Zum Inhalt springen

Legal

Data Processing Addendum

Effective date: 17 August 2026. Forms part of our Terms of Service and applies automatically wherever we process personal data on your behalf as described below. Available in English only at this time — see our Privacy Policy for how we handle your own account data.

1. Roles

This Addendum applies where Ignion Apps (“Processor”, “we”) processes personal data on behalf of a customer (“Controller”, “you”) in the course of providing the Cluesia accessibility scanning service (the “Service”). You are the controller for personal data appearing in the content of websites you submit for scanning; we process it solely as your processor, on your documented instructions (submitting a URL for scanning constitutes such an instruction).

2. Subject matter and duration

Processing is carried out for the duration of your subscription or purchase, and continues only as needed to retain the deliverables (reports, findings) you purchased — see Section 6 for retention.

3. Nature and purpose of processing

Automated accessibility scanning of the URLs you designate: crawling public (non-authenticated) pages, rendering them in a sandboxed headless browser, capturing DOM content and a screenshot per page, running automated WCAG 2.1 AA / EN 301 549 checks, and — where you’ve purchased a report — generating AI-assisted remediation guidance and image alt-text suggestions from that captured content.

4. Categories of data subjects and data

Data subjects: primarily visitors to, or individuals named/pictured on, the websites you submit — captured incidentally, not targeted. Secondarily, your own authorised users of the Service (see our Privacy Policy for that relationship, where we are controller).

Data types: whatever personal data appears in the rendered HTML or visible on-screen at the URLs you submit — names, contact details, or images, at your discretion since you choose which URLs to submit. We do not request or process special categories of data (GDPR Art. 9) deliberately, and ask that you do not submit pages designed to surface such data for scanning.

5. Our obligations as processor

  • Process personal data only on your documented instructions, unless required otherwise by law.
  • Ensure personnel with access are bound by confidentiality obligations.
  • Implement appropriate technical and organisational security measures (GDPR Art. 32) — see Section 9 of our Privacy Policy for specifics (sandboxed scanning, SSRF guards, encryption in transit, restrictive CSP).
  • Engage sub-processors only as listed in Section 6, with notice before adding a new one.
  • Assist you, insofar as reasonably possible, in responding to data subject requests and in your own Art. 32–36 obligations (security, breach notification, DPIAs) concerning this processing.
  • Notify you without undue delay after becoming aware of a personal data breach affecting your data.
  • At the end of the relationship, delete or return personal data per Section 6’s retention terms.
  • Make available information reasonably necessary to demonstrate compliance with this Addendum.

6. Retention and deletion

Raw screenshots captured during scanning are deleted automatically after 90 days. Findings and generated reports are retained as the purchased deliverable and are not automatically deleted; on written request we will delete a specific site’s data ahead of that schedule, subject to any retention we’re independently required to keep for accounting/tax purposes (e.g. transaction records via Dodo Payments).

7. Sub-processors

You authorise the use of the following sub-processors, each engaged under terms providing an equivalent level of data protection:

  • Supabase — database and authentication, hosted in the EU (Frankfurt).
  • Cloudflare (R2) — report and screenshot storage, EU-jurisdiction bucket.
  • Dodo Payments Inc. — payment processing and billing (Merchant of Record).
  • Google (Gemini API) — AI-assisted remediation and alt-text generation.
  • Resend — transactional email delivery.

We’ll give notice (e.g. by email or an update to this page with a changed effective date) before adding a new sub-processor, and you may object on reasonable data-protection grounds.

8. International transfers

Where a sub-processor processes data outside the EEA, the transfer is made under Standard Contractual Clauses or another valid transfer mechanism under GDPR Chapter V.

9. Audit rights

On reasonable prior notice, and no more than once per year absent cause, we’ll provide information reasonably necessary to demonstrate compliance with this Addendum, including responding to a written questionnaire in lieu of an on-site audit.

10. Governing law

This Addendum is governed by the same law and jurisdiction as our Terms of Service: the laws of India, with the courts of Gujarat, India having exclusive jurisdiction.

11. Requesting an executed copy

If your organisation requires a separately signed copy of this Addendum (e.g. for your own vendor compliance records), contact [email protected].

Data Processing Addendum — Cluesia