01Scope and parties
When finalised and accepted or executed, this addendum will be between the customer ("you") and Accessible.org, LLC, a Texas limited liability company ("we"), and will form part of the terms of service. It will apply to personal data we process on your behalf when providing StrongPrivacy, and will prevail over the terms where they conflict on data protection. Posting it here is not itself a claim that the agreement or any transfer schedule has been executed.
02Roles
You are the controller of personal data about visitors to your websites, and of the personal data you put into your workspace. We are your processor for that data and process it only on your documented instructions. We are a controller only for the account, billing and security information described in the privacy policy.
03Processing details
- Subject matter and purpose: providing StrongPrivacy for your websites: publishing consent configurations, recording visitors' consent choices, scanning your sites, and storing and exporting the resulting evidence.
- Duration: for as long as you use the Service, and afterwards until deletion under section 10.
- Data subjects: visitors to your websites; your team members; and the people named in data requests you record.
- Personal data: pseudonymous visitor keys with the consent categories, region, configuration version, source and time of each choice; team members' names and email addresses; the contact details you give for your sites; and the references you record for data requests.
- Special categories: none are required, and you agree not to submit them.
04Your instructions
Your configuration of the Service, and this addendum, are your complete instructions. We will tell you if we believe an instruction breaks data protection law, and will not process your data for any other purpose unless the law requires it, in which case we will tell you first where the law allows.
05Confidentiality
The reviewed application’s staff-access path requires an enrolled time-based one-time password, a current step-up verification and an authorised workspace assignment; staff actions use the application’s audit-event path.
Before this addendum is executed, the operator must confirm that every person authorised to process customer data is contractually bound by confidentiality and that production access, identity-provider and log settings enforce the same control outside the application code.
06Security measures
The reviewed application implements the controls below. They are not an independent security audit, and the executed addendum must include only measures the operator has also verified in the production infrastructure:
- private routes derive the workspace from the authenticated identity and pass that identifier into reviewed data-access paths, with separate authorised staff access controls;
- salted scrypt password hashing and signed, revocable sessions;
- AES-256-GCM encryption of stored connector credentials;
- pseudonymous consent records that exclude IP addresses and browser details, chained with cryptographic hashes so alteration can be detected;
- signature or shared-secret verification on the supported Stripe, Shopify and WordPress integration-message routes;
- rate limiting, an audit trail of sign-ins, changes and exports, and strict security headers; and
- scans in an isolated browser whose network access is restricted to public addresses, with query strings and credentials removed from stored scan reports.
07Subprocessors
The final subprocessor schedule will be published on the subprocessors page after the legal entities, locations, contracts and transfer safeguards are verified. Before a listed provider processes customer personal data, we will bind it to applicable data-protection terms and remain responsible as the law requires. The executed addendum will state the notice period and objection process; the proposed period in this draft is at least 30 days, with objections sent to info@accessible.org.
08Assistance with requests and assessments
The Service lets you look up a visitor's consent records by their key, record and track data requests, and export evidence, so that you can answer data subjects yourself. If a data subject contacts us directly about your data, we will pass the request to you. We will also give you reasonable help with data protection impact assessments and consultations with authorities about the Service.
09Personal data breaches
We will notify you without undue delay after becoming aware of a breach affecting your personal data, with the information we have about its nature, likely consequences and the measures taken, and will update you as we learn more, so that you can meet your own notification duties.
10Deletion and return
The application includes a retention worker intended to delete consent records, scan reports and audit events after the workspace retention window, and dashboard export routes for current data. Production scheduling, backups and provider-level deletion must be verified before this draft becomes an executed commitment.
When you stop using the Service, export what you need, then ask us at info@accessible.org to delete your workspace. We will delete your personal data within 30 days of confirming the request, except where the law requires us to keep it, and confirm in writing when it is done.
11Information and audits
We will make available the information reasonably needed to show that we meet this addendum, including answers to security questionnaires. If that is not enough, you may audit our compliance once a year, on reasonable notice, at your cost, and under confidentiality, in a way that does not expose other customers' data.
12International transfers
We are based in the United States, and personal data may be processed there and in other countries where verified subprocessors operate. A cross-border transfer mechanism is not completed merely by naming the European Commission's Standard Contractual Clauses in this page.
Before a restricted transfer that needs contractual safeguards, the parties must execute the appropriate SCC module and options and complete the required schedules. Those materials must include the parties and roles, transfer description, data subjects and data categories, retention, competent authority, governing law and forum, technical and organisational measures, and the subprocessor information. Section 3 is useful input but is not a substitute for those completed annexes.
UK transfers also require the completed Part 1 tables of the UK Addendum or another valid UK safeguard. Swiss transfers require the applicable Swiss adaptations. The parties must also assess the transfer and document supplementary measures where required. Contact info@accessible.org for the completed transfer package; this draft page does not claim that unsigned schedules have already been incorporated.
The completion requirements are described by the European Commission's SCC guidance and the ICO's UK Addendum guidance.
13Liability
Each party's liability under this addendum is subject to the limitation of liability in the terms of service, except where the law does not allow it to be limited.
Questions, or requests for a prior version of this document, go to info@accessible.org.