Data Processing Agreement
Last updated: 29 August 2026
This agreement applies when you use adasafe to scan pages behind a login. On public pages we rarely touch anyone's personal data. The moment a scan signs in as one of your users, it can see theirs — so for that processing you are the controller, we are the processor, and these are the terms we work under. It supplements our Terms of Service; where the two differ on processing, this document governs.
1. Subject matter, duration and purpose
We process personal data only to run the accessibility audits you ask for and to return the results. Processing lasts as long as your account does, plus the retention periods in section 8. Scan results are kept for 12 months; a saved login is kept for 12 months from the day you save it, and is deleted sooner if a scan finds it no longer works or you delete it yourself.
2. Processing only on your instructions
We process personal data only on your documented instructions. Starting a scan is that instruction; choosing to use a saved login extends it to the pages that login can reach. We do not use anything a scan sees to train models, to build profiles, or for any purpose of our own. If we ever believed an instruction breached data protection law, we would tell you rather than act on it.
3. Confidentiality
Access is limited to the people who need it to operate the service, under confidentiality obligations that survive the end of their engagement. adasafe is operated by a small team; access to production data is restricted accordingly.
4. Security of processing (Art. 32)
Data is encrypted in transit and at rest. A saved login is encrypted separately with AES-256-GCM under a key held in the runtime environment and never in the database, so a copy of the database on its own cannot read it. We never store the raw HTML of a scanned page — only violation metadata such as the rule, the severity, and a CSS selector. Every table enforces row-level security so one customer's data is not reachable from another's session.
5. Sub-processors
We use the sub-processors listed in our Privacy Policy, and authenticated scanning does not add a new one. What changes is what reaches them: results from a page behind your login can contain your end users' personal data, and those results flow to our database and email provider, and to any webhook or Slack channel you configure. If you ask us to generate fixes, violation metadata — and, for image violations, the image itself — is sent to Anthropic. Choosing scan-only sends nothing to Anthropic at all. We will give you notice of any new sub-processor with a chance to object.
6. Assisting with data subject rights
We help you meet requests from your end users. Because we hold results rather than a copy of your systems, the usual answer is deletion: you can delete any scan, and deleting your account removes your data on the schedule in section 8. Ask us and we will help locate and remove anything a scan captured about a specific person.
7. Personal data breaches
If we become aware of a breach affecting your data we will notify you without undue delay, with what we know and what we are doing about it, so you can meet your own 72-hour obligation under Art. 33.
8. Return and deletion
You can delete a scan, a saved login, or your whole account at any time from your account page. On account deletion we remove your personal data and keep only what law requires — a hashed record that a deletion happened, never the identifier itself. Scan results are deleted automatically after 12 months, and saved logins after 12 months or sooner if they stop working.
9. Audits and information
We will provide the information reasonably needed to demonstrate that we meet these obligations, and will cooperate with an audit you or your auditor carry out, on reasonable notice and without disrupting the service.
10. International transfers
Data may be processed in the United States and the European Union. For transfers out of the EU/UK we rely on the Standard Contractual Clauses with the relevant sub-processor.
Contacting us
For anything in this agreement, including a signed copy or a data subject request, write to support@adasafe.ai. We answer processor requests ahead of general support.