Parties and order of precedence
The controller is the customer using the friendlyuse platform. The processor is Peter Csipkay (friendlyuse), Starnberg near Munich.
This DPA supplements the main contract for use of the platform. In the event of conflict, the data protection provisions of this DPA take precedence to the extent Art. 28 GDPR is concerned.
Subject matter and duration
The subject matter is the processing of personal data on behalf of the customer for the operation of the accessibility widget, domain and token management, usage statistics, scanner, support, and billing.
Processing begins upon activation of the customer account and ends upon termination of the main contract, subject to statutory retention obligations and agreed deletion periods.
Nature and purpose of processing
- Provision, maintenance, and security of the platform.
- Delivery and validation of the widget script for registered domains.
- Storage of domains, tokens, configurations, roles, usage statistics, scanner results, and support history.
- Counting unique monthly visitors via a hash of IP address, user agent, and domain, without permanently storing raw IP addresses for this metric.
- Billing, contract management, and fulfilment of statutory documentation obligations.
Categories of data and data subjects
- Account and contact data of the customer's employees.
- Login, role, authorisation, and usage logs.
- Domains, widget tokens, widget configurations, feature usage, session metadata, and technical metadata.
- Scanner URLs, page structure, automated findings, and scan reports, to the extent the customer uses the scanner.
- Support data to the extent the customer provides it in the context of a support request.
- Data subjects include in particular users of the customer account, the customer's contacts, visitors to the customer's domains within the pseudonymised usage statistics, and potentially persons whose data is contained in content provided or scanned by the customer.
Widget on customer domains
The customer decides on which domains the widget is embedded and is responsible for informing their website visitors.
friendlyuse processes widget usage data only to the extent required for validation, abuse protection, usage statistics, plan measurement, and error analysis.
Instructions
friendlyuse processes personal data only on documented instructions from the customer, unless a statutory obligation requires otherwise.
Instructions may be given via the contract, the product, e-mail, or support channels. friendlyuse will inform the customer if, in our assessment, an instruction infringes data protection law.
Confidentiality and security
friendlyuse binds all persons involved in processing to confidentiality. Access to production systems follows the principle of least privilege and is regularly reviewed.
Technical and organisational measures include, among others, encryption in transit, access controls, logging, backup concepts, tenant separation, MFA for administrative access, and security monitoring.
Sub-processors
friendlyuse may engage sub-processors provided they ensure an adequate level of data protection and contractually undertake data protection obligations at least equivalent to those in this DPA.
At the current product stage, the envisaged sub-processors include in particular Supabase for authentication and database, and Stripe for payment processing. Additional hosting, e-mail, monitoring, and support providers must be finalised before the productive go-live.
Material changes to sub-processors will be communicated to customers in advance. Customers may object on important data protection grounds.
Assistance to the customer
- Assistance with data subject rights requests to the extent they concern the processing under this DPA.
- Assistance with notifications of personal data breaches under Art. 33 and 34 GDPR.
- Provision of appropriate information for data protection impact assessments.
- Evidence of compliance with obligations under Art. 28 GDPR upon request.
Return, deletion and audit
After termination of the contract, friendlyuse will delete or export personal data at the customer's choice, unless statutory retention obligations prevent this.
The customer may verify compliance with this DPA by means of appropriate evidence. On-site audits are possible with reasonable prior notice where documentary evidence is insufficient and operational and security interests are safeguarded.