Skip to content

Data processing addendum

A web page you capture can show names, faces, messages or other personal data of people who are not our customers. This addendum sets out how CurlShot handles that data for you. It is part of the terms of service and needs no signature.

Last updated

1. When this addendum applies

This addendum applies whenever we process personal data for you that is contained in the addresses, HTML, Markdown, scripts, cookies or headers you send, in the pages our browser loads at your request, or in the files we render from them ("customer data"), and a data protection law applies to that processing: the EU or UK General Data Protection Regulation (GDPR), the Swiss Federal Act on Data Protection, or a US state privacy law. Words such as "controller", "processor" and "personal data" mean what those laws say. "We" is CurlShot; "you" is the customer that accepted the terms of service.

It does not cover the data we handle about you as our customer (your account, billing and usage). For that we are the controller, and the privacy policy applies.

2. Roles

For customer data you are the controller, or a processor acting for your own customers, and we are your processor (or sub-processor). You decide which pages to capture and what to do with the results; we carry that out.

3. What is processed

  • Subject matter and purpose: rendering the pages and content you specify into image, PDF and video files, storing those files for a limited time so they can be cached and downloaded, and keeping a history of your requests.
  • Nature: loading, rendering, storing, transmitting and deleting.
  • Duration: for as long as you use the service, and after that until the data is deleted as described below.
  • Kinds of personal data: whatever is visible on the pages you capture or contained in what you send. You choose this; we do not. Typical examples are names, contact details, pictures and text written by people.
  • People concerned: the people who appear on those pages or in that content, for example your own users, customers or staff, or members of the public.

The service is not designed for special categories of data (such as health data) or data about criminal convictions. Do not send them unless you have a lawful basis and the capture really requires it.

4. Your instructions

We process customer data only on your documented instructions. Your instructions are the terms of service, this addendum, and each request you send through the API or the dashboard with the options you chose. We do not use customer data for our own purposes, do not sell it, and do not use it to train machine-learning models.

If the law requires us to process customer data in another way, we will tell you first, unless that law forbids it. If we think an instruction breaks data protection law, we will tell you and may hold the request until you confirm or change it.

5. Confidentiality

The people we authorise to work with customer data are bound by a duty of confidentiality, and have access only as far as their work requires. Our staff do not look at the content of your renders unless you ask for help with a specific request, or it is needed to investigate abuse, a security incident or a fault.

6. Security measures

We keep in place technical and organisational measures appropriate to the risk, including:

  • encryption of traffic in transit between you and the service;
  • each render in its own private browser context, destroyed afterwards, so cookies and content never pass between customers;
  • hashed passwords, and encrypted storage of API secret keys and of the tokens of connected services;
  • removal or masking of credentials (cookies, authorization and similar headers) before a request is written to the history;
  • blocking of requests to private networks and internal addresses;
  • access to stored files only for the account that made them, or through an expiring link issued to that account for the file;
  • automatic deletion of rendered files and history after their retention period;
  • access to production systems limited to the people who need it;
  • rate limits, monitoring and alerts for faults and abuse;
  • regular backups, and a tested way to restore them.

We may change these measures as technology moves on, but never in a way that lowers the overall level of protection.

7. Sub-processors

You give us general permission to use other processors ("sub-processors") for customer data. Those in use now are our hosting providers, which run the servers and the database, and Sentry (error reports). Our payment and email providers do not receive customer data.

Each sub-processor is bound by a written contract with data protection duties no weaker than those in this addendum, and we remain responsible to you for what it does. Before we add or replace a sub-processor we update this page, and tell account holders by email, at least 30 days in advance. If you object on reasonable data protection grounds within that time and we cannot offer a way around it, you may end the paid plan and receive a refund for the unused time.

8. Helping you meet your duties

Taking into account what the service does and the information we have, we help you, by appropriate technical and organisational means, to:

  • answer requests from people who use their data protection rights. The history in the dashboard lets you find the requests concerned, and on your request we delete a given file or history entry before its normal expiry. If such a person writes to us about your data, we will not answer the request ourselves; we pass it to you where we can tell which customer it concerns;
  • carry out data protection impact assessments and consult an authority, where the law requires it of you;
  • meet your own duties on security and on reporting breaches.

9. Personal data breaches

If we become aware of a breach of security that leads to the accidental or unlawful destruction, loss, alteration or disclosure of customer data, or access to it, we will tell you without undue delay at the email address of your account. We will describe what happened, the data and people likely to be affected so far as we know, and what we are doing about it, and we will add to that as we learn more. Telling you about a breach is not an admission of fault.

10. Deletion and return

Rendered files are deleted automatically at the end of their cache lifetime, at most 30 days after the render, and the history of a request after 30 days. You can download your files through the API until then. When your account is closed, the same schedule runs out for whatever is left, and backup copies are overwritten in the normal rotation. We keep customer data longer only where a law that applies to us requires it, and then only for that purpose.

11. Information and audits

On request we give you the information needed to show that we meet the duties in this addendum, including answers to a reasonable security questionnaire. Where that is not enough for what the law requires of you, you or an independent auditor bound by confidentiality may carry out an audit, at most once a year unless there has been a breach, with at least 30 days' written notice, during business hours, at your cost, and without access to other customers' data.

12. International transfers

We and our sub-processors may process customer data outside the country where you are. Where we pass personal data that is subject to EU, UK or Swiss law to a sub-processor in a country without an adequacy decision, we put in place a transfer safeguard the law accepts, such as the European Commission's standard contractual clauses.

Where you send us personal data that is subject to the GDPR and we receive it in a country without an adequacy decision, the standard contractual clauses in Commission Implementing Decision (EU) 2021/914 form part of this addendum, as follows:

  • Module Two applies where you are a controller, and Module Three where you are a processor. You are the data exporter and we are the data importer.
  • Clause 7 (docking) and the optional wording in Clause 11 do not apply.
  • Clause 9: option 2 (general written authorisation), with the notice period stated above.
  • Clauses 17 and 18: the law and the courts of the EU member state where you are established; if there is none, Ireland.
  • Annex I is filled in with the parties to the terms of service and the details in section 3 above; the competent authority is the one for your establishment. Annex II is the list of measures in section 6. Annex III is the list in section 7.

For transfers subject to UK law, the International Data Transfer Addendum issued by the UK Information Commissioner (version B1.0) applies together with those clauses, with its tables filled in from the same information. For transfers subject to Swiss law, references to the GDPR are read as references to the Swiss Federal Act on Data Protection and the competent authority is the Swiss Federal Data Protection and Information Commissioner. If the clauses conflict with the rest of the agreement, the clauses win.

13. US state privacy laws

Where a US state privacy law applies, we act as your service provider or processor. We do not sell or share customer data, do not keep, use or disclose it outside our direct business relationship with you or for any purpose other than providing the service, and do not combine it with personal data from other sources except as those laws allow a service provider to do. We will tell you if we can no longer meet these duties.

14. Your duties

  • You have a lawful basis for capturing the pages you request and for every use you make of the results.
  • You have told the people concerned what the law requires you to tell them.
  • Your instructions to us are lawful.
  • You choose a cache lifetime in line with how long you are allowed to keep the data, and ask us to delete a file earlier when you must.
  • You keep your keys safe and control who in your organisation can use them.

15. Liability, term and precedence

The limits of liability in the terms of service apply to this addendum, except that nothing here limits what either side owes to the people whose data is concerned or to an authority. The addendum lasts as long as we process customer data for you. If it conflicts with the terms of service on a matter of data protection, the addendum wins.

If your organisation needs a signed copy, or has questions about this addendum, write to us through the contact form or [email protected].