Privacy & Cookie Policy
🔒 Short version: We collect only what we need. We do not sell your data. We do not share it with third parties except where required to run the service. You can request deletion of your data at any time by emailing hello@mycrawlbot.com.
1. Who We Are
MyCrawlBot is a digital services practice operated by Dineshkumar Sengodan, registered in Rome, Italy (P.IVA: 03294670603). We provide AI chatbot development, web design, digital marketing and AI integration services to businesses worldwide.
For all data protection matters, contact us at: hello@mycrawlbot.com
2. What Data We Collect
2.1 Data you give us directly
- Contact form: name, email address, service interest, project description
- Email correspondence: any information included in emails you send to us
- Client onboarding: business name, contact details, project scope — under a signed data processing agreement
2.2 Data collected automatically
- Analytics cookies (only if you consent): page views, session duration, referral source — collected via Google Analytics 4, with IP anonymisation enabled
- Server logs: IP address, browser type, pages visited — retained for up to 30 days for security purposes
2.3 Data we do NOT collect
- We do not collect payment card details — payments are processed by third-party providers (Stripe, PayPal, Wise) under their own privacy policies
- We do not collect sensitive personal data (health, religion, political views, etc.)
- We do not build advertising profiles or sell data to third parties
3. Why We Use Your Data (Legal Basis)
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Respond to contact form enquiries | Name, email, message | Legitimate interest / Pre-contractual steps |
| Deliver contracted services | Contact details, project data | Performance of a contract |
| Send project updates and invoices | Name, email, billing details | Performance of a contract |
| Website analytics | Anonymised usage data | Consent |
| Legal and accounting obligations | Invoice and transaction data | Legal obligation (Italian fiscal law) |
| Security and fraud prevention | Server logs, IP address | Legitimate interest |
4. Cookie Policy
Cookies are small text files stored on your device. We use them in compliance with EU ePrivacy Directive and GDPR. We do not set any non-essential cookies without your prior consent.
4.1 Strictly Necessary Cookies
These are required for the website to function. They do not track you and cannot be disabled.
| Cookie | Purpose | Duration |
|---|---|---|
| mcb_cookie_consent | Stores your cookie consent preferences | 12 months |
4.2 Analytics Cookies (consent required)
Used to understand how visitors interact with the site. All data is anonymised. Set only after you give consent.
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
| _ga | Google Analytics 4 | Distinguish unique visitors | 2 years |
| _ga_* | Google Analytics 4 | Persist session state | 2 years |
4.3 Marketing Cookies (consent required)
Used to deliver relevant advertising and measure campaign performance. Set only after you give consent.
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
| _fbp | Meta (Facebook) | Track visits for ad targeting | 3 months |
| _gcl_au | Google Ads | Conversion tracking | 3 months |
4.4 Preference Cookies (consent required)
Remember your settings and personalisation choices across visits.
4.5 Manage Your Cookie Preferences
You can review and change your cookie settings at any time:
You can also clear cookies at any time through your browser settings. Note that disabling all cookies may affect website functionality.
5. How Long We Keep Your Data
- Contact form enquiries: 2 years from last contact, unless a contract follows
- Client project data: 5 years after project completion (Italian fiscal retention requirement)
- Invoice and billing records: 10 years (Italian Civil Code art. 2220)
- Analytics data: 14 months (Google Analytics default, with anonymisation)
- Server logs: 30 days
6. Who We Share Data With
We do not sell, rent or trade your personal data. We share it only where necessary to deliver the service:
| Recipient | Purpose | Location |
|---|---|---|
| Formspree | Contact form processing | USA (SCCs in place) |
| Google Analytics | Website analytics (consent only) | USA (SCCs in place) |
| Vercel | Website hosting | USA/EU (SCCs in place) |
| Stripe / PayPal / Wise | Payment processing | USA/EU |
| Register.it | Email hosting | Italy (EU) |
| GitHub | Code repository / deployment | USA (SCCs in place) |
All third-party processors are bound by data processing agreements and operate under GDPR-compliant terms or EU Standard Contractual Clauses (SCCs).
7. International Transfers
Some of our service providers are based outside the European Economic Area (EEA), primarily in the United States. Where data is transferred outside the EEA, we ensure appropriate safeguards are in place — specifically EU Standard Contractual Clauses (SCCs) as approved by the European Commission under GDPR Article 46.
8. Your Rights Under GDPR
As a data subject in the EU/EEA, you have the following rights. To exercise any of them, email hello@mycrawlbot.com — we will respond within 30 days.
- Right to access: Request a copy of the personal data we hold about you
- Right to rectification: Ask us to correct inaccurate or incomplete data
- Right to erasure: Ask us to delete your data ("right to be forgotten")
- Right to restriction: Ask us to limit how we process your data
- Right to portability: Receive your data in a structured, machine-readable format
- Right to object: Object to processing based on legitimate interest
- Right to withdraw consent: Withdraw consent for analytics or marketing cookies at any time — this does not affect lawfulness of prior processing
- Right to lodge a complaint: You can complain to the Italian data protection authority (Garante per la protezione dei dati personali) or the supervisory authority in your country of residence
9. Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss or disclosure. These include:
- HTTPS encryption on all pages (TLS 1.2+)
- Access-controlled systems and tools
- Regular security reviews of third-party processors
- No storage of payment card data on our systems
Despite these measures, no internet transmission is 100% secure. If you suspect a data breach involving your personal data, please contact us immediately at hello@mycrawlbot.com.
10. Children's Privacy
Our services are not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has submitted personal data to us, please contact us and we will delete it promptly.
11. Changes to This Policy
We may update this policy from time to time to reflect changes in our practices or applicable law. We will update the "Last updated" date at the top of this page. For significant changes, we will display a notice on the website. Continued use of the site after changes constitutes acceptance of the updated policy.
12. Contact & Complaints
For any questions, requests or complaints regarding this privacy policy or your personal data:
- Email: hello@mycrawlbot.com
- Controller: Dineshkumar Sengodan — MyCrawlBot
- P.IVA: 03294670603
- Registered address: Rome, Italy
If you are not satisfied with our response, you have the right to lodge a complaint with the Italian Garante or your local EU supervisory authority.