Effective date: 13 July 2026 Version: 1.0
This Data Processing Agreement ("DPA") forms part of the a11yfy Terms of Service (the "Agreement") between:
- Controller: the customer accepting the Agreement (the "Customer"); and
- Processor: Zoltan Csordas E.V., Malom utca 11/1, 2367 Újhartyán, Hungary, operating the a11yfy platform ("a11yfy").
It reflects the parties' agreement with regard to the processing of personal data by a11yfy on behalf of the Customer, as required by Article 28 of Regulation (EU) 2016/679 ("GDPR"). It applies to Customers that act as a controller (or as a processor on behalf of a third-party controller) of personal data contained in documents they submit to the Service.
1. Definitions
Terms such as "personal data", "processing", "data subject", "controller", "processor", "sub-processor", and "personal data breach" have the meanings given in the GDPR. "Customer Data" means personal data contained in documents uploaded by the Customer to the Service and in the output files generated from them.
2. Subject matter, duration, nature and purpose of processing
| Item | Description |
|---|---|
| Subject matter | Automated accessibility analysis and remediation of documents uploaded by the Customer |
| Duration | The term of the Agreement, plus the retention periods in Section 9 |
| Nature of processing | Storage, layout and text analysis (including OCR), AI-assisted generation of accessibility metadata (e.g. alternative texts, document structure), validation, generation and delivery of remediated output files and conformance certificates |
| Purpose | Providing the a11yfy document-remediation service as described in the Agreement |
| Types of personal data | Any personal data contained in Customer documents (determined by the Customer; typically names, contact details, identification numbers, or financial data) |
| Categories of data subjects | Determined by the Customer (typically employees, customers, citizens, or other persons referred to in the documents) |
The Customer acknowledges that a11yfy has no knowledge of, or control over, the content of uploaded documents, and warrants that it has a lawful basis for the processing of all personal data contained in them.
The Service is not designed or intended for the processing of special categories of personal data (Article 9 GDPR) or personal data relating to criminal convictions and offences (Article 10 GDPR). The Customer shall not upload documents containing such data except as expressly permitted under the Agreement, and remains solely responsible for the content of its uploads.
3. Instructions
a11yfy shall process Customer Data only on the Customer's documented instructions, including with regard to transfers to third countries, unless required to do so by EU or Member State law (in which case a11yfy shall inform the Customer before processing, unless the law prohibits it). The Agreement, this DPA, and the Customer's use of the Service's features constitute the Customer's complete documented instructions. a11yfy shall inform the Customer if, in its opinion, an instruction infringes the GDPR.
4. Confidentiality
a11yfy ensures that persons authorised to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and access Customer Data only to the extent required to provide and support the Service.
5. Security (Art. 32 GDPR)
a11yfy implements and maintains appropriate technical and organisational measures, including:
- encryption of Customer Data in transit (TLS 1.2+) and at rest;
- logical access controls, scoped API keys, and role-based access within the platform;
- audit logging of security-relevant events;
- network-level isolation of the processing infrastructure; processing compute located in EU data centres;
- automatic deletion schedules for input documents, output files, and intermediate processing caches, as described in the Privacy Policy and the documentation (as updated from time to time); in any event, Customer Data associated with a completed processing job is deleted no later than 90 days after job completion;
- exclusion of Customer Data from error-diagnostics telemetry (no document content or PII in crash reports);
- a contractual and technical commitment that Customer Data is never used to train AI models.
6. Sub-processors
6.1 General authorisation. The Customer grants a11yfy general written authorisation to engage sub-processors in the following categories:
| Category | Purpose | Location |
|---|---|---|
| Cloud infrastructure and storage providers | Hosting, storage, CDN, security | EU data centres (US-headquartered providers) |
| Document-conversion compute providers | Isolated execution of the remediation pipeline | EU |
| Specialised document-analysis and AI service providers | Layout analysis, OCR, AI-generated accessibility descriptions | EU and USA |
| Error-diagnostics providers | Technical error reports (configured to exclude personal data) | EU ingest (US parent) |
A current, detailed list of engaged sub-processors is available on request at support@a11yfy.com.
6.2 Notice and objection. Customers may subscribe to notifications of sub-processor changes by emailing support@a11yfy.com with the subject "Subscribe to sub-processor updates" (or through any successor mechanism announced in the documentation). a11yfy shall give notice of any intended addition or replacement of a sub-processor at least 14 days before it takes effect; notice given through the subscription mechanism constitutes notice under this DPA, and the Customer is responsible for subscribing. The Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection in good faith within 30 days, the Customer may terminate the affected part of the Service.
6.3 Flow-down. a11yfy imposes on each sub-processor, by contract, data-protection obligations materially equivalent to those in this DPA, and remains fully liable to the Customer for the performance of each sub-processor's obligations.
7. International transfers
Customer Data is processed primarily in EU data centres. Where a sub-processor processes personal data outside the European Economic Area (in particular, US-based specialised document-analysis and AI providers), the transfer is made under the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 (module 3, processor-to-processor, as applicable), supplemented where necessary by additional safeguards, or under another valid transfer mechanism pursuant to Chapter V GDPR (including, where applicable, an adequacy decision such as the EU–US Data Privacy Framework for certified recipients).
8. Personal data breach notification
a11yfy shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, in a timeframe that reasonably enables the Customer to comply with its own notification obligations under Article 33(1) GDPR. The notification shall include, to the extent then available: the nature of the breach, the categories and approximate volume of data and data subjects concerned, the likely consequences, the measures taken or proposed, and a contact point; where full details are not yet available, a11yfy may provide the information in phases as it becomes available. a11yfy shall cooperate with the Customer and take reasonable steps to mitigate the effects of the breach. Notification is not an acknowledgement of fault or liability.
9. Deletion and return
- Input documents, output files, and processing caches are deleted automatically in accordance with the deletion schedules described in the Privacy Policy and the documentation (as updated from time to time), and in any event no later than 90 days after completion of the relevant processing job. The Customer may delete documents earlier at any time via the application.
- Upon termination of the Agreement or deletion of the Customer's account, a11yfy shall delete all remaining Customer Data within the account-deletion schedule set out in the Privacy Policy (7-day grace period, then permanent erasure), unless EU or Member State law requires longer storage (e.g. billing records under tax law).
- Prior to deletion, the Customer may retrieve output files via the application or API (this constitutes return of the data in a structured, commonly used format).
10. Assistance
Taking into account the nature of the processing, a11yfy shall assist the Customer, by appropriate technical and organisational measures and insofar as possible, in fulfilling the Customer's obligations to respond to data-subject requests (Arts. 12–23 GDPR) and in ensuring compliance with Arts. 32–36 GDPR (security, breach notification, DPIAs, prior consultation), at the Customer's reasonable request. The Customer shall reimburse a11yfy's reasonable costs incurred in providing such assistance, except where the request results from a11yfy's breach of this DPA.
11. Audit
a11yfy shall make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 GDPR, and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to:
- at least 30 days' prior written notice, no more than once per 12-month period (except following a personal data breach or at the instruction of a supervisory authority);
- audits being conducted during business hours, without unreasonable disruption, and under confidentiality obligations;
- any auditor mandated by the Customer not being a competitor of a11yfy and being suitably qualified and independent;
- a11yfy first satisfying the request, where adequate, through existing documentation, third-party attestations, or written responses; an on-site inspection may be requested where such materials are not reasonably sufficient to demonstrate compliance, or where required by a supervisory authority.
The Customer bears the costs of any audit, including reimbursement of a11yfy's reasonable costs of supporting it.
12. Precedence and liability
In case of conflict between this DPA and the Agreement regarding the processing of personal data, this DPA prevails.
Liability under or in connection with this DPA is subject to the exclusions and limitations of liability in the Agreement, to the extent permitted by law. Any limitation of liability in the Agreement applies as a single aggregate limit to all claims arising under the Agreement and this DPA together, and the exclusion of indirect and consequential damages in the Agreement applies equally to claims under this DPA. a11yfy shall not be liable for a claim to the extent it arises from a11yfy processing Customer Data in accordance with the Customer's documented instructions. Nothing in this Section limits or excludes a11yfy's liability towards data subjects or competent supervisory authorities under applicable law.
Contact: support@a11yfy.com