LEGAL
Privacy notice
We monitor public web pages and hold the evidence that monitoring produces. This notice says exactly what that means for personal data — including the parts that are genuinely uncomfortable to write down.
Who we are
The controller for the data described here is EAACompliance.org, The Bradfield Centre, Cambridge Science Park Road, Cambridge, CB4 0GA, United Kingdom, operating eaacompliance.org. Contact us at [email protected].
We are established in the United Kingdom and serve customers across the European Union, so two regimes apply to us: the UK GDPR for our UK processing, and the EU GDPR where we offer services to people in the EU. Where they differ, we apply the stricter obligation rather than the more convenient one.
When you use the platform to scan your own websites, the roles reverse: for the scan results and evidence relating to your sites, you are the controller and we are your processor, on the terms of our data processing agreement.
What we process
| Category | What it is | Where it comes from |
|---|---|---|
| Account data | Your name, email address and Google account identifier | Google, when you sign in — we never receive or store a password |
| Organization data | Organization name, plan, seats, notification address, billing details | You, and Stripe for payment records |
| Scan data | URLs, rendered page structure, rule identifiers, CSS selectors and short markup snippets from the pages we scan | Our scanner, on domains you have verified |
| Journey data | Rule identifiers, selectors, URLs, step names and timestamps from recorded authenticated flows | The journey recorder, in your tester’s own browser |
| Evidence records | The append-only ledger: verifications, scans, sign-offs, exports and who made them | Generated by the platform as you use it |
| Technical data | IP address and user agent attached to a sign-in session, and rate-limit counters | Your browser, when you sign in or call the API |
| Page requests | One row per page you request: the time, the path, the referring site’s host name, your user agent, your IP address, the country your request arrived from, the status we answered with, and a short value derived from your address and user agent so that several requests can be recognised as one visit | Your browser, on every page of this site |
Legal bases
- Performance of a contract (Art. 6(1)(b) GDPR) — running the platform, scanning your domains, producing your evidence and documents, and taking payment.
- Legitimate interests (Art. 6(1)(f)) — securing the service, rate limiting, preventing abuse, and keeping the operational records that let us diagnose failures. We keep these to what a reasonable customer would expect.
- Legal obligation (Art. 6(1)(c)) — retaining invoices and tax records for the statutory period.
Where it is processed
Scanning runs on infrastructure located in the European Union. The web application and its database are currently hosted in Singapore, which means account data, organization data and evidence records are transferred outside the EEA. That transfer is covered by the European Commission’s Standard Contractual Clauses, and we have assessed the transfer as required.
Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| EU scanning host | Scanner infrastructure | European Union |
| Application host | Web application and database | Singapore |
| Cloudflare | DNS, TLS termination and protection against abuse | Global edge, EU data centres for European visitors |
| Sign-in (OpenID Connect) only — we receive your email, name and account identifier | Global | |
| Stripe | Payments, invoices and tax handling. Card details go to Stripe and never reach us | EU / US, SCCs in place |
We will list changes to this table on our changelog before they take effect, so you can object if a new sub-processor does not suit you.
How long we keep it
- Evidence records — for the retention period of your plan (3 to 60 months). Ledger entries are never edited or deleted within that period; that is what makes them evidence.
- Raw scan pages — pruned earlier than the ledger, since the finding and its selector are the durable part.
- Account and organization data — while your organization exists, and then removed on request. Deletion is a request we confirm with you, not a button that silently destroys an audit trail you may need.
- Invoices — for the statutory retention period, regardless of account deletion.
- Sign-in sessions — 30 days, or until you sign out.
Your rights
You have the rights to access, rectification, erasure, restriction, portability and objection under the GDPR, and the right to complain to a supervisory authority. Write to [email protected] and we will respond within one month.
One honest limitation: erasing evidence records erases the very thing that demonstrates your monitoring history. We will always do it if you ask, and we will tell you what you are giving up first.
Cookies
One first-party cookie, eaa_s, holds your sign-in session for 30 days. There are no analytics cookies, no advertising cookies, and no third-party trackers anywhere on this site — which is why you are not being asked to dismiss a consent banner.
We do count page requests, and we are specific about it because the previous version of this notice was not. Every page you request writes one row holding the time, the path, the referring site’s host name, your user agent, your IP address, the two-letter country Cloudflare reports, the status we answered with, and a short hash of your address and user agent that lets us tell one visit from two. Rows are kept for 90 days and then deleted.
What that does not include: no cookie is set for it, nothing is loaded from a third party to do it, no identifier follows you to another site, and we do not use it to build a profile or to advertise. You are not asked to dismiss a consent banner because the cookie we set is the sign-in one and nothing else, not because we keep nothing.
We rely on legitimate interests for this: running a site we can see the shape of, and telling real visitors apart from crawlers. If you would rather we did not, write to [email protected] and we will remove your rows.
Changes to this notice
Every version of this notice is dated, and material changes are announced on the changelog. We do not quietly rewrite a privacy notice, for the same reason we do not quietly rewrite a ledger.