Data processing agreement#
This page is a data processing agreement under Art. 28 GDPR. It applies automatically to every account, without a separate signature. If you need a countersigned copy for your records, ask via the contact address in the Imprint and we will provide one.
Roles#
When you embed our icon endpoints on your website, your visitors' browsers send requests (carrying an IP address and request headers) to our servers on your initiative. For that processing, you are the controller and we (botBrains GmbH, the operator) are your processor. For platform account data (your email address, name, organization, claimed domains), we are the controller - see the Privacy policy.
Subject matter, duration, nature and purpose#
We process the data on your instructions to serve favicons to your visitors: answering their icon requests and applying rate limits. By design almost nothing is processed and nothing is retained - requests are not logged (no IP addresses, user agents, or referrers), and the only per-visitor state is a salted IP hash held in memory for rate limiting, whose salt rotates daily. The agreement runs for as long as your account exists.
Categories of data and data subjects#
The data is the transient request metadata of visitors whose browsers load icons from us (IP address and request headers, processed in memory and not stored). Data subjects are your users and audience. You are responsible for having a legal basis for directing your visitors' browsers to the Service, and for mentioning us in your own privacy notice where required.
Our obligations as processor#
- We process the data only on your documented instructions. Embedding our endpoints and your domain configuration are such instructions - we serve what is requested and nothing more.
- Persons with access to our systems are bound to confidentiality.
- We apply the technical and organisational measures described in the Compliance page.
- We use sub-processors only as listed in the Subprocessor list (currently only Hetzner Online GmbH, hosting in Germany/EU). We will give notice of intended changes, and you may object by closing your account.
- We assist you, to the extent reasonable for a service of this kind, in responding to data-subject requests (access, rectification, erasure). Note that icon requests are not recorded - we cannot look up "all icons requested by person X" because that information never exists at rest; the honest answer to such requests is that no stored data exists.
- Deletion: your claimed domains and tenant configuration are deleted when your account is deleted. There is no visitor data to delete.
- We notify you of personal-data breaches affecting your data without undue delay after becoming aware of them.
Audit rights#
We make available the information necessary to demonstrate compliance with this agreement, primarily by answering your questionnaires and written enquiries via the contact address in the Imprint. Given the size and nature of the service, remote information requests are the standard audit form; on-site audits require prior agreement on scope and timing.
Instructions and liability#
If we believe an instruction infringes the GDPR, we will tell you. Statutory liability rules apply; see also the Terms of service.
Last updated: August 2026.