Skip to content

Data Processing Agreement

Version 1.1 — Effective date: June 23, 2026 — Last updated: June 23, 2026

This Data Processing Agreement (the "DPA") forms part of the Terms of Service between WCAGC, operated by Pavel Charkasau, ul. Garbary 100, 61-757 Poznań, Poland, NIP 7831856003 (the "Processor"), and the Customer (the "Controller"). It applies only when WCAGC processes Customer Personal Data on the Customer's behalf and is intended to satisfy Article 28 GDPR.

WCAGC remains an independent controller for account-holder registration, authentication, billing, security, transactional communications, and its own legal obligations, as described in the Privacy Policy.

1. Scope and Definitions

"Customer Personal Data" means personal data processed by WCAGC on behalf of the Customer as described in Annex I. Other GDPR terms have the meanings in Article 4 GDPR.

This DPA applies for the term of the Service and until Customer Personal Data has been returned or deleted under Section 9.

2. Processing and Customer Instructions

2.1. WCAGC retrieves and analyzes Customer-selected web pages, stores the resulting accessibility findings and evidence, and presents results and derived reports to the Customer. Page content may incidentally contain personal data already published on those pages.

2.2. WCAGC processes Customer Personal Data only on documented instructions, including the Agreement, this DPA, and the Customer's use of Service features, unless Union or Member State law requires processing. Where legally permitted, WCAGC will inform the Customer before processing required by law.

2.3. Additional instructions require written agreement and may be subject to reasonable fees where they fall outside the Service's standard functionality.

2.4. WCAGC will inform the Customer if, in its opinion, an instruction infringes applicable data-protection law.

2.5. The Customer is responsible for its instructions, legal basis, transparency obligations, and authority to scan each submitted site. The Customer must not use the Service to collect special-category data or private/authenticated content without a separate written agreement.

3. Processor Obligations

WCAGC will:

  1. ensure persons authorized to process Customer Personal Data are bound by confidentiality;
  2. implement measures appropriate to risk as described in Annex II;
  3. engage Sub-processors only under Section 4;
  4. taking account of the nature of processing, assist the Customer with data-subject requests through available Service functionality and reasonable additional assistance;
  5. assist with Articles 32–36 GDPR taking account of the nature of processing and information available to WCAGC;
  6. delete or return Customer Personal Data under Section 9; and
  7. make available information reasonably necessary to demonstrate Article 28 compliance and support audits under Section 10.

4. Sub-processors

4.1. The Customer grants general written authorization for the Sub-processors in Annex III.

4.2. WCAGC will inform account owners of an intended addition or replacement with reasonable advance notice where practicable and allow objections on reasonable data-protection grounds. If an urgent security, availability, or legal requirement prevents advance notice, WCAGC may make the change first and notify the Customer as soon as reasonably practicable.

4.3. If a justified objection cannot be resolved, the Customer may stop using and terminate the affected Service before the new Sub-processor begins processing, where advance notice was possible.

4.4. WCAGC will impose Article 28-equivalent data-protection obligations on Sub-processors and remains responsible for their performance to the extent required by GDPR.

5. International Transfers

Primary application, worker, PostgreSQL, Redis, and RabbitMQ resources are configured in Stockholm, Sweden. Tigris object storage is globally distributed and therefore Customer Personal Data stored there is not represented as EU-only.

Where Chapter V GDPR applies, WCAGC will use an applicable adequacy decision, the EU–US Data Privacy Framework for a certified recipient, or European Commission Standard Contractual Clauses with supplementary measures where appropriate.

6. Data-Subject Requests

If WCAGC receives a request concerning Customer Personal Data, it will forward it to the Customer where legally permitted and will not respond on the merits except on documented instruction or where required by law. The Customer remains responsible for the response. Built-in deletion and re-scan features are the primary assistance mechanism; additional bespoke work may be charged at reasonable cost where GDPR permits.

7. Personal Data Breach

WCAGC will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The initial notice may be based on information then available and supplemented in phases without undue further delay. Where available, WCAGC will describe the nature of the breach, affected categories and approximate volumes, likely consequences, a contact point, and mitigation measures.

The Customer is responsible for deciding whether Articles 33 or 34 require notifications by the Customer. Nothing in this Section replaces WCAGC's own obligations where it acts as controller.

8. Confidentiality and Security

WCAGC will process Customer Personal Data only through personnel and providers who need access for the Service and are subject to confidentiality. Measures may evolve with risk and technology, provided the overall level of protection is not materially reduced. Annex II describes the current baseline and is not a guarantee that every possible security event can be prevented.

9. Return and Deletion

9.1. During the term, the Customer may use available Service features to delete sites and associated results.

9.2. On Account or organization deletion, access is disabled immediately and the deletion workflow begins without a recovery grace period. Operational Customer Personal Data is deleted or irreversibly anonymized as the workflow completes.

9.3. If the Customer requires a return of Customer Personal Data, it must request it before initiating deletion. After deletion begins, WCAGC is not required to reconstruct data that has already been deleted. Unless return is requested before deletion, the Customer instructs WCAGC to delete the data.

9.4. A narrowly defined record may be retained only where Union or Member State law requires it or where necessary for the establishment, exercise, or defence of legal claims; it will be isolated from ordinary product use and deleted when that purpose ends.

9.5. Provider-level disaster-recovery copies that cannot be selectively edited are not used for ordinary processing and are overwritten under the provider's rotation. On request, WCAGC will provide reasonable written confirmation of completion of the active-system deletion workflow.

10. Compliance Information and Audits

10.1. WCAGC will first provide documentation reasonably necessary to demonstrate compliance, subject to confidentiality and protection of other customers and system security.

10.2. If that documentation is insufficient, the Customer may request an audit by itself or an independent, non-competitor auditor. Audits are limited to once in any 12-month period unless a competent authority requires more or there is a substantiated breach affecting Customer Personal Data. They require reasonable written notice, must occur during business hours, avoid operational disruption, and may not expose other customers' data, penetration-test production, or require disclosure of secrets.

10.3. The Customer bears its audit costs and WCAGC's reasonable costs for assistance beyond standard documentation, unless the audit identifies material non-compliance by WCAGC.

11. Liability and Final Terms

Liability under this DPA is subject to the Agreement's limitations to the maximum extent permitted by law. Nothing limits liability that cannot legally be limited, including rights under Article 82 GDPR.

This DPA prevails over the Agreement for conflicting terms about Customer Personal Data and is governed by Polish law without prejudice to mandatory GDPR provisions. WCAGC may update security measures and Annex III in accordance with Section 4, provided protection is not materially reduced.


Annex I — Processing Details

ItemDescription
Subject matterCrawling and automated accessibility scanning of Customer-selected sites; storage and presentation of findings, evidence, reports, conformance mappings, and generated statements
DurationService term until return or deletion under Section 9
Nature and purposeAutomated retrieval of public pages, accessibility analysis, storage and display of Customer-requested results
Data categoriesPersonal data incidentally present in public page content or evidence, typically names, job titles, contact details, photographs, and user-generated content; contact details or text the Customer enters into statements
Data subjectsEmployees, representatives, users, content authors, and other individuals mentioned on Customer-selected pages
Special categoriesNot intended. Scanning content predominantly containing Article 9 or Article 10 data requires a separate written agreement
RetentionWhile needed to provide the active Service; deleted on Customer action or under the immediate post-termination workflow in Section 9, subject only to narrow legal-retention exceptions

Annex II — Technical and Organizational Measures

AreaCurrent baseline
Transport securityHTTPS/TLS for public Service traffic
Credential securitySalted password hashes; secrets supplied through managed production secret configuration; no plaintext password storage
AuthenticationShort-lived access credentials, HTTP-only Secure cookies, CSRF protection, revocable sessions and trusted devices
Authorization and isolationRole-based organization access and tenant-scoped data access
Production accessRestricted to authorized personnel on a need-to-know basis
Data minimizationFindings retain capped or relevant evidence; analytics excludes query strings, submitted scan URLs, and scan identifiers
PseudonymizationPublic-scan IP addresses represented in scan storage as keyed HMAC values, not raw IPs
RetentionImmediate outbox payload redaction after delivery; 30-day public-scan and webhook-ledger sweeps; bounded auth-record retention; immediate account/tenant deletion workflow
Crawler safeguardsPublic-site access only through configured crawler behavior, rate limits, and anti-abuse controls
AvailabilityProvider health checks and automated restart; recovery measures depend on the configured infrastructure services
MonitoringSecurity-relevant and error logging without a separately configured indefinite archive
Incident handlingInvestigation, containment, mitigation, and Customer notice without undue delay under Section 7

Annex III — Authorized Sub-processors

Sub-processorServiceProduction processing location / transfer basis
Fly.io, Inc.Application and worker compute, PostgreSQL and RabbitMQ infrastructurePrimary resources in Stockholm, Sweden (arn); US provider access and published Sub-processors subject to an applicable DPF certification and/or SCCs
Upstash, Inc.Managed Redis for short-lived rate limits and application coordinationStockholm, Sweden (arn); SCCs and/or applicable DPF certification for non-EEA access
Tigris Data, Inc.Private object storage for scan evidence and generated imagesGlobally distributed; SCCs and/or applicable DPF certification for non-EEA processing
Pingram (formerly NotificationAPI)Transactional email delivery to Customer UsersConfigured EU endpoint, documented Frankfurt data centre; adequacy and/or SCCs where non-EEA processing applies

Stripe and Google Analytics process WCAGC account/billing or consent-based analytics data for WCAGC's controller purposes and are outside this DPA's Customer Personal Data scope.


Processor: WCAGC, ul. Garbary 100, 61-757 Poznań, Poland — privacy@wcagc.com

Related documents: Terms of Service · Privacy Policy

The English-language version of these documents is the legally binding one.