Data Processing Agreement
Last updated: July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer", the data controller) and Aulys ("Processor") whenever Aulys processes personal data on your behalf under Art. 28 GDPR. If your organization requires a countersigned copy for its own records, contact privacy@aulys.com.
1. Subject matter and duration
Processing covers the personal data Customer submits to Aulys (account data, and any personal data incidentally captured in scanned page content or screenshots) for the duration of the Customer's subscription, plus any post-termination retention period described in Section 8.
2. Nature and purpose of processing
Aulys processes personal data solely to provide the Service: running accessibility scans on URLs the Customer submits, generating reports, and operating the Customer's account, billing, and support.
3. Processor obligations
- Process personal data only on the Customer's documented instructions.
- Ensure persons authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational security measures (Art. 32 GDPR).
- Assist the Customer in responding to data-subject rights requests.
- Notify the Customer without undue delay after becoming aware of a personal data breach.
4. Sub-processors
Customer authorizes Aulys to engage the following sub-processors, each bound by equivalent data-protection obligations:
- Supabase — authentication.
- Neon — primary database (AWS
us-east-1, United States). - Dodo Payments — billing and payment processing.
- Railway — API hosting.
- Vercel — web application hosting.
- PostHog — product analytics (consent-gated).
- Google Gemini / Groq — AI-generated remediation suggestions.
Aulys will notify Customer of any intended addition or replacement of sub-processors, giving Customer the opportunity to object.
5. International transfers
Where personal data is transferred outside the EEA (notably to the United States via the Neon database), the transfer is governed by the relevant sub-processor's Standard Contractual Clauses or another valid transfer mechanism under Chapter V GDPR.
6. Audit rights
Aulys will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA and will allow for audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable advance notice and confidentiality.
7. Deletion or return of data
Upon termination of the Service, Aulys will delete or return all personal data processed on Customer's behalf, unless applicable law requires continued storage.
8. Contact
Questions about this DPA: privacy@aulys.com.