Version 2026-08-19-v2-counsel-review · Effective 15 August 2026
DataCrawl Privacy Notice
Counsel-review draft. This notice describes current product processing and is intended for legal review before final adoption.
1. Who controls your data
Asenda AI, operating DataCrawl (“we”), controls account, portal and business-contact information. Customers generally control personal data contained in their search, fetch and extraction instructions; for that data, we act on their instructions as a service provider or processor. Contact: digest@asenda.ai.
2. Data we collect
- Account: email address, password hash, verification, plan and acceptance records.
- Service: API-key references, application and tenant references, job type/status, timestamps, credit use, cache and provider-tier outcomes. Operational evidence uses pseudonymous references and suppresses raw targets where designed.
- Customer instructions and results: URLs, queries, extraction instructions and returned content needed to execute a request, subject to configured retention.
- Technical and security: IP address, browser/device and request metadata, authentication events, rate-limit and abuse signals.
- Billing and communications: billing identifiers and transaction status from payment providers, support messages and notification preferences. We do not receive full payment-card numbers.
3. Why and legal bases
We process data to provide and bill for the Service, authenticate users, fulfil requests and support accounts (contract); secure, debug and improve reliability, prevent abuse, keep audit evidence and understand aggregate use (legitimate interests); comply with tax, accounting, sanctions, legal-process and security obligations (legal obligation); and send optional marketing only where consent or applicable law permits. You may withdraw consent without affecting earlier lawful processing.
4. Sharing
We share only what is necessary with infrastructure, database/cache/queue, email and communications, observability, payment and search/fetch providers; professional advisers; and authorities where legally required. Customer instructions may necessarily be sent to the selected data source or provider. We do not sell personal information or share it for cross-context behavioural advertising.
5. International transfers
Providers may process data outside your country. Where required, we use adequacy decisions, contractual safeguards or another lawful transfer mechanism. Contact us for information about applicable safeguards.
6. Retention
We retain account and billing records while the account is active and as needed for legal obligations. Job/request metadata is generally short-lived according to the product’s configured TTL; current operational attempt/activity evidence is retained for approximately 7–30 days. Administrative audit, incident, node-lifecycle and moderation evidence may be retained up to 400 days. Security and rate-limit records use shorter operational windows. Backups expire on their normal rotation. We delete or de-identify data when no longer needed, subject to legal holds.
7. Security
We use access controls, TLS, secret separation, pseudonymous operational references, bounded retention, audit trails and monitoring appropriate to the data and risk. No internet service can guarantee absolute security. Notify us promptly if you suspect credential compromise.
8. Your choices and rights
Depending on your location, you may request access, correction, deletion, restriction, objection, portability, or information about categories, sources, purposes and recipients. You may withdraw consent and lodge a complaint with your local supervisory authority. California residents may also request to know, correct or delete covered information and may not be discriminated against for exercising applicable rights. Because we do not sell or share personal information for cross-context behavioural advertising, no “Do Not Sell or Share” opt-out is currently required. We may verify identity and may retain information where an exception applies.
9. Cookies
The portal uses necessary session and security cookies for login, CSRF protection and account continuity. We do not currently use third-party advertising cookies. If optional analytics or marketing cookies are introduced, we will update this notice and obtain consent where required.
10. Children
The Service is for business users aged 18 or older and is not directed to children. Do not submit children’s personal data unless you have a documented lawful basis and DataCrawl has agreed in writing.
11. Automated decisions
Automated controls may rate-limit, retry, quarantine or suspend requests for security, reliability and provider-limit reasons. They do not make decisions producing legal or similarly significant effects about individuals.
12. Contact and complaints
Send privacy requests to digest@asenda.ai. We will respond within the period required by applicable law. EU/EEA and UK users may complain to the supervisory authority where they live or work, or where an alleged infringement occurred.
13. Changes
We will publish updates with a new effective date and provide additional notice for material changes where required.