Data Processing Agreement
The Article 28 GDPR contract for data BotPass processes on a customer’s behalf.
This Agreement is entered into under Article 28(3) GDPR between:
- Controller: the Customer identified in the BotPass account.
- Processor: San Mateo Capital, S.L., CIF B67381368, C/ Roger de Lluria 137, 08037 Barcelona, Spain.
It forms part of, and is subject to, the BotPass Terms of Service. Where the two conflict on a matter of personal data, this Agreement prevails.
It takes effect when the Customer opens a BotPass account and lasts as long as BotPass processes personal data on the Customer's behalf.
1. Roles#
The Customer is the controller. BotPass is the processor and acts only on the Customer's documented instructions.
The Customer's use of the service — connecting a site, installing the plugin, accepting a proposal, configuring prompts — constitutes its documented instructions. Any other instruction must be in writing and may carry a charge if it requires work outside the service.
BotPass will inform the Customer if, in its opinion, an instruction infringes the GDPR or other data protection law. BotPass may refuse to carry it out.
2. Subject matter and duration#
Subject matter: provision of the BotPass service — measuring how AI systems read and cite the Customer's website, running controlled experiments on it, and reporting the results.
Duration: the term of the Customer's subscription, plus the deletion period in section 11.
3. Nature and purpose of the processing#
Collection, storage, structuring, analysis, anonymisation and erasure of request data from the Customer's websites, for the purpose of operating the service.
4. Categories of data subjects#
- Visitors to the Customer's websites, including the operators of automated crawlers, and the human readers whose visits the plugin records.
- The Customer's own personnel who use the BotPass application. (Their account data is also covered by the Privacy Policy, where BotPass is the controller. Both descriptions are true and neither replaces the other.)
- Any individual whose personal data appears in the Customer's published page content, which BotPass fetches and stores in order to analyse it.
5. Categories of personal data#
BotPass writes a log row for each relevant request to a Customer site. That row may contain:
| Field | Personal data? |
|---|---|
| IP address | Yes. Under Art. 4(1) GDPR an IP address is personal data |
| User agent string | Possibly, in combination |
| Referring URL | Possibly, if the referrer carries identifiers |
| Requested URL, method, status code | Only if the URL itself carries identifiers |
| Country, derived from the IP | Yes, as a derived attribute |
| Bot identity, event type, timing, token counts, cache status | No |
The great majority of these rows describe automated crawlers, not people. But not all of them do: the log also records the referred human visits that follow an AI citation, and those rows carry the visitor's IP address. We are not going to describe this data as "just bot traffic", because it is not.
BotPass also stores copies of the Customer's page content in order to render, compare and analyse it. If the Customer publishes personal data on its own website, that personal data is processed here too.
No special categories of data under Art. 9 GDPR are knowingly processed. The Customer must not use BotPass to process them, and must not place them in prompt text.
6. Retention and erasure#
- Request logs are anonymised after twelve months. The IP address, user agent and referrer are irreversibly removed. The counts and timings stay, because the extraction ratio, the re-crawl detector and the experiment analysis are computed from them, and deleting the rows outright would silently rewrite the Customer's own history.
- On request, BotPass will hard-erase all log rows for a Customer. This is a real deletion, not an anonymisation, and it is destructive: the Customer's extraction ratio and any experiment evidence drawn from that traffic go with it. BotPass will say so before doing it, and then do it.
- Page content copies are deleted or superseded as part of normal operation and on account termination.
7. Security measures (Art. 32)#
BotPass implements appropriate technical and organisational measures, including:
- Encryption of data in transit (TLS).
- Access control: per-customer API keys; strict tenant isolation, so that a request authenticated for one site cannot read or write another's data.
- Administrative access restricted to identified operator accounts, protected by two-factor authentication and network restrictions.
- Secrets held in a managed secret store, never in source code.
- Audit logging of administrative actions.
- Retention limits and automated anonymisation as set out in section 6.
- Segregation of environments; production data is not used for development.
These measures are reviewed periodically and may be updated, provided the level of protection is not reduced.
8. Confidentiality#
Everyone authorised by BotPass to process the Customer's personal data is bound by a duty of confidentiality that survives the end of their engagement.
9. Sub-processors#
The Customer gives general authorisation for BotPass to engage sub-processors. BotPass imposes on each of them data protection obligations no less protective than those in this Agreement, and remains fully liable to the Customer for their performance.
Current sub-processors:
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| Amazon Web Services EMEA SARL | Hosting, database, object storage, queues | Ireland (eu-west-1) |
| Stripe | Payment processing | EU / United States |
| Resend | Transactional email | EU / United States |
| OpenAI | AI provider queried during measurement | United States |
| Anthropic | AI provider queried during measurement | United States |
| Google (Gemini, and optional sign-in) | AI provider queried during measurement; authentication | United States |
| Perplexity | AI provider queried during measurement | United States |
BotPass will give the Customer at least thirty days' notice before adding or replacing a sub-processor. If the Customer reasonably objects on data protection grounds within that period, it may terminate the affected part of the service without penalty, refunded pro rata.
What reaches the AI providers. BotPass sends them the measurement question and records the answer, the cited URLs and whether the Customer's page was among them. It does not send account data, billing data, request logs or visitor IP addresses. The Customer must not place personal data in prompt text.
10. International transfers#
All Customer data is stored in the European Union.
Transfers to the sub-processors located in the United States are made under the European Commission's Standard Contractual Clauses (Decision 2021/914), module three (processor to processor), and, where the sub-processor is certified, under the EU–US Data Privacy Framework, together with the supplementary measures BotPass considers appropriate following its transfer impact assessment.
Copies of the safeguards are available on request.
11. Deletion or return at the end of the contract#
Within ninety days of the end of the subscription, BotPass will delete the Customer's personal data, unless EU or Member State law requires it to be kept.
Before deleting, and on request during that window, BotPass will make the Customer's data available for export.
Two things are deliberately outside this:
- Aggregate experiment results already contributed to the shared evidence grid. They contain no personal data and no identifier of the Customer, and they are not deleted. This is stated in section 7 of the Terms of Service.
- Interventions already applied to the Customer's own pages. They are changes to the Customer's content, on the Customer's server. BotPass has no access to undo them and will not claim otherwise.
12. Assistance to the Controller#
BotPass will assist the Customer, taking into account the nature of the processing and the information available to it, with:
- Data subject requests (Arts. 12–23). Requests from website visitors go to the Customer, who is their controller. If a visitor writes to BotPass instead, BotPass will not answer on the Customer's behalf; it will forward the request without undue delay and help the Customer respond.
- Security, breach notification and impact assessments (Arts. 32–36).
13. Personal data breach#
BotPass will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Customer's data.
The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where the information is not all available at once, it will be provided in phases, without delaying the first notification.
BotPass will not require the Customer's approval before notifying a supervisory authority of a breach that BotPass itself is obliged to report.
14. Audit#
BotPass will make available to the Customer the information necessary to demonstrate compliance with Art. 28 GDPR, and will allow and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.
Audits are subject to: reasonable prior notice of at least thirty days; no more than once per twelve months, unless a breach or a supervisory authority's instruction makes another necessary; conduct during business hours and without unreasonable disruption; and a confidentiality undertaking from the auditor. The Customer bears the cost of the audit unless it reveals material non-compliance.
15. Liability#
Liability under this Agreement is subject to the limitations in the Terms of Service, except where the GDPR provides otherwise. Article 82 GDPR governs liability towards data subjects and is not altered by this Agreement.
16. Governing law#
This Agreement is governed by Spanish law, and the courts of Barcelona have exclusive jurisdiction.
Annex I — Summary of the processing#
| Controller | The Customer |
| Processor | San Mateo Capital, S.L. |
| Subject matter | Measuring AI reading and citation of the Customer's website; running controlled experiments on it |
| Duration | Term of the subscription + 90 days |
| Nature | Collection, storage, structuring, analysis, anonymisation, erasure |
| Purpose | Providing the BotPass service |
| Data subjects | Website visitors (human and automated), the Customer's personnel, individuals named in the Customer's published content |
| Data categories | IP address, user agent, referrer, requested URL, derived country, request metadata; page content |
| Special categories | None. Prohibited by section 5 |
| Retention | Logs anonymised at 12 months; hard erasure on request; full deletion 90 days after termination |