Data Processing Addendum
Last updated: June 16, 2026
This Data Processing Addendum ("DPA") applies where Scrapegg Software Private Limited processes personal data on behalf of a business customer in connection with Superlurk, and forms part of our Terms of Service. For most individual users, Superlurk acts as the controller and our Privacy Policy applies instead.
1. Roles & scope
For personal data a business customer submits or that we process on its behalf, the customer is the controller and Scrapegg Software Private Limited is the processor. We process that data only to provide and support the service, for the duration of the agreement.
- Subject matter & nature — providing the Superlurk search and answer service.
- Categories of data subjects— the customer's authorized users.
- Types of personal data — account identifiers and emails, queries and conversation content, and usage/credit logs. The customer must not submit special-category data except as strictly necessary and lawful.
2. Our commitments as processor
- process personal data only on the customer's documented instructions, including for transfers, unless required otherwise by law (in which case we notify the customer where permitted);
- ensure people authorized to process the data are under an appropriate duty of confidentiality;
- implement appropriate technical and organizational security measures (such as encryption in transit, access controls, and least-privilege practices);
- assist the customer, taking into account the nature of processing, with responding to data-subject requests and with security, breach-notification, and data-protection-impact obligations;
- notify the customer without undue delay after becoming aware of a personal-data breach affecting their data;
- delete or return personal data at the end of the agreement, except where law requires retention; and
- make available the information needed to demonstrate compliance and allow for reasonable audits.
3. Sub-processors
The customer gives a general authorization for us to engage the sub-processors listed on our Sub-processors page. We impose data-protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance. We'll update that page and, where required, give advance notice of any new sub-processor and a chance to object on reasonable data-protection grounds.
4. International transfers
Where processing involves transferring personal data out of the EEA, the UK, or Switzerland to a country without an adequacy decision, the parties rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) and, for UK data, the UK International Data Transfer Addendum, which are incorporated into this DPA by reference and completed in the executable version.
5. Liability & order of precedence
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. If there is a conflict between this DPA and the rest of the agreement on the subject of data protection, this DPA controls.
6. Requesting a signed DPA
Business customers who need a countersigned DPA can request one by emailing legal@superlurk.com (or privacy@superlurk.com) with the contracting entity's legal name and signatory details. We'll return an executable copy — including the completed transfer-mechanism annexes — for signature.