Art. 13/14 GDPR
Privacy policy · Datenschutzerklärung
What we process when you visit this site, hold an account, run browsers on our infrastructure or send us a notice — and what we deliberately never look at.
draft 2026-10-04 · unreviewed
1. Controller / Verantwortlicher
[PLACEHOLDER: registered legal name incl. legal form (GmbH / UG (haftungsbeschränkt))], [PLACEHOLDER: street and house number], [PLACEHOLDER: postal code and city], Deutschland. E-Mail: [PLACEHOLDER: privacy contact email]. Full provider details: Impressum.
Data protection officer: [PLACEHOLDER: data protection officer — or, if none is required (fewer than 20 people regularly processing personal data, §38(1) BDSG), the sentence “No data protection officer is required.”].
2. In one paragraph
We are infrastructure for businesses. For your account, billing and our own abuse handling we are the controller. For whatever your browsers process we are a processor acting on your instructions, governed by our data processing agreement. We record connection metadata — never page content or response bodies — and the infrastructure is in the EU.
3. Visiting this website
Our edge server deliberately writes no access log. Our services write operational logs (errors, security events such as rejected logins); an entry can contain an IP address or an email address when the event concerns it. Logs are rotated by size and overwritten: [PLACEHOLDER: how long container logs survive in practice under the size-based rotation (5 × 20 MB per service), e.g. “usually a few days, at most 30 days”]. Legal basis: Art. 6(1)(f) GDPR, our interest in a secure and operable service. There is no analytics or advertising tracking on this site.
4. Your account
When you create an account we process your email address, display name and a password hash — or, if you sign in with Google or GitHub, the profile data those providers release for authentication (name, email address, profile picture URL). We also store:
- whether your email address is verified, and a two-factor secret if you turn two-factor authentication on;
- when you accepted our Terms, Acceptable Use Policy and DPA, which version you accepted, and your confirmation that you act as a business (§14 BGB);
- for each signed-in browser session: its IP address and user agent, for as long as that login session is valid;
- your organisation, its members and invitations, subscription status, and API-key metadata (name, prefix, a SHA-256 hash, created / last-used / revoked times). We never store an API key in readable form;
- the emails we send you: address verification, password reset, confirmation of the terms you accepted, payment and service notices, and statements of reasons (Terms §7).
Legal basis: Art. 6(1)(b) GDPR (the contract); for the acceptance record and security data also Art. 6(1)(f) (proving what was agreed, protecting accounts). Retention: while your account exists. When an organisation is closed, its data stays retrievable for 30 days after the service ends and is then erased; a user who belongs to no other organisation is erased with it. Exceptions are listed in sections 6, 7 and 8.
5. Sign-up protection
- Cloudflare Turnstile (when enabled). The sign-up, login and password-reset forms then load a challenge from Cloudflare, Inc. (USA), which evaluates your IP address and browser characteristics to tell people from bots. Legal basis: Art. 6(1)(f) GDPR (keeping automated account creation out); access to your device for this purpose is strictly necessary for the service you request (§25(2) No. 2 TDDDG). Transfer basis: see section 11. You can tell it is on: the widget is visible on the form.
- Breached-password check (when enabled). When you set a password, the first five characters of its SHA-1 hash are sent to the Pwned Passwords service (api.pwnedpasswords.com) to check it against known breaches. Your password, its full hash and your email address never leave our server.
6. Payments, tax and sanctions screening
Subscriptions are billed through Stripe Payments Europe Ltd. Card data is entered on Stripe’s pages and never reaches our servers. Stripe Checkout collects your name or company name, email address, billing address and VAT ID, and Stripe issues the invoices. We store the Stripe customer and subscription references, the plan, the subscription status and billing period, and payment-failure and dispute events. Stripe’s own privacy information and terms apply in addition: [PLACEHOLDER: links to Stripe’s privacy policy and data-processing terms].
At checkout we check the billing country against the countries we do not serve because of EU sanctions, and — when a sanctions list is configured — the billing name against it; possible matches are held for manual review. Legal basis: Art. 6(1)(c) GDPR together with the EU sanctions regulations and the Außenwirtschaftsgesetz, and Art. 6(1)(b) for billing.
Retention. Invoices and booking records (name, billing address, VAT ID, invoice contents) are kept for 8 years from the end of the calendar year of issue (§147(3) AO, §14b(1) UStG, §257(4) HGB) — at Stripe and in our accounting archive, not in the service database. Business letters relevant for tax purposes are kept for 6 years. When your organisation is erased we keep the subscription record that links it to those invoices, and the billing and account events listed in section 7 until the connection log’s own retention ends.
7. Browser sessions — the connection log
Your automation drives browsers in workers dedicated to your organisation. The DevTools Protocol traffic is piped through our gateway without being read. We record connection metadata only:
- per session: start and end time, organisation, the ID of the API key used, session ID, the worker and host it ran on, the IP address of the connecting client, the public IP address of that host (also when you use your own proxy — a browser can send traffic around a proxy — in which case we also record the proxy’s host and port, never its credentials), close reason, and the number of bytes piped;
- per client attaching to or leaving a session: the time and its IP address;
- per REST call (screenshot, PDF, content, scrape): the target hostname — not the path, query string or page content — and the outcome, including refused targets;
- per worker, in 15-minute windows: the bytes it sent and received over its network interface (internet traffic and the DevTools traffic to our gateway alike);
- per billing or account event of your organisation: a completed checkout (billing country, Terms acceptance and version, the types — not the numbers — of tax IDs entered), payment reminders, payment disputes, fraud warnings and refunds, a VAT ID removed or not verifiable, suspensions with their reason, and close requests and their withdrawal.
We do not record the URLs your browsers open over the DevTools Protocol, page content, response bodies, form input or credentials. Screenshots, PDFs and HTML from the REST API are streamed back to you and not stored. Browser profiles (cookies, storage, downloads) are deleted when each session ends. We never resell anything a session retrieves.
Purposes. Running the service (capacity, debugging, enforcing your plan’s concurrency), detecting misuse as described in Terms §6, and answering an abuse complaint or a lawful request about one of our IP addresses at a given time — several customers can share one IP address, so without this log we could not tell whose session it was. Legal basis: Art. 6(1)(f) GDPR (security of the service, defence against misuse and claims), and Art. 6(1)(c) where a legal obligation to answer applies.
Retention. The connection log (billing and account events included) is append-only and kept for 3 years (1095 days), then deleted automatically; it survives the erasure of an account for that period. The session list shown in your dashboard (with client and outbound IP addresses) is deleted after 90 days, except sessions named in an open abuse case, which are kept until the case is closed. Traffic-volume records are kept while your account exists. Only our operators can query this data.
You can download all of this for your organisation at any time; see switching and export.
8. Notices under Art. 16 DSA and abuse reports
When you report allegedly illegal content or activity through the abuse form or by email, we process your name, email address, the content of your notice (URLs, explanation, attachments you send) and, for network-abuse reports, the IP addresses, times and targets you report. We send you a confirmation of receipt and our decision; to stop our form being used to send email to third parties, we count confirmations per recipient address, stored only as a hash.
Legal basis: Art. 6(1)(c) GDPR together with Art. 16 DSA, and Art. 6(1)(f) for reports outside Art. 16 (for example a provider forwarding a network-abuse complaint). We do not pass your name or email address to the customer concerned; the statement of reasons they receive describes the notice without identifying you. Alerts to our staff about new notices contain no personal data. Retention: [PLACEHOLDER: retention of Art. 16 notices after the decision, e.g. 3 years — the retention job does not prune abuse reports yet, so they are kept until this is decided and implemented].
9. Operator alerts and backups
- Operator alerts (when enabled). Events that need a person — failed hosts, payment disputes, sanctions-screening hits, traffic-volume alerts — are posted to a chat webhook at [PLACEHOLDER: operator-alert chat / webhook provider — name and location]. Alerts carry internal identifiers (organisation, host and subscription IDs) and, for billing and screening events, the organisation or billing name concerned; never page content or notifier identities. Legal basis: Art. 6(1)(f) GDPR.
- Backups. The service database is backed up nightly. Each dump is encrypted before it leaves the server and, when offsite backups are enabled, copied to [PLACEHOLDER: offsite backup storage provider — name, seat and location (a separate account from Hetzner)], which cannot read it. Every copy, local and offsite, expires after 14 days, so data we erase is gone from all backups within 15 days. Legal basis: Art. 6(1)(f) GDPR and Art. 32 (availability).
10. Recipients
We do not sell personal data and do not use it for advertising. These parties receive personal data from us, each only for the purpose stated:
- Hetzner Online GmbH — Server hosting and network for the control plane and all browser workers (processor). Locations: Falkenstein and Nuremberg (Germany), Helsinki (Finland).
- [PLACEHOLDER: offsite backup storage provider — name, seat and location (a separate account from Hetzner)] — Offsite copy of the nightly control-plane database backup, encrypted before upload with a key the provider does not hold (processor). Locations: EU.
- Stripe Payments Europe Ltd. (Ireland) — payments, invoicing and tax calculation; see section 6.
- Our transactional email provider, [PLACEHOLDER: transactional email provider — name, seat and processing location (an EU provider is planned)] — delivers the emails described in sections 4 and 8 (processor).
- Google Ireland Ltd. and GitHub, Inc. (USA) — only if you choose to sign in with them; they learn that you signed in to us, and we receive the profile data listed in section 4.
- Cloudflare, Inc. (USA) — Turnstile bot protection, when enabled; see section 5.
- The operator-alert provider, [PLACEHOLDER: operator-alert chat / webhook provider — name and location], when enabled; see section 9.
- Our uptime monitor, [PLACEHOLDER: external uptime-monitor / status-page provider — name and location] — it only calls our public health endpoints and receives no personal data from us.
- Courts, authorities and law enforcement, where the law obliges us to disclose data (Art. 6(1)(c) GDPR).
The list of subprocessors for customer data, with the notification duty on changes, is part of the DPA.
11. Transfers outside the EU/EEA
The service infrastructure and the connection log stay in the EU (Falkenstein and Nuremberg (Germany), Helsinki (Finland)). Transfers to the USA happen only through the optional sign-in providers (Google, GitHub), Cloudflare Turnstile when enabled, and Stripe’s group companies for payment processing. They rest on the EU–US Data Privacy Framework adequacy decision where the recipient is certified, and otherwise on the European Commission’s standard contractual clauses (Art. 45, 46(2)(c) GDPR). Questions about a specific transfer: [PLACEHOLDER: legal / DPA contact email].
12. Cookies and similar technologies
Strictly necessary cookies only: the cookies our login system needs to keep you signed in. No analytics, no advertising, no cross-site tracking, so no consent banner is required (§25(2) No. 2 TDDDG). Fonts are served from our own origin. The only third-party script is Cloudflare Turnstile on the sign-up and login forms, when enabled (section 5).
13. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21) — objection in particular against processing based on Art. 6(1)(f). Organisation owners and admins can download a full export of their organisation’s data from the dashboard at any time. For everything else write to [PLACEHOLDER: privacy contact email] — we answer within one month.
You may also lodge a complaint with a supervisory authority. The one competent for us: [PLACEHOLDER: competent supervisory authority for the registered seat (Landesdatenschutzbeauftragte/r)].
14. Changes
We publish the current version here and notify account holders by email before a substantial change takes effect.