Data Processing Agreement
Last updated: July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between TrustScan ("Processor") and you ("Controller") when processing personal data in connection with the use of TrustScan services.
1. Definitions
Capitalized terms not defined herein shall have the meaning set forth in the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR").
2. Processing of Personal Data
2.1 Nature and Purpose: The Processor shall process personal data on behalf of the Controller for the purpose of providing website compliance scanning services, including crawling websites, analyzing content, generating compliance reports, and sending notifications.
2.2 Categories of Data Subjects: End users and visitors of websites that the Controller submits for scanning.
2.3 Types of Personal Data: Publicly available website content, metadata, and any personal data incidentally collected during website crawling (e.g., names, email addresses found in public pages).
2.4 Processing Duration: For the duration of the Controller's use of the Service, plus retention periods as described in the Privacy Policy.
3. Controller Obligations
The Controller warrants that they have obtained all necessary consents and have a lawful basis for the processing of personal data in connection with the Service. The Controller shall not submit websites for scanning that contain special category data as defined in Article 9 of the GDPR.
4. Processor Obligations
4.1 The Processor shall process personal data only on documented instructions from the Controller.
4.2 The Processor shall ensure that persons authorized to process personal data are bound by confidentiality obligations.
4.3 The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
4.4 The Processor shall assist the Controller in fulfilling its obligations regarding data subject rights, data breach notifications, and data protection impact assessments.
4.5 The Processor shall notify the Controller without undue delay upon becoming aware of a personal data breach.
5. Subprocessing
The Controller consents to the Processor engaging the following subprocessors:
- Cloudflare, Inc. — Cloud infrastructure and hosting (D1 database, R2 storage, KV cache, Queues)
- Stripe, Inc. — Payment processing
- Resend, Inc. — Email delivery
- PostHog, Inc. — Product analytics (if consented)
- Google LLC — Website analytics (if consented)
The Processor shall notify the Controller of any changes to subprocessors, and the Controller may object within 14 days. See our full list at /subprocessors.
6. Data Transfers
Personal data may be transferred to and processed in countries outside the European Economic Area (EEA). Such transfers shall be governed by Standard Contractual Clauses (SCCs) as approved by the European Commission, or other appropriate transfer mechanisms as recognized under applicable data protection law.
7. Data Subject Rights
The Processor shall assist the Controller in responding to data subject requests under Chapter III of the GDPR, including rights of access, rectification, erasure, restriction, portability, and objection.
8. Security Measures
The Processor maintains the following technical and organizational security measures:
- Encryption of data in transit (TLS 1.3)
- Encryption of sensitive data at rest
- Access controls with least-privilege principle
- Regular security assessments and penetration testing
- Employee background checks and confidentiality agreements
- Incident response procedures
- Regular data backups with disaster recovery plans
9. Data Breach Notification
The Processor shall notify the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Controller data. Notification shall include the nature of the breach, categories and approximate number of data subjects affected, and measures taken or proposed to address the breach.
10. Deletion of Data
Upon termination of the Service, the Processor shall delete or return all personal data processed on behalf of the Controller within 90 days, unless applicable law requires continued storage. Free tier data (last 3 scans) and Pro tier data (full subscription history) are retained as described in the Privacy Policy.
11. Liability
Each party's liability arising out of or related to this DPA shall be subject to the limitations of liability set forth in the Terms of Service.
12. Governing Law
This DPA shall be governed by the laws of the European Union, without regard to conflict of law provisions.
13. Contact
For questions about this DPA or to request execution of this DPA, contact us at: legal@trustscanaudit.com