Scope
This list applies to customer use of the friendlyuse platform: account, dashboard, domain and token management, widget delivery, visitor metering, scanner, support, and billing.
The customer remains the controller for their own website. friendlyuse processes customer data as a processor to the extent that processing takes place within the platform and under the DPA.
Currently envisaged service providers
- Supabase: authentication, PostgreSQL database, tenant-separated storage, and backend infrastructure for account, domain, token, widget, scanner, and usage data. Role: processor/sub-processor. Registered address, region, and transfer mechanism must be documented based on the final Supabase project.
- Stripe (planned, once enabled): checkout, billing portal, invoices, payment status, tax and payment processing for paid plans. Role: processor or independent controller depending on the processing activity.
- Hosting/app infrastructure: delivery of the marketing website, app, API, and widget file. Provider, data centre region, and transfer mechanism are not yet finally documented in the project materials and must be added before go-live.
- E-mail/support: sending transactional e-mails, support communication, and security notifications. Provider and role are not yet finally documented and must be added before go-live.
- Monitoring/security: error analysis, security monitoring, and operational logs, if used in production. Provider, data categories, and retention periods must be added before go-live.
Categories of data
- Customer master data and business contact details.
- Login, role, and authorisation data.
- Domains, tokens, widget configurations, and technical metadata.
- Pseudonymised usage statistics, in particular unique monthly visitors counted via a hash of IP address, user agent, and domain.
- Scanner URLs, scan timestamps, and automated accessibility findings.
- Support content and billing or payment status data.
Changes
friendlyuse will notify customers of material changes to sub-processors with reasonable notice. Customers may object on important data protection grounds.
Before publication it must be decided whether this list is maintained statically on the website or whether customers are additionally notified of changes by e-mail or dashboard notification.
Still to be finalised
- Full provider company name and contracting party for each service provider.
- Country of registration, hosting region, and any third-country transfers.
- Link to DPA, sub-processor list, and security documentation for each provider.
- Retention periods for logs, support data, scanner reports, and billing data.