Power Scraping

Data Processing Addendum

Version 2026-09-25 · Machine-readable version (JSON)

This addendum forms part of the Terms of Service (version 2026-09-25) and is accepted by accepting them.

This addendum forms part of the Terms of Service between you and SVG ASSOCIATES LTD, trading as Power Scraping. It sets out, as Article 28(3) of the UK GDPR requires, how we process the personal data in collected material on your behalf: only on your documented instructions, under a duty of confidentiality, with appropriate security, through the sub-processors named here, with help for your data-subject and security obligations, deleting or returning the data at the end, and open to audit.

1. Parties, incorporation and definitions

This addendum is between you, the customer named on the account, as controller, and SVG ASSOCIATES LTD, trading as Power Scraping, company number 17391911, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, as processor. It forms part of the Terms of Service and is accepted by accepting them; it has no separate acceptance. If it conflicts with the Terms of Service on a data protection matter, this addendum prevails. Customer Personal Data means the personal data in the records your paired extension sends us for your jobs, and everything we derive from them. It does not include account data, for which we are the controller under the privacy notice. Controller, processor, personal data, processing, data subject and personal data breach have the meanings they have in the UK GDPR.

2. Roles

You are the controller of Customer Personal Data and we process it on your behalf. The collection step runs in your browser, under your Instagram account, for jobs you start; the extension that performs it is written and published by us and decides which fields are extracted. If a supervisory authority or a court finds that this makes you and us joint controllers of the collection and transmission step, this clause is the arrangement Article 26 of the UK GDPR requires for that step: you are responsible for the lawful basis for collecting each target you declare, for your entitlement to collect it, and for giving the people in it the notice your jurisdiction requires under Articles 13 and 14; we are responsible for what the extension is built to read and send, for limiting it to the allowlisted fields of declared targets, for the security of the data once it reaches us, and for the privacy notice that describes the extension; each of us answers a data-subject request that reaches it and tells the other within five working days; and a data subject may exercise their rights against either of us. The essence of this arrangement is published in our privacy notice. Everything after the collection step remains processing on your behalf under this addendum.

3. Subject matter, duration, nature and purpose, data and data subjects

Subject matter: providing the service described in the Terms of Service. Duration: the life of your account, and then the time it takes to delete the data under the deletion clause. Nature and purpose: receiving the records your extension sends for jobs you start; holding them in a staging table until the job is processed, and for no more than two days; storing them; enriching them with venue, location and food signals and the evidence behind each signal; metering them against your plan; making them available to you through the dashboard, the API, the connector and exports; and deleting them. Types of personal data: Instagram handles, post identifiers and permalinks, post dates and capture times, captions and anything in them (including names, mentions and hashtags), location labels, media type, links to images and video (which may show people), like and comment counts, and the fields derived from them. The extension never sends comments, and we never fetch the images or video themselves: a record keeps only the links. Categories of data subjects: the holders of the Instagram accounts you declare as targets, and people named, tagged or shown in their posts. Special category and criminal-offence data: not intended, and you must not instruct processing aimed at them.

4. Processing only on your documented instructions (Art. 28(3)(a))

We process Customer Personal Data only on your documented instructions - the Terms of Service, the acceptable-use terms, your target declarations, the jobs you start and the settings you choose - including with regard to transfers to a third country, unless UK law requires us to do otherwise, in which case we will tell you before processing unless that law forbids it. We will tell you immediately if, in our opinion, an instruction infringes the UK GDPR or other data protection law. You are responsible for your instructions complying with data protection law and for having a lawful basis for the processing.

5. Confidentiality (Art. 28(3)(b))

Access to Customer Personal Data is limited to the people who operate the service, and each of them is bound by a duty of confidentiality, contractual or statutory, before they get access.

6. Security (Art. 28(3)(c) and Art. 32)

We take the measures Article 32 requires, which the privacy notice's security clause describes. Among them: the service never receives, stores or uses your Instagram password or session; every query is scoped to your account; passwords, API keys and pairing tokens are stored only as hashes; records of any account other than a job's declared target are dropped on our server; expired records are purged automatically; and an audit trail records who did what. We keep these measures under review and will not reduce their overall effectiveness during the life of your account.

7. Sub-processors (Art. 28(2), 28(3)(d) and 28(4))

You give us general written authorisation to engage sub-processors. Those that may process Customer Personal Data today: Render, which hosts the API, the worker and the database in its Frankfurt (Germany) region; and our business email provider, which receives email sent to stefano@svgassociates.co.uk and processes Customer Personal Data only if you include some in an email to us. Cloudflare serves our website and DNS and does not carry traffic to our API, so it does not process Customer Personal Data. Stripe processes billing data, not Customer Personal Data. There is no third-party collection provider, and no places, mapping or external AI model provider receives Customer Personal Data. We will tell the account owner by email at least 30 days before we add or replace a sub-processor that will process Customer Personal Data, and you may object; if we cannot reasonably meet the objection, you may end your subscription and we will refund fees you prepaid for the period after it ends, as the refunds clause of the Terms of Service provides. Each sub-processor is bound by contract to data protection obligations that give sufficient guarantees in the manner Article 28(4) requires, and we remain liable to you for its performance of them. We will tell you, on request, which data processing terms bind each sub-processor.

8. Helping you with data-subject requests (Art. 28(3)(e))

Taking into account the nature of the processing, we help you answer requests from data subjects with appropriate technical and organisational measures: you can download a job's records as CSV or JSON Lines, revoke a target, and ask us to delete a target's data at any time. When a target is revoked because the person behind it objected, the profile is suppressed across the whole service and cannot be declared again by any customer. If a request about Customer Personal Data reaches us directly, we tell you within five working days. Because the roles clause makes us responsible for part of the collection step, we also act on such a request ourselves as the privacy notice describes, and tell you what we did.

9. Security, breaches and impact assessments (Art. 28(3)(f))

We help you meet your obligations under Articles 32 to 36 - security, notification of personal data breaches, data protection impact assessments and prior consultation - taking into account the nature of the processing and the information available to us. We notify you of a personal data breach affecting Customer Personal Data without undue delay after becoming aware of it, with the information Article 33(3) requires as it becomes available. The data protection impact assessment we keep for the service is available to you on request.

10. Deletion or return at the end (Art. 28(3)(g))

Customer Personal Data is deleted automatically at the end of your plan's retention window. When your account closes you can download your records first; at your choice we then delete the remaining Customer Personal Data, or return it as CSV or JSON Lines and then delete it, within 30 days of closure, unless UK law requires us to keep it. Audit events, which name targets and declared bases but hold no post content, are kept for 24 months and then deleted.

11. Information and audits (Art. 28(3)(h))

We make available to you the information necessary to demonstrate compliance with Article 28 and this addendum, and we allow for and contribute to audits, including inspections, by you or an auditor you mandate. We answer a written questionnaire first. An inspection needs 30 days' written notice, takes place in business hours, at most once a year unless a regulator requires it or a personal data breach has occurred, at your cost, and under a duty of confidentiality. We tell you immediately if, in our opinion, an audit instruction infringes data protection law.

12. International transfers

Render processes Customer Personal Data in the European Economic Area; its own support staff or sub-processors may reach it from outside the EEA. Our business email provider (only if you email us Customer Personal Data) may process it outside the UK. We transfer Customer Personal Data outside the UK only with a transfer mechanism that UK law recognises: UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework, for a provider certified under it) or the UK International Data Transfer Addendum to the EU standard contractual clauses, as the sub-processor's own data processing terms provide. We will tell you, on request, which mechanism applies to each sub-processor.

13. Liability

Each party's liability under this addendum is subject to the limitation of liability in the Terms of Service. Nothing in this addendum limits either party's liability to a data subject under Article 82 of the UK GDPR, or any liability that cannot lawfully be limited.