ComplyPages

Data Processing Addendum

Zuletzt aktualisiert: 5 July 2026

1. Purpose

This Data Processing Addendum (“DPA”) forms part of the agreement between ComplyPages and the customer where the parties agree that this DPA applies.

ComplyPages is operated by Bobook Limited, Venture Hub, 136 Capel Street, Dublin 1, D01 T2C9, Ireland.

This DPA applies where ComplyPages processes personal data on behalf of a customer as a processor in connection with ComplyPages services.

2. Definitions

In this DPA:

  • “Customer” means the organisation using ComplyPages services.
  • “ComplyPages”, “we”, “us”, or “our” means Bobook Limited operating the ComplyPages service.
  • “Customer Personal Data” means personal data processed by ComplyPages on behalf of the Customer under the agreement.
  • “Controller”, “processor”, “personal data”, “processing”, “data subject”, and “supervisory authority” have the meanings given in the GDPR.
  • “GDPR” means Regulation (EU) 2016/679, and where applicable, the UK GDPR or equivalent data protection law.

3. Roles of the parties

For business contact data, billing data, marketing data, website analytics, and service administration data, ComplyPages may act as an independent controller as described in our Privacy Policy.

For Customer Personal Data processed solely to provide paid scan, report, retest, monitoring, or related services on behalf of the Customer, the Customer is the controller and ComplyPages is the processor, unless otherwise agreed in writing.

4. Processing instructions

ComplyPages will process Customer Personal Data only:

  • To provide the services;
  • According to the agreement and this DPA;
  • According to documented instructions from the Customer;
  • As required by applicable law.

The Customer’s instructions include processing necessary to provide snapshots, fix packs, reports, retests, monitoring, support, security, and related service administration.

If ComplyPages believes an instruction infringes applicable data protection law, we will inform the Customer where legally permitted.

5. Customer responsibilities

The Customer is responsible for:

  • Having a valid legal basis for the processing;
  • Providing any required notices to data subjects;
  • Ensuring it has authority to request review of the relevant website or flow;
  • Ensuring the processing instructions are lawful;
  • Responding to data subject requests where the Customer is the controller;
  • Reviewing whether the services are appropriate for the Customer’s compliance needs.

6. Nature and purpose of processing

ComplyPages may process Customer Personal Data to:

  • Review public website flows;
  • Generate accessibility observations;
  • Create screenshots or visual evidence;
  • Prepare developer-ready reports;
  • Provide retesting and monitoring;
  • Store report history;
  • Provide support;
  • Secure and operate the service;
  • Maintain service records;
  • Comply with the agreement.

7. Categories of personal data

Customer Personal Data may include:

  • Business contact details submitted by the Customer;
  • Public website content captured in screenshots or reports;
  • Publicly visible names, contact details, or other information incidentally appearing on reviewed pages;
  • Website URLs and page metadata;
  • Accessibility issue evidence;
  • Technical logs and scan metadata;
  • Support communications;
  • Report comments or instructions submitted by the Customer.

ComplyPages does not intentionally collect special category personal data, payment card data, private customer account data, or sensitive form data as part of standard public-flow scanning.

8. Categories of data subjects

Data subjects may include:

  • Customer employees and representatives;
  • Website visitors whose information is publicly visible on reviewed pages;
  • Publicly listed staff, authors, presenters, contacts, or business representatives;
  • Individuals mentioned in public website content;
  • Users communicating with ComplyPages.

9. Duration of processing

Processing continues for the duration of the agreement and any retention period described in the agreement, Privacy Policy, or service record.

Unless otherwise agreed, scan reports and related materials may be retained for up to 24 months after delivery or last customer interaction, and longer where needed for legal, accounting, dispute, security, or audit purposes.

10. Confidentiality

ComplyPages will ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.

11. Security measures

ComplyPages will implement appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.

Measures may include access controls, limited personnel access, secure hosting practices, provider due diligence, encryption in transit where supported, account and credential controls, logging and monitoring, backup and recovery measures where applicable, internal data-handling procedures, incident review procedures, and subprocessor management.

Additional details are provided in Annex II.

12. Subprocessors

The Customer authorises ComplyPages to use subprocessors to provide the services.

ComplyPages will use subprocessors under appropriate contractual obligations. Where required, ComplyPages will impose data protection obligations on subprocessors that are materially similar to those in this DPA.

ComplyPages may update its subprocessor list from time to time. If required by the applicable agreement, Customers may object to a new subprocessor on reasonable data protection grounds.

13. International transfers

Where Customer Personal Data is transferred outside the European Economic Area, ComplyPages will use appropriate transfer safeguards where required, such as adequacy decisions, Standard Contractual Clauses, or equivalent measures.

14. Assistance with data subject requests

Taking into account the nature of the processing, ComplyPages will provide reasonable assistance to the Customer for responding to data subject requests where the Customer cannot reasonably fulfil the request without ComplyPages’ assistance.

If ComplyPages receives a request directly from a data subject relating to Customer Personal Data, we may direct the request to the Customer unless legally required to respond.

15. Assistance with compliance

Taking into account the nature of the processing and information available to ComplyPages, we will provide reasonable assistance with security obligations, personal data breach obligations, data protection impact assessments, and supervisory authority consultations where required by applicable data protection law and where the Customer cannot reasonably meet the obligation without ComplyPages’ assistance.

16. Personal data breach

If ComplyPages becomes aware of a personal data breach affecting Customer Personal Data, we will notify the Customer without undue delay.

The notification will include available information reasonably required for the Customer to meet its obligations, such as the nature of the incident, affected data categories, likely consequences, and measures taken or proposed.

17. Deletion or return

At the end of the services, and upon written request, ComplyPages will delete or return Customer Personal Data where required and reasonably possible, unless retention is required by law, legitimate business record needs, security, dispute resolution, or backup/archive systems.

18. Audit and information rights

ComplyPages will make available reasonable information necessary to demonstrate compliance with this DPA.

Audits must be reasonable, limited, non-disruptive, subject to confidentiality, and not compromise the security or confidentiality of other customers or systems. ComplyPages may satisfy audit requests through security documentation, policies, summaries, or third-party reports where appropriate.

19. Liability

Liability under this DPA is subject to the limitations and exclusions of liability in the applicable agreement, unless prohibited by applicable law.

20. Order of precedence

If there is a conflict between this DPA and the main agreement regarding data protection, this DPA will control to the extent of the conflict.

21. Contact

Privacy contact: privacy@complypages.com Legal contact: legal@complypages.com General contact: hello@complypages.com

Operator: Bobook Limited, Venture Hub, 136 Capel Street, Dublin 1, D01 T2C9, Ireland.

---

Data Processing Addendum | ComplyPages