Data Processing Agreement
When your agency uses Rampsight to monitor its clients’ websites, we process some personal data on your behalf. This agreement is our contract for that processing under Article 28 of the GDPR: what we do, what we promise, which providers we use, and how your data is protected and deleted. It forms part of the Terms of Service and needs no separate signature.
1. Parties and scope
This Data Processing Agreement (the “DPA”) is between the agency that holds a Rampsight account (the “Customer”) and Reuber Bruno Nunes Menezes, an individual established in Belo Horizonte, MG, Brazil, trading as Rampsight (“Rampsight”, the “Processor”). It forms part of the Terms of Service and applies whenever the Customer uses the Service to process personal data of its own clients or of end users, in which case the Customer acts as controller (or as processor on behalf of its clients) and Rampsight acts as its processor under Article 28 of the EU General Data Protection Regulation (GDPR).
The Customer’s own account data (names and emails of its team, company details) is processed by Rampsight as a controller, as described in the Privacy Policy; it is not the subject of this DPA.
2. Subject matter, duration, nature and purpose
- Subject matter: the automated accessibility monitoring service described in the Terms.
- Duration: the term of the Customer’s account, plus the deletion period in section 7.
- Nature and purpose: crawling and testing the websites the Customer registers, storing the results (issues, scores, page URLs and short HTML excerpts of failing elements), generating reports and accessibility statements under the Customer’s brand, hosting published statements, and providing team accounts and integrations (Slack, Jira, the public API) that the Customer configures.
- Instructions: Rampsight processes personal data only on the Customer’s documented instructions, which are the Terms, this DPA and the settings the Customer chooses in the product (for example which sites to scan and which statements to publish).
3. Categories of data subjects and personal data
Data subjects: members of the Customer’s team; contacts the Customer names in accessibility statements (for example an accessibility contact email of its client); and, incidentally, people whose personal data appears in the content of pages that are scanned (for instance a name on an “About us” page).
Personal data: names and email addresses of team members; URLs of registered sites and of pages found while crawling; short HTML excerpts of failing elements (which may incidentally contain personal data present on the page); statement contact details; issue references the Customer sends to Jira. Rampsight does not intend to collect special categories of data (Article 9 GDPR) and the Customer agrees not to register sites for the purpose of processing such data through the Service.
4. Rampsight's obligations as processor
- process personal data only on the Customer’s documented instructions, including regarding transfers outside the EEA, unless required by law (in which case Rampsight informs the Customer before processing, where the law allows);
- ensure that the people authorised to process the data are bound by confidentiality;
- implement the technical and organisational measures in section 8;
- engage subprocessors only under the conditions in section 6;
- assist the Customer, taking into account the nature of the processing, in responding to data-subject requests (access, rectification, erasure, portability, restriction, objection) — in practice, most requests can be fulfilled by the Customer directly in the product; for the rest, write to privacy@rampsight.com;
- assist the Customer with its obligations regarding security, breach notification and data protection impact assessments, given the information available to Rampsight;
- notify the Customer without undue delay, and in any case within 48 hours of becoming aware, of a personal data breach affecting the Customer’s data, with the information the Customer needs to meet its own notification duties;
- delete or return the personal data at the end of the service, as set out in section 7;
- make available the information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits (section 9).
5. Customer's obligations
- the Customer warrants that it has the right to have the registered websites scanned and monitored (see “Acceptable use” in the Terms) and a lawful basis for any personal data it processes through the Service;
- the Customer is responsible for the accuracy of the data it enters (for example statement contact details) and for what it publishes under its brand;
- where the Customer acts as processor for its own clients, it is responsible for having obtained their authorisation to engage Rampsight as a subprocessor.
6. Subprocessors
The Customer gives Rampsight general authorisation to engage the subprocessors below. Rampsight remains responsible for their performance and imposes data protection obligations on them that are no less protective than this DPA.
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Web application hosting | Global edge network |
| Supabase | Database (all customer data) | Frankfurt, EU |
| Railway | Scan worker and PDF rendering infrastructure | EU |
| Resend | Transactional email (sign-in, password reset, notifications) | Ireland, EU |
| GoDaddy | DNS and email routing | Global |
Rampsight informs the Customer at least 14 days before adding or replacing a subprocessor, by email or inside the product. The Customer may object on reasonable data protection grounds; if no solution is found, the Customer may terminate the account before the change takes effect, with a pro-rata refund of any prepaid, unused period. The current list is also kept in the Privacy Policy. The merchant of record (payments) is an independent controller, not a subprocessor.
7. Deletion and return of data
When the Customer deletes its account, or on written request after the account is closed, Rampsight deletes the personal data processed on the Customer’s behalf within 30 days; residual copies in encrypted backups expire within 90 days. Before deletion the Customer can export its data through the product (reports, statements and the public API). Rampsight keeps data only where EU or Member State law requires it, and only for as long as that law requires.
8. Technical and organisational measures
Taking into account the state of the art, the costs of implementation and the nature of the processing, Rampsight applies at least the following measures:
- encryption in transit (TLS) for every connection to the Service, the database and the subprocessors;
- customer data stored in an EU-hosted database with encryption at rest provided by the hosting platform;
- passwords stored only as salted hashes; sessions in httpOnly cookies; integration secrets (for example Jira API tokens) encrypted at rest with a key derived from a server secret;
- strict tenant isolation: every query is scoped to the account the request belongs to; API keys are stored as hashes;
- least-privilege access: only the operator and the systems that run the Service can reach production data, over authenticated channels;
- network safeguards on the scanner (private and internal addresses are never crawled) and on outbound integrations (allow-listed hosts only);
- regular encrypted backups by the database provider, expiring within 90 days;
- logging and monitoring of the application and the scan worker for errors and unusual activity.
9. Information and audits
On request, Rampsight provides the information reasonably necessary to demonstrate compliance with this DPA, including this document, the subprocessor list and a description of the security measures. Where that is not sufficient, the Customer (or an independent auditor bound by confidentiality) may audit Rampsight’s compliance once per year, with at least 30 days’ notice, during business hours, without disrupting the Service and at the Customer’s cost.
10. International transfers
Customer data is stored and processed in the EU (see the subprocessor list). Rampsight is operated from Brazil, so the operator may access personal data from outside the EEA for support, maintenance and security purposes. Such access takes place under the European Commission’s Standard Contractual Clauses (Module 2, controller to processor), which the parties incorporate into this DPA by reference, together with the measures in section 8. Any subprocessor located outside the EEA is bound by the same clauses.
11. Liability, term and governing law
Liability under this DPA is subject to the limitations in the Terms of Service, except where the GDPR does not allow such limits. This DPA applies for as long as Rampsight processes personal data on the Customer’s behalf. In case of conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails. The governing law and venue are those of the Terms. Questions about this DPA: privacy@rampsight.com.