Skip to content

New Official SDKs for TypeScript, Python and Go

SerpKite
Get API key

Data Processing Addendum

Effective 3 October 2026.

This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Customer") and Anastasia Klimova, trading as SerpKite, 1732 Oberon Crescent, Mississauga, Ontario L4X 2K8, Canada ("SerpKite") and applies when SerpKite processes Customer Personal Data on Customer's behalf. It is incorporated automatically for all customers. Enterprise customers may sign a countersigned copy; email [email protected].

1. Definitions

"Data Protection Law" means the GDPR, UK GDPR, the Swiss FADP and US state privacy laws such as the CCPA/CPRA, as applicable. "Customer Personal Data" means personal data contained in API requests Customer sends (such as query text and target URLs) and in the results SerpKite returns. "Controller", "processor", "processing" and "personal data breach" have the meanings in the GDPR.

2. Roles and instructions

Customer is the controller (or a processor acting for its controller) and SerpKite is a processor of Customer Personal Data. SerpKite processes it only on Customer's documented instructions, which are: to fetch, parse, format and return search results and web pages as requested through the API, and to keep usage metadata for billing and abuse prevention. SerpKite will tell Customer if it believes an instruction violates Data Protection Law. For CCPA purposes SerpKite is a service provider and will not sell or share Customer Personal Data or use it outside the direct business relationship.

3. Details of processing

Subject matterProviding the SerpKite API
DurationThe term of the Terms, plus deletion periods below
Nature and purposeTransmitting queries to search engines and web pages via proxies; parsing and formatting results; returning them to Customer
Data subjectsIndividuals named in Customer's queries or appearing in public search results or web pages
Categories of dataNames and other identifiers in query text; names, titles, snippets and URLs in public results. Customer should not send special-category data
Retention Query text is never logged. Each successful result is held in a non-persistent cache for up to 6 hours by default, 30 minutes for news, 1 hour for web pages and 24 hours for autocomplete, under a SHA-256 hash of the normalized request and without Customer's identity; it is returned only to requests that send max_age and accept its age. A batch job's request is cleared once processed and its result deleted 24 hours after completion. Usage metadata (no query text) is deleted after 31 days

4. Confidentiality

SerpKite ensures that anyone authorized to process Customer Personal Data is bound by confidentiality obligations.

5. Security measures

  • Encryption in transit (TLS) on all public endpoints; origin servers reachable only through Cloudflare Tunnel, with no inbound ports.
  • API keys, session tokens and login tokens stored only as SHA-256 hashes.
  • No logging of query text, API keys, cookies, webhook URLs or database query parameters; usage metadata deleted after 31 days.
  • Default-deny network policies between services; least-privilege access to production; secrets kept outside source control.
  • Encrypted backups of account and billing data, kept for 30 days, with tested restores.
  • Monitoring and alerting on availability and abuse.

6. Subprocessors

Customer authorizes the subprocessors listed at /legal/subprocessors. SerpKite imposes data protection terms on each that are no less protective than this DPA, remains responsible for them, and gives at least 30 days' notice of new subprocessors. Customer may object on reasonable grounds; if we can't resolve the objection, Customer may terminate the affected Service and receive a refund of unused prepaid credits.

7. Data subject requests

SerpKite holds Customer Personal Data only in the short-lived cache and batch results described in section 3. Cache entries are keyed by a one-way hash and can't be looked up by person, and all of it expires on its own within the windows above. SerpKite will promptly forward any request it receives and provide reasonable assistance.

8. Personal data breaches

SerpKite will notify Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data, with the information Customer reasonably needs to meet its obligations.

9. Assistance and audits

SerpKite will provide reasonable assistance with data protection impact assessments and consultations with authorities, and make available information necessary to demonstrate compliance with this DPA. SerpKite does not yet hold a SOC 2 report; until it does, audits are satisfied by written responses to security questionnaires and, for enterprise customers, a reasonable remote audit once per year on 30 days' notice.

10. International transfers

Where Customer Personal Data is transferred outside the EEA, UK or Switzerland to a country without an adequacy decision, the Standard Contractual Clauses adopted by Commission Decision (EU) 2021/914 (Module 2 where Customer is a controller, Module 3 where Customer is a processor) and, for UK transfers, the UK International Data Transfer Addendum are incorporated by reference, with these elections:

  • Clause 7 (docking clause) applies.
  • Clause 9: option 2, general written authorization, with the notice period in section 6.
  • Clause 11: the optional redress language does not apply.
  • Clauses 17 and 18: the law and courts of the EU Member State in which Customer is established, or Ireland if that law does not allow third-party beneficiary rights.
  • Annex I (parties, description of transfer): section 3 of this DPA, with Customer as data exporter and SerpKite as data importer. Annex II (technical and organizational measures): section 5. Annex III (subprocessors): the Subprocessors page.
  • UK Addendum Tables 1 to 3 are completed with the same information; either party may end it as set out in its Section 19.

An EU processing region for enterprise customers is planned for Q1 2027.

11. Deletion

On termination, SerpKite deletes any remaining Customer Personal Data within 30 days (including backups), except where retention is required by law.

12. Order of precedence

If this DPA conflicts with the Terms, this DPA prevails for the processing of Customer Personal Data.

Last updated: 3 October 2026