Privacy Policy — CrawlReady
Privacy Policy — CrawlReady
Last updated: June 20, 2026
1. Data Controller
The data controller for personal data is:
NBM CONSEIL
Simplified single-shareholder joint-stock company (SASU)
Registered office: 1 Allée d'Artois, 92390 Villeneuve-la-Garenne, France
Registered with the Nanterre Trade and Companies Register under no. 903 552 578 00010
VAT no.: FR21903552578
Single point of contact (including for GDPR rights): contact@crawlready.eu
2. Data We Collect
We collect and process only the data strictly necessary to provide the service:
Account: email address, hashed password (bcrypt) and display name (optional), for authentication and account management.
Audit: submitted URLs, crawled URLs, extracted content (metadata, titles, schemas), scores and alerts, for running the audit service.
Context: city, industry, site type and Google Business URL (optional), for personalising local recommendations.
Payment: transaction metadata (amount, date, status, credit type) via Stripe, for credit management and accounting. No card number is ever stored by us.
Technical data: IP address (anonymised after 90 days), user-agent and access logs, for security, abuse prevention and debugging.
Data we do NOT collect: first name, last name, postal address, phone number, date of birth, precise geolocation data, advertising cookies, third-party tracking.
3. Purposes and Legal Bases
Each processing activity is based on a legal ground under the GDPR:
Provision of the audit service: performance of contract (Art. 6.1.b GDPR).
Credit and subscription management: performance of contract.
Sending reports by email: performance of contract.
Security and account notifications: legitimate interest (Art. 6.1.f GDPR).
Invoice retention: legal obligation (Art. 6.1.c GDPR).
Abuse prevention and security: legitimate interest.
No marketing communications are sent without prior explicit consent.
4. Sub-processors and Transfers
We work with carefully selected sub-processors:
Replit, Inc. (United States): application hosting and database. Safeguards: Standard Contractual Clauses (SCCs) of the European Commission.
Stripe, Inc. (United States / Ireland): payment processing. Safeguards: PCI-DSS certification; banking data is collected directly by Stripe.
Resend, Inc. (United States): transactional email delivery. Safeguards: Standard Contractual Clauses (SCCs).
Anthropic PBC (United States): AI-powered enrichment of audit reports (Claude). Safeguards: Standard Contractual Clauses (SCCs); data is transmitted without any direct personal identifier.
Transfers outside the European Union are carried out on the basis of the European Commission's Standard Contractual Clauses (Decision 2021/914).
5. Retention Periods
Account data: account lifetime + 30 days.
Audit reports: 24 months from the date of generation, then automatic deletion.
Billing data: 10 years (statutory accounting obligation).
Technical logs and IP addresses: 90 days.
Session cookies: 7 days of inactivity or upon logout.
6. Your Rights (GDPR)
In accordance with Regulation (EU) 2016/679 and the applicable data protection legislation, you have the following rights:
Right of access (Art. 15): obtain a copy of your personal data.
Right to rectification (Art. 16): correct inaccurate data.
Right to erasure (Art. 17): request deletion of your data, subject to legal retention obligations.
Right to data portability (Art. 20): receive your data in a structured format.
Right to object (Art. 21): object to processing based on legitimate interest.
Right to restriction (Art. 18): temporarily suspend processing of your data.
To exercise your rights: contact@crawlready.eu (response within 30 days maximum).
If you are unable to resolve a dispute, you may lodge a complaint with the relevant data protection authority.
7. Cookies & Trackers
CrawlReady uses only strictly necessary cookies required for the service to function:
Cookie session_id (HTTP-only, Secure, SameSite=Strict): maintains authentication, retained for 7 days or until the end of the session.
No advertising, third-party tracking, audience analytics (Google Analytics, Meta Pixel, etc.) or marketing personalisation cookies are used.
No consent is required for strictly necessary cookies (in accordance with applicable data protection guidelines and Article 5.3 of the ePrivacy Directive).
8. Security
Technical and organisational measures in place:
HTTPS/TLS encryption in transit.
Passwords hashed (bcrypt).
Cookies HTTP-only, Secure, SameSite=Strict.
Role-based access control (RBAC).
Access logging.
Production access restricted to the legal representative.
9. Data Relating to Minors
This service is not intended for individuals under the age of 16. If you believe we hold data relating to a minor, please contact us immediately.
10. Policy Updates
This policy may be updated to reflect legal or service changes. In the event of a material change, you will be notified by email or via an in-app notification.
11. Contact
For any questions regarding the protection of your data:
contact@crawlready.eu