Scrape.Email policy center
Data Processing Addendum
This addendum defines baseline controller and processor obligations for customer account data and customer-directed email operations in Scrape.Email.
Roles and scope
For customer account data and licensed catalog data, each party acts as an independent controller for its own purposes. When Scrape.Email stores a customer's brand prompt, saved-lead organization, connected-mailbox configuration, message content, or recipient instructions solely to provide requested functions, Scrape.Email acts as the customer's processor and the customer acts as controller.
Documented instructions
We process data only to authenticate users; provide search, reveal, export, campaign, API, webhook, AI drafting, SMTP sending, and read-only inbox synchronization; fulfill purchases; provide support; prevent fraud; and secure the service. The customer instructs processing through product controls and support requests and will not submit special-category, children's, financial-account, health, or government-identifier data.
Confidentiality and safeguards
Authorized personnel and contractors are bound by confidentiality duties. Measures include salted password hashing, HTTP-only signed sessions, account-scoped authorization checks, one-time API and webhook secrets, encrypted SMTP and webhook credentials, TLS certificate validation, public-host enforcement, private storage, signed payment webhooks, bounded requests, incremental read-only mailbox access, security headers, and operational logging.
Subprocessors and transfers
Approved subprocessors are listed in the Privacy Policy: Cloudflare, Stripe, Cryptomus, DeepSeek, the managed application host and database operator, and any SMTP or IMAP provider selected by the customer. Scrape.Email remains responsible for processor obligations delegated to subprocessors. Restricted international transfers use adequacy decisions, Standard Contractual Clauses, the UK Addendum, certified transfer frameworks, or another valid mechanism as applicable.
Security incidents
We will investigate a confirmed personal-data breach, take reasonable containment and remediation steps, and notify the affected customer without undue delay and no later than 72 hours after confirmation, unless law requires earlier notice. Notice will include the known nature, affected data, likely consequences, mitigations, and a contact point. This deadline does not apply to unsuccessful attacks that do not compromise customer personal data.
Rights requests, audits, and assistance
Taking into account the processing, we will reasonably assist with data-subject requests, security assessments, breach obligations, and deletion or return requests. We will provide available compliance information on written request. Customer-specific audits must be proportionate, protect other customers and security information, occur no more than once annually unless a confirmed incident requires more, and may be subject to reasonable costs.
Return and deletion
On termination or verified account closure, we will delete or anonymize processor data within 30 days, except required payment records, suppression records, legal holds, and encrypted backups that rotate within 90 additional days. The fixed category periods in the Privacy Policy apply while the account remains active.