Legal
Data processing agreement
This agreement governs how Upscrape processes personal data on a customer's behalf when providing the service.
Contents
This Data Processing Agreement ("DPA") is between Sylego LLC, a Wyoming limited liability company doing business as Upscrape ("Upscrape"), and the customer that accepts or enters into an agreement for the service ("Customer").
This DPA forms part of the Upscrape Terms of Service or another agreement governing Customer's use of the service (the "Agreement"). It is effective when Customer accepts the Agreement or when both parties sign an order that incorporates it. If there is a conflict concerning Customer Personal Data, the order of precedence is the applicable Standard Contractual Clauses, this DPA, and then the Agreement.
01
Application
This DPA applies only to the extent Upscrape processes Customer Personal Data as a Processor on Customer's behalf in providing the service. It does not apply to information for which Upscrape determines the purposes and means of processing as an independent Controller, including account, billing, security, support, and business relationship information handled under the Privacy Policy.
The annexes describe the processing, security measures, and authorized Subprocessors and form part of this DPA.
02
Definitions
"Customer Personal Data" means Personal Data contained in Customer inputs, requests, credentials, results, and other content processed by Upscrape on Customer's behalf. "Data Protection Laws" means privacy and data protection laws applicable to that processing, including where applicable the EU GDPR, UK GDPR, Swiss Federal Act on Data Protection, and United States state privacy laws.
"Controller," "Processor," "Data Subject," "Personal Data," "Processing," and "Personal Data Breach" have the meanings given by applicable Data Protection Laws. "Subprocessor" means a third party appointed by Upscrape to process Customer Personal Data on Customer's behalf. Capitalized terms not defined here have the meanings in the Agreement.
03
Roles and processing scope
Customer is the Controller or Processor, as applicable, and Upscrape is Customer's Processor or Subprocessor. Each party will comply with the obligations Data Protection Laws impose on its role.
Upscrape will process Customer Personal Data to provide, secure, maintain, and support the service as described in the Agreement, Customer's use and configuration of the service, documented support requests, and Annex I. The processing continues for the term of the Agreement and the limited retention period described below.
04
Documented instructions
Upscrape will process Customer Personal Data only on Customer's documented instructions, including for international transfers, unless applicable law requires other processing. The Agreement, this DPA, Customer's API or MCP requests, account configuration, and documented support requests constitute Customer's instructions.
If law requires processing outside those instructions, Upscrape will inform Customer before processing unless the law prohibits notice. Upscrape will notify Customer if, in its reasonable opinion, an instruction violates Data Protection Laws. Upscrape may suspend the affected processing while the parties address the issue and is not required to perform an unlawful instruction.
05
Customer obligations
Customer is responsible for the lawfulness, accuracy, quality, and scope of Customer Personal Data and its instructions. Customer will provide all required notices, obtain all required rights and consents, establish a lawful basis, respond to Data Subjects, and use the service and results in accordance with Data Protection Laws.
Customer will limit Personal Data to what is necessary for its use case and will not submit special-category, highly sensitive, health, biometric, payment-card, government-identifier, or children's data unless the parties expressly agree in writing and Customer has a lawful basis and appropriate safeguards. Customer is responsible for securely configuring its account, credentials, integrations, and downstream systems.
06
Personnel and confidentiality
Upscrape will limit access to Customer Personal Data to personnel who need access to provide, secure, or support the service. Authorized personnel will be subject to confidentiality obligations and receive instructions appropriate to their responsibilities. Confidentiality obligations continue after their engagement ends.
07
Security
Taking into account the state of the art, implementation costs, processing context, and risk to Data Subjects, Upscrape will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The current measures are summarized in Annex II.
Upscrape may update its safeguards as technology and risks change, provided the overall level of protection does not materially decrease during the term. Customer acknowledges that no service can eliminate every security risk.
08
Subprocessors
Customer gives Upscrape general written authorization to use the Subprocessors described in Annex III. Upscrape will require each Subprocessor to protect Customer Personal Data through a written agreement that imposes obligations appropriate to the processing and no less protective in substance than the relevant obligations of this DPA. Upscrape remains responsible for a Subprocessor's performance of those obligations to the extent required by Data Protection Laws.
Upscrape will provide at least 15 days' advance notice by email or through the service before a new Subprocessor begins processing Customer Personal Data. Customer may object during that period on reasonable data protection grounds. The parties will work in good faith on a commercially reasonable alternative. If none is available, Customer may stop using the affected capability or terminate only the affected service. This is Customer's sole remedy for an unresolved Subprocessor objection.
A website, marketplace, social network, data source, account, or other third party that Customer directs Upscrape to access or receive data from is a "Customer-Directed Third Party," not an Upscrape Subprocessor. Customer authorizes the disclosures needed to execute its request and is responsible for that third party's terms and data handling.
09
Data Subject requests
Taking into account the nature of the processing, Upscrape will provide reasonable assistance through available service functionality and technical measures so Customer can respond to requests to exercise Data Subject rights.
If Upscrape receives a request concerning Customer Personal Data, it will refer the requester to Customer when reasonably identifiable and will not independently respond on Customer's behalf unless Customer instructs it or law requires. Customer remains responsible for evaluating and responding to each request.
10
Compliance assistance
Taking into account the nature of processing and information available to Upscrape, Upscrape will provide reasonable assistance with Customer's obligations concerning security, breach notification, data protection impact assessments, and prior consultation with regulators.
Upscrape may charge reasonable fees for assistance that is unusually burdensome, repetitive, or outside standard service functionality, unless the assistance is required because Upscrape breached this DPA. The parties will agree on scope and fees before that work begins where practicable.
11
Personal Data Breaches
Upscrape will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. Notice will be sent to the account contact or another contact designated by Customer.
As information becomes reasonably available, notice will describe the nature of the breach, affected data and Data Subjects, likely consequences, mitigation taken or proposed, and a contact for follow-up. Upscrape will take reasonable steps to contain, investigate, and mitigate the breach and will reasonably cooperate with Customer. Notice is not an admission of fault or liability.
Unsuccessful attempts or events that do not result in unauthorized access to Customer Personal Data are not Personal Data Breaches under this DPA.
12
Return and deletion
Customer may retrieve available results through the service during their retention period. API and MCP request inputs, results, and associated execution errors are normally deleted within 30 days of processing.
After termination of the affected service or a valid deletion instruction, Upscrape will delete remaining Customer Personal Data within 30 days unless applicable law requires retention. If law requires retention, Upscrape will isolate and protect the retained data and process it only for that legal requirement. On written request, Upscrape will provide reasonable confirmation of deletion.
13
Information and audits
Upscrape will make available information reasonably necessary to demonstrate compliance with Article 28 and this DPA. Customer should first use current documentation, questionnaires, summaries, and independent reports that Upscrape makes available.
If that information is insufficient, Customer may conduct one audit in any 12-month period through an independent, qualified auditor that is not a competitor and is bound by confidentiality. Customer must give at least 30 days' notice, limit the audit to relevant systems and records, conduct it during normal business hours without disrupting operations, and bear its costs. An audit may not expose another customer's information, source code, security testing results that would increase risk, or privileged information.
The annual limit and advance notice do not apply where a regulator requires an audit or Customer reasonably believes a confirmed Personal Data Breach or material breach of this DPA requires one. The parties will agree reasonable scope and safeguards before any access.
14
International transfers
Customer authorizes Upscrape and its authorized Subprocessors to process Customer Personal Data in the countries identified in Annex III. Upscrape will use a lawful transfer mechanism where Data Protection Laws require one.
For restricted transfers of Customer Personal Data from the European Economic Area or Switzerland to Upscrape in the United States, the European Commission Standard Contractual Clauses adopted by Decision 2021/914 are incorporated by reference. Module Two applies when Customer is a Controller and Module Three applies when Customer is a Processor. Clause 7 does not apply; Clause 9 uses Option 2 with the 15-day notice period in this DPA; the optional language in Clause 11 does not apply; Ireland supplies the governing law under Clause 17 and courts under Clause 18. The competent supervisory authority is determined under Clause 13. Annexes I through III of this DPA complete the corresponding SCC annexes.
For restricted transfers governed by UK law, the UK International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner's Office is incorporated by reference. The parties are the exporter and importer identified in this DPA, the selected EU SCC module and annexes above complete its tables, and neither party may terminate the Addendum solely because the ICO issues a revised form. For Swiss transfers, references to the GDPR include the Swiss Federal Act on Data Protection, references to EU Member States include Switzerland where appropriate, and the competent authority is the Swiss Federal Data Protection and Information Commissioner.
If a transfer mechanism becomes invalid, the parties will cooperate in good faith to implement a lawful alternative. Nothing in this DPA modifies the SCCs in a way that conflicts with Data Protection Laws.
15
United States privacy laws
Where applicable, Upscrape acts as Customer's service provider or processor for Customer Personal Data. Upscrape will not sell or share Customer Personal Data, retain, use, or disclose it outside the direct business relationship except as permitted by applicable law, or combine it with personal information received from another source except as permitted to provide the service.
Upscrape certifies that it understands and will comply with these restrictions. Customer may take reasonable and appropriate steps to help ensure processing is consistent with applicable obligations and may require Upscrape to stop and remediate unauthorized use. Upscrape will notify Customer if it determines it can no longer meet an applicable service-provider or processor obligation.
16
Liability
Each party's liability arising from this DPA is subject to the exclusions, limitations, procedures, and aggregate liability cap in the Agreement. Nothing in this section limits liability to the extent a limitation is prohibited by applicable law or alters the allocation of liability in the Standard Contractual Clauses.
17
General terms
This DPA remains effective while Upscrape processes Customer Personal Data. Amendments must be in writing, except Upscrape may update this DPA to comply with law or make changes that do not materially reduce protection. Material changes will be communicated through the service or account email.
If a provision is unenforceable, it will be modified to the minimum extent necessary and the remainder remains effective. Governing law and dispute terms in the Agreement apply except where Data Protection Laws or the Standard Contractual Clauses require otherwise.
Annex I
Details of processing
Parties
Data exporter: Customer and any Customer affiliate authorized under the Agreement. Customer's contact details and activities are those associated with its account or order.
Data importer: Sylego LLC, doing business as Upscrape, 30 North Gould Street, Suite N, Sheridan, Wyoming 82801, United States. Privacy contact: [email protected]. Upscrape provides the data-access and processing services described in the Agreement.
Subject matter and purpose
Providing APIs, MCP tools, platform capabilities, result delivery, support, security, and related services that Customer requests.
Nature of processing
Receiving, transmitting, accessing, retrieving, collecting, structuring, normalizing, comparing, hosting, storing, returning, troubleshooting, securing, and deleting Customer Personal Data.
Duration and frequency
Processing occurs when Customer submits a request or uses a configured capability during the Agreement. Request inputs, results, and associated execution errors are normally retained for 30 days. Compact monitor run metadata may be retained for up to 90 days; monitor snapshots and detected-change data are normally retained for 30 days. Other processing ends according to Section 12.
Categories of Data Subjects
Customer's users, personnel, contractors, clients, prospects, and end users; users or other individuals represented in Customer inputs; and individuals whose information appears in public platform or website data requested by Customer.
Categories of Personal Data
Identifiers and contact details; online and device identifiers; public profile, creator, marketplace, review, employment, business, location, and social content; customer-supplied queries and parameters; credentials and authorization data; service usage and diagnostic information; and other Personal Data Customer submits or directs Upscrape to retrieve.
Sensitive data
The service is not designed for special-category or highly sensitive data. Customer must not submit such data unless expressly agreed in writing. If agreed, the frequency, safeguards, and restrictions in the written order also apply.
Customer instructions
The Agreement, this DPA, Customer's requests and configurations, and documented support instructions. For Module Three transfers, Customer will provide Upscrape with relevant Controller instructions and notify Upscrape of changes.
Annex II
Technical and organizational measures
- Access control: role-based and least-privilege access, authentication controls, restricted production access, and account-level authorization.
- Credential protection: protected storage for customer-provided credentials, hashing for secrets where verification rather than recovery is required, and controls against exposing secrets in public interfaces.
- Transmission security: encryption in transit using current transport security protocols and protected service endpoints.
- Data separation: logical account separation, environment separation, scoped keys and tokens, and controls designed to prevent cross-account access.
- System security: security updates, hardened configuration, network controls, dependency management, and measures designed to reduce unauthorized access and malicious activity.
- Logging and monitoring: operational, security, request-status, and error logging; service monitoring; and investigation procedures for suspicious or abnormal activity.
- Availability and recovery: service monitoring, controlled deployment processes, recovery procedures, and measures appropriate to restoring availability after an incident.
- Development practices: change review, testing proportionate to risk, separation of development and production functions, and restricted use of production data.
- Incident response: processes to identify, contain, investigate, mitigate, document, and communicate confirmed Personal Data Breaches.
- Retention: scheduled deletion of request inputs, results, and execution errors after the applicable retention period, subject to documented exceptions.
- Personnel: confidentiality obligations, access limited by role and need, and removal of access when no longer required.
- Review: periodic evaluation of safeguards and updates in response to material changes in risk, systems, or law.
Annex III
Authorized Subprocessors
Upscrape engages Subprocessors in the categories below to process Customer Personal Data. Upscrape maintains a current list identifying each Subprocessor by name, purpose, and processing location, and will provide it to Customer on request at [email protected]. Account, billing, support, and optional marketing providers that process data only for Upscrape as Controller are described separately in the Privacy Policy.
| Category | Purpose | Processing location |
|---|---|---|
| Infrastructure providers | Application, database, compute, and storage infrastructure | European Union |
| Network and security providers | Network routing, traffic protection, and security services | United States and global network locations |
| Network access providers | Proxy and regional network routing for capabilities that require it | United States and customer-selected or global network locations |
Customer-Directed Third Parties and sources selected through a capability are not Subprocessors, as explained in Section 8. Upscrape will provide notice before adding a Subprocessor that can process Customer Personal Data.
18
Contact
Questions, rights requests, audit requests, and DPA notices may be sent to:
Sylego LLC, doing business as Upscrape30 North Gould Street, Suite N
Sheridan, Wyoming 82801
United States
[email protected]