PAGEFLOCK / DATA PROCESSING

Know where the data goes.

How account data and requested content are handled, and what to arrange before your workflow needs a data processing agreement.

Updated 17 September 2026 · Version 1.3
01

Different data, different roles

The operator determines how account data is used for authentication, billing and security. You choose source URLs, collection purposes and downstream uses. Where requested content includes personal data processed on your instructions, controller and processor obligations must be established for the workflow and applicable law.

02

The processing in scope

pageflock fetches permitted public HTML, extracts text, links and metadata, returns results and records request metadata. Collections additionally save extracted content for access and export during their seven-day window. Retention and account rights are described in the Privacy Notice.

03

Providers and transfers

Hosting, email and enabled payment processing may involve providers. Search queries and localisation parameters are sent to Serper when enabled; video metadata requests send canonical URLs to YouTube. The operator must disclose providers, purposes, locations and applicable transfer safeguards below. Do not assume data stays in a particular country or that a transfer agreement is in place.

04

Requesting a DPA

Contact the privacy address before sending personal data that requires a data processing agreement. Describe your organisation, source categories, purpose, locations and volume without attaching personal records. A DPA must establish instructions, confidentiality, safeguards, subprocessors, rights assistance, incident handling, deletion, transfers and audit arrangements. This information page is not an executed DPA.

05

Minimise what you collect

Choose only pages needed for your purpose, avoid private or sensitive data and export only what you can lawfully keep. Page content is not included in account export; download it from the collection before expiry. Delete finished collections when no longer needed.

OPERATOR & CONTACT

Who runs pageflock.

Legal operator
HYVE LABS LLC
Business address
Sharjah Media City (Shams), Sharjah, United Arab Emirates
Registration country
United Arab Emirates
Privacy requests
abdul@hyvelabs.tech

Providers, locations and transfers

pageflock is operated by HYVE LABS LLC and hosted on Google Cloud Platform (application, collection worker and PostgreSQL database in the EU region europe-west1; some Google services may process data in the United States). Payments are handled by Stripe on its hosted checkout; card details are collected and stored by Stripe, never by pageflock. Optional web, news and video search sends your query and country/language to Serper (serper.dev). Transactional email (verification and purchase receipts) is delivered through Resend. Optional, consent-based product analytics use Google Analytics. YouTube metadata requests use Google public oEmbed. These processors act under their own terms; where personal data is transferred internationally they rely on their own standard contractual clauses and safeguards.

Payment record retention

Paid and expired checkout records (checkout identifiers, amounts, credits and dates) are kept, separately from your account profile, for at least five years after the transaction to meet UAE tax and accounting obligations. Encrypted database backups are retained for up to 30 days before rotation. Account request history is pruned after 30 days and collection results after seven days.

Contact & account help
YOUR PRIVACY

Choose what works for you. You can reopen these settings from the footer at any time.