Legal
Data Processing Agreement
Last Updated: July 13, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Visara Labs ("Data Processor") and the Customer ("Data Controller"). This DPA reflects the parties' agreement with regard to the processing of Personal Data under applicable Data Protection Laws, including the GDPR and CCPA.
1. Definitions
- "Data Protection Laws" means all applicable laws and regulations relating to the processing of Personal Data, including but not limited to the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the California Consumer Privacy Act ("CCPA").
- "Personal Data" means any information relating to an identified or identifiable natural person processed by Visara Labs on behalf of the Customer.
- "Sub-processor" means any third party engaged by Visara Labs to process Personal Data on behalf of the Customer.
2. Processing of Personal Data
Visara Labs will only process Personal Data in accordance with the Customer's documented instructions, which are generally fulfilled by the Customer's use of the Crawlix service. Visara Labs will not process Personal Data for any other purpose, unless required to do so by applicable law.
The types of Personal Data processed may include names, email addresses, IP addresses, and behavioral data collected during web crawling, provided such data is exposed on the target websites being audited.
3. Security Measures
Visara Labs implements and maintains robust technical and organizational security measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include encryption in transit and at rest, regular security audits, and strict access controls.
4. Sub-processors
The Customer agrees that Visara Labs may engage Sub-processors to assist in providing the Service. Visara Labs maintains a current list of Sub-processors on our Legal page. We will notify Customers of any intended changes concerning the addition or replacement of Sub-processors, giving the Customer the opportunity to object to such changes.
Visara Labs ensures that all Sub-processors are bound by contractual obligations providing at least the same level of data protection as required under this DPA.
5. Data Subject Rights
Taking into account the nature of the processing, Visara Labs will assist the Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Customer's obligation to respond to requests for exercising Data Subjects' rights laid down in Chapter III of the GDPR or other applicable laws.
6. Personal Data Breach
Visara Labs will notify the Customer without undue delay after becoming aware of a Personal Data Breach. We will provide sufficient information to allow the Customer to meet any obligations to report or inform Data Subjects of the breach under Data Protection Laws.
7. Return or Deletion of Data
Upon termination of the Services, Visara Labs will, at the choice of the Customer, delete or return all Personal Data to the Customer and delete existing copies unless applicable law requires storage of the Personal Data.
8. International Transfers
If Visara Labs processes Personal Data originating from the EEA, UK, or Switzerland in a country that has not been designated by the European Commission or Swiss Federal Data Protection Authority as providing an adequate level of protection, such transfers shall be governed by the Standard Contractual Clauses (SCCs).
Contacting Our DPO
If you need to execute a signed copy of this DPA or contact our Data Protection Officer, please reach out to:
Email: dpo@visaralabs.com