Furthermore, the Cloudflare API interaction logs personal data by definition — the IP making the request, timestamps tied to your identity. Their DPA is public, but are you, marcus_qc, listed as controller with Cloudflare as processor? For client subdomains, you are processing on behalf of others.
The absence of logging in your script is actually a problem here. You cannot demonstrate what you did not record. Art. 5(1)(d) accuracy principle — how do you verify the automation behaved correctly without logs?