Data Processing Agreement
Last Updated: April 24, 2026
1. Introduction
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between FixMyWeb (“Processor”, “we”, “us”) and you (“Controller”, “Customer”) and governs the processing of personal data by FixMyWeb on behalf of the Customer in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
2. Definitions
- Personal Data — Any information relating to an identified or identifiable natural person (Article 4(1) GDPR).
- Processing — Any operation performed on personal data, including collection, storage, retrieval, use, disclosure, or deletion.
- Sub-processor — A third party engaged by FixMyWeb to process personal data on behalf of the Customer.
3. Scope and Purpose of Processing
FixMyWeb processes personal data solely to provide automated accessibility scanning (WCAG 2.2 / EAA) and related services as described in the Terms of Service. Types of personal data processed may include:
- URLs and websites submitted for accessibility analysis (which may contain personal data)
- Customer account information (email address)
- API usage metadata (timestamps, scan results, request IDs)
- IP address (for rate limiting, hashed and short-term)
Scan results are stored to allow the Customer to access their own accessibility reports. FixMyWeb does not retain the full HTML content of scanned pages after analysis is complete.
4. Obligations of the Processor
- Process personal data only on documented instructions from the Controller, unless required by EU or Member State law.
- Ensure that persons authorized to process personal data have committed themselves to confidentiality.
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk (see Section 6).
- Assist the Controller in responding to data subject requests exercising their rights under GDPR Articles 15–22.
- Delete or return all personal data to the Controller after the end of the service provision, at the Controller’s choice.
- Make available all information necessary to demonstrate compliance and allow for audits.
5. Sub-processors
FixMyWeb uses the following sub-processors. The Customer authorizes the use of these sub-processors:
- Vercel Inc. — Application hosting and edge delivery (United States, EU data region available).
- Stripe Inc. — Payment processing and subscription management (United States, SCCs in place).
- Upstash Inc. — Redis database for rate limiting, session management, and scan history storage (EU, Frankfurt).
- Sentry (Functional Software Inc.) — Error monitoring and observability (EU region, no PII sent by policy).
We will notify the Customer of any intended changes to sub-processors, giving the Customer the opportunity to object within 30 days.
6. Security Measures
- Encryption in transit — All data is transmitted over TLS 1.3.
- Encryption at rest — Stored data (account information, API keys) is encrypted using AES-256.
- Access controls — API keys are hashed with SHA-256. Access to production systems is restricted and logged.
- Rate limiting — All public endpoints are rate-limited by IP to prevent abuse.
- Isolated scanning — Each scan runs in a sandboxed, single-use environment.
- Regular security reviews — Periodic security assessments, dependency scanning, and CodeQL code analysis.
7. Data Breach Notification
In the event of a personal data breach, FixMyWeb will notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach. The notification will include:
- A description of the nature of the breach
- The categories and approximate number of data subjects affected
- The likely consequences of the breach
- The measures taken or proposed to address the breach
8. International Data Transfers
Where personal data is transferred outside the EEA, FixMyWeb ensures that appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, or reliance on adequacy decisions where applicable.
9. Data Subject Rights
FixMyWeb assists the Controller in fulfilling obligations to respond to data subject requests under GDPR Articles 15–22, including the right of access, rectification, erasure, restriction, portability, and objection. Customers and end users may exercise their rights via the data export and data closure endpoints. Closure requests are confirmed via email before any action is taken, providing the required undo window per WCAG 3.3.6.
10. Duration and Termination
This DPA remains in effect for the duration of the Customer’s use of FixMyWeb services. Upon termination, FixMyWeb will delete all personal data processed on behalf of the Controller within 30 days, unless retention is required by applicable law.
11. Contact
For questions about this DPA or to request a signed copy, please contact us at privacy@fixmyweb.dev.