Legal
Data processing agreement
These documents are templates under review. They are not legal advice. Provider details follow once the company is registered.
This agreement applies when a customer uses the Ambolt Link Checker cloud checks (a free account or a paid plan) and personal data is processed on the customer's behalf. It follows Article 28 of the General Data Protection Regulation (GDPR).
1. Parties and roles
- Controller: the customer who holds the account.
- Processor: Ambolt. Provider details follow once the company is registered. Contact: hello@ambolt.dev.
2. Subject, nature and purpose
The processor checks the links on the controller's websites, on a schedule or on request, and produces results, alerts and reports for the controller. Processing lasts while the account exists, and ends as set out in section 9.
3. Personal data and data subjects
- Data: page and link addresses found on the controller's sites (an address can contain a name or an identifier), the anchor text of links, and the controller's contact e-mail for alerts and reports.
- Data subjects: people named in link addresses or anchor text on the controller's sites, and the controller's own users of the account.
- No special categories of data are intended to be processed.
4. Instructions
The processor processes personal data only on the controller's documented instructions, which are these terms, the account settings and the plan. If an instruction appears to break data protection law, the processor says so.
5. Confidentiality and security
People who process the data are bound to confidentiality. The processor keeps appropriate technical and organisational measures under Article 32, including: hosting in the EU (Frankfurt), encryption in transit (HTTPS only), access limited to what operations need with key-only server access, no third-party scripts on the processor's sites, minimal logging, and deletion on schedule.
6. Sub-processors
The controller authorises these sub-processors:
- DigitalOcean (hosting, Frankfurt, EU)
- Cloudflare (network and DNS)
- Resend (alert and report e-mail, EU region)
- A merchant of record for billing, named when billing opens
The processor gives notice of a new sub-processor at least 30 days in advance on this page and in the changelog. The controller may object; if no solution is found, the controller may cancel and is refunded for the unused period.
7. Assistance
The processor helps the controller answer data subject requests and, where relevant, with security, breach notification and data protection impact assessments, taking into account the nature of the processing and the information available to the processor.
8. Personal data breaches
The processor notifies the controller without undue delay, and at the latest 48 hours after becoming aware of a breach that affects the controller's data, with the information available at that time.
9. Retention, deletion and return
Link addresses from cloud checks are kept for 30 days and then deleted. When the account ends, the processor deletes the controller's data within 30 days, unless law requires keeping it. Reports the controller has downloaded stay with the controller.
10. Transfers
Data is stored in the EU. Where a sub-processor processes data outside the EU or EEA, the transfer relies on an adequacy decision or the European Commission's standard contractual clauses.
11. Audits
The processor makes available the information needed to show compliance with this agreement, and allows for and contributes to reasonable audits, with notice and at the controller's cost.
12. Order of precedence
If this agreement conflicts with the terms of use, this agreement wins for the processing of personal data. It becomes part of the terms when billing opens. Agency customers may ask for a countersigned copy at hello@ambolt.dev.