SimplifyAccess Logo
help_outline Help Pricing
Content expand

    Data Processing Addendum (DPA)

    Last updated: June 2026

    1. Parties

    This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Controller") and undosa LLC, operating under the SimplifyAccess brand ("Processor"), regarding the processing of personal data in connection with the Services.

    Processor

    undosa LLC
    8 The Green B
    Dover, DE 19901
    United States

    Controller

    The legal entity or individual accepting the Terms of Service and using the Services.

    2. Scope and Purpose

    This DPA applies whenever SimplifyAccess processes personal data on behalf of a Customer in connection with the provision of:

    • Accessibility Widget

    • Accessibility Management Platform

    • Accessibility Reporting and Monitoring

    • AI-Powered Accessibility Features

    • API Services

    • Customer Support Services

    The parties acknowledge that the Customer acts as the Controller and SimplifyAccess acts as the Processor for personal data processed under this DPA.

    3. Processing Instructions

    SimplifyAccess shall process personal data only:

    • On documented instructions from the Customer;

    • As necessary to provide the Services;

    • As required by applicable law.

    The Customer instructs SimplifyAccess to process personal data as necessary to provide and maintain the Services described in the Terms of Service and this DPA.

    4. Categories of Data Subjects

    The categories of data subjects may include:

    • Customer users

    • Website visitors

    5. Categories of Personal Data

    Depending on the Services used, SimplifyAccess may process:

    Customer Account Data

    • Name

    • Email address

    • Password hash

    • Account credentials

    • Subscription information

    • Billing information

    • Session information

    Website Content Data

    • Website URLs

    • Website content processed for accessibility analysis

    • Website content processed for accessibility simplification

    • Website content processed for accessibility reporting

    Technical Data

    • IP addresses

    • Browser information

    • Device information

    • Request logs

    • Security logs

    6. Processor Obligations

    SimplifyAccess shall:

    • Process personal data only in accordance with documented instructions from the Customer;

    • Ensure persons authorized to process personal data are subject to confidentiality obligations;

    • Implement appropriate technical and organizational measures to protect personal data;

    • Assist the Customer in fulfilling applicable data protection obligations where required by law;

    • Notify the Customer of personal data breaches without undue delay where legally required;

    • Delete or return personal data upon termination of the Services in accordance with this DPA.

    7. Confidentiality

    SimplifyAccess shall ensure that all personnel with access to personal data are subject to appropriate confidentiality obligations and receive access only where necessary to perform their duties.

    Access to personal data is restricted to authorized personnel with a legitimate business need.

    8. Security Measures

    SimplifyAccess shall implement appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.

    The security measures currently implemented are described in Annex II.

    9. Subprocessors

    The Customer authorizes SimplifyAccess to engage subprocessors for the provision of the Services.

    A list of approved subprocessors is included in Annex III.

    SimplifyAccess shall remain responsible for the performance of its subprocessors to the extent required by applicable law.

    10. International Data Transfers

    Personal data may be transferred to countries outside the European Economic Area ("EEA"), including the United States.

    Where such transfers occur, SimplifyAccess shall implement appropriate safeguards, including one or more of the following:

    • EU Standard Contractual Clauses ("SCCs");

    • EU-U.S. Data Privacy Framework participation where applicable;

    • Other lawful transfer mechanisms recognized under applicable data protection laws.

    11. Assistance to the Controller

    Taking into account the nature of the processing, SimplifyAccess shall provide reasonable assistance to the Customer in fulfilling obligations relating to:

    • Personal data breach notifications;

    • Data protection impact assessments where required;

    • Regulatory inquiries;

    • Data deletion requests;

    • Other obligations under applicable data protection laws.

    12. Security Incidents

    If SimplifyAccess becomes aware of a confirmed personal data breach affecting Customer personal data, SimplifyAccess shall notify the Customer without undue delay.

    Such notification shall include information reasonably available regarding:

    • The nature of the incident;

    • The affected data;

    • Potential consequences;

    • Measures taken or proposed to address the incident.

    13. Deletion and Return of Data

    Upon termination of the Services or upon written request by the Customer, SimplifyAccess shall delete Customer personal data unless retention is required by applicable law.

    Inactive accounts resulting from non-payment may be retained for up to fourteen (14) days before deletion.

    Backup copies containing Customer data may remain in secure backup systems until overwritten through normal backup rotation procedures.

    14. Audit Rights

    Upon written request, SimplifyAccess shall provide information reasonably necessary to demonstrate compliance with this DPA.

    Audits shall be limited to documentation reviews, written questionnaires, compliance reports, certifications, and similar reasonable verification methods unless otherwise required by applicable law.

    Any on-site audit must:

    • Be required by applicable law;

    • Be subject to reasonable advance written notice;

    • Be conducted during normal business hours;

    • Avoid disruption of Services;

    • Protect confidential information and the rights of other customers.

    Each party shall bear its own costs associated with any audit unless otherwise required by law.

    15. Liability

    The liability of the parties under this DPA shall be subject to the limitations and exclusions of liability set forth in the Terms of Service, except where prohibited by applicable law.

    16. Term

    This DPA shall remain in effect for as long as SimplifyAccess processes personal data on behalf of the Customer.

    Upon termination of the Services and completion of all applicable deletion obligations, this DPA shall automatically terminate.

    Annex I – Details of Processing

    Subject Matter

    Provision of accessibility-related software, services, support, reporting, APIs, and accessibility management tools.

    Duration

    For the duration of the Customer's use of the Services and any applicable retention periods.

    Nature of Processing

    • Collection

    • Storage

    • Organization

    • Analysis

    • Retrieval

    • Transmission

    • Accessibility optimization

    • Security monitoring

    • Customer support

    Purpose of Processing

    • Operation of the Accessibility Widget

    • Operation of the Accessibility Management Platform

    • Accessibility analysis and reporting

    • AI-powered accessibility features

    • API functionality

    • Customer support

    • Security and abuse prevention

    Categories of Data Subjects

    • Customer users

    • Website visitors

    Categories of Personal Data

    Customer Account Data

    • Name

    • Email address

    • Password hash

    • Subscription information

    • Billing information

    • Session information

    Website Content Data

    • Website URLs

    • Website content

    • Accessibility analysis data

    • Accessibility simplification data

    Technical Data

    • IP addresses

    • Browser information

    • Device information

    • Security logs

    • Request logs

    Annex II – Technical and Organizational Measures

    Access Control

    • Role-based access controls

    • Principle of least privilege

    • Restricted administrative access

    • Account access monitoring

    Authentication Security

    • Password hashing

    • Secure authentication procedures

    • Strong password requirements

    • Session management controls

    Network Security

    • Firewalls

    • Intrusion detection technologies

    • Intrusion prevention technologies

    • Malware protection systems

    • Vulnerability scanning

    • Security monitoring systems

    Encryption

    • TLS encryption for data in transit

    • Encryption at rest where applicable

    • Encrypted backups where applicable

    Monitoring and Logging

    • Security logging

    • Audit trails

    • System monitoring

    • Abuse detection mechanisms

    • Incident response procedures

    Availability and Recovery

    • Automated backups

    • Disaster recovery procedures

    • Infrastructure redundancy where applicable

    • Service monitoring

    Development Security

    • Code reviews

    • Security testing

    • Vulnerability management

    • Dependency monitoring

    • Security-focused deployment processes

    Personnel Security

    • Confidentiality obligations

    • Access restrictions

    • Need-to-know access principles

    Annex III – Approved Subprocessors

    Subprocessor Purpose Location
    Amazon Web Services (AWS) Hosting, infrastructure, storage, databases, monitoring European Union and United States
    Stripe, Inc. Payment processing and billing United States
    OpenAI, LLC AI-powered accessibility and text processing services United States
    Google LLC Analytics, reCAPTCHA, infrastructure services European Union and United States
    Functional Software, Inc. (Sentry) Error monitoring and diagnostics United States
    Mailgun Technologies, Inc. Transactional email delivery United States

    Data Retention Schedule

    Data Category Retention Period
    Security logs and request logs 7 days
    Customer account data Until account deletion or termination
    Subscription and billing data As required by applicable law and accounting obligations
    Customer support tickets Until account deletion
    Website accessibility analysis data Until account deletion or deletion request
    Website simplification data Until account deletion or deletion request
    Backup data Up to 6 months
    Inactive unpaid accounts Up to 14 days before deletion

    Order of Precedence

    In the event of a conflict between this DPA and the Terms of Service, this DPA shall prevail solely with respect to matters relating to the processing of personal data.

    Edit

    Confirm This Action

    Incorrect Password