Data Processing Agreement
Version 1.6 — Effective date: August 8, 2026 — Last updated: August 8, 2026
This Data Processing Agreement (the "DPA") forms part of the Terms of Service between WCAGC, operated by Pavel Charkasau, ul. Garbary 100, 61-757 Poznań, Poland, NIP 7831856003 (the "Processor"), and the Customer (the "Controller"). It applies only when WCAGC processes Customer Personal Data on the Customer's behalf and is intended to satisfy Article 28 GDPR.
WCAGC remains an independent controller for account-holder registration, authentication, billing, security, transactional communications, and its own legal obligations, as described in the Privacy Policy.
1. Scope and Definitions
"Customer Personal Data" means personal data processed by WCAGC on behalf of the Customer as described in Annex I. Other GDPR terms have the meanings in Article 4 GDPR.
This DPA applies for the term of the Service and until Customer Personal Data has been returned or deleted under Section 9.
2. Processing and Customer Instructions
2.1. WCAGC retrieves and analyzes Customer-selected web pages, stores the resulting accessibility findings and evidence, and presents results and derived reports to the Customer. Page content may incidentally contain personal data already published on those pages.
2.2. WCAGC processes Customer Personal Data only on documented instructions, including the Agreement, this DPA, and the Customer's use of Service features, unless Union or Member State law requires processing. Where legally permitted, WCAGC will inform the Customer before processing required by law.
2.3. Additional instructions require written agreement and may be subject to reasonable fees where they fall outside the Service's standard functionality.
2.4. WCAGC will inform the Customer if, in its opinion, an instruction infringes applicable data-protection law.
2.5. The Customer is responsible for its instructions, legal basis, transparency obligations, authority to scan each submitted site, and authority to inspect each page on which it runs the Extension. The Customer must not instruct the crawler to reach authenticated or non-public areas of a site, and must not use the Service to collect special-category or criminal-offence data, without a separate written agreement. Where the Customer runs the Extension on a page it is authorized to inspect — including localhost, a staging environment, or a page behind the Customer's own sign-in — the Customer remains the controller of the bounded markup fragments it chooses to save and is responsible for having a lawful basis to transmit any personal data they contain.
2.6. Where the Customer enables screenshot analysis, each visual check it starts is a separate documented instruction to transmit a rendered image of the selected page. Because an image cannot be minimized in the way a markup fragment can, the Customer is responsible for choosing pages accordingly, and must not run a visual check on a page whose displayed content is predominantly special-category or criminal-offence data.
3. Processor Obligations
WCAGC will:
- ensure persons authorized to process Customer Personal Data are bound by confidentiality;
- implement measures appropriate to risk as described in Annex II;
- engage Sub-processors only under Section 4;
- taking account of the nature of processing, assist the Customer with data-subject requests through available Service functionality and reasonable additional assistance;
- assist with Articles 32–36 GDPR taking account of the nature of processing and information available to WCAGC;
- delete or return Customer Personal Data under Section 9; and
- make available information reasonably necessary to demonstrate Article 28 compliance and support audits under Section 10.
4. Sub-processors
4.1. The Customer grants general written authorization for the Sub-processors in Annex III.
4.2. WCAGC will inform account owners of an intended addition or replacement with reasonable advance notice where practicable and allow objections on reasonable data-protection grounds. If an urgent security, availability, or legal requirement prevents advance notice, WCAGC may make the change first and notify the Customer as soon as reasonably practicable.
4.3. If a justified objection cannot be resolved, the Customer may stop using and terminate the affected Service before the new Sub-processor begins processing, where advance notice was possible.
4.4. WCAGC will impose Article 28-equivalent data-protection obligations on Sub-processors and remains responsible for their performance to the extent required by GDPR.
5. International Transfers
Primary application, worker, PostgreSQL, Redis, and RabbitMQ resources are configured in Stockholm, Sweden. Tigris object storage is globally distributed and therefore Customer Personal Data stored there is not represented as EU-only. Evidence images — including a screenshot captured for screenshot analysis, for the up-to-24-hour period before it is deleted — are held in that object storage and share this position; it is unchanged by Annex III's EU-only statement about the model Sub-processor, which concerns inference rather than storage.
Where Chapter V GDPR applies, WCAGC will use an applicable adequacy decision, the EU–US Data Privacy Framework for a certified recipient, or European Commission Standard Contractual Clauses with supplementary measures where appropriate.
6. Data-Subject Requests
If WCAGC receives a request concerning Customer Personal Data, it will forward it to the Customer where legally permitted and will not respond on the merits except on documented instruction or where required by law. The Customer remains responsible for the response. Built-in deletion and re-scan features are the primary assistance mechanism; additional bespoke work may be charged at reasonable cost where GDPR permits.
7. Personal Data Breach
WCAGC will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The initial notice may be based on information then available and supplemented in phases without undue further delay. Where available, WCAGC will describe the nature of the breach, affected categories and approximate volumes, likely consequences, a contact point, and mitigation measures.
The Customer is responsible for deciding whether Articles 33 or 34 require notifications by the Customer. Nothing in this Section replaces WCAGC's own obligations where it acts as controller.
8. Confidentiality and Security
WCAGC will process Customer Personal Data only through personnel and providers who need access for the Service and are subject to confidentiality. Measures may evolve with risk and technology, provided the overall level of protection is not materially reduced. Annex II describes the current baseline and is not a guarantee that every possible security event can be prevented.
9. Return and Deletion
9.1. During the term, the Customer may use available Service features to delete sites and associated results.
9.2. On Account or organization deletion, access is disabled immediately and the deletion workflow begins without a recovery grace period. Operational Customer Personal Data is deleted or irreversibly anonymized as the workflow completes.
9.3. If the Customer requires a return of Customer Personal Data, it must request it before initiating deletion. After deletion begins, WCAGC is not required to reconstruct data that has already been deleted. Unless return is requested before deletion, the Customer instructs WCAGC to delete the data.
9.4. A narrowly defined record may be retained only where Union or Member State law requires it or where necessary for the establishment, exercise, or defence of legal claims; it will be isolated from ordinary product use and deleted when that purpose ends.
9.5. Provider-level disaster-recovery copies that cannot be selectively edited are not used for ordinary processing and are overwritten under the provider's rotation. On request, WCAGC will provide reasonable written confirmation of completion of the active-system deletion workflow.
10. Compliance Information and Audits
10.1. WCAGC will first provide documentation reasonably necessary to demonstrate compliance, subject to confidentiality and protection of other customers and system security.
10.2. If that documentation is insufficient, the Customer may request an audit by itself or an independent, non-competitor auditor. Audits are limited to once in any 12-month period unless a competent authority requires more or there is a substantiated breach affecting Customer Personal Data. They require reasonable written notice, must occur during business hours, avoid operational disruption, and may not expose other customers' data, penetration-test production, or require disclosure of secrets.
10.3. The Customer bears its audit costs and WCAGC's reasonable costs for assistance beyond standard documentation, unless the audit identifies material non-compliance by WCAGC.
11. Liability and Final Terms
Liability under this DPA is subject to the Agreement's limitations to the maximum extent permitted by law. Nothing limits liability that cannot legally be limited, including rights under Article 82 GDPR.
This DPA prevails over the Agreement for conflicting terms about Customer Personal Data and is governed by Polish law without prejudice to mandatory GDPR provisions. WCAGC may update security measures and Annex III in accordance with Section 4, provided protection is not materially reduced.
Annex I — Processing Details
| Item | Description |
|---|---|
| Subject matter | Crawling and automated accessibility scanning of Customer-selected sites; storage and presentation of findings, evidence, reports, conformance mappings, and generated statements |
| Duration | Service term until return or deletion under Section 9 |
| Nature and purpose | Automated retrieval of public pages, accessibility analysis, storage and display of Customer-requested results, storage of accessibility findings and bounded page fragments captured by the Customer in its own browser and submitted by explicit user action, and, where the Customer enables it, transmission of bounded page fragments to the model Sub-processor listed in Annex III for the generation of remediation guidance. Where the Customer separately enables screenshot analysis, transmission of one rendered screenshot of the visible area of one Customer-selected page, together with the position and size of elements that already failed an automated check, to the same Sub-processor for the generation of visual observations |
| Data categories | Personal data incidentally present in page content or evidence retrieved by the crawler or captured by the Customer with the Extension — typically names, job titles, contact details, photographs, and user-generated content, including content displayed only to a signed-in user of a page the Customer is authorized to inspect; contact details or text the Customer enters into statements. Where screenshot analysis is separately enabled, a rendered image of a Customer-selected page, which may contain any personal data that page displays and to which the text-masking measures described in Annex II cannot be applied |
| Data subjects | Employees, representatives, users, individuals the Customer invites to the Client Portal, content authors, users of the Customer's own applications whose data is displayed on a page checked with the Extension, and other individuals mentioned on pages selected by the Customer |
| Special categories | Not intended. Scanning content predominantly containing Article 9 or Article 10 data requires a separate written agreement |
| Retention | While needed to provide the active Service; deleted on Customer action or under the immediate post-termination workflow in Section 9, subject only to narrow legal-retention exceptions. A screenshot captured for screenshot analysis is deleted within 24 hours of capture and is not served after that point, independently of any other retention period |
Annex II — Technical and Organizational Measures
| Area | Current baseline |
|---|---|
| Transport security | HTTPS/TLS for public Service traffic |
| Credential security | Salted password hashes; secrets supplied through managed production secret configuration; no plaintext password storage |
| Authentication | Short-lived access credentials, HTTP-only Secure cookies, CSRF protection, revocable sessions and trusted devices |
| Authorization and isolation | Role-based organization access and tenant-scoped data access |
| Production access | Restricted to authorized personnel on a need-to-know basis |
| Data minimization | Findings retain capped or relevant evidence; analytics excludes query strings, submitted scan URLs, and scan identifiers |
| AI feature controls (guidance, observations, selector suggestions) | Disabled by default and enabled only by a Customer administrator; only bounded page fragments, selectors, rule metadata, and semantic page digests are transmitted; credentials, authentication envelopes, form input values, cookies, screenshots, and complete page source are excluded from these features; page digests are erased after processing; prompts and generated text are excluded from application logs and analytics |
| Screenshot analysis controls | A separate administrator consent, distinct from and additional to the AI feature consent above and off by default; disabling AI processing also disables screenshot analysis in the same operation, and re-enabling AI processing does not re-enable it. Every capture requires all of: the plan grant, the AI consent, the screenshot consent, and an available monthly allowance — no one of these substitutes for another. Only on a domain the Customer has verified, only on explicit user action, never in the background or on a schedule, never as part of an ordinary scan, and rate-limited. One capture is the visible area of the page, not its full length; element geometry is transmitted as coordinates only and carries no text. The image is deleted within 24 hours of capture and is refused at the 24-hour mark whether or not the scheduled deletion pass has run. Results carry a fixed low confidence and a manual-confirmation label, are stored apart from findings, and do not enter issue counts, trends, comparisons, CI results, or evidence packs |
| Extension data controls | Runs only on explicit user action; results remain in the browser until the user saves them; cookies, request headers, typed form input, local storage, screenshots and full page HTML are never read or transmitted; a transmitted markup fragment is the failing element's own markup, capped at 2,000 characters and stored and rendered as text; repository source hints are optional, are validated as relative paths on both the client and the server so that a developer's local filesystem path is rejected, and can be disabled by the user; extension telemetry is not collected |
| Pseudonymization | Public-scan IP addresses represented in scan storage as keyed HMAC values, not raw IPs |
| Retention | Immediate outbox payload redaction after delivery; 30-day public-scan and webhook-ledger sweeps; bounded auth-record retention; immediate account/tenant deletion workflow |
| Crawler safeguards | Public-site access only through configured crawler behavior, rate limits, and anti-abuse controls |
| Availability | Provider health checks and automated restart; recovery measures depend on the configured infrastructure services |
| Monitoring | Security-relevant and error logging without a separately configured indefinite archive |
| Incident handling | Investigation, containment, mitigation, and Customer notice without undue delay under Section 7 |
Annex III — Authorized Sub-processors
| Sub-processor | Service | Production processing location / transfer basis |
|---|---|---|
| Fly.io, Inc. | Application and worker compute, PostgreSQL and RabbitMQ infrastructure | Primary resources in Stockholm, Sweden (arn); US provider access and published Sub-processors subject to an applicable DPF certification and/or SCCs |
| Upstash, Inc. | Managed Redis for short-lived rate limits and application coordination | Stockholm, Sweden (arn); SCCs and/or applicable DPF certification for non-EEA access |
| Tigris Data, Inc. | Private object storage for scan evidence and generated images | Globally distributed; SCCs and/or applicable DPF certification for non-EEA processing |
| Pingram (formerly NotificationAPI) | Transactional email delivery to Customer Users | Configured EU endpoint, documented Frankfurt data centre; adequacy and/or SCCs where non-EEA processing applies |
| Amazon Web Services EMEA SARL (Amazon Bedrock) | Optional generation of remediation guidance, suggested code, semantic observations, and login-selector suggestions from bounded page fragments selected by the Customer after an organization administrator enables the feature; and, only where an administrator has given the separate screenshot-analysis consent, generation of visual observations from one rendered screenshot of a Customer-selected page | A geography-restricted (eu.*) inference profile confines processing within AWS European regions (request entry point eu-north-1, Stockholm; the profile may route inference to other AWS EU regions, and to no region outside the EU). Request content is minimized before transmission: email addresses, telephone numbers, payment card numbers, IBANs and other long numeric identifiers are masked, and passwords, authentication envelopes, cookies, form input values, and complete page source are never sent. Screenshots are not sent unless an organization administrator has separately enabled screenshot analysis — a consent distinct from and additional to enabling AI processing, off by default, and available only on the Professional and Agency plans. Where it is enabled, one rendered screenshot of the visible area of a Customer-selected verified page is transmitted per Customer-initiated visual check; masking cannot be applied to an image, so that image may contain any personal data the page displays, and it is deleted within 24 hours of capture. Account-level data retention is set to none in every reachable AWS European region, so request and response content is not retained after the response is returned, is not shared with third-party model providers, and is not used to train models; Amazon's abuse-detection processes may still examine flagged content. Model invocation logging is not enabled. The contracting entity is established in the EU; applicable adequacy, DPF certification, and/or SCCs govern any non-EEA access |
Stripe and Google Analytics process WCAGC account/billing or consent-based analytics data for WCAGC's controller purposes and are outside this DPA's Customer Personal Data scope.
An issue tracker the Customer connects (GitHub or Jira) is not a Sub-processor. It is a destination the Customer nominates and controls, to which WCAGC transmits Customer Personal Data only on the Customer's explicit per-finding instruction, using credentials the Customer supplied. The Customer is responsible for that destination and for its own agreement with the tracker provider.
Processor: WCAGC, ul. Garbary 100, 61-757 Poznań, Poland — privacy@wcagc.com
Related documents: Terms of Service · Privacy Policy
The English-language version of these documents is the legally binding one.