Legal & GDPR Compliance
We operate within strict legal frameworks, ensuring all data extraction activities comply with GDPR, CCPA, UK Data Protection Act, and international data protection regulations.
GDPR Compliance Framework
Our operations are built on the principles of the General Data Protection Regulation (EU) 2016/679 and UK GDPR.
Data Transparency
We clearly disclose what data is collected, how it's processed, and for what purpose. All extraction activities are logged and auditable.
Data Minimization
We collect only the data explicitly specified by our clients. No unnecessary personal data is harvested or stored beyond the extraction scope.
Data Security
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access is restricted to authorized personnel with role-based permissions.
Legal Basis
We operate under legitimate interest for publicly available data. We do not extract data behind authentication or from restricted areas.
Data Protection Measures
Comprehensive safeguards to protect extracted data throughout its lifecycle.
Encryption
- • TLS 1.3 for all data transfers
- • AES-256 encryption at rest
- • Secure key management (HSM)
- • Encrypted backups
Access Control
- • Role-based access control (RBAC)
- • Multi-factor authentication
- • Audit logging for all access
- • Principle of least privilege
Data Retention
- • Configurable retention policies
- • Automated data purging
- • Right to erasure support
- • Data portability compliance
Our Ethical Boundaries
We maintain strict ethical guidelines for all data extraction activities.
We do not extract personally identifiable information unless explicitly requested for legitimate business purposes.
We do not extract data from behind login walls or authenticated areas without proper authorization.
We respect robots.txt directives and implement rate limiting to avoid impacting target server performance.
We do not extract copyrighted, licensed, or otherwise restricted content without proper permissions.
Terms of Service Summary
Service Agreement
By using WebHarvest Systems services, you agree to use extracted data in compliance with all applicable laws and regulations. You are responsible for ensuring your use case is lawful in your jurisdiction.
Data Processing Agreement (DPA)
For clients processing personal data, we provide a comprehensive DPA that outlines our role as a data processor, security measures, sub-processor list, and data transfer mechanisms.
Liability & Indemnification
WebHarvest Systems provides data extraction services as a tool. Clients are responsible for determining the legality of their intended use. We maintain professional indemnity insurance and limit our liability per the service agreement.
Compliance Questions?
Our data protection officer is available to discuss your specific compliance requirements and provide documentation.