AccessLedger

Data processing

Data processing addendum

Version 2026-07-31. Operated by Access Ledger. These terms form part of the terms of service and apply automatically whenever we handle personal data on your behalf.

We are not lawyers and this is not legal advice. This document describes what our software actually does and what we undertake to do. It has not been reviewed by a solicitor. If your organisation needs a negotiated or signed agreement, write to [email protected] and we will work through it with you.

1. Who is who

For the personal data in your own account, meaning your name, your email address, your billing details and your support history, we are the controller. That is covered by the privacy policy.

For anything personal that ends up inside a scan of your website, meaning the URLs you ask us to test and the fragments of your public HTML that our findings quote, you are the controller and we are your processor. This addendum covers that relationship. It is Article 28 of the GDPR and UK GDPR, and it is the reason a business buyer asks for a document like this.

2. What we process, and why

Scope of the processing
Subject matter Automated accessibility testing of web pages you control, and a dated record of what was found and fixed.
Duration For as long as your account exists, plus the retention periods set out in the privacy policy.
Nature and purpose Fetching pages you have proved you control, running automated WCAG checks against them, storing the findings, and rendering reports.
Types of personal data Whatever your own public pages contain. We do not seek personal data, but an HTML snippet quoted in a finding can incidentally contain a name, an address or an email if your page shows one.
Categories of data subject Visitors to and users of your website, as reflected in your public pages.
Special category data Not sought and not expected. Do not point this service at pages showing health, biometric or other special category data.

3. Our undertakings as processor

  • We process on your documented instructions. In practice your instructions are the sites you add, the schedule you set and the scans you trigger.
  • We do not use anything scanned for our own purposes. We do not sell it, we do not train anything on it, and we do not use it to market to your visitors.
  • Everyone with access is bound to confidentiality. Today that is a single owner-operator, which is stated plainly rather than dressed up as a team.
  • We take the security measures described in section 6.
  • We use only the sub-processors named in section 4, and we will tell you before adding another.
  • We help you answer requests from your own data subjects, so far as the data sits in our system.
  • We help you with your obligations under Articles 32 to 36, including breach notification and impact assessments, on request.
  • At the end of the contract we delete your data, or return it first if you ask. The JSON export at /privacy/export is the return mechanism and it already works.
  • We make available the information needed to demonstrate compliance with Article 28. See section 8 on audits.

4. Sub-processors

These are the only third parties that touch data in this system today.

Current sub-processors
Company Function What it receives Location
Stripe, Inc. Payments and subscription billing Your email address, billing details and card data, which you enter on Stripe pages. Card numbers never reach our servers. United States
Mailgun Technologies, Inc. Transactional and marketing email delivery Your email address and the contents of the messages we send you. United States (the US API region is the one configured)
Cloudflare, Inc. DNS, CDN and TLS at the edge Your IP address, the pages you request, and connection metadata, as any network in front of a website does. Global edge network, operator headquartered in the United States
Google LLC (Google Analytics 4) Website analytics, opt-in only Only if you opt in: your IP address, the pages you view here, and a randomly generated identifier stored in a cookie. If you decline or have not answered, Google receives nothing at all and no request is made to Google. United States, and Google infrastructure worldwide
InterServer, Inc. Virtual private server hosting the application and its database Everything in this inventory, because the database sits on their hardware. United States

One clarification on that list. Google Analytics measures page views on this website. Where it is running it receives the address and title of the page being viewed, a random identifier and your IP address as Google receives it, which on a page inside an account means the URL of that page. It does not receive scan results, issue detail or any other account content, because none of that is passed to it. It is opt-in in the EU, EEA, UK and Switzerland, off entirely for anyone who declines, and the product works identically either way. Stripe, Mailgun, Cloudflare and InterServer are the sub-processors that carry the processing we do on your behalf.

We will give you notice by email before adding or replacing a sub-processor, and you may object. If you object and we cannot resolve it, you may cancel without penalty for the remainder of the term you have paid for.

5. International transfers

Our servers are in the United States. The application, the database and the generated reports all sit on a virtual private server hosted by InterServer in the United States. If you or your data subjects are in the EU, the EEA, the UK or Switzerland, your data crosses a border the moment it reaches us. There is no EU-hosted option today and we are not going to imply that there is.

That transfer needs a lawful basis under Chapter V of the GDPR. Standard Contractual Clauses, with the UK International Data Transfer Addendum where UK data is involved, are the mechanism we offer. If you need them executed, ask and we will sign them.

Two limitations we would rather you heard from us. First, we have not appointed a representative in the EU or the UK under Article 27. A US business offering services to people in those territories is generally expected to have one unless the processing is occasional and low risk. Second, no transfer impact assessment has been carried out. Both are on the list, and a business customer asking is what moves them up it. If either matters to your own compliance position, tell us before you buy rather than after.

6. Security

What is actually implemented, rather than a list of things that sound reassuring:

  • Traffic is encrypted in transit. TLS terminates at Cloudflare and again at our own server, which accepts connections only from Cloudflare.
  • Passwords are stored as scrypt hashes with a per-user salt. We never see or store a plaintext password.
  • Session tokens are stored as SHA-256 digests, so a database leak does not hand over live sessions. Signing out takes effect server side immediately.
  • IP addresses are never stored. Only a one-way hash is kept, and only to rate limit abuse.
  • Customer sessions and administrator sessions live in separate tables, so a bug in customer sign-in has no path to producing an administrator.
  • A Content-Security-Policy of script-src 'self' means the browser refuses third-party script outright, so an escaping mistake in a quoted HTML snippet cannot become script execution. It is widened per request only for a visitor who has consented to analytics, and only to Google's analytics hosts.
  • State-changing administrator actions require a CSRF token and are written to an append-only audit log.
  • The scanner refuses private network addresses, so it cannot be turned into a probe against internal systems.
  • Card details never reach our servers. They are entered on Stripe pages.

What we do not claim. The database is not separately encrypted at rest beyond whatever the hosting provider applies to its own storage. There is no SOC 2 report, no ISO 27001 certificate and no penetration test. We have no formally scheduled automated backup rotation, which means an erasure reaches everything live but a manual snapshot taken during a deployment could still contain a record until it is deleted. If your procurement process requires any of those, we are not the right vendor yet and we would rather say so now.

7. Personal data breaches

If we become aware of a breach affecting data we process for you, we will tell you without undue delay and in any case in time for you to meet your own 72 hour obligation under Article 33. We will tell you what we know, what we do not yet know, and what we are doing about it, and we will keep telling you as it develops.

8. Audits

We will answer reasonable written questions about our processing and provide the information needed to demonstrate compliance with Article 28. Given that this is a one person operation running on a single server, we do not offer on-site audits, and any audit right is limited to once in a twelve month period unless a regulator or a breach requires otherwise.

9. Data subject requests

If one of your data subjects contacts us directly, we will not answer them on your behalf. We will tell them to contact you and we will tell you it happened. Where a request concerns data inside your account, our export and erasure tooling is what we use to help you answer it. Your own account data is covered separately at your data page.

10. Deletion and return

Close your account and ask us to delete, and we erase within 30 days. Erasure is executed by a recorded, reviewable process that writes down what was destroyed and what was kept. Payment records are kept because tax and accounting law requires them, which Article 17(3)(b) permits, and that exception is described in full in the privacy policy.

11. Liability

Nothing in this addendum changes the liability cap in the terms of service. Where the law does not permit a cap, the law wins.

Contact

Privacy and data protection questions: [email protected].