Data Processing Agreement
The Article 28 GDPR terms under which CheckFox processes personal data on behalf of its customers.
This Data Processing Agreement (the "DPA") forms part of the Terms & Conditions between Crofte Studio S.à r.l.-S, Luxembourg (RCS B310079) ("the Processor", "I", "me") and the customer using CheckFox ("the Controller", "you"). It is drafted on the model of Commission Implementing Decision (EU) 2021/915 laying down standard contractual clauses between controllers and processors.
No signature is required, but one is available
Accepting the Terms & Conditions concludes this DPA in writing within the meaning of Article 28(9), and it applies automatically. If your procurement process requires a signed copy, ask and I will counter-sign this document unchanged. I do not negotiate variations: a single, identical agreement for every customer is what lets me keep the commitments in it.
1. Definitions and roles
"Personal data", "processing", "controller", "processor", "sub-processor", "data subject" and "personal data breach" have the meaning given to them in Article 4 of Regulation (EU) 2016/679 ("GDPR").
"Customer Personal Data" means personal data contained in the content you place in CheckFox: audits, samples, criteria results, comments, notes, screenshots, uploaded files, accessibility statements, remediation plans and user journeys.
- You are the controller
- of the Customer Personal Data. You decide what goes into an audit and why.
- I am the processor
- of that data, acting only on your instructions.
- I am a separate controller
- of your account, billing and support data, which is governed by the Privacy Policy, not by this DPA.
2. Subject matter, duration, nature and purpose
The subject matter of the processing is the provision of the CheckFox accessibility audit service. Its nature, purpose, the types of personal data and the categories of data subjects are described in Annex 1.
The processing lasts for as long as your subscription is in force, plus the return and deletion period set out in section 11.
3. Processing on documented instructions
I process Customer Personal Data only on your documented instructions, including as regards transfers to a third country, unless I am required to do otherwise by Union or Member State law. In that case I will inform you of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
Your instructions are: the Terms & Conditions, this DPA, and the actions you take through the interface and the API, including connecting an optional integration.
I will inform you if, in my opinion, an instruction infringes the GDPR or another data protection provision, and may suspend that instruction until it is confirmed or amended.
I do not use Customer Personal Data for my own purposes, do not sell it, and do not use it to train artificial intelligence models.
4. Confidentiality
Access to Customer Personal Data is restricted to the persons who need it to provide or maintain the service. Those persons are bound by a duty of confidentiality that survives the end of their engagement, and are granted the least privilege needed for their task.
5. Security of processing
I implement the technical and organisational measures set out in Annex 2 to ensure a level of security appropriate to the risk, in accordance with Article 32.
Those measures may be updated to keep pace with technical developments, provided the level of protection is not reduced. The current version is always the one published on this page.
6. Sub-processors
You give a general written authorisation for the engagement of sub-processors, in accordance with Article 28(2). The sub-processors engaged at the date of this document are listed in Annex 3 and kept current at checkfox.eu/subprocessors.
Before a new sub-processor starts processing Customer Personal Data, I will publish it on that page and notify subscribed customers at least 30 days in advance.
You may object to a new sub-processor on reasonable, data-protection grounds within that period. I will then try to offer you a change that removes the objection. If none can be found, you may terminate the affected subscription and receive a pro-rata refund of the unused period.
I impose on each sub-processor the same data protection obligations as those set out in this DPA, and I remain fully liable to you for its performance.
7. International transfers
Customer Personal Data is stored in the European Union. Where a sub-processor is established outside the EEA, the transfer relies on the standard contractual clauses adopted by the European Commission under Implementing Decision (EU) 2021/914, supplemented where applicable by the provider's certification under the EU-US Data Privacy Framework. The safeguard applying to each provider is stated in Annex 3.
8. Assistance with data subject rights
Taking into account the nature of the processing, I assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests from data subjects exercising their rights under Chapter III of the GDPR.
In practice, the interface already lets you search, correct, export and delete the content of an audit yourself, which covers most requests without my involvement. If a data subject contacts me directly about content you control, I will not answer on your behalf: I will tell them to contact you and will inform you promptly.
9. Assistance with security, notification and impact assessments
I assist you in ensuring compliance with Articles 32 to 36, taking into account the nature of the processing and the information available to me. That includes assistance with your data protection impact assessment and, where required, with prior consultation of the supervisory authority.
10. Personal data breach
I notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data.
The notification will describe, to the extent known at the time:
- the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned;
- the likely consequences of the breach;
- the measures taken or proposed to address it and to mitigate its effects;
- a point of contact for further information.
Where all the facts are not yet available, I send a first notification within the deadline and complete it as the investigation progresses, rather than delaying it until the picture is complete.
Who tells the data subjects
Notifying the supervisory authority under Article 33(1) and the data subjects under Article 34 is your decision as controller, not mine. My role is to give you, in time, what you need to make it. I will not contact your end users directly about a breach unless you ask me to, or unless the law requires it.
I keep an internal register of personal data breaches in accordance with Article 33(5), including those that are not notifiable.
11. Return and deletion
At the end of the provision of services, you choose whether Customer Personal Data is returned to you or deleted. Export is available from the interface at any time, and remains available for 30 days after termination.
After that period, the data is deleted from the live systems. It disappears from backups within 35 days at the latest, since backups are rotated rather than edited.
I retain data beyond that point only where Union or Member State law requires it, and in that case only for what the law requires and for as long as it requires it.
12. Information and audits
I make available to you the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or by an auditor you mandate.
So that this stays workable for a small operator, audits follow this order:
- First, the published documentation: this DPA, Annex 2 and the sub-processor register, plus a completed security questionnaire on request.
- If that is not sufficient, a remote review or a call, at no cost to you.
- If that is still not sufficient, an on-site inspection: once per calendar year, on 30 days' written notice, during business hours, under a confidentiality agreement, at your expense, and without disrupting the service or exposing another customer's data.
A supervisory authority exercising its own powers is not subject to these limits.
13. Liability, term and governing law
Liability under this DPA is governed by Article 82 of the GDPR and by the limitation of liability in the Terms & Conditions, except where the GDPR does not permit such a limitation.
This DPA takes effect when you accept the Terms & Conditions and remains in force for as long as I process Customer Personal Data on your behalf. Where it conflicts with the Terms & Conditions on a data protection matter, this DPA prevails.
It is governed by the law of Luxembourg, without prejudice to the rights data subjects derive from the GDPR.
Annex 1. Description of the processing
| Item | Description |
|---|---|
| Subject matter | Provision of the CheckFox accessibility audit platform |
| Duration | The term of the subscription, plus the return and deletion period in section 11 |
| Nature | Storage, structuring, retrieval, display, export and deletion of content you create |
| Purpose | Allowing you to carry out, document, share and publish accessibility audits |
| Frequency | Continuous, for as long as the service is used |
| Categories of data subjects | Your staff who use the tool, and any identifiable individual appearing in audit content (for example in a screenshot or a comment) |
| Types of personal data | Identification data of your users (name, email, role); free-text content you enter; images and files you upload; any personal data those may incidentally contain |
| Special categories | None requested and none required. If you place such data in an audit, you do so as controller and on your own responsibility |
Keep audits free of personal data where you can
An accessibility audit rarely needs to identify anyone. Redacting a screenshot before uploading it, and writing about the interface rather than about the person using it, reduces your exposure and mine at no cost to the audit's quality.
Annex 2. Technical and organisational measures
The measures below are in place as at the effective date of this document.
Access control and authentication
- Passwords stored only as salted hashes; the clear text is never persisted.
- Optional multi-factor authentication, enforced at the database level once enabled, so that a session without the second factor cannot read protected rows even if it bypasses the interface.
- Row-level security on every table holding user data: authorisation is enforced by the database, not only by the application.
- Role-based permissions inside a workspace, least privilege by default.
- Administrative access restricted to the operator, over authenticated channels only.
- Privileged service credentials held exclusively in server-side code, never shipped to the browser.
Encryption and data segregation
- TLS for all traffic between the browser, the API and the database.
- Encryption at rest for the database and for file storage.
- Logical segregation of customers by workspace, enforced by database policies.
- Files served through expiring signed URLs rather than from public buckets.
- Uploaded vector images sanitised on upload to remove active content.
Availability and resilience
- Automated daily backups with point-in-time recovery, held by the database provider inside the European Union.
- Backup rotation such that deleted data disappears within 35 days.
- Managed, patched infrastructure for the database, the storage and the application backend.
- Content delivery and origin protection in front of the public site.
Governance, logging and development
- Activity logging inside a workspace, so an owner can see who changed what.
- Server and security logs retained for 12 months.
- Dependencies monitored for known vulnerabilities and updated when advisories are published.
- Data protection considered when features are designed, in line with Article 25.
- Register of personal data breaches maintained under Article 33(5).
- Data processing agreements concluded with every sub-processor listed in Annex 3.
Certifications
Stated plainly
CheckFox holds no ISO 27001 or SOC 2 certification. It is operated by a single person, and a certification of that kind would not currently be honest to claim. The measures above are what is actually in place, and the infrastructure providers underneath (listed in Annex 3) do hold such certifications for the layers they operate.
Annex 3. Authorised sub-processors
The current list, with each provider's legal entity, purpose, hosting location and transfer safeguard, is published and kept up to date at checkfox.eu/subprocessors. That page forms part of this Annex, and changes to it follow the notice procedure in section 6.
Printed from checkfox.eu. Check the site for the current version.