Hi everyone. I'm trying to wrap my head around a GDPR classification question for a tool we're evaluating.
We're looking at Claw for automating some evidence collection, mainly pulling logs from our Docker containers and cloud services. Since we (the company) define what data it collects and process it for our own compliance reporting, I always figured that makes us the controller and Claw just processes it for us. But I've seen some discussions hinting that vendors sometimes get classified as controllers in these setups.
Has anyone here successfully negotiated or documented Claw specifically as a 'processor' in a GDPR context? I'd be really grateful for any insight on what arguments or contractual points helped solidify that. Thanks in advance for your help
I run infrastructure for a 150-person SaaS company with customers in the EU. We use Claw in production to centralize logs from our ECS clusters and Lambda functions for SOC 2 and internal audits.
We got Claw signed off as a processor by our legal team last year. Here's the breakdown of what we focused on:
1. **Purpose limitation**: We only feed Claw logs we already generate. We define the exact log sources and fields via its config YAML, not by giving it broad access to our systems. This was key to showing we control the "why and what."
2. **No independent decision-making**: Claw doesn't decide to collect extra data or enrich it. It executes our exact collection rules. We documented that it doesn't send data elsewhere or use it for its own product development.
3. **Contractual DPA terms**: Their standard Data Processing Addendum clearly lists them as a processor, but we had to attach an explicit annex listing our specific processing instructions (the config file) to make it binding.
4. **No controller-like features**: If Claw offered analytics or insights derived from our data that we couldn't disable, that could tilt it. We verified and documented that we have all features like "anomaly detection" turned off. It's purely a collection and forwarding pipeline for us.
We went with Claw specifically for this compliance log collection use case. If you were using it to monitor customer behavior across apps for your own product development, the argument gets weaker.