Data processing agreement
Data processing agreement
Our data processing agreement under Article 28 GDPR: roles, security measures, subprocessors and international transfer for the scan processing.
Last updated: 12 September 2026
Version 2026-09-12
This is the version that currently applies.
1. What this is
This data processing agreement (DPA) under Article 28 GDPR governs the personal data that Wexlo, a trading name of Rybier Consulting (KvK 66637694), President Allendelaan 263, 1068 VM Amsterdam, processes on your behalf when scanning the websites you designate. It applies automatically as part of our general terms and conditions for every customer: no signature is required. If you need a signed copy for your own records, email hello@wexlo.eu and we will send you one. Where this DPA and the terms conflict on a point of data protection, this DPA prevails.
2. Roles
For the scan processing described here, you are the controller (or a processor for your own clients; in that case we act as your sub-processor) and we are your processor: you determine which domains we scan and we process what is on those pages solely to produce your reports. For your account, orders and invoices we are an independent controller; that processing is covered in the privacy policy and falls outside this DPA.
3. Subject matter, duration, nature and purpose
Subject matter: automated accessibility scanning of the websites you register, and generating and delivering the associated reports. Duration: the term of your subscription, plus the deletion period in Article 10. Nature: automated collection and analysis of publicly accessible web pages. Purpose: solely delivering the reports and associated features of your subscription, never for our own purposes.
4. What data this involves
Categories of data: the personal data that happens to be visible on the publicly accessible pages of the websites you designate (for example names on a team page). Categories of data subjects: visitors to, and people who appear on, those websites. By design we minimise this radically: from the automated scan we store only structured findings (the rule, the WCAG criterion, the severity and a CSS selector), and never screenshots or HTML of your pages. The realistic residue of personal data from the scan is therefore limited to whatever can appear in a URL or CSS selector.
Where one of our assessors additionally carries out a manual assessment, we do record screenshots and raw measurement output of the pages assessed, including one screenshot per step of the keyboard pass. That is needed to substantiate a finding and to hand over the full set on request. Those screenshots show the page as a visitor sees it without logging in; personal data visible on them therefore also appears on the screenshot. They sit with the same sub-processor as the reports (Cloudflare R2, EU jurisdiction) and are deleted at most 12 months after the measurement date, or sooner at your request. The storage is not publicly accessible: the material is stored encrypted, only travels over an encrypted connection, and can only be opened through a link we create on request, which expires after seven days at most.
5. Your instructions
We process only on your documented instructions. Registering a domain and configuring your subscription are those instructions; additional instructions can be agreed by email. We will tell you if, in our judgement, an instruction breaches the GDPR. Beyond your instructions we process only where EU or member state law requires it, and we inform you of that in advance unless that law prohibits it.
6. Confidentiality and security
Access to personal data is limited to people who need it to deliver the service and who are bound by confidentiality. Taking into account the state of the art and the nature of the data, we apply the measures of article 32 GDPR, including: TLS encryption in transit (enforced with HSTS), encryption at rest at our database and storage providers, EU-hosted infrastructure, data minimisation by design (the automated scan stores no screenshots or HTML; the evidence from a manual assessment is stored, as article 4 describes), one-time login links instead of passwords, least-privilege access, rate limiting and logging of security-relevant events.
7. Sub-processors
You give general consent to the sub-processors listed below. We announce additions or replacements by email at least 30 days in advance; if you object on reasonable data protection grounds and we cannot offer a solution, you may terminate your subscription as of the date the change takes effect.
- Scalingo: application hosting (Paris, France)
- Fly.io: scan worker that visits your pages (Frankfurt region, Germany; US company)
- Neon: database for scan findings (Frankfurt, Germany region; US company)
- Cloudflare: report and evidence storage (R2, EU jurisdiction), DNS and firewall (US company)
- Upstash: job queue and rate limiting (EU region; US company)
- Mailjet: report delivery by email (Paris, France; Sinch group)
- Resend: backup for email delivery; sends only when Mailjet fails (Ireland region; US company)
- Google (Workspace): our customer service mailbox, so every email you send us passes through it and stays there (EU region; US company)
- Anthropic: AI-generated report text from structured findings, and the AI assessment of the text-based WCAG criteria on bounded page fragments (United States; our API agreement records that your data is not used for training)
- Sentry: error monitoring (EU data residency region)
Every subprocessor is bound by a data processing agreement with obligations materially equivalent to these, and we remain fully liable to you for their compliance.
8. International transfers
Processing takes place in the EU, with one exception we state plainly: the AI steps run through Anthropic's API in the United States, covered by the EU Standard Contractual Clauses. There are two such steps, and they do not send the same data. For the report text, only the structured findings are sent. For the AI assessment of the textual WCAG criteria on paid scans, bounded fragments of the page itself are also sent: the page title, the headings, the alt text of images, the link text, a short piece of surrounding text per element, and the sentences that contain a cue for a sensory instruction. These may include personal data that is visible on that page. The fragments sent are not stored as such: they exist only for the duration of the call. What we do retain are the structured findings that result from it (these may include a short quote from the assessed element, as with any scan finding), plus a non-traceable technical hash so unchanged pages do not need to be reassessed. A copy of the applied Standard Contractual Clauses is available on request via hello@wexlo.eu. Some EU-region subprocessors (Neon, Fly.io, Cloudflare, Upstash, Google, Resend) are US companies; their processing for us stays within EU regions, and any transfer that does take place relies on the EU-US Data Privacy Framework for entities certified under it, and otherwise on the EU Standard Contractual Clauses.
9. Assistance and data breach notification duty
Taking into account the nature of the processing, we help you with requests from data subjects (access, deletion and the other rights under Chapter III GDPR) and, where relevant, with your obligations under Articles 32 to 36 GDPR, including data protection impact assessments. We notify you without undue delay after becoming aware of a data breach affecting your data, with the information Article 33(3) GDPR requires, so you can meet your own notification obligations.
10. Deletion and return
If your subscription ends, you can export your reports from the customer portal. On request, we delete the scan findings and reports we hold for you; in any event we delete or anonymise them in line with the retention periods in the privacy policy, except where EU or Dutch law requires us to keep specific data (such as invoices).
11. Audits
We make available the information reasonably necessary to demonstrate compliance with article 28 GDPR: this page, our security summary and the relevant commitments from our subprocessor agreements. You may audit once per contract year, with at least 30 days' notice, during office hours, without access to other customers' data, and at your own expense; where possible, we address audits with documentation first.
12. Liability and applicable law
The liability arrangement from the general terms and conditions also applies to this DPA. Dutch law applies. This DPA exists in English (https://wexlo.eu/dpa), in Dutch and in French (https://wexlo.eu/fr/dpa); if the versions differ, the English version prevails.