Legal
Data Processing Agreement
Version 1.0. Forms part of the Terms of Service between the customer ("Controller") and Kaabist Bilişim ve Yazılım Hizmetleri Limited Şirketi ("Processor").
1. Roles and scope
- The customer is the controller of the personal data its programs collect, the inputs it passes them and the session state it stores ("Customer Personal Data"). Kaabist processes it as a processor, only to run the customer's programs and provide the service.
- Kaabist is a controller only for account, billing and security data, under the Privacy Policy.
2. Details of processing (Annex I)
| Subject matter | Running web automation programs: visiting websites, filling forms, extracting data, storing results, snapshots and sessions |
| Duration | The term of the agreement, then deletion as in section 8 |
| Nature and purpose | Automated retrieval, storage, transformation and delivery of data the customer's programs specify |
| Data subjects | Whoever the customer's targets and inputs concern; decided by the customer |
| Categories of data | Decided by the customer: page content, extracted fields, inputs (including credentials the customer chooses to store), session cookies and storage state |
| Special categories | None intended; the customer must not process them without a legal basis (see the Acceptable Use Policy) |
3. Kaabist's obligations
Kaabist will:
- process Customer Personal Data only on the customer's documented instructions (the programs, options and settings it submits), and tell the customer if an instruction appears to break the law;
- ensure its personnel are bound by confidentiality;
- apply the measures in section 4;
- use sub-processors only as in section 5;
- assist the customer, as far as the service allows, with data subjects' requests (export, deletion, access) and with impact assessments;
- notify personal data breaches as in section 6;
- delete or return data at the end of the service as in section 8;
- make available the information needed to demonstrate compliance and allow audits as in section 7.
4. Security measures (Annex II)
- Encryption. Session storage state, stored passwords and secret inputs, webhook signing secrets and bring-your-own provider credentials are encrypted with a data key per organisation, wrapped by a master key held in a separate key-management service (OpenBao Transit). Plaintext never leaves the worker process's memory and never appears in logs, snapshots, screenshots or webhooks; password fields are redacted before a page is captured. TLS protects data in transit.
- Isolation. Browser contexts are isolated per job; jobs that use a session or secret inputs run in a browser process of their own organisation. Every outbound request leaves through one gateway that refuses private, loopback, link-local and metadata addresses.
- Access. Role-based access within organisations; two-factor authentication required for owners and admins; API keys stored as hashes; every privileged action recorded in an audit log the application cannot change.
- Hardening. Containers run as non-root with a read-only filesystem and no capabilities; the code and dependencies are scanned for secrets and vulnerabilities on every change.
- Resilience. Backups are taken continuously, and restoring them is rehearsed.
- Data minimisation. Live view frames are never stored; snapshots exclude session state; retention follows the customer's plan.
5. Sub-processors
The customer authorises the sub-processors on the sub-processor list. Kaabist gives at least 30 days' notice of a new sub-processor by e-mail and on that page; the customer may object on reasonable data-protection grounds and, if no solution is found, terminate the affected service. Kaabist imposes data-protection obligations on each sub-processor no less protective than this agreement and remains responsible for them. Providers the customer connects itself (bring-your-own proxies, models or CAPTCHA solvers) are the customer's, not Kaabist's sub-processors.
6. Personal data breaches
Kaabist notifies the customer without undue delay, and within 48 hours, after becoming aware of a breach affecting Customer Personal Data, with what is known: nature, categories and approximate numbers, likely consequences, measures taken. It updates the customer as more is known. The customer remains responsible for notifying authorities and data subjects (GDPR: 72 hours; KVKK: 72 hours).
7. Audits
Kaabist provides, on request and at most once a year, the information reasonably needed to show compliance (policies, the threat model, test reports). On-site audits need 30 days' notice, happen during business hours and are at the customer's cost.
8. Deletion and return
- The customer can export its data at any time (a zip linked by e-mail, valid seven days) and ask
for its organisation's data to be deleted (
POST /v1/org/data-deletion). - Deletion is carried out within 24 hours: object storage, sessions, programs, provider settings, webhooks, schedules, members and keys are erased; job records are emptied and dropped after 30 days; the credit ledger and payment records are kept as accounting law requires; the audit log is kept with every person replaced by a pseudonym; usage statistics are kept under a random token that no longer names the customer. The requester receives an e-mail when it is done.
- Backups age out within two years.
9. International transfers
Kaabist hosts Customer Personal Data in the EU (Germany) by default. Transfers to sub-processors outside the EU or Türkiye rely on the mechanisms named on the sub-processor list.
10. Liability
Liability under this agreement follows the Terms of Service.