TabToCart

Data Processing Agreement (summary)

Last updated: 25 September 2026

This DPA forms part of the Terms when TabToCart processes personal data on behalf of the customer (for example client contact emails entered for reports, or personal data incidentally visible on public pages of scanned websites), in accordance with Article 28 GDPR.

  1. Roles — The customer is the controller; Maxime Ragionieri, Entrepreneur individuel (EI), trading as TabToCart is the processor.
  2. Subject matter — Automated accessibility testing and reporting. Categories of data: business contact details of report recipients; personal data incidentally present on public web pages (screenshots, snippets). Data subjects: customer's staff and clients; persons named on public pages.
  3. Instructions — We process personal data only on documented instructions (the Terms and the product configuration).
  4. Confidentiality — Persons authorised to process data are bound by confidentiality.
  5. Security — Technical and organisational measures described in the Privacy Policy (encryption in transit, hashed credentials, isolation of scanners, access control, encrypted backups, retention limits).
  6. Sub-processors — The customer authorises the sub-processors listed below. We notify changes by email 30 days in advance; the customer may object and terminate.
    • Render Services, Inc. — Hosting of servers, database and backups — Frankfurt, Germany (EU); US company, Standard Contractual Clauses
    • Stripe Payments Europe Ltd. — Payments, invoicing, tax calculation — Ireland (EU); transfers under Stripe's DPA
    • Sendinblue SAS (Brevo) — Transactional and lifecycle emails — France (EU)
    • Cloudflare, Inc. (optional) — DNS, CDN, bot protection (Turnstile) — EU/US; EU-US Data Privacy Framework
  7. Assistance — We assist with data-subject requests and data-protection impact assessments as far as reasonably possible.
  8. Breaches — We notify the customer without undue delay and within 48 hours of becoming aware of a personal data breach.
  9. Deletion — On termination, data is deleted within 30 days (backups within 35 days), except where retention is legally required.
  10. Audits — We provide information necessary to demonstrate compliance; on-site audits at the customer's cost with 30 days' notice, once per year.
  11. Transfers — Data is hosted in the EU. Any transfer outside the EEA relies on an adequacy decision or Standard Contractual Clauses.

Contact: hello@tabtocart.com. A signed copy can be requested by email.