Data Processing Agreement
Last updated: June 17, 2026
This Data Processing Agreement ("DPA") is incorporated into the ByteKit Terms of Service and forms part of the agreement between Hunt Labs Inc, operating ByteKit ("ByteKit," "Processor," "we," "us," or "our"), and the customer that accepts the Terms ("Customer," "Controller," or "you").
This DPA applies when ByteKit processes Personal Data on behalf of Customer through the Service. If this DPA conflicts with the Terms regarding processing of Personal Data, this DPA controls. If this DPA conflicts with Standard Contractual Clauses incorporated below, the Standard Contractual Clauses control to the extent of the conflict.
1. Definitions
Capitalized terms not defined in this DPA have the meanings given in the Terms or applicable Data Protection Law.
- "Captured Content" means HTML, Markdown, screenshots, recordings, sitemap data, extracted content, and other artifacts produced by the Service in response to a Customer request.
- "Data Protection Law" means the GDPR, UK GDPR, Swiss Federal Act on Data Protection, CCPA/CPRA, and other privacy or data-protection laws applicable to the processing under this DPA.
- "Personal Data" means information relating to an identified or identifiable natural person that ByteKit processes on Customer's behalf through the Service.
- "Sub-Processor" means a third party engaged by ByteKit to process Personal Data on Customer's behalf in connection with the Service.
2. Processing Details
| Item | Description |
|---|---|
| Subject matter | Processing Personal Data submitted to, transmitted through, captured by, stored in, or returned from the Service on Customer's behalf. |
| Duration | The term of the Terms, plus any retention period described in this DPA, customer settings, an order form, or applicable law. |
| Nature and purpose | Fetching, rendering, capturing, transforming, storing, transmitting, deleting, exporting, and returning content from URLs or other inputs submitted by Customer; operating, securing, supporting, and improving the Service as permitted by this DPA. |
| Categories of data subjects | Determined by Customer's targets and inputs. May include customers, employees, prospects, website visitors, authors, reviewers, public figures, members of the public, and other individuals whose data appears in target content. |
| Categories of Personal Data | Determined by Customer's targets and inputs. May include names, email addresses, postal addresses, phone numbers, online identifiers, IP addresses, page content, images, communications, browsing activity, and other data published or rendered at target URLs. |
| Sensitive data | Customer must not submit or capture sensitive data unless Customer has a lawful basis, has provided all required notices and consents, and ByteKit has agreed in writing where required by the Terms or Acceptable Use Policy. |
3. Roles
For Captured Content and Personal Data processed through the Service on Customer's behalf, Customer is the controller and ByteKit is the processor or service provider.
For account administration, billing, website operations, security, fraud prevention, abuse detection, telemetry, aggregate analytics, and similar business operations, ByteKit acts as an independent controller under the Privacy Policy.
Each request submitted through the Service is a documented instruction from Customer to ByteKit to perform the processing necessary to provide the Service.
4. Processor Obligations
ByteKit will:
- process Personal Data only on Customer's documented instructions, unless applicable law requires otherwise;
- ensure that personnel authorized to process Personal Data are subject to confidentiality obligations;
- implement appropriate technical and organizational measures designed to protect Personal Data;
- assist Customer, taking into account the nature of the processing and information available to ByteKit, with data-subject requests and obligations under applicable Data Protection Law;
- notify Customer without undue delay after becoming aware of a Personal Data breach affecting Personal Data processed under this DPA;
- at Customer's choice and subject to applicable law, delete or return Personal Data after the end of the Services;
- make available information reasonably necessary to demonstrate compliance with this DPA; and
- impose data-protection obligations on Sub-Processors that are no less protective than those required by this DPA.
5. Customer Obligations
Customer will:
- comply with Data Protection Law in connection with its use of the Service;
- provide all required notices and obtain all required rights, permissions, consents, and legal bases for Customer's use of the Service;
- ensure that Customer's instructions are lawful;
- ensure that Customer's targets, inputs, and use cases comply with the Terms and Acceptable Use Policy;
- avoid submitting or capturing sensitive data unless legally permitted and approved by ByteKit where required; and
- respond to data-subject requests for Personal Data in Captured Content where Customer is the controller.
6. AI and Service Improvement
ByteKit may use request metadata, telemetry, usage data, and aggregate service data to evaluate, secure, train, and improve Service systems such as routing, retry behavior, anti-abuse systems, extraction quality, fraud detection, and reliability monitoring.
ByteKit does not use Captured Content to train models by default. If ByteKit offers an opt-in content-training feature, ByteKit will use Captured Content for that purpose only where Customer affirmatively opts in or agrees in writing.
For content-based training that Customer has opted into, ByteKit may process the relevant Captured Content for the agreed improvement purpose. Customer is responsible for ensuring that its opt-in and underlying instructions are lawful for the Personal Data involved.
ByteKit does not sell trained models, model weights, embeddings, or training datasets derived from customer Captured Content.
7. Sub-Processors
Customer authorizes ByteKit to engage the Sub-Processors and service providers listed below in connection with the Service. Providers that process Captured Content or Personal Data on Customer's behalf act as Sub-Processors; providers that support account administration, billing, authentication, communications, and infrastructure process Personal Data for which ByteKit is the controller under the Privacy Policy. Each provider's role is noted below.
| Sub-Processor | Role | Data categories | Processing location | Classification |
|---|---|---|---|---|
| Hetzner Online GmbH | Compute hosting for gateway, workers, databases, and supporting services | Captured Content, Personal Data in Captured Content, request metadata, logs, and operational data | Germany and United States | Hosting and processing |
| Amazon Web Services, Inc. | Cloud infrastructure and secrets management | Service operational data and configuration; AWS Secrets Manager stores service secrets only — no Captured Content or Customer Personal Data | United States | Infrastructure and secrets |
| Backblaze, Inc. (B2) | Object storage for screenshots, recordings, and persisted captured content | Captured Content and related metadata | United States | Storage |
| Cloudflare, Inc. | CDN, DDoS mitigation, edge proxy, Pages, Workers, and related network services | Network metadata, request metadata, dashboard and website traffic, documentation traffic | Global edge | Network, security, and hosting |
| Groq, Inc. | LLM inference for optional Markdown cleaning (clean_markdown) |
Captured Content (extracted Markdown) submitted for cleaning, which may contain Personal Data | United States | Processing (AI inference) |
| OpenAI, L.L.C. | LLM inference for content extraction and transformation features | Captured Content submitted for processing, which may contain Personal Data | United States | Processing (AI inference) |
| Clerk, Inc. | Authentication and account identity management | Account and identity data (name, email, OAuth identifiers, authentication metadata) | United States | Authentication |
| Stripe, Inc. | Payment processing, billing, and subscription management | Billing contact, billing address, tax details, payment tokens, and transaction history | United States | Payments |
| Resend, Inc. | Transactional and operational email delivery | Email address, communications content and metadata | United States | Communications |
ByteKit may add or change hosting and infrastructure providers, including across additional regions and hosting companies, as the Service scales. Such changes are subject to the advance-notice and objection process below.
ByteKit will provide at least 30 days' advance notice before adding or replacing a Sub-Processor, unless a shorter period is required for security, legal, availability, or emergency reasons. Notice may be given by email, dashboard notice, update to this DPA, or another reasonable method.
Customer may object to a new Sub-Processor on reasonable data-protection grounds during the notice period. If the parties cannot resolve the objection, Customer may terminate the affected Service as described in the Terms or applicable order form.
ByteKit remains responsible for Sub-Processors' performance of their data-protection obligations under this DPA.
8. Security Measures
ByteKit maintains technical and organizational measures designed to protect Personal Data, including:
- access controls for accounts, API keys, administrative systems, and production infrastructure;
- encryption in transit for client-facing endpoints and service communications where supported;
- encryption at rest or provider-equivalent storage protections for production data stores;
- least-privilege access practices for personnel and contractors;
- logging, monitoring, rate limiting, and abuse-detection controls;
- secrets-management practices designed to prevent secrets from being committed to source control;
- backup, recovery, and deletion practices appropriate to the Service; and
- incident-response procedures for investigating and responding to security events.
ByteKit may update these measures from time to time, provided the update does not materially reduce the overall security of the Service.
9. Personal Data Breach
ByteKit will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Personal Data processed under this DPA. The notice will include available information reasonably required for Customer to meet its breach-notification obligations, and ByteKit will supplement the notice as more information becomes available.
ByteKit's notice of or response to a Personal Data breach is not an admission of fault or liability.
10. Data-Subject Requests
Taking into account the nature of the processing, ByteKit will reasonably assist Customer with data-subject requests relating to Personal Data processed under this DPA.
If ByteKit receives a request directly from an individual concerning Personal Data in Captured Content, ByteKit may refer the request to Customer, ask the individual to contact Customer, or provide reasonable assistance where ByteKit can identify the relevant Customer.
11. Retention, Deletion, and Return
Captured Content is retained according to Customer settings, the applicable order form, the Service's standard retention period, or a shorter deletion request submitted through available Service functionality.
Customer may delete available Captured Content through the dashboard, API, or other supported tooling. Deletion from backups, logs, caches, and disaster-recovery systems may occur on a delayed cycle, unless faster deletion is required by applicable law and technically feasible.
After termination or expiration of the Service, Customer may export available Captured Content for 30 days, unless access was terminated for cause or export would create legal or security risk. After that 30-day period, ByteKit will delete Captured Content, except where an order form provides otherwise or where law permits or requires continued retention.
Request metadata, billing records, audit logs, security records, and account data are retained under ByteKit's Privacy Policy and are not Captured Content.
12. International Transfers
ByteKit and its Sub-Processors may process Personal Data in the United States, the European Economic Area, the United Kingdom, Switzerland, and other countries where ByteKit or its Sub-Processors operate.
Where required for transfers from the EEA, United Kingdom, or Switzerland to a country that is not subject to an adequacy decision, the parties incorporate the following transfer mechanisms:
- the European Commission's Standard Contractual Clauses, Implementing Decision (EU) 2021/914, Module Two (controller to processor);
- the UK International Data Transfer Addendum to the EU Standard Contractual Clauses; and
- the Swiss adaptations required by the Swiss Federal Act on Data Protection.
For the Standard Contractual Clauses:
| Annex item | Description |
|---|---|
| Data exporter | Customer, as identified in the account, order form, or acceptance record. |
| Data importer | Hunt Labs Inc, operating ByteKit. |
| Transfer description | The processing described in Section 2. |
| Categories of data subjects and Personal Data | The categories described in Section 2. |
| Frequency | Continuous for the term of the Service. |
| Purpose | Providing, securing, supporting, and maintaining the Service. |
| Retention | As described in Section 11. |
| Sub-processors | As listed in Section 7. |
| Technical and organizational measures | As described in Section 8. |
| Governing law and forum | The law and forum specified in the Terms, unless the Standard Contractual Clauses require otherwise. |
13. CCPA/CPRA Service Provider Terms
To the extent the CCPA/CPRA applies, ByteKit acts as a service provider or contractor for Personal Data processed on Customer's behalf under this DPA.
ByteKit will not:
- sell or share Personal Data processed on Customer's behalf;
- retain, use, or disclose Personal Data for any purpose other than the business purposes described in this DPA, the Terms, or as otherwise permitted by the CCPA/CPRA;
- retain, use, or disclose Personal Data outside the direct business relationship between ByteKit and Customer, except as permitted by the CCPA/CPRA; or
- combine Personal Data received from or on behalf of Customer with personal information received from another source, except as permitted by the CCPA/CPRA.
ByteKit certifies that it understands and will comply with these restrictions.
14. Audits
On reasonable written request and no more than once in any 12-month period, ByteKit will provide information reasonably necessary to demonstrate compliance with this DPA.
Where legally required and where documentation is insufficient, Customer may request an audit conducted by Customer or a mutually acceptable independent auditor. Audits must be subject to reasonable notice, confidentiality, security, scope, timing, and cost requirements.
15. Liability and Term
This DPA remains in effect while ByteKit processes Personal Data on Customer's behalf.
Liability arising under this DPA is subject to the limitations and exclusions in the Terms, except to the extent prohibited by applicable law or the Standard Contractual Clauses.