Draft — not legal advice, and not yet reviewed by legal counsel.
This is a contract. It was drafted by the people who built the product so that it describes what the software actually does, and it has not been reviewed by a lawyer. It must be — together with the Standard Contractual Clauses referenced in clause 12 — before it is offered to a customer or relied on by one. Every [HIGHLIGHTED VALUE] is a blank the operator must still fill in.
1. Parties, roles and scope
This agreement is between the customer organisation that accepted it (the Controller) and [LEGAL ENTITY NAME], [REGISTERED ADDRESS] (the Processor). It governs the Processor's processing of personal data contained in Customer Content — principally screenshots, console output and page metadata captured from the websites the Controller configures.
It does not govern the Processor's own account, billing and usage data, for which the Processor is the controller; that processing is described in the Privacy Policy.
This agreement takes effect when the Controller creates an organisation or otherwise accepts the Terms of Service, and lasts as long as the Processor processes Customer Content.
2. Processing on documented instructions
The Processor processes Customer Content only on the Controller's documented instructions, which are: (a) this agreement and the Terms of Service; (b) the configuration the Controller creates in the product — the sites, environments, URLs, viewports, credentials, actions, schedules and AI setting; and (c) any job the Controller or its users queue.
The Processor will tell the Controller if, in its opinion, an instruction infringes data protection law, and may decline to act on it. The Processor will not process Customer Content for its own purposes, will not sell it, and will not use it to train machine-learning models.
3. Confidentiality of personnel
Everyone the Processor authorises to access Customer Content is bound by an obligation of confidentiality that survives the end of their engagement, and is granted access only where necessary to operate the service or to resolve a support request the Controller raised. Such access is recorded.
4. Security of processing
The Processor implements the technical and organisational measures set out in Annex II, taking account of the state of the art, the cost of implementation, and the risk to data subjects. The Processor may update those measures provided the level of protection is not reduced.
5. Sub-processors
The Controller gives the Processor general authorisation to engage the sub-processors listed in Annex III. The Processor will:
- impose on each sub-processor data-protection obligations no less protective than those in this agreement;
- remain fully liable to the Controller for a sub-processor's performance;
- give the Controller at least 30 days' notice by email before adding or replacing a sub-processor.
If the Controller reasonably objects to a new sub-processor within that period, the parties will discuss it in good faith; if no solution is found, the Controller may terminate the affected part of the service and receive a refund of the unused portion of any prepaid fees.
6. Data subject requests
Where a data subject contacts the Processor about Customer Content, the Processor will not respond substantively but will forward the request to the Controller without undue delay. The Processor will assist the Controller in responding, using the product's own export and deletion capabilities and, where those are insufficient, by reasonable manual assistance.
7. Personal data breaches
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Content, and in any event in time for the Controller to meet its own notification deadlines. The notification will describe the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed. The Processor will provide updates as the investigation progresses and will not delay an initial notification in order to complete it.
8. Assistance with impact assessments
Taking into account the nature of the processing and the information available to it, the Processor will provide reasonable assistance with data protection impact assessments and prior consultations with a supervisory authority. This document, the Privacy Policy and the completed security questionnaire the Processor maintains are intended to answer most such requests without a bespoke exercise.
9. Return and deletion
The Processor operates no automated deletion of Customer Content. Customer Content is retained for as long as the Controller's organisation exists and is deleted when the Controller deletes it — an individual run, a site, or the whole organisation — or when the Controller requests erasure. The retention period shown for the Controller's plan in Annex I is a minimum availability commitment by the Processor; it is not a deletion schedule and the Processor does not represent it as one.
Deletion of the organisation is available to the Controller self-serve, on every plan, without contacting the Processor. It executes after a grace period of 7 days, during which the Controller may cancel the request, and then permanently removes the organisation's users, sites, runs, screenshots, diff images, usage records and email-log entries.
Termination or cancellation of a subscription does not, by itself, delete Customer Content: the organisation moves to the free plan and its data remains available for export. On the Controller's written request the Processor will delete all Customer Content without undue delay and confirm the deletion in writing. The Controller may export at any time without assistance. The Processor may retain data where law requires it, for as long as that law requires, and will keep it protected and processed for no other purpose.
The one record the Processor does prune on a schedule is the audit log, which relates to use of the platform rather than to Customer Content. Audit records are pruned daily and retained for at least 30 days and at most 365 days, bounded by the Controller's plan retention period where that is shorter.
10. Information and audits
The Processor will make available the information necessary to demonstrate compliance with Article 28 — including this agreement, the Privacy Policy, the security description, and a completed security questionnaire on request.
Where the Controller requires an audit beyond that, the parties will agree its scope, timing and cost in advance. Audits are limited to once per year unless a supervisory authority or a substantiated breach requires otherwise, must be conducted during business hours, must not compromise other customers' confidentiality, and are at the Controller's cost.
11. AI analysis — an instruction you control
AI diff analysis is a processing operation the Controller switches on or off. When it is enabled, the Processor transmits the baseline image, the current image, the diff image and the page URL of the analysed result to the AI sub-processor named in Annex III. Nothing else about the Controller's account is transmitted.
An analysis is performed only when one is requested for a specific result. On a plan whose entitlements exclude AI diff analysis the platform refuses to perform one, and no Customer Content is transmitted for this purpose at all.
The switch. Every organisation, on every plan including the free plan, has a control that disables AI diff analysis entirely for that organisation. An administrator of the organisation sets it in the application under Configs → AI. It is not a paid feature and it is not tied to a plan.
While that switch is off, the platform refuses every AI analysis for the organisation on the server — a manual request, an automatic analysis following a comparison run, a queued analysis job, and any run started through the public API alike — and refuses it before any content leaves the platform, so no Customer Content whatsoever is transmitted to the AI sub-processor. The refusal overrides the plan: an organisation whose plan includes AI diff analysis still gets none while the switch is off. The setting is stored against the organisation and survives a change of plan, and each change to it is written to the audit log with the actor and the time.
Reading that record. The audit entry is written on every plan, without exception. Reading and exporting the audit log inside the application is a separate plan capability, available on the Agency plan and above (and during the trial), so a Controller on a lower plan has the record but cannot read it in the application. The Processor makes those entries available on request under clause 10. Nothing about the switch itself, or about the refusal it causes, depends on the plan.
Turning the switch off does not delete analyses already produced and stored before it was set; those are deleted with the run, the site or the organisation in the ordinary way described in clause 9. Separately, the Processor operates a deployment-wide setting that can suppress automatic analysis for everyone; that setting can only ever withhold analysis, never grant it, and never overrides the Controller's switch.
12. International transfers
Where the Processor or a sub-processor transfers Customer Content outside the European Economic Area, the transfer is made under the European Commission's Standard Contractual Clauses (Module Three, processor to processor, where applicable) together with the supplementary measures described in Annex II. The only transfer of captured page content outside the EEA is the AI analysis described in clause 11; it occurs only when an analysis is requested, and it does not occur at all for an organisation that has switched AI analysis off under that clause.
The Processor's public website also loads web fonts from Google, which discloses visitors' IP addresses to a US provider. That processing concerns website visitors, not Customer Content, and is described in the Privacy Policy; it is not a sub-processor of Customer Content and is therefore not listed in Annex III.
13. Liability and precedence
The limitations of liability in the Terms of Service apply to this agreement. If this agreement conflicts with the Terms of Service in respect of the processing of Customer Content, this agreement prevails. If it conflicts with the Standard Contractual Clauses, those Clauses prevail.
14. Annex I — details of processing
Subject matter and duration
Automated capture, storage, comparison and presentation of renderings of the Controller's nominated web pages, for as long as the Controller's organisation exists and until the Controller deletes the content or the organisation, or requests erasure under clause 9.
Nature and purpose
Visual regression testing and console-error monitoring of websites, including optional AI-assisted classification of visual differences.
Types of personal data
- Any personal data visible on the pages the Controller configures — for example names, photographs, job titles, contact details or user-generated content displayed on those pages, captured incidentally as part of the page image.
- Any personal data present in URLs, page titles or console messages of those pages.
- Authentication credentials the Controller supplies for an environment, where those identify a person.
Categories of data subjects
Determined entirely by the Controller's choice of pages: typically the Controller's own staff, its clients' staff, and visitors or members whose data appears on the captured pages.
Retention
Captured content is retained until the Controller deletes it or requests erasure (clause 9). The Processor runs no automated retention deletion. The figures below are the Processor's minimum availability commitment per plan — the period for which it undertakes to keep captured content available — and not periods after which content is destroyed:
| Plan | Minimum availability commitment |
|---|---|
| Free | 7 days |
| Starter | 30 days |
| Studio | 3 months |
| Agency | 6 months |
| Scale | 6 months |
15. Annex II — technical and organisational measures
- Encryption in transit. TLS for all access to the application, the API and the object storage.
- Access control. Every request is authenticated and authorised against the requesting user's organisation on the server. Roles are owner, admin and member. API keys are scoped and rate-limited.
- Tenant isolation. Sites, runs, screenshots, keys and audit records are bound to a single organisation; cross-organisation access is refused, and this is covered by an automated test suite that runs as a foreign organisation's admin.
- Secret handling. Passwords and API keys are stored only as hashes. Environment HTTP-auth and proxy credentials are write-only in the interface, never returned in plaintext by the API, and never logged.
- Screenshot confidentiality. Stored images are not publicly listed and are not served from guessable public URLs; they are served only to authenticated members of the owning organisation, and the product provides no public sharing mechanism.
- Logging and accountability. Significant actions are recorded in an audit log with actor, timestamp and source IP address.
- Segregation of duties. Only platform operators can reach production data, and only to operate the service or answer a raised support request.
- Resilience. [BACKUP FREQUENCY AND RETENTION]. Queued work survives a restart and is retried rather than dropped.
- Supplementary transfer measures. Content sent to the AI sub-processor is limited to the images and URL of a single analysed result, is not used for model training, and can be switched off entirely by the Controller — on every plan, self-serve, under Configs → AI in the application, enforced on the server for every path that could otherwise start an analysis (see clause 11).
- Deletion. Self-serve deletion of a run, a site or the whole organisation, on every plan, with a 7-day cancellable grace period before an organisation deletion executes. There is no automated per-plan retention deletion — see clause 9, which says so rather than implying otherwise.
- Assurance. The Processor holds no third-party security certification and has not commissioned a penetration test to date; it states this openly rather than implying otherwise.
16. Annex III — authorised sub-processors
| Sub-processor | Processing activity | Location |
|---|---|---|
| Stripe | Payments, subscription management and invoicing (billing data only — not Customer Content) | Ireland / United States |
| Anthropic (Claude) | AI classification of visual diffs, only while the Controller leaves AI analysis enabled under clause 11 — no content is sent while that switch is off | United States |
| [HOSTING PROVIDER AND REGION] | Hosting of the application, database and screenshot storage | [HOSTING REGION] |
| [EMAIL DELIVERY PROVIDER AND REGION] | Delivery of transactional email | [MAIL PROVIDER REGION] |
To subscribe to sub-processor change notices, or to request a countersigned copy of this agreement, write to [PRIVACY EMAIL].