Data Processing Addendum
Effective: 24 August 2026.
This DPA forms part of the agreement between the customer ("Customer") and the provider identified in the applicable ScreenshotMCP order or invoice ("Provider") when Provider processes Personal Data on Customer's behalf. Controller, Processor and Personal Data have the meanings given by applicable data-protection law, including the GDPR where applicable.
1. Roles and instructions
Customer is the Controller (or Processor acting for another Controller) of Customer Personal Data submitted in target URLs, page content or capture requests, and Provider is the Processor (or Sub-processor). Provider will process Customer Personal Data only to provide, secure and support ScreenshotMCP under the agreement, Customer's configuration and documented instructions, unless law requires otherwise.
2. Nature and purpose
Processing may include receiving a URL/request; retrieving the selected web page; rendering HTML, text, images, scripts and network resources; creating screenshot or Page Context output; caching or storing artifacts according to configuration; returning results to Customer; metering usage; preventing abuse; and troubleshooting failures.
3. Confidentiality
Provider will limit access to Customer Personal Data to personnel and contractors who need access to perform the service and who are subject to appropriate confidentiality obligations.
4. Security
Provider will maintain technical and organizational measures appropriate to the processing and risk, which may include least-privilege access, protected server-side configuration, network encryption, target restrictions for private/internal resources, isolation controls, audit/security logs, dependency and vulnerability management, backup controls and incident-response procedures. Customer is responsible for lawful targets and protecting its API keys and target credentials.
5. Sub-processors
Customer authorizes Provider to use sub-processors for hosting, storage, observability, security, support and functions needed to operate the service. Provider will impose materially comparable data-protection obligations and remains responsible to the extent required by law. Material new sub-processors may be communicated through service documentation or Customer contact; Customer may raise a reasonable data-protection objection within 14 days.
6. Target websites
A website Customer instructs ScreenshotMCP to visit is a Customer-selected third party, not automatically a Provider sub-processor. The target may independently receive IP address, user-agent and ordinary HTTP request data from the rendering infrastructure. Customer is responsible for the lawfulness of directing Provider to that target.
7. Data-subject rights
Taking into account the nature of processing, Provider will reasonably assist Customer with data-subject requests where Customer cannot fulfill them without Provider's help. Provider may refer requesters to Customer when Customer controls the relevant data.
8. Personal Data Breaches
Provider will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data and provide reasonably available information to support Customer's legal obligations. Notification is not an admission of fault or liability.
9. DPIAs and regulatory assistance
Provider will provide reasonable assistance, based on information available to Provider, for Customer's data-protection impact assessments and consultations with supervisory authorities relating to ScreenshotMCP.
10. Deletion and return
At termination or on Customer's documented request, Provider will delete or return Customer Personal Data according to available service controls, unless law requires retention. Deleted data may remain in protected backups until normal rotation expires.
11. International transfers
If GDPR-, UK GDPR- or Swiss-protected Customer Personal Data is transferred to a country without an applicable adequacy decision, the parties will use an appropriate lawful mechanism. Where appropriate, the 2021 EU Standard Contractual Clauses are incorporated by reference using the module matching the parties' roles, and UK-protected transfers will use the applicable UK addendum or successor mechanism.
12. Audit information
Provider will make available information reasonably necessary to demonstrate compliance with this DPA. If insufficient, Customer may request a reasonable audit no more than once annually, or following a material incident, subject to confidentiality, security, scope and scheduling safeguards. Audits must not expose other customers' data or materially disrupt the service.
13. Customer obligations
Customer is responsible for lawfulness, minimization and accuracy of Customer Personal Data; required privacy notices; a lawful basis for capturing target content; third-party rights; and avoiding highly sensitive or regulated data unless expressly agreed.
14. Liability and precedence
Liability under this DPA is subject to the agreement's liability provisions except where law requires otherwise. This DPA controls over conflicting agreement language specifically regarding Customer Personal Data processing.
Annex I — Processing details
Data subjects: people whose information appears on customer-selected websites or in Customer account/support data. Data categories: page text, images and identifiers; names/contact details visible in target content; IP/request metadata; screenshot pixels; structured Page Context; job IDs, timestamps and technical logs. Duration: service term plus configured cache/artifact and backup/legal retention. Sensitive data: not intentionally required; Customer must avoid special-category or regulated data unless expressly agreed.
Annex II — Security measures
Measures may include controlled administrative access, server-side secret storage, authenticated API/MCP access, transport encryption, restrictions on private-network targets, isolation appropriate to browser execution, logging, dependency review, backup/recovery controls and incident response.
Annex III — Sub-processor information
Provider may use infrastructure hosting, storage, security/observability and operational-support providers. Payment providers may independently process billing data and are not necessarily sub-processors for capture content. An up-to-date operational list can be requested through the support contact shown in the service or purchase receipt.