Data Processing Addendum (DPA)
Last updated: June 2026
1. Parties
This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Controller") and undosa LLC, operating under the SimplifyAccess brand ("Processor"), regarding the processing of personal data in connection with the Services.
Processor
undosa LLC
8 The Green B
Dover, DE 19901
United States
Controller
The legal entity or individual accepting the Terms of Service and using the Services.
2. Scope and Purpose
This DPA applies whenever SimplifyAccess processes personal data on behalf of a Customer in connection with the provision of:
-
Accessibility Widget
-
Accessibility Management Platform
-
Accessibility Reporting and Monitoring
-
AI-Powered Accessibility Features
-
API Services
-
Customer Support Services
The parties acknowledge that the Customer acts as the Controller and SimplifyAccess acts as the Processor for personal data processed under this DPA.
3. Processing Instructions
SimplifyAccess shall process personal data only:
-
On documented instructions from the Customer;
-
As necessary to provide the Services;
-
As required by applicable law.
The Customer instructs SimplifyAccess to process personal data as necessary to provide and maintain the Services described in the Terms of Service and this DPA.
4. Categories of Data Subjects
The categories of data subjects may include:
-
Customer users
-
Website visitors
5. Categories of Personal Data
Depending on the Services used, SimplifyAccess may process:
Customer Account Data
-
Name
-
Email address
-
Password hash
-
Account credentials
-
Subscription information
-
Billing information
-
Session information
Website Content Data
-
Website URLs
-
Website content processed for accessibility analysis
-
Website content processed for accessibility simplification
-
Website content processed for accessibility reporting
Technical Data
-
IP addresses
-
Browser information
-
Device information
-
Request logs
-
Security logs
6. Processor Obligations
SimplifyAccess shall:
-
Process personal data only in accordance with documented instructions from the Customer;
-
Ensure persons authorized to process personal data are subject to confidentiality obligations;
-
Implement appropriate technical and organizational measures to protect personal data;
-
Assist the Customer in fulfilling applicable data protection obligations where required by law;
-
Notify the Customer of personal data breaches without undue delay where legally required;
-
Delete or return personal data upon termination of the Services in accordance with this DPA.
7. Confidentiality
SimplifyAccess shall ensure that all personnel with access to personal data are subject to appropriate confidentiality obligations and receive access only where necessary to perform their duties.
Access to personal data is restricted to authorized personnel with a legitimate business need.
8. Security Measures
SimplifyAccess shall implement appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
The security measures currently implemented are described in Annex II.
9. Subprocessors
The Customer authorizes SimplifyAccess to engage subprocessors for the provision of the Services.
A list of approved subprocessors is included in Annex III.
SimplifyAccess shall remain responsible for the performance of its subprocessors to the extent required by applicable law.
10. International Data Transfers
Personal data may be transferred to countries outside the European Economic Area ("EEA"), including the United States.
Where such transfers occur, SimplifyAccess shall implement appropriate safeguards, including one or more of the following:
-
EU Standard Contractual Clauses ("SCCs");
-
EU-U.S. Data Privacy Framework participation where applicable;
-
Other lawful transfer mechanisms recognized under applicable data protection laws.
11. Assistance to the Controller
Taking into account the nature of the processing, SimplifyAccess shall provide reasonable assistance to the Customer in fulfilling obligations relating to:
-
Personal data breach notifications;
-
Data protection impact assessments where required;
-
Regulatory inquiries;
-
Data deletion requests;
-
Other obligations under applicable data protection laws.
12. Security Incidents
If SimplifyAccess becomes aware of a confirmed personal data breach affecting Customer personal data, SimplifyAccess shall notify the Customer without undue delay.
Such notification shall include information reasonably available regarding:
-
The nature of the incident;
-
The affected data;
-
Potential consequences;
-
Measures taken or proposed to address the incident.
13. Deletion and Return of Data
Upon termination of the Services or upon written request by the Customer, SimplifyAccess shall delete Customer personal data unless retention is required by applicable law.
Inactive accounts resulting from non-payment may be retained for up to fourteen (14) days before deletion.
Backup copies containing Customer data may remain in secure backup systems until overwritten through normal backup rotation procedures.
14. Audit Rights
Upon written request, SimplifyAccess shall provide information reasonably necessary to demonstrate compliance with this DPA.
Audits shall be limited to documentation reviews, written questionnaires, compliance reports, certifications, and similar reasonable verification methods unless otherwise required by applicable law.
Any on-site audit must:
-
Be required by applicable law;
-
Be subject to reasonable advance written notice;
-
Be conducted during normal business hours;
-
Avoid disruption of Services;
-
Protect confidential information and the rights of other customers.
Each party shall bear its own costs associated with any audit unless otherwise required by law.
15. Liability
The liability of the parties under this DPA shall be subject to the limitations and exclusions of liability set forth in the Terms of Service, except where prohibited by applicable law.
16. Term
This DPA shall remain in effect for as long as SimplifyAccess processes personal data on behalf of the Customer.
Upon termination of the Services and completion of all applicable deletion obligations, this DPA shall automatically terminate.
Annex I – Details of Processing
Subject Matter
Provision of accessibility-related software, services, support, reporting, APIs, and accessibility management tools.
Duration
For the duration of the Customer's use of the Services and any applicable retention periods.
Nature of Processing
-
Collection
-
Storage
-
Organization
-
Analysis
-
Retrieval
-
Transmission
-
Accessibility optimization
-
Security monitoring
-
Customer support
Purpose of Processing
-
Operation of the Accessibility Widget
-
Operation of the Accessibility Management Platform
-
Accessibility analysis and reporting
-
AI-powered accessibility features
-
API functionality
-
Customer support
-
Security and abuse prevention
Categories of Data Subjects
-
Customer users
-
Website visitors
Categories of Personal Data
Customer Account Data
-
Name
-
Email address
-
Password hash
-
Subscription information
-
Billing information
-
Session information
Website Content Data
-
Website URLs
-
Website content
-
Accessibility analysis data
-
Accessibility simplification data
Technical Data
-
IP addresses
-
Browser information
-
Device information
-
Security logs
-
Request logs
Annex II – Technical and Organizational Measures
Access Control
-
Role-based access controls
-
Principle of least privilege
-
Restricted administrative access
-
Account access monitoring
Authentication Security
-
Password hashing
-
Secure authentication procedures
-
Strong password requirements
-
Session management controls
Network Security
-
Firewalls
-
Intrusion detection technologies
-
Intrusion prevention technologies
-
Malware protection systems
-
Vulnerability scanning
-
Security monitoring systems
Encryption
-
TLS encryption for data in transit
-
Encryption at rest where applicable
-
Encrypted backups where applicable
Monitoring and Logging
-
Security logging
-
Audit trails
-
System monitoring
-
Abuse detection mechanisms
-
Incident response procedures
Availability and Recovery
-
Automated backups
-
Disaster recovery procedures
-
Infrastructure redundancy where applicable
-
Service monitoring
Development Security
-
Code reviews
-
Security testing
-
Vulnerability management
-
Dependency monitoring
-
Security-focused deployment processes
Personnel Security
-
Confidentiality obligations
-
Access restrictions
-
Need-to-know access principles
Annex III – Approved Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, infrastructure, storage, databases, monitoring | European Union and United States |
| Stripe, Inc. | Payment processing and billing | United States |
| OpenAI, LLC | AI-powered accessibility and text processing services | United States |
| Google LLC | Analytics, reCAPTCHA, infrastructure services | European Union and United States |
| Functional Software, Inc. (Sentry) | Error monitoring and diagnostics | United States |
| Mailgun Technologies, Inc. | Transactional email delivery | United States |
Data Retention Schedule
| Data Category | Retention Period |
|---|---|
| Security logs and request logs | 7 days |
| Customer account data | Until account deletion or termination |
| Subscription and billing data | As required by applicable law and accounting obligations |
| Customer support tickets | Until account deletion |
| Website accessibility analysis data | Until account deletion or deletion request |
| Website simplification data | Until account deletion or deletion request |
| Backup data | Up to 6 months |
| Inactive unpaid accounts | Up to 14 days before deletion |
Order of Precedence
In the event of a conflict between this DPA and the Terms of Service, this DPA shall prevail solely with respect to matters relating to the processing of personal data.