This Data Processing Agreement ("DPA") forms part of the Terms of Service between Maximiliano Nicolás Alemandi / Crafy Holding ("Data Processor") and the business customer ("Data Controller") utilizing the CrafyCAPTCHA service (the "Service").


1. Definitions

For the purposes of this DPA:

2. Scope and Nature of Processing

The Processor will process Personal Data solely to provide the CrafyCAPTCHA bot-mitigation service to the Controller. The processing operations include the collection, pseudonymization, temporary caching, and analysis of network and behavioral data to prevent automated fraud.

Categories of Data Subjects: End-users visiting the Controller's web applications protected by CrafyCAPTCHA.

Types of Personal Data: IP Addresses (pseudonymized immediately via cryptographic hashing), User-Agent strings, and transient behavioral metrics (e.g., mouse movements, puzzle solve times).

3. Controller Instructions

The Processor shall process Personal Data only on documented instructions from the Controller, including those set forth in the Terms of Service and this DPA, unless required to do so by applicable law.

4. Confidentiality

The Processor shall ensure that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5. Security of Processing (Art. 32 GDPR)

The Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures include:

6. Sub-processors

The Controller provides general authorization for the Processor to engage Sub-processors. The current list of Sub-processors includes:

The Processor will notify the Controller (e.g., via email or dashboard notification) at least 30 days before adding or replacing any critical Sub-processor, giving the Controller the opportunity to object.

7. International Data Transfers

Any transfer of Personal Data outside the European Economic Area (EEA) shall be governed by appropriate safeguards. For Cloudflare, transfers are covered under the EU-US Data Privacy Framework (DPF). For Hostinger, transfers are covered by Standard Contractual Clauses (SCCs).

8. Data Subject Rights and Assistance

The Processor shall, insofar as possible, assist the Controller by appropriate technical and organizational measures, for the fulfillment of the Controller's obligation to respond to requests for exercising the data subject's rights.

Note regarding Article 11 GDPR: Because the Processor strictly pseudonymizes IP addresses via one-way cryptographic hashing, the Processor is not in a position to identify the data subject. Therefore, the Processor cannot directly fulfill access or erasure requests based solely on an IP address provided by the Controller, as it cannot be linked to the hashed records without compromising the security of the hashing salt.

9. Personal Data Breach Notification

The Processor shall notify the Controller without undue delay (and in any event within 48 hours) after becoming aware of a Personal Data breach. The Processor will provide reasonable assistance and information to the Controller to facilitate the Controller's compliance with its own breach notification obligations.

10. Deletion of Personal Data

Data is subject to strict automated retention policies (e.g., validation flows are purged within 12 hours, and hashed reputation records within 80 days). Upon termination of the Service, the Processor shall delete all remaining Personal Data belonging to the Controller, unless applicable law requires continued storage.

11. Audits

The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, provided such audits are conducted during normal business hours and with reasonable prior notice.

Audit Costs and Limits: Any audits requested by the Controller shall be conducted at the Controller's sole expense. The Controller is limited to one (1) audit per calendar year, unless an additional audit is required by a competent data protection authority or immediately following a confirmed Personal Data breach.

12. Duration and Termination

This DPA shall remain in effect for as long as the Processor processes Personal Data on behalf of the Controller. Upon termination of the Service, this DPA shall automatically terminate, subject to the obligations regarding deletion and return of Personal Data outlined in Section 10.

13. Governing Law

This DPA shall be governed by and construed in accordance with the laws applicable to the Terms of Service. Any disputes arising under this DPA shall be resolved in accordance with the dispute resolution provisions of the Terms of Service.