Data Processing Addendum
Last updated 14 September 2026
Draft: this document has been prepared as a template and has not yet been reviewed by legal counsel. It will be finalised before Openwell accepts paying customers.
This Addendum forms part of the Terms of Service between Openwell (“Processor”) and the customer (“Controller”) and applies wherever Openwell processes personal data on the Controller's behalf.
1. Subject matter and duration
Processing of personal data contained in the websites the Controller designates for scanning, for the duration of the Controller's subscription plus the retention periods in the Privacy Policy.
2. Nature and purpose
Crawling and rendering designated pages; capturing markup, screenshots, and accessibility trees; analysing them for accessibility issues; generating proposed code changes; producing reports. No other purpose.
3. Categories of data and data subjects
Whatever personal data appears on the designated pages — typically names, contact details, or user-generated content of the Controller's site visitors, customers, or staff. The Controller should avoid designating authenticated pages that expose personal data unless necessary.
4. Processor obligations
- Process personal data only on the Controller's documented instructions (designating a site for scanning is an instruction).
- Ensure staff with access are bound by confidentiality.
- Implement appropriate technical and organisational measures (Annex 2).
- Engage sub-processors only under equivalent terms, and give 30 days' notice of changes (Annex 3).
- Assist the Controller with data-subject requests, impact assessments, and breach notifications; notify the Controller without undue delay, and within 72 hours, of a personal data breach.
- Delete or return all personal data at the end of the service, and delete existing copies unless law requires retention.
- Make available the information necessary to demonstrate compliance and allow audits on reasonable notice.
5. International transfers
[Placeholder: transfer mechanism and, where applicable, incorporation of the EU Standard Contractual Clauses (Module 2) / UK Addendum.]
Annex 1 — Processing details
As set out in sections 1–3.
Annex 2 — Technical and organisational measures
- Encryption in transit (TLS) and at rest.
- Tenant isolation enforced in the application and by database row-level security.
- Crawlers run network-isolated with private-address blocking.
- Role-based access within the customer organisation; platform administration behind a separate control.
- Rate limiting, audit logging, error monitoring, daily database backups with tested restore.
- Screenshots and page snapshots retained 90 days by default.
Annex 3 — Sub-processors
[Placeholder list, to be confirmed: Vercel (hosting), Fly.io (worker compute), Neon (database), Upstash (queue), Stripe (payments), Resend (email), Sentry (error monitoring), Anthropic (AI analysis of scan artefacts).]