Legal

Data Processing Agreement

The Article 28 GDPR contract for data BotPass processes on a customer’s behalf.

Version 1.0 · Effective 9 September 2026

This Agreement is entered into under Article 28(3) GDPR between:

It forms part of, and is subject to, the BotPass Terms of Service. Where the two conflict on a matter of personal data, this Agreement prevails.

It takes effect when the Customer opens a BotPass account and lasts as long as BotPass processes personal data on the Customer's behalf.


1. Roles#

The Customer is the controller. BotPass is the processor and acts only on the Customer's documented instructions.

The Customer's use of the service — connecting a site, installing the plugin, accepting a proposal, configuring prompts — constitutes its documented instructions. Any other instruction must be in writing and may carry a charge if it requires work outside the service.

BotPass will inform the Customer if, in its opinion, an instruction infringes the GDPR or other data protection law. BotPass may refuse to carry it out.

2. Subject matter and duration#

Subject matter: provision of the BotPass service — measuring how AI systems read and cite the Customer's website, running controlled experiments on it, and reporting the results.

Duration: the term of the Customer's subscription, plus the deletion period in section 11.

3. Nature and purpose of the processing#

Collection, storage, structuring, analysis, anonymisation and erasure of request data from the Customer's websites, for the purpose of operating the service.

4. Categories of data subjects#

5. Categories of personal data#

BotPass writes a log row for each relevant request to a Customer site. That row may contain:

FieldPersonal data?
IP addressYes. Under Art. 4(1) GDPR an IP address is personal data
User agent stringPossibly, in combination
Referring URLPossibly, if the referrer carries identifiers
Requested URL, method, status codeOnly if the URL itself carries identifiers
Country, derived from the IPYes, as a derived attribute
Bot identity, event type, timing, token counts, cache statusNo

The great majority of these rows describe automated crawlers, not people. But not all of them do: the log also records the referred human visits that follow an AI citation, and those rows carry the visitor's IP address. We are not going to describe this data as "just bot traffic", because it is not.

BotPass also stores copies of the Customer's page content in order to render, compare and analyse it. If the Customer publishes personal data on its own website, that personal data is processed here too.

No special categories of data under Art. 9 GDPR are knowingly processed. The Customer must not use BotPass to process them, and must not place them in prompt text.

6. Retention and erasure#

7. Security measures (Art. 32)#

BotPass implements appropriate technical and organisational measures, including:

These measures are reviewed periodically and may be updated, provided the level of protection is not reduced.

8. Confidentiality#

Everyone authorised by BotPass to process the Customer's personal data is bound by a duty of confidentiality that survives the end of their engagement.

9. Sub-processors#

The Customer gives general authorisation for BotPass to engage sub-processors. BotPass imposes on each of them data protection obligations no less protective than those in this Agreement, and remains fully liable to the Customer for their performance.

Current sub-processors:

Sub-processorPurposeLocation of processing
Amazon Web Services EMEA SARLHosting, database, object storage, queuesIreland (eu-west-1)
StripePayment processingEU / United States
ResendTransactional emailEU / United States
OpenAIAI provider queried during measurementUnited States
AnthropicAI provider queried during measurementUnited States
Google (Gemini, and optional sign-in)AI provider queried during measurement; authenticationUnited States
PerplexityAI provider queried during measurementUnited States

BotPass will give the Customer at least thirty days' notice before adding or replacing a sub-processor. If the Customer reasonably objects on data protection grounds within that period, it may terminate the affected part of the service without penalty, refunded pro rata.

What reaches the AI providers. BotPass sends them the measurement question and records the answer, the cited URLs and whether the Customer's page was among them. It does not send account data, billing data, request logs or visitor IP addresses. The Customer must not place personal data in prompt text.

10. International transfers#

All Customer data is stored in the European Union.

Transfers to the sub-processors located in the United States are made under the European Commission's Standard Contractual Clauses (Decision 2021/914), module three (processor to processor), and, where the sub-processor is certified, under the EU–US Data Privacy Framework, together with the supplementary measures BotPass considers appropriate following its transfer impact assessment.

Copies of the safeguards are available on request.

11. Deletion or return at the end of the contract#

Within ninety days of the end of the subscription, BotPass will delete the Customer's personal data, unless EU or Member State law requires it to be kept.

Before deleting, and on request during that window, BotPass will make the Customer's data available for export.

Two things are deliberately outside this:

12. Assistance to the Controller#

BotPass will assist the Customer, taking into account the nature of the processing and the information available to it, with:

13. Personal data breach#

BotPass will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Customer's data.

The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where the information is not all available at once, it will be provided in phases, without delaying the first notification.

BotPass will not require the Customer's approval before notifying a supervisory authority of a breach that BotPass itself is obliged to report.

14. Audit#

BotPass will make available to the Customer the information necessary to demonstrate compliance with Art. 28 GDPR, and will allow and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.

Audits are subject to: reasonable prior notice of at least thirty days; no more than once per twelve months, unless a breach or a supervisory authority's instruction makes another necessary; conduct during business hours and without unreasonable disruption; and a confidentiality undertaking from the auditor. The Customer bears the cost of the audit unless it reveals material non-compliance.

15. Liability#

Liability under this Agreement is subject to the limitations in the Terms of Service, except where the GDPR provides otherwise. Article 82 GDPR governs liability towards data subjects and is not altered by this Agreement.

16. Governing law#

This Agreement is governed by Spanish law, and the courts of Barcelona have exclusive jurisdiction.


Annex I — Summary of the processing#

ControllerThe Customer
ProcessorSan Mateo Capital, S.L.
Subject matterMeasuring AI reading and citation of the Customer's website; running controlled experiments on it
DurationTerm of the subscription + 90 days
NatureCollection, storage, structuring, analysis, anonymisation, erasure
PurposeProviding the BotPass service
Data subjectsWebsite visitors (human and automated), the Customer's personnel, individuals named in the Customer's published content
Data categoriesIP address, user agent, referrer, requested URL, derived country, request metadata; page content
Special categoriesNone. Prohibited by section 5
RetentionLogs anonymised at 12 months; hard erasure on request; full deletion 90 days after termination