Data Processing Addendum
Last updated September 10, 2026
This Data Processing Addendum (“DPA”) describes how PixelPioneer, LLC processes data on behalf of your workspace when you use CrawlSpec, and which third parties (“subprocessors”) we use to do it.
Purpose of processing
We process the data described in our Privacy Policy to operate the Service: crawling and evaluating sites you attest ownership of, generating recommendations and content briefs, importing and displaying Google Search Console data you connect, and billing your subscription.
Subprocessors
| Subprocessor | Purpose | Region |
|---|---|---|
| Vercel | Hosts the CrawlSpec web application | Singapore (sin1) |
| DigitalOcean | Hosts the crawl worker and the Postgres database | Singapore (sgp1) |
| Stripe | Payment processing and subscription billing | United States, global |
| PayPal | Payment processing and subscription billing, where you pay by PayPal instead of card | United States, global |
| Anthropic | Generates content briefs from your Google Search Console data | United States |
| DataForSEO | Keyword volume, related-keyword, and SERP research | European Union |
| Google Search Console API | Imports search query and performance data you connect | United States, global |
| Resend | Sends transactional email (verification, password reset, invitations) | United States |
| Cloudflare | DNS resolution for crawlspec.dev (DNS records only, no traffic proxying) | Global |
This table reflects the subprocessors CrawlSpec's own code integrates with today. We will update it, and notify workspace owners by email, before adding a new subprocessor that handles workspace content.
Anthropic and training
Under Anthropic's Commercial Terms of Service, content submitted through the API is not used to train Anthropic's models.
DataForSEO
DataForSEO's own data processing agreement applies where GDPR governs your data; we have not independently verified its terms for jurisdictions outside GDPR's scope, and state this rather than claim broader coverage than we can confirm.
Security measures
- Third-party API credentials you add are encrypted at rest with AES-256-GCM, per-record keys wrapped by a rotating platform key.
- All traffic to and from the Service is encrypted in transit (TLS).
- Access to a workspace is controlled by two independent checks: your platform sign-in, and your role within that specific workspace.
- Our staff reach a workspace's content only through the audited, time-boxed support-access grant described in our Privacy Policy.
Data location
The application and database run in Singapore. Subprocessors above may process data in other regions as noted in the table; we choose subprocessors that meet our security bar rather than promising a single-region guarantee across every subprocessor.
Changes to subprocessors
We will update the table above and notify workspace owners by email before a new subprocessor begins handling workspace content.
Contact
Questions about this DPA: legal@crawlspec.dev.