Skip to main content
ConformWatch
  • The report
  • How it works
  • What it can't do
  • Pricing
Send me a client site and I'll scan it
Legal

Data processing agreement

The agreement that puts our processor relationship on contractual footing: when you point us at a site, this is what we owe you for the data that comes back.

Version 1.0 · 1 August 2026

How to execute this

Email [email protected] from your agency’s domain stating that you agree to this DPA, naming your legal entity and the version above — we confirm by reply, and both emails together form the executed agreement. If your clients require signed copies or your own paper, send it over.

1. Parties and purpose

This Data Processing Agreement (“DPA”) is between Dime Corporation Ltd (Company No. 13175488), trading as Letrix Labs / ConformWatch, of 124 City Road, London, EC1V 2NX, United Kingdom (the “Processor”, “we”, “us”) and the agency or business executing it (the “Agency”, “you”). It governs personal data we process on your instructions when providing accessibility scanning and reporting (the “Services”), supplements our terms of service, and forms part of the contract between us. “Data Protection Law” means the UK GDPR and Data Protection Act 2018 and, where applicable, the EU GDPR.

2. Roles

For personal data contained in scanned websites (“Scan Data”), you are the controller — or, where you act for your own client, a processor — and we are your processor or sub-processor, acting only on your documented instructions. Requesting a scan of a site is such an instruction. For your own account and contact data we are an independent controller, as described in our privacy policy; this DPA does not cover that data.

3. Details of processing

Subject matter and nature: fetching publicly reachable pages of websites you designate, running automated accessibility checks, storing text-stripped results and generating reports. Duration: the term of our engagement plus the retention periods below. Purpose: providing the Services to you.Categories of data: any personal data published on scanned pages — typically names, job titles, contact details and user-generated content such as reviews; our text-stripping (Annex B) removes most of it before storage. Data subjects: individuals whose data appears on scanned sites, such as your client’s staff and their customers. Special categories: not sought; if present on a scanned page, exposure is minimised by text-stripping.

4. Our obligations

We will:

(a) process Scan Data only on your documented instructions, unless UK or EU law requires otherwise, in which case we tell you first where the law allows; (b) ensure anyone processing it is bound by confidentiality; (c) apply the technical and organisational measures in Annex B; (d) assist you, without undue delay, with data subject requests and with your obligations on security, breach notification and impact assessments, taking into account the nature of the processing; (e) notify you without undue delay after becoming aware of a personal data breach affecting Scan Data, with enough detail for you to meet your own notification duties; (f) delete or return Scan Data at the end of the Services as set out in clause 7; and (g) make available information reasonably necessary to demonstrate compliance with this DPA, and allow and contribute to audits as set out in clause 8.

5. Sub-processors

You authorise the sub-processors listed in section 11 of ourprivacy policy. We will update that list and notify you before any new sub-processor touches Scan Data; if you object on reasonable data-protection grounds within 30 days and we cannot offer an alternative, you may terminate the affected Services. We remain responsible for our sub-processors’ performance and impose data-protection obligations on them equivalent to this DPA.

6. International transfers

Scan Data is stored in the UK and EEA. Where an instruction or a sub-processor involves a transfer outside the UK/EEA, we ensure a lawful transfer mechanism — adequacy, the UK IDTA or Addendum, or EU standard contractual clauses — and will execute those instruments with you where required. Scans run from US-based nodes only where you request it; such nodes fetch and return data and do not store it.

7. Deletion and return

Raw scan results are deleted within 90 days of each scan in the ordinary course. At the end of the Services — or earlier on request — we delete or return remaining Scan Data and reports within 30 days, except where law requires retention. Anonymised, text-stripped artifacts that no longer constitute personal data fall outside this DPA and may be retained.

8. Audit

Once per year, or following a breach affecting your Scan Data, you may audit our compliance with this DPA — in the first instance through written questions and documentation, which satisfies this right unless Data Protection Law requires more. Any on-site exercise requires 30 days’ notice, must not disrupt operations, and is at your cost.

9. Liability and term

Liability under this DPA is subject to the exclusions and cap in theterms of service, save where Data Protection Law does not permit it to be limited. This DPA runs for as long as we process Scan Data for you, and clauses that should survive, survive. It is governed by the laws of England and Wales.

Annex A — instruction scope

Your standing instruction: scan the sites you designate, on the schedule you request, with any robots.txt preference and URL exclusions you set; store results text-stripped; generate and deliver reports to you. Anything beyond this needs a written instruction.

Annex B — technical and organisational measures

Transport encryption (TLS) on all connections. Storage of personal data confined to UK and EEA data centres (Hetzner, LeaseWeb, UpCloud, Vultr). Text-stripping of stored HTML fragments at the point of capture — tag, attributes and selector retained; text content discarded — as structural data minimisation. No screenshots; no credential handling; public pages only. Access to production systems and Scan Data restricted to the founder, with two-factor authentication on all provider accounts. Sub-processors bound by DPAs. Raw results deleted within 90 days; deletion honoured on instruction per clause 7.

This DPA is published for review and execution. It has been prepared carefully but is pending review by counsel; if your legal team has queries or required amendments, email[email protected].

Who you're dealing with

ConformWatch is built by an independent founder. Support is answered by a human.

There's no support portal and no tier-one script. If something breaks, you email me and I fix it. If you ask for something the product can't do, I'll say so rather than put it on a roadmap slide.

Get in touch

  • [email protected]
  • Send me a client site and I'll scan it

On this page

  • The report
  • How it works
  • What automated monitoring can't do
  • Pricing

Copyright © 2026 ConformWatch. All rights reserved.

Operated by Letrix Labs, a trading name of Dime Corporation Ltd (13175488), registered in England & Wales.

124 City Road, London, EC1V 2NX, United Kingdom.

  • Terms of Service
  • Privacy Policy
  • Data Processing Agreement