friendlyuse
KnowledgeBlogScannerPricing
Log inSign up
friendlyuse › Legal › Data Processing Agreement (DPA)
Legal · Privacy

Data Processing Agreement (DPA)

This DPA describes the data processing arrangement agreed between the customer and friendlyuse when using the friendlyuse platform.

Last updated
26. Mai 2026
Contact
hello@friendlyuse.com
Note

This page is carefully researched but does not replace individual legal advice.

Parties and order of precedence

The controller is the customer using the friendlyuse platform. The processor is Peter Csipkay (friendlyuse), Starnberg near Munich.

This DPA supplements the main contract for use of the platform. In the event of conflict, the data protection provisions of this DPA take precedence to the extent Art. 28 GDPR is concerned.

Subject matter and duration

The subject matter is the processing of personal data on behalf of the customer for the operation of the accessibility widget, domain and token management, usage statistics, scanner, support, and billing.

Processing begins upon activation of the customer account and ends upon termination of the main contract, subject to statutory retention obligations and agreed deletion periods.

Nature and purpose of processing

  • Provision, maintenance, and security of the platform.
  • Delivery and validation of the widget script for registered domains.
  • Storage of domains, tokens, configurations, roles, usage statistics, scanner results, and support history.
  • Counting unique monthly visitors via a hash of IP address, user agent, and domain, without permanently storing raw IP addresses for this metric.
  • Billing, contract management, and fulfilment of statutory documentation obligations.

Categories of data and data subjects

  • Account and contact data of the customer's employees.
  • Login, role, authorisation, and usage logs.
  • Domains, widget tokens, widget configurations, feature usage, session metadata, and technical metadata.
  • Scanner URLs, page structure, automated findings, and scan reports, to the extent the customer uses the scanner.
  • Support data to the extent the customer provides it in the context of a support request.
  • Data subjects include in particular users of the customer account, the customer's contacts, visitors to the customer's domains within the pseudonymised usage statistics, and potentially persons whose data is contained in content provided or scanned by the customer.

Widget on customer domains

The customer decides on which domains the widget is embedded and is responsible for informing their website visitors.

friendlyuse processes widget usage data only to the extent required for validation, abuse protection, usage statistics, plan measurement, and error analysis.

Instructions

friendlyuse processes personal data only on documented instructions from the customer, unless a statutory obligation requires otherwise.

Instructions may be given via the contract, the product, e-mail, or support channels. friendlyuse will inform the customer if, in our assessment, an instruction infringes data protection law.

Confidentiality and security

friendlyuse binds all persons involved in processing to confidentiality. Access to production systems follows the principle of least privilege and is regularly reviewed.

Technical and organisational measures include, among others, encryption in transit, access controls, logging, backup concepts, tenant separation, MFA for administrative access, and security monitoring.

Sub-processors

friendlyuse may engage sub-processors provided they ensure an adequate level of data protection and contractually undertake data protection obligations at least equivalent to those in this DPA.

At the current product stage, the envisaged sub-processors include in particular Supabase for authentication and database, and Stripe for payment processing. Additional hosting, e-mail, monitoring, and support providers must be finalised before the productive go-live.

Material changes to sub-processors will be communicated to customers in advance. Customers may object on important data protection grounds.

Assistance to the customer

  • Assistance with data subject rights requests to the extent they concern the processing under this DPA.
  • Assistance with notifications of personal data breaches under Art. 33 and 34 GDPR.
  • Provision of appropriate information for data protection impact assessments.
  • Evidence of compliance with obligations under Art. 28 GDPR upon request.

Return, deletion and audit

After termination of the contract, friendlyuse will delete or export personal data at the customer's choice, unless statutory retention obligations prevent this.

The customer may verify compliance with this DPA by means of appropriate evidence. On-site audits are possible with reasonable prior notice where documentary evidence is insufficient and operational and security interests are safeguarded.

Legal basis and research
  • DSGVO Verordnung (EU) 2016/679
  • Art. 28 DSGVO Auftragsverarbeitung
  • Art. 32 DSGVO Sicherheit der Verarbeitung
friendlyuse

The accessibility widget for websites: drop in one script, enable assistive controls, save visitor preferences.

Product

  • Widget
  • Embedding
  • Pricing
  • Free scan

Use cases

  • Website
  • Online shop
  • E-commerce

Account

  • Sign up
  • Log in

Legal

  • Imprint
  • Privacy
  • Terms
  • Accessibility statement
© 2026 friendlyuse