policy.

13. Annexes

  • Annex A — processing details: categories, purposes and duration, as set out in §§2–3.
  • Annex B — technical and organisational measures: the full Art. 32 description, summarised in §5.
  • Annex C — subprocessors: the table in §6.

Annex B in full and a signature-ready copy: [PLACEHOLDER: legal / DPA contact email].