Seatext library / BotRefund evidence
Which Personal Data Does BotRefund Process for Bot Detection Under GDPR?
BotRefund processes IP addresses, user agent strings, and behavioral signals such as mouse movement and click patterns, but only to the extent necessary for bot detection. These signals are kept as evidence, cross-checked across...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
Under GDPR, BotRefund processes only the personal data needed to distinguish human visitors from bots. That includes IP addresses, user agent strings, and behavioral signals like mouse movement, click timing, and page interaction patterns. But it does not treat any single signal as a verdict. Instead, it cross-checks each piece of evidence against independent browser, network, device, and behavior data, then applies strict retention limits so the processing stays minimal and purposeful.
BotRefund acts as a data processor for website owners, evaluating each visit in real time to protect against ad fraud and bot-driven financial loss. The data it collects is not used for profiling individuals or for any purpose beyond bot detection. If you run a website and want to know exactly what happens with your visitors' data when you use BotRefund, this article walks through every category, why it is needed, and the limitations built in for GDPR compliance.
What personal data does BotRefund actually process?
BotRefund's detection process relies on 106 independent checks across four broad categories: browser, network, device, and behavior. Each check produces a signal, and the signals are combined into a prediction. Here is what falls into each category:
IP addresses and network data
An IP address identifies the connection a visitor uses. BotRefund processes IP addresses and related network facts like ports, geolocation, and proxy indicators. The Suspicious Ports check, for example, looks for mismatches when a connection, location, and language disagree—a common sign of proxy rotation or masking. But a single mismatch is never enough to label someone a bot.
User agent strings and browser fingerprints
Every browser sends a user agent string that describes its type, version, and operating system. BotRefund also reads hardware and GPU details, installed fonts, and other browser attributes. The CPU Concurrency Lie check looks for a device that claims one set of specs while its graphics, audio, or processor behavior tells a different story. This is a classic sign of a virtual machine or spoofed profile.
Behavioral signals
How a person moves a mouse, clicks, scrolls, and pauses creates a unique pattern. BotRefund tracks these interactions to spot anomalies like robotic linear movements, superhuman input speed (under 1ms), grid-aligned paths, or absent clicks and scrolls. The Monitor Sync Anomaly and Impossible Tab Speed checks look for timing and movement patterns that a script cannot naturally reproduce.
Why does BotRefund need this data?
The purpose is straightforward: to identify automated traffic that clicks ads and drains ad budgets. Bot clicks can steal up to 20% of your Google and Meta ad spend. BotRefund uses the data to build a reliable picture of each visit, and that picture is the basis for proving bot clicks and negotiating refunds with the ad platforms.
Each data category serves a specific role. Network data helps detect proxy and VPN abuse. Device and browser fingerprints expose spoofing and virtual machines. Behavioral signals catch scripts that cannot mimic human imperfection. Without this data, accurate bot detection is impossible.
How does BotRefund stay GDPR-compliant?
GDPR requires data minimization, purpose limitation, and strict retention. BotRefund's approach follows those principles in three concrete ways:
- Data minimization: It only processes data that is directly needed for bot detection. No social security numbers, no email contents, no browsing history beyond the session.
- Purpose limitation: The data is used only to determine whether a visit is human or automated. It is not used for advertising, profiling, or selling to third parties.
- Retention limits: Signals are kept only as long as needed to support refund claims and then deleted. BotRefund does not keep raw behavioral logs indefinitely.
BotRefund also treats each signal as evidence, not a final verdict. A single anomaly—like using a privacy tool or traveling—can produce unexpected behavior for genuine people. The cross-checking process ensures that no one is flagged as a bot based on one data point alone.
Key facts about BotRefund's detection process
| Fact | Details |
|---|---|
| Number of independent checks | 106 different signals across browser, network, device, and behavior data |
| Accuracy | 99% when signals are corroborated by the AI prediction model |
| Approach to anomalies | A single anomaly is never a bot verdict; signals are cross-checked |
| Data categories | IP, user agent, hardware/GPU, fonts, mouse movement, click timing, session length, etc. |
| GDPR stance | Data minimization, purpose limitation, no indefinite retention |
Limitations and privacy safeguards you should know
GDPR says you must not collect more data than necessary. BotRefund respects that, but it still collects technical identifiers that some privacy advocates view as sensitive. The key limitation is that no single signal can be used to make a decision. That protects real users with privacy tools, corporate networks, or unusual devices.
Another limitation is that behavioral analysis is probabilistic, not deterministic. A bot might mimic human behavior well, and a human might behave in ways that look robotic. BotRefund's AI prediction weighs the complete pattern, but it is never a perfect science. The 99% accuracy claim comes from corroboration across many independent checks, not from a single tell.
Finally, the data is processed in the context of ad fraud prevention. It is not used to track individuals across the web or to build profiles. This aligns with GDPR's purpose limitation principle. If you are a website owner, you still need to inform your users that you use bot detection services and obtain any necessary consent, depending on your jurisdiction.
Frequently asked questions about BotRefund and GDPR
Does BotRefund store IP addresses permanently?
No. BotRefund keeps IP addresses only as long as they are needed to support bot detection and refund claims. Once the purpose is fulfilled, the data is deleted.
Can I use BotRefund without telling my users?
No. GDPR requires transparency. You must inform visitors that you process their data for bot detection and explain the legal basis, typically legitimate interest or consent.
What is BotRefund's role under GDPR?
BotRefund acts as a data processor. It processes personal data on your behalf and does not use it for its own purposes. You remain the data controller.
Does BotRefund sell or share visitor data?
No. The data is used solely for bot detection and refund recovery. BotRefund does not sell personal data or use it for advertising.
How does BotRefund handle false positives?
BotRefund's cross-checked approach minimizes false positives. A single anomaly is not enough to label a visit as bot activity. The AI prediction model weighs the entire pattern before making a determination.
What happens to the data after a refund claim is settled?
The data is deleted or anonymized once it is no longer needed. BotRefund applies strict retention limits to comply with GDPR data minimization.
Using BotRefund for GDPR-compliant bot protection
If you are evaluating BotRefund for your website, the key takeaway is that it collects only what it needs to stop bots and nothing more. You can add BotRefund in about one minute with no credit card required, and start with a free bot audit. The audit will show you exactly what kind of bot traffic is hitting your ads and how much of your ad spend is being wasted.
With a clear picture of the data processed and the safeguards in place, you can make an informed decision that balances ad fraud protection with GDPR compliance.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.