This Data Processing Agreement ("DPA") forms part of the Terms of Service between Maximiliano Nicolás Alemandi / Crafy Holding ("Data Processor") and the business customer ("Data Controller") utilizing the CrafyCAPTCHA service (the "Service").
1. Definitions
For the purposes of this DPA:
- "Data Protection Laws" means all applicable worldwide privacy and data protection laws and regulations, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
- "Personal Data" means any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller.
- "Sub-processor" means any third party engaged by the Data Processor to process Personal Data on behalf of the Controller.
2. Scope and Nature of Processing
The Processor will process Personal Data solely to provide the CrafyCAPTCHA bot-mitigation service to the Controller. The processing operations include the collection, pseudonymization, temporary caching, and analysis of network and behavioral data to prevent automated fraud.
Categories of Data Subjects: End-users visiting the Controller's web applications protected by CrafyCAPTCHA.
Types of Personal Data: IP Addresses (pseudonymized immediately via cryptographic hashing), User-Agent strings, and transient behavioral metrics (e.g., mouse movements, puzzle solve times).
3. Controller Instructions
The Processor shall process Personal Data only on documented instructions from the Controller, including those set forth in the Terms of Service and this DPA, unless required to do so by applicable law.
4. Confidentiality
The Processor shall ensure that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5. Security of Processing (Art. 32 GDPR)
The Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures include:
- Privacy by Design (Pseudonymization): IP addresses are never stored in plain text. They undergo an irreversible HMAC-SHA256 hashing process with a secret salt at the edge before being committed to any database.
- Encryption: Data is encrypted in transit (TLS/HTTPS).
- Local Processing: Threat intelligence and geolocation lookups (FireHOL and MaxMind) are performed locally on the Processor's servers to prevent third-party leakage of End-User IPs.
6. Sub-processors
The Controller provides general authorization for the Processor to engage Sub-processors. The current list of Sub-processors includes:
- Cloudflare, Inc. (USA): Content Delivery Network (CDN), Web Application Firewall (WAF), and Turnstile challenge delivery.
- Hostinger (USA): Backend hosting infrastructure.
- Redis.io (USA): External cache and rate-limiting infrastructure (receives only hashed identifiers).
The Processor will notify the Controller (e.g., via email or dashboard notification) at least 30 days before adding or replacing any critical Sub-processor, giving the Controller the opportunity to object.
7. International Data Transfers
Any transfer of Personal Data outside the European Economic Area (EEA) shall be governed by appropriate safeguards. For Cloudflare, transfers are covered under the EU-US Data Privacy Framework (DPF). For Hostinger, transfers are covered by Standard Contractual Clauses (SCCs).
8. Data Subject Rights and Assistance
The Processor shall, insofar as possible, assist the Controller by appropriate technical and organizational measures, for the fulfillment of the Controller's obligation to respond to requests for exercising the data subject's rights.
Note regarding Article 11 GDPR: Because the Processor strictly pseudonymizes IP addresses via one-way cryptographic hashing, the Processor is not in a position to identify the data subject. Therefore, the Processor cannot directly fulfill access or erasure requests based solely on an IP address provided by the Controller, as it cannot be linked to the hashed records without compromising the security of the hashing salt.
9. Personal Data Breach Notification
The Processor shall notify the Controller without undue delay (and in any event within 48 hours) after becoming aware of a Personal Data breach. The Processor will provide reasonable assistance and information to the Controller to facilitate the Controller's compliance with its own breach notification obligations.
10. Deletion of Personal Data
Data is subject to strict automated retention policies (e.g., validation flows are purged within 12 hours, and hashed reputation records within 80 days). Upon termination of the Service, the Processor shall delete all remaining Personal Data belonging to the Controller, unless applicable law requires continued storage.
11. Audits
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, provided such audits are conducted during normal business hours and with reasonable prior notice.
Audit Costs and Limits: Any audits requested by the Controller shall be conducted at the Controller's sole expense. The Controller is limited to one (1) audit per calendar year, unless an additional audit is required by a competent data protection authority or immediately following a confirmed Personal Data breach.
12. Duration and Termination
This DPA shall remain in effect for as long as the Processor processes Personal Data on behalf of the Controller. Upon termination of the Service, this DPA shall automatically terminate, subject to the obligations regarding deletion and return of Personal Data outlined in Section 10.
13. Governing Law
This DPA shall be governed by and construed in accordance with the laws applicable to the Terms of Service. Any disputes arising under this DPA shall be resolved in accordance with the dispute resolution provisions of the Terms of Service.