← Back to site

Data Processing Agreement

Operated by 1click2open · Effective 23 June 2026

This Data Processing Agreement is a template prepared for 1click2open and should be reviewed by qualified legal counsel before you rely on it.

This Data Processing Agreement ("DPA") forms part of the Terms & Conditions between you ("Customer", the controller) and 1click2open ("Proofwright", the processor), and applies where Proofwright processes personal data on the Customer's behalf — for example, data about the Customer's own client sites brought into the console. It reflects Article 28 of the EU General Data Protection Regulation (GDPR).

1. Roles & scope

The Customer is the controller (or a processor acting for its own clients) and Proofwright is the processor. Each party will comply with applicable data-protection law. The subject matter, duration, nature, purpose, data types and categories of data subject are set out in Annex I.

2. Processor obligations

Proofwright will:

  • Process personal data only on the Customer's documented instructions (including as set out in the Terms and this DPA), unless required by law, in which case it will inform the Customer where permitted.
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Implement the technical and organisational measures set out in Annex II (Art. 32).
  • Assist the Customer, as far as reasonably possible, with responding to data-subject requests and with its obligations under Arts. 32–36 (security, breach notification, impact assessments).
  • At the Customer's choice, delete or return personal data at the end of the services and delete existing copies, unless retention is required by law.
  • Make available the information reasonably necessary to demonstrate compliance and allow for audits under Section 6.

3. Sub-processors

The Customer gives general authorisation for Proofwright to engage the sub-processors listed in Annex III to provide the Service. Proofwright imposes data-protection obligations on each sub-processor no less protective than this DPA and remains liable for their performance. Proofwright will give at least 30 days' notice (by email or on this page) before adding or replacing a sub-processor, during which the Customer may object on reasonable data-protection grounds.

4. Security

Proofwright maintains the technical and organisational measures described in Annex II, including encryption in transit, hashed credentials, access control, tenant isolation, rate limiting, tamper-evident evidence logging and off-site backups.

5. Personal-data breaches

Proofwright will notify the Customer without undue delay, and in any event within 72 hours of becoming aware, of a personal-data breach affecting the Customer's data, with the information reasonably available to help the Customer meet its own obligations.

6. Audits

Proofwright will make available the information necessary to demonstrate compliance and, on reasonable prior notice and subject to confidentiality, allow audits (including inspections) by the Customer or an auditor it mandates, no more than once per year unless required by a supervisory authority.

7. International transfers

Where processing involves transferring personal data outside the European Economic Area, the parties rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), incorporated by reference and completed by the details in the Annexes, and/or other valid transfer mechanisms.

8. Liability & term

Each party's liability under this DPA is subject to the limitations in the Terms. This DPA remains in effect for as long as Proofwright processes personal data for the Customer.

Annex I — Details of processing

  • Subject matter: provision of the Proofwright CRA readiness and evidence Service.
  • Duration: the term of the Customer's subscription plus the retention period set out in the Privacy Policy.
  • Nature & purpose: hosting, inventorying, analysis, monitoring and evidence generation to support the Customer's CRA due diligence.
  • Data subjects: the Customer's personnel and, where the Customer brings such data in, its end clients' personnel (e.g. site administrators, security contacts).
  • Categories of data: names, business email addresses, account credentials, site and component identifiers, IP addresses, and any personal data present in submitted SBOMs, support messages or configuration. The Service is not intended for special-category data.

Annex II — Technical & organisational measures

  • Encryption of data in transit (TLS); credentials stored hashed.
  • Strict multi-tenant isolation; every read and write is ownership-scoped.
  • Role-based access control and least-privilege admin gating.
  • Rate limiting and abuse protection on authentication and public endpoints.
  • Tamper-evident, hash-sealed evidence logging.
  • Continuous, off-site, point-in-time backups of the evidence store.
  • Vulnerability monitoring and a coordinated-disclosure channel for the Service itself.

Annex III — Sub-processors

  • Cloudflare, Inc. — edge, Pages, D1 database, R2 backup storage and Access — United States / global edge.
  • The Fly.io Company — console application and evidence-store hosting — European Union.
  • Resend — transactional email — United States.
  • PayPal — payment processing — European Union / United States.

Contact

Questions about this DPA: connect@proofwright.eu.

Proofwright is a workflow and evidence tool — not legal advice, and a readiness score is not a determination of legal compliance. Please verify regulatory references independently.