Legal

Data Processing Agreement

Version 1.0. Forms part of the Terms of Service between the customer ("Controller") and Kaabist Bilişim ve Yazılım Hizmetleri Limited Şirketi ("Processor").

1. Roles and scope

  • The customer is the controller of the personal data its programs collect, the inputs it passes them and the session state it stores ("Customer Personal Data"). Kaabist processes it as a processor, only to run the customer's programs and provide the service.
  • Kaabist is a controller only for account, billing and security data, under the Privacy Policy.

2. Details of processing (Annex I)

Subject matterRunning web automation programs: visiting websites, filling forms, extracting data, storing results, snapshots and sessions
DurationThe term of the agreement, then deletion as in section 8
Nature and purposeAutomated retrieval, storage, transformation and delivery of data the customer's programs specify
Data subjectsWhoever the customer's targets and inputs concern; decided by the customer
Categories of dataDecided by the customer: page content, extracted fields, inputs (including credentials the customer chooses to store), session cookies and storage state
Special categoriesNone intended; the customer must not process them without a legal basis (see the Acceptable Use Policy)

3. Kaabist's obligations

Kaabist will:

  1. process Customer Personal Data only on the customer's documented instructions (the programs, options and settings it submits), and tell the customer if an instruction appears to break the law;
  2. ensure its personnel are bound by confidentiality;
  3. apply the measures in section 4;
  4. use sub-processors only as in section 5;
  5. assist the customer, as far as the service allows, with data subjects' requests (export, deletion, access) and with impact assessments;
  6. notify personal data breaches as in section 6;
  7. delete or return data at the end of the service as in section 8;
  8. make available the information needed to demonstrate compliance and allow audits as in section 7.

4. Security measures (Annex II)

  • Encryption. Session storage state, stored passwords and secret inputs, webhook signing secrets and bring-your-own provider credentials are encrypted with a data key per organisation, wrapped by a master key held in a separate key-management service (OpenBao Transit). Plaintext never leaves the worker process's memory and never appears in logs, snapshots, screenshots or webhooks; password fields are redacted before a page is captured. TLS protects data in transit.
  • Isolation. Browser contexts are isolated per job; jobs that use a session or secret inputs run in a browser process of their own organisation. Every outbound request leaves through one gateway that refuses private, loopback, link-local and metadata addresses.
  • Access. Role-based access within organisations; two-factor authentication required for owners and admins; API keys stored as hashes; every privileged action recorded in an audit log the application cannot change.
  • Hardening. Containers run as non-root with a read-only filesystem and no capabilities; the code and dependencies are scanned for secrets and vulnerabilities on every change.
  • Resilience. Backups are taken continuously, and restoring them is rehearsed.
  • Data minimisation. Live view frames are never stored; snapshots exclude session state; retention follows the customer's plan.

5. Sub-processors

The customer authorises the sub-processors on the sub-processor list. Kaabist gives at least 30 days' notice of a new sub-processor by e-mail and on that page; the customer may object on reasonable data-protection grounds and, if no solution is found, terminate the affected service. Kaabist imposes data-protection obligations on each sub-processor no less protective than this agreement and remains responsible for them. Providers the customer connects itself (bring-your-own proxies, models or CAPTCHA solvers) are the customer's, not Kaabist's sub-processors.

6. Personal data breaches

Kaabist notifies the customer without undue delay, and within 48 hours, after becoming aware of a breach affecting Customer Personal Data, with what is known: nature, categories and approximate numbers, likely consequences, measures taken. It updates the customer as more is known. The customer remains responsible for notifying authorities and data subjects (GDPR: 72 hours; KVKK: 72 hours).

7. Audits

Kaabist provides, on request and at most once a year, the information reasonably needed to show compliance (policies, the threat model, test reports). On-site audits need 30 days' notice, happen during business hours and are at the customer's cost.

8. Deletion and return

  • The customer can export its data at any time (a zip linked by e-mail, valid seven days) and ask for its organisation's data to be deleted (POST /v1/org/data-deletion).
  • Deletion is carried out within 24 hours: object storage, sessions, programs, provider settings, webhooks, schedules, members and keys are erased; job records are emptied and dropped after 30 days; the credit ledger and payment records are kept as accounting law requires; the audit log is kept with every person replaced by a pseudonym; usage statistics are kept under a random token that no longer names the customer. The requester receives an e-mail when it is done.
  • Backups age out within two years.

9. International transfers

Kaabist hosts Customer Personal Data in the EU (Germany) by default. Transfers to sub-processors outside the EU or Türkiye rely on the mechanisms named on the sub-processor list.

10. Liability

Liability under this agreement follows the Terms of Service.

Opening soon

Kaabist is getting ready for launch. The panel, the docs and the status page open on launch day.