Legal
Data Processing Agreement
Last updated 1 October 2026
This Data Processing Agreement ("DPA") is part of the Terms between you (the customer) and Web Freestyle SRL (IDNO 1021600031185, VAT 0509192, str. Alba-Iulia 21, of. 1, MD-2051, Chișinău, Republic of Moldova). It applies whenever Crustat processes personal data about the visitors of your websites, and meets Article 28 of the EU GDPR, the UK GDPR, and the personal data protection law of the Republic of Moldova. You don't need to sign anything: it applies automatically. If you need a signed copy, write to hello@crustat.com.
1. Roles
You are the controller of your visitors' personal data. Web Freestyle SRL is your processor. We process that data only to provide Crustat, and only on your documented instructions: the Terms, this DPA, and the sites and settings you choose in your account. If we believe an instruction breaks data protection law, we tell you.
2. The processing
| Subject | Measuring visits to your websites and showing you statistics |
|---|---|
| Duration | While your account is active, then until deletion as in section 9 |
| Data subjects | Visitors of your websites |
| Nature of the processing | Receiving each page visit from the visitor's browser, building a daily one-way code from it, and storing the result as statistics. Nothing is stored on visitors' devices: no cookies, no local storage. The script only checks for an opt-out flag that you can set on your own browser to leave your own visits out. |
| Personal data | Page addresses, referring pages, window width, country, browser, operating system, device type, and a daily one-way code (a hash of that day's random salt, the website, the IP address and the browser details). Each day's salt is deleted after two days, after which the codes can no longer be linked to an IP address or browser. IP addresses and full browser details are processed only in memory and never stored. |
| Special categories | None. Don't put special-category data (such as health data) in page addresses you track. |
3. Confidentiality
Only people who need access to run Crustat can access personal data, and they are bound to keep it confidential.
4. Security
We keep appropriate technical and organisational measures, including: encryption in transit and at rest; no storage of IP addresses; a new random salt for each day's visitor codes, deleted after two days; separation of each customer's data; access limited by role, with strong authentication; logging and monitoring of access; regular updates and backups; and review of these measures as risks change.
5. Subprocessors
You give general permission for us to use subprocessors. We choose them carefully and bind each one to data protection terms at least as strict as this DPA. We remain responsible for them. Current subprocessors:
| Subprocessor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, network, storage of visit and account data | Global network; USA | Standard contractual clauses; EU-US Data Privacy Framework |
| Google LLC | Sign-in with Google (customer accounts only, if chosen) | USA | Standard contractual clauses; EU-US Data Privacy Framework |
| Payment provider | Payments, invoices, tax (customer billing data only) | Named in the dashboard before first payment | Standard contractual clauses where needed |
| Email provider | Sending account and report emails (customer email only) | Named in the dashboard | Standard contractual clauses where needed |
We tell you by email at least 30 days before adding or replacing a subprocessor that handles your visitors' data. If you object on reasonable data protection grounds and we can't solve it, you can cancel and we refund any prepaid time you haven't used.
6. International transfers
Where personal data leaves the EU, the UK or Moldova for a country without an adequacy decision, the transfer is covered by the European Commission's standard contractual clauses (with the UK addendum where it applies), or by the recipient's certification under the EU-US Data Privacy Framework. By accepting the Terms, you and we enter into the standard contractual clauses (module 2, controller to processor, for Web Freestyle SRL as processor) for transfers from you to us, to the extent they are needed.
7. Helping you
- Visitor requests: Crustat doesn't identify visitors, so most requests can be answered from what's here. If you receive a request to see, correct or delete data, we help you respond. If a visitor contacts us directly, we pass the request to you.
- Assessments: we give you the information you reasonably need for a data protection impact assessment or a consultation with an authority.
8. Personal data breaches
If we become aware of a breach affecting your visitors' personal data, we tell you without undue delay, and within 48 hours at the latest, with what we know: what happened, the data and people affected, likely consequences, and what we are doing about it. We update you as we learn more.
9. Deletion and return
You can export your data at any time while your account is active. When you delete a site, or your account is closed or deactivated, we delete the related personal data from our systems within 90 days, unless the law requires us to keep it.
10. Audits
We make available the information needed to show we meet this DPA, and answer reasonable written questions. Where that isn't enough, you may audit our compliance once a year, at your cost, with 30 days' notice, in a way that protects other customers' data and our confidential information; an independent auditor bound to confidentiality may do it for you.
11. The rest
The limits of liability in the Terms apply to this DPA. If this DPA and the Terms conflict about personal data, this DPA wins. If the standard contractual clauses apply and conflict with this DPA, the clauses win.
Contact
Web Freestyle SRL, str. Alba-Iulia 21, of. 1, MD-2051, Chișinău, Republic of Moldova. hello@crustat.com