This Data Processing Agreement is a template prepared for 1click2open and should be reviewed by qualified legal counsel before you rely on it.
This Data Processing Agreement ("DPA") forms part of the Terms & Conditions between you ("Customer", the controller) and 1click2open ("Proofwright", the processor), and applies where Proofwright processes personal data on the Customer's behalf — for example, data about the Customer's own client sites brought into the console. It reflects Article 28 of the EU General Data Protection Regulation (GDPR).
1. Roles & scope
The Customer is the controller (or a processor acting for its own clients) and Proofwright is the processor. Each party will comply with applicable data-protection law. The subject matter, duration, nature, purpose, data types and categories of data subject are set out in Annex I.
2. Processor obligations
Proofwright will:
- Process personal data only on the Customer's documented instructions (including as set out in the Terms and this DPA), unless required by law, in which case it will inform the Customer where permitted.
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement the technical and organisational measures set out in Annex II (Art. 32).
- Assist the Customer, as far as reasonably possible, with responding to data-subject requests and with its obligations under Arts. 32–36 (security, breach notification, impact assessments).
- At the Customer's choice, delete or return personal data at the end of the services and delete existing copies, unless retention is required by law.
- Make available the information reasonably necessary to demonstrate compliance and allow for audits under Section 6.
3. Sub-processors
The Customer gives general authorisation for Proofwright to engage the sub-processors listed in Annex III to provide the Service. Proofwright imposes data-protection obligations on each sub-processor no less protective than this DPA and remains liable for their performance. Proofwright will give at least 30 days' notice (by email or on this page) before adding or replacing a sub-processor, during which the Customer may object on reasonable data-protection grounds.
4. Security
Proofwright maintains the technical and organisational measures described in Annex II, including encryption in transit, hashed credentials, access control, tenant isolation, rate limiting, tamper-evident evidence logging and off-site backups.
5. Personal-data breaches
Proofwright will notify the Customer without undue delay, and in any event within 72 hours of becoming aware, of a personal-data breach affecting the Customer's data, with the information reasonably available to help the Customer meet its own obligations.
6. Audits
Proofwright will make available the information necessary to demonstrate compliance and, on reasonable prior notice and subject to confidentiality, allow audits (including inspections) by the Customer or an auditor it mandates, no more than once per year unless required by a supervisory authority.
7. International transfers
Where processing involves transferring personal data outside the European Economic Area, the parties rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), incorporated by reference and completed by the details in the Annexes, and/or other valid transfer mechanisms.
8. Liability & term
Each party's liability under this DPA is subject to the limitations in the Terms. This DPA remains in effect for as long as Proofwright processes personal data for the Customer.
Annex I — Details of processing
- Subject matter: provision of the Proofwright CRA readiness and evidence Service.
- Duration: the term of the Customer's subscription plus the retention period set out in the Privacy Policy.
- Nature & purpose: hosting, inventorying, analysis, monitoring and evidence generation to support the Customer's CRA due diligence.
- Data subjects: the Customer's personnel and, where the Customer brings such data in, its end clients' personnel (e.g. site administrators, security contacts).
- Categories of data: names, business email addresses, account credentials, site and component identifiers, IP addresses, and any personal data present in submitted SBOMs, support messages or configuration. The Service is not intended for special-category data.
Annex II — Technical & organisational measures
- Encryption of data in transit (TLS); credentials stored hashed.
- Strict multi-tenant isolation; every read and write is ownership-scoped.
- Role-based access control and least-privilege admin gating.
- Rate limiting and abuse protection on authentication and public endpoints.
- Tamper-evident, hash-sealed evidence logging.
- Continuous, off-site, point-in-time backups of the evidence store.
- Vulnerability monitoring and a coordinated-disclosure channel for the Service itself.
Annex III — Sub-processors
- Cloudflare, Inc. — edge, Pages, D1 database, R2 backup storage and Access — United States / global edge.
- The Fly.io Company — console application and evidence-store hosting — European Union.
- Resend — transactional email — United States.
- PayPal — payment processing — European Union / United States.
Contact
Questions about this DPA: connect@proofwright.eu.