Legal
Data Processing Addendum
For customers who send personal data through the API and need a processor agreement under the GDPR, the UK GDPR or India's DPDP Act.
Last updated 20 September 2026
1. Scope and roles
This Addendum forms part of the Terms of Service between you ("Customer") and Truscan Inc. ("Processor"). It applies where, in using the service, you send us personal data for which you are the controller.
For account and billing information we are a controller in our own right, and our Privacy Policy governs that. For data you submit through the API, including query text, you are the controller and we process it only on your instructions.
The service is a web search API. It is not designed for special category data as defined in Article 9 of the GDPR, and you should not send it.
2. Processing on your instructions
We process personal data only to provide the service and as otherwise instructed by you in writing, unless required to do otherwise by law, in which case we will tell you first unless the law forbids it.
We will tell you if, in our opinion, an instruction infringes applicable data protection law.
3. Details of the processing
| Item | Detail |
|---|---|
| Subject matter | Provision of a web search and content extraction API |
| Duration | For as long as your account is open, plus the retention periods stated below |
| Nature and purpose | Receiving a query, retrieving and ranking public web results, optionally extracting page content, and returning a response |
| Types of personal data | Any personal data contained in a query you send, plus request metadata including IP address and user agent |
| Categories of data subject | Your end users and any individuals named in a query |
| Retention | Request logs are deleted automatically 30 days after creation. Queries, URLs, questions and results are never stored. |
4. Confidentiality
Access to personal data is limited to personnel who need it to operate the service, and everyone with access is bound by an obligation of confidentiality.
5. Security measures
We maintain technical and organisational measures appropriate to the risk, including those described in Annex II below. We may update them, provided the level of protection is not reduced.
6. Sub-processors
You give general authorisation for the sub-processors listed below. We impose data protection obligations on each of them no less protective than those in this Addendum, and we remain liable for their performance.
| Sub-processor | Purpose | Data it receives |
|---|---|---|
| Dodo Payments | Payment processing and invoicing, acting as merchant of record | Name, email address, billing address and payment method. As merchant of record they are the seller of record and a controller in their own right for the transaction. We never receive or store full card numbers. |
| ZeptoMail | Transactional and contact email | Recipient email address, name and the content of the message |
| Our own servers | Servers, storage and backups, operated by us rather than a managed platform | All service data at rest, encrypted in transit |
| Google, Bing, DuckDuckGo, Brave, Wikipedia and other public engines | Search recall, reached through a metasearch node we host ourselves | The query text only. No account identifier, API key or IP address of yours is passed to them. |
We will give at least 30 days notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds, you may terminate the affected part of the service and we will refund unused credit on a pro rata basis.
Queries reach the upstream search engines through a metasearch node we host ourselves. Those engines receive the query text and nothing that identifies you, your account or your end user.
7. Data subject requests
Taking into account the nature of the processing, we will assist you with appropriate technical and organisational measures in responding to requests to exercise data subject rights. If a request reaches us directly, we will not respond to it substantively and will refer the individual to you, unless you instruct otherwise.
8. Personal data breach
We will notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting your data, and will provide the information you reasonably need to meet your own notification obligations.
9. Assistance with assessments
We will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, to the extent they relate to our processing and the information is available to us.
10. International transfers
Where we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, the European Commission's Standard Contractual Clauses are incorporated into this Addendum by reference, with us as data importer, together with the UK International Data Transfer Addendum where the UK GDPR applies.
11. Audit
We will make available the information reasonably necessary to demonstrate compliance with this Addendum. You may request an audit no more than once in any 12 month period, on 30 days written notice, during business hours, without unreasonably disrupting our operations, and subject to confidentiality. You bear your own costs.
12. Deletion and return
On termination, we will delete personal data processed on your behalf. Request logs are deleted automatically within 30 days of creation, so they expire on their own schedule rather than at the moment of termination. Queries, URLs, questions and the results we return are never written to a database, so there is nothing of that kind to delete. We will retain data only where law requires it, and will keep it protected for as long as we hold it.
13. Liability
Each party's liability under this Addendum is subject to the limitation of liability in the Terms of Service.
Annex I: Parties and processing
Data exporter: the Customer, being the account holder identified in our records. Data importer: Truscan Inc., 111B S Governors Ave # 82225, Dover, DE 19904, United States, contactable at support@truscan.co.
The subject matter, duration, nature, purpose, data types and categories of data subject are those set out in section 3 above.
Annex II: Technical and organisational measures
- Encryption in transit for all external traffic, using TLS with HSTS enabled.
- Passwords hashed with bcrypt at cost 12; API keys and reset tokens stored only as SHA-256 fingerprints.
- Internal service endpoints not routable from the internet and gated by a separate internal credential.
- Rate limiting at the edge, and outbound fetches guarded against server-side request forgery by validating the resolved address.
- Request bodies excluded from logs by design.
- Queries, URLs and questions are never written to a database, so there is nothing to expire.
- Automatic expiry of request logs after 30 days.
- Session tokens expiring after 24 hours; password reset tokens after one hour or first use.
- Access to production limited to personnel who require it.
14. Contact and signature
This Addendum takes effect when you accept the Terms of Service and applies automatically. If you need a countersigned copy for your records, write to support@truscan.co with your account email and company details.