Data processing agreement
For customers who need Article 28 terms in writing. This forms part of the terms of service.
Last updated 14 September 2026 · Privacy · Terms · Refunds · Cookies · DPA · Security
Roles
Where you use urlshot.io to capture pages that contain personal data, you are the controller and MB Tech256 is the processor. We process that data only to provide the service and only on your instructions — which, in practice, are the requests your API keys make.
For your own account — your email address, your sessions, your billing — we are the controller, and the privacy policy governs that instead.
What we process on your behalf
| Subject matter | Rendering web pages you nominate and returning images |
|---|---|
| Duration | For as long as your account is open, plus the retention periods below |
| Nature and purpose | Automated capture, metering, and showing you your own usage |
| Types of data | Whatever appears on the pages you capture, which we do not inspect; plus the hostname of each target and the metadata of each request |
| Categories of data subject | Determined by you, through the pages you choose to capture |
We do not store the full target URL, only the hostname. We do not retain rendered images beyond the cache lifetime you set with cache_ttl, which cannot exceed 24 hours, and cached images are never shared between workspaces.
Our obligations
- We process personal data only on your documented instructions, including on transfers.
- Everyone with access is bound by confidentiality, and access is limited to those who need it to operate the service.
- We keep the technical and organisational measures described on the security page, which is written to be checked rather than to reassure.
- We help you respond to data subject requests, and with your obligations on security, breach notification and impact assessments, so far as is reasonable given what we hold.
- We notify you without undue delay after becoming aware of a personal data breach affecting your data.
Sub-processors
You authorise the following. We will give notice before adding or replacing any of them, and you may object.
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | API edge, authentication cache, per-workspace usage counters, screenshot cache, inbound email routing, bot check for the website demo (Turnstile) | Global edge network |
| Amazon Web Services EMEA SARL | Browser rendering | eu-central-1, Frankfurt |
| Railway Corp. | Application hosting and the PostgreSQL database | European Union |
| Mailgun Technologies, Inc. | Account email — verification, password reset | European Union (api.eu.mailgun.net) |
Each is bound by terms no less protective than these. Where a sub-processor is outside the EEA, transfers rely on the European Commission's standard contractual clauses.
Deletion and return
- Individual request records, including target hostnames: deleted after 30 days.
- Aggregated counts with no hostname: kept for 730 days.
- Cached images: deleted when the
cache_ttlyou set expires, at most 24 hours. - On closing your account, request records and API keys are deleted immediately and your account record is stripped of personal data. Financial records are retained where tax law requires it.
You can export your usage from the dashboard at any time while the account is open.
Audits
We will provide the information reasonably needed to demonstrate compliance with this agreement, and will contribute to audits carried out by you or an auditor you appoint. We hold no third-party certification today, and say so plainly rather than implying otherwise.
Getting this signed
This page is the agreement and applies automatically to every customer. If your organisation needs a countersigned copy, or your own paper, write to hello@urlshot.io.