DIRECTIVE (EU) 2019/882 · IN FORCE SINCE 28 JUNE 2025 EU-HOSTED · GDPR-CLEAN
EAA Compliance

LEGAL

Data processing agreement

VERSION 1.0 · EFFECTIVE 1 May 2026 · FORMS PART OF THE TERMS OF SERVICE

This is the agreement your legal team will ask for. It applies automatically when you use the platform — you do not need to request a signed copy to be covered by it, though we will sign one if your procurement requires it.

Scope

This agreement governs our processing of personal data on your behalf when you use eaacompliance.org, and takes precedence over any conflicting term elsewhere in our documentation.

Roles

For data we process to run the platform for you — scan results from your domains, recorded journeys, sign-offs and your ledger — you are the controller and we are the processor. For our own account, billing and security records we are the controller, and our privacy notice describes that separately.

Our obligations

  • Process personal data only on your documented instructions, which include your use of the platform and its API.
  • Ensure that everyone authorized to process it is bound by confidentiality.
  • Implement the technical and organisational measures set out in Annex 2.
  • Assist you with data subject requests, impact assessments and regulator engagement, to the extent the data is in our systems.
  • Make available the information needed to demonstrate compliance with Article 28 GDPR.
The best security measure here is what we refuse to collect. The journey recorder strips form values, cookies, credentials, page HTML and screenshots inside your tester’s browser, before upload. Scans store rule identifiers, CSS selectors and short markup snippets — not page content. Data we never receive cannot be breached, subpoenaed or mishandled by us.

Sub-processors

You give general authorisation for the sub-processors listed in our privacy notice. We will announce any addition or replacement on the changelog before it takes effect, giving you a reasonable opportunity to object; if you object on reasonable data-protection grounds and we cannot accommodate it, you may terminate the affected service without penalty.

Security measures

Set out in Annex 2 below. We review them at least annually and whenever we materially change the architecture.

International transfers

Scanning runs in the European Union. The application and database are hosted in Singapore, and we are established in the United Kingdom. Transfers outside the EEA rely on the European Commission’s Standard Contractual Clauses together with the UK addendum where relevant, supported by a transfer impact assessment which we will share with you on request.

Breach notification

We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your data, with what we know at that point rather than waiting for a complete picture. Our own incident record is public at /status.

Audits

You may audit our compliance with this agreement once per year, or after a breach affecting your data, on reasonable notice. In most cases our documentation, architecture description and the evidence in your own ledger will answer the questions; where they do not, we will accommodate a proportionate audit.

Return and deletion

You can export your complete evidence file at any time without asking us. On termination we delete your data after the retention period of your plan, or sooner on your written request — with the one caveat we state everywhere: deleting evidence deletes the proof of your monitoring history, so we confirm before acting.

Annex 1 — the processing

ItemDetail
Subject matterAutomated and human-assisted accessibility testing of the customer’s websites, and retention of the resulting evidence
DurationFor the term of the subscription, plus the retention period of the plan
Nature and purposeRendering and analysing web pages, storing findings and sign-offs, generating conformance documents
Types of personal dataAccount identifiers (name, email, Google account id); IP address and user agent attached to sessions; any personal data incidentally present in public page markup captured in a short snippet; names of people who sign off criteria
Categories of data subjectsThe customer’s staff and authorized testers; individuals whose data appears publicly on the scanned pages
Special categoriesNone sought. The platform is not designed to process special category data and customers should not direct it at pages where such data is exposed

Annex 2 — technical and organisational measures

  • Data minimisation by design — in-browser stripping of journey payloads; selectors and snippets rather than page content.
  • Authentication — Google sign-in only; no passwords stored anywhere; sessions are first-party cookies with hashed tokens and a 30-day lifetime.
  • Credentials at rest — API keys, webhook secrets and session tokens are stored hashed, never in plaintext; keys are shown once at creation.
  • Transport — every connection between you and us, and between our own systems, is encrypted in transit with TLS 1.2 or better, with HSTS and a strict content security policy carrying no inline scripts or styles. Traffic reaches our servers through Cloudflare, which terminates TLS at its edge and re-encrypts to our origin; the scan bridge between our Singapore application and our EU scanning infrastructure runs over that same proxied HTTPS path. We describe this precisely rather than claiming end-to-end encryption we do not operate.
  • Authorisation — organization-scoped queries throughout; agency access to a client workspace is re-checked on every request and recorded in that client’s ledger.
  • Integrity — the evidence ledger is append-only; no code path updates or deletes an entry, and corrections are new entries.
  • Isolation — the scanner runs on separate EU infrastructure from the application, reachable only over an authenticated bridge.
  • Monitoring — automated health checks with a public status page and incident history; errors logged outside the web root.
  • Resilience — daily database backups with restore tested before each major release.
  • People — access limited to named staff, listed and revocable; staff can read customer data but cannot alter evidence records.

SIGNED COPY OR SUPPLIER QUESTIONNAIRE: [email protected]