Legal

Data processing addendum

Applies automatically to every business customer. No signature required to rely on it — though we will sign a copy if your process needs one.

In effect since . Webshotter, France.

1. Roles

You are the controller of the personal data contained in the pages you ask us to render and in the parameters you send. Webshotter is the processor of that data. For your own account data — your name, your email address, your billing details — we are the controller, and the privacy policy governs it.

2. Subject matter and duration

  • Subject matter: rendering web pages into images or PDFs at your instruction.
  • Duration: for as long as you have an account, plus the retention windows below.
  • Nature and purpose: loading a URL you supply in an isolated browser, capturing it, returning the result, and keeping the record of it.
  • Types of personal data: whatever the page you send us contains, plus the URL itself, the IP address and user-agent of the calling system, and the account contact details.
  • Categories of data subject: determined by you. We do not know who appears on the pages you render.

3. Our instructions

We process personal data only on your documented instructions — which, for this Service, is the API request itself. We will tell you if an instruction appears to breach data protection law, and we may refuse it. Where the law requires us to process for another reason, we will tell you first unless the law forbids it.

4. Confidentiality

Everyone with access to customer data is bound by confidentiality obligations, and access is granted on need. Nobody at Webshotter looks at your webshots except when you ask for help or when we are investigating abuse or a security incident.

5. Security measures

These are the measures actually implemented, not an aspiration:

  • Isolation per render. Every capture runs in its own browser context, destroyed after use. No cookie, cache or storage crosses between renders.
  • SSRF refusal. Private, loopback, link-local and cloud-metadata addresses are refused, including public hostnames that resolve to them and redirects that land on them.
  • Credentials. API tokens are stored only as hashes and shown once. Passwords are hashed. Tokens can be restricted to specific domains and to specific caller IP addresses.
  • Encryption. TLS in transit everywhere, including between the application and its database, cache and object storage. Images at rest live in encrypted object storage.
  • Retention limits. Enforced by a scheduler, not by intent — see the retention table.
  • Least data. A render you do not ask us to store is never written anywhere durable; its file exists only to carry the bytes out of the worker and is deleted on collection.

6. Subprocessors

You give general authorisation for the subprocessors listed on the subprocessors page. We give 30 days' notice before adding one, we impose data-protection terms on each of them no less protective than these, and we remain liable to you for what they do.

7. Helping you answer data subjects

Most requests you receive, you can satisfy yourself: your webshots and your request log are visible and deletable in the dashboard, and deleting a render deletes its image. Where you need more, we will help — at no charge, and within a timeframe that lets you meet your own deadline.

8. Personal data breaches

We notify you without undue delay, and in any case within 48 hours of becoming aware of a breach affecting your data, with what we know: what happened, what data was involved, what we are doing, and what you may need to do. Notice goes to the account owner's address, and to any additional security contact you have given us.

9. International transfers

Application hosting and image storage are in the EU. Transfers to our United States subprocessors rely on the European Commission's standard contractual clauses, which are incorporated into this addendum by reference and which prevail over anything in it that conflicts with them.

10. Deletion and return

You can delete any webshot at any time, and deleting your account deletes the teams you own and everything in them. On termination, anything not already deleted is removed within 90 days by the scheduled prune. We do not keep an archival copy.

11. Audits

We will answer a reasonable security questionnaire once a year and provide the information needed to demonstrate compliance with this addendum. We are a small team: an on-site audit is available where the law requires one, at your cost, with reasonable notice.

12. Order of precedence

Where this addendum conflicts with the terms of service, this addendum wins for matters of personal data processing. The standard contractual clauses win over both.

Questions a policy cannot answer

If something here is unclear, or your legal team needs it in another shape, write to us — a person reads that address.