Privacy policy
How JKC Software B.V. processes personal data as controller, on what basis, for how long, and what it deliberately does not do.
Published 1.1 · 2026-09-21
Last updated: 21 September 2026
This notice explains how JKC Software B.V. processes personal data when you use WebCrew, visit webcrew.ai, or contact us.
1. Who we are
JKC Software B.V., Philitelaan 57, 5617 AK Eindhoven, the Netherlands, KvK 42082783, is the controller for the processing described here. You can reach us about privacy at privacy@webcrew.ai.
We are not required to appoint a data protection officer under article 37 GDPR and have not appointed one. privacy@webcrew.ai reaches the person who is accountable for this notice.
2. Two roles, and which one applies
| Data | Our role | Governed by |
|---|---|---|
| Your account, your workspace, your billing, your support conversations | Controller | This notice |
| Personal data inside the websites you connect — your clients' data | Processor, acting on your instructions | The Data Processing Agreement, and your own privacy notice |
| Visitors to webcrew.ai | Controller | This notice and the Cookie Statement |
The distinction matters: for the second row we decide nothing about purposes. If a visitor to one of your clients' websites asks about their data, the answer comes from you, and we help you give it.
3. What we process, why, and on what basis
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Account identity: name, email, the stable subject identifier from your sign-in provider | Creating, securing and administering your account | Performance of a contract (art. 6(1)(b)) | Account lifetime + 30 days after closure |
| Sign-in events, session records, IP address at sign-in | Keeping sessions secure, detecting and preventing abuse | Legitimate interest (art. 6(1)(f)): keeping accounts and tenants safe | 12 months |
| Workspace configuration, policies, approvals, audit records | Operating the service you configured, and proving what ran and who approved it | Performance of a contract | Per plan retention, so the evidence stays available to you |
| Command log: the commands WebCrew runs on a connected site over SSH or the Connector — the command line, the target path or object, the exit status, and what authorised it (a Policy, a named user's Approval, or an agent run) | Executing the work you configured, and proving afterwards what ran on a site, on whose authority and with what result, so an Action can be rolled back, investigated or disputed | Performance of a contract; legitimate interest (art. 6(1)(f)) in an operations record that can be checked | With the audit trail, per plan retention. See clause 3.1 |
| Contact and billing details, invoices, payment status | Charging you; meeting bookkeeping and tax law | Contract; legal obligation (art. 6(1)(c)) | 7 years from the end of the financial year (Dutch bookkeeping law) |
| Support and sales correspondence | Answering you, and keeping a record of what was agreed | Contract; legitimate interest in a usable record | 24 months after the last contact |
| Product telemetry: errors, performance, feature usage, tied to a workspace | Finding faults and deciding what to build | Legitimate interest: a working, improving product | 13 months |
| Agent prompts and AI-generated responses | Performing the specific task you asked the agent to do (see the AI Transparency Notice) | Performance of a contract | Not retained separately: processed transiently to serve the request, then discarded on our side. What lands in the audit trail is the resulting Action and its outcome, not the prompt text |
| Anonymised, aggregate AI feature-usage metrics: which capability was used, how often, not the prompt content | Deciding what to build and measuring whether AI features work | Legitimate interest: a working, improving product | 13 months, same as other product telemetry |
| Website analytics and marketing cookies on webcrew.ai | Understanding what works on the marketing site | Consent (art. 6(1)(a)), where required | Per the Cookie Statement |
| Newsletter or product-update email, where you asked for it | Sending what you asked for | Consent, withdrawable in every message | Until you withdraw |
Where we rely on legitimate interest, we have weighed our interest against your rights. In each case above the processing is what a customer would expect from an operations product, it is limited to what the purpose needs, it is never used to profile you or to make decisions about you, and you can object under clause 7.
3.1 The command log on connected sites
When WebCrew acts on a connected site it records what it did. This is the clause that says how far that recording goes.
What we record. The command or API call, the site and the path or object it targeted, when it ran, how long it took, whether it succeeded, and its provenance: the Policy that permitted it, the named user who approved it, or the agent run that produced it. Standard error output is kept where a command failed, because a failure you cannot read is a failure you cannot fix.
What we do not record. We do not keep the contents of the files a command read or wrote, rows from your database, or the output of a successful command beyond what the Action needs to report. Credentials, keys, tokens and anything matching a secret pattern are redacted before the entry is written, not after. We do not log interactive shell sessions, because there are none: WebCrew issues discrete commands, not a terminal a person types into.
Data minimisation. The log exists to answer three questions — what ran, who allowed it, what happened. A field that answers none of them is not collected. Where a command argument would carry personal data from your client's site, the entry keeps the argument's shape, not its content.
Retention. Command entries live in the audit trail and follow its retention: the period stated for your plan, so the evidence outlasts the dispute it might have to settle. Standard error output from failed commands is truncated to 90 days. After termination, Annex B of the Data Processing Agreement governs deletion.
Opt-out. A workspace owner can switch off command-body logging for a workspace. Until the switch appears in the workspace's security settings, ask privacy@webcrew.ai and we set it for you — the right does not wait for the button. With it off we still record the Action, its target, its provenance and its outcome — the accountability record the service cannot work without — but not the command line itself. Turning it off makes some support and rollback work slower, and we will say so rather than pretend otherwise. There is no opt-out from the Action record itself.
What we will not do with it. We do not use command logs to train machine learning models, we do not build a cross-customer knowledge base or security baseline from them, and we do not read them except to run the service, to investigate an incident or a suspected abuse, or where the law requires it. If that ever changes, it changes by a written amendment with notice, never silently.
4. Where the data comes from
Almost all of it comes from you. Your identity comes from the sign-in provider you choose (Google, GitHub or Microsoft) — we receive the identity they assert, never their password, and we gain no access to your account there beyond authentication. Payment status comes from our payment processor. Nothing is bought from data brokers, and we do not enrich your record from third-party sources.
5. What we deliberately do not do
- We do not sell personal data, and we do not share it for advertising.
- We do not train machine-learning models on the content of connected websites, and our AI provider is contractually excluded from training on our traffic.
- We do not run third-party advertising or analytics trackers inside the product.
- We do not read your clients' website data except as needed to perform the work you configured — and the audit trail records that work.
- We make no automated decisions that produce legal effects or similarly significantly affect you within the meaning of article 22 GDPR. WebCrew automates work on websites, not decisions about people.
6. Who receives the data
We use a small set of processors — hosting, payment processing, AI inference, backup storage, transactional email — each listed with what it does, where it sits, and its transfer mechanism in the Subprocessor Register. They act on our instructions under article 28 agreements and for no purpose of their own.
Beyond that, personal data goes to third parties only where the law requires it, where it is necessary to establish or defend a legal claim, or to a professional adviser bound by confidentiality. In a merger or transfer of the business, data transfers with it and you are told beforehand.
Transfers outside the EEA happen only where the Subprocessor Register says so, and then on an adequacy decision (including the EU–US Data Privacy Framework where the recipient is certified) or the EU Standard Contractual Clauses with a transfer assessment and supplementary measures where the assessment calls for them. Ask us at privacy@webcrew.ai for a copy of the safeguards.
7. Your rights
You can ask us for access to your personal data, correction, deletion, restriction of processing, and a portable copy of the data you gave us. You can object to processing based on legitimate interest, on grounds relating to your situation. Where processing rests on consent you can withdraw it at any time, without affecting what happened before.
Write to privacy@webcrew.ai. We answer within one month and tell you if we need the extension article 12(3) allows. We may ask for enough information to be sure it is you — never more than that.
If your request concerns data inside a website connected by an agency, we forward it to that agency, because they are the controller for it.
You can complain to the Autoriteit Persoonsgegevens (Hoge Nieuwstraat 8, 2514 EL The Hague, autoriteitpersoonsgegevens.nl), or to the supervisory authority where you live or work. We would rather hear it first.
8. Security
We protect personal data with encryption in transit and at rest for backups, server-side session records, role-based access scoped to an organisation, tenant isolation, an append-only audit trail, signed connector requests, and dependency and secret scanning in our build. Annex A of the Data Processing Agreement describes the measures in full, and the Security Overview keeps a dated account of what exists today and what is planned. No measure is described here as more complete than it is.
9. Children
WebCrew is a business service. It is not directed at children and we do not knowingly process the personal data of anyone under 16 in the controller role.
10. Changes to this notice
We update this notice when the processing changes. The date at the top is the version date, and material changes are announced in the product or by email before they take effect. Superseded versions are available on request.
| Version | In force | What changed |
|---|---|---|
| 1.1 | 21 September 2026 | First version published on webcrew.ai. Adds clause 3.1 and the command-log row in clause 3: what WebCrew records when it runs commands on a connected site, on what basis, for how long, and how to switch the command body off |
| 1.0 | — | Approved internally on 18 September 2026 and superseded before publication. Never in force |
11. Contact
JKC Software B.V. · Philitelaan 57, 5617 AK Eindhoven, the Netherlands · privacy@webcrew.ai