Data processing
Last updated: 17 August 2026.
When you use WebRobot to process personal data, you are the controller and we are the processor: we process that data only to deliver the service and only on your instructions. Article 28 GDPR requires this to be put in writing.
Requesting the agreement
Write to legal@webrobot.eu with your company name and registered address. We reply with the text to sign. We also accept your own template, if you have one.
We do not publish a pre-filled text here: a binding agreement is meant to be read and signed, not assumed because it sat on a page.
What it covers, in substance
- Subject matter and duration — processing lasts as long as the service contract.
- Nature of the data — that of your users who access the platform (name, email, role) and whatever the sources you choose to process contain. You determine the latter: we do not know it in advance and do not use it for other purposes.
- Instructions — we process data only to deliver the service. We do not use it to train models and do not pass it to third parties.
- Confidentiality — anyone with access is bound by confidentiality and limited to what support requires.
- Sub-processors — the list is public and updated before a new provider enters service, so you can object in time.
- Security measures — described on the security page, including the ones we do not have yet.
- Breaches — we inform you without undue delay, with what we know at the time, even when the picture is incomplete.
- Data subject rights — we assist you when one of your users exercises theirs.
- End of the relationship — on your request we return or delete the data. Backups age out on their own cycle, today 24 hours.
Transfers outside the EEA
The core infrastructure is in the European Union. Some optional features involve processing in the United States, listed one by one under sub-processors. Those who must avoid it can leave them disabled, or run the platform on their own infrastructure.
