TagAudit

Data Processing Agreement

Last updated 5 August 2026 · Forms part of the Terms of Service

1. Roles

When you submit a website for scanning, you instruct us to capture what that site transmits. Whatever personal data the site leaks into its tracking belongs to that site's visitors. For that data, you are the controller and Edwin OÜ is your processor. You are responsible for having a lawful basis to have the site audited; that is why our Terms require you to own the site or have the owner's permission.

2. What processing this covers

3. Your instructions

We process this data only on your documented instructions. Submitting a scan is the instruction. We will not use the data for anything except producing your report — not analysis, not enrichment, not training, not sale. If we ever believe an instruction of yours breaks data protection law, we will tell you.

4. Confidentiality

Everyone who works on TagAudit and could access this data is bound by confidentiality obligations.

5. Security

We protect the data with measures appropriate to the risk (Article 32), including: masking identifying values before storage (see our Privacy Policy, section 3), encryption in transit, access controls, and automatic deletion of raw scan artefacts after 30 days. We treat masked evidence as personal data and protect it accordingly.

6. Sub-processors

You give us general written authorisation to use the sub-processors below. We will tell account holders by email at least 30 days before adding or replacing a sub-processor for this data; if you object on reasonable data protection grounds, you may close your account before the change takes effect.

Sub-processorWhat forWhereScan-artefact data?
HetznerHosting and running the serviceEU (Germany)Yes — hosts everything
AnthropicClassifying what kind of business a site is and naming page typesUnited StatesNo. Receives only page title, headline, meta description, language, currency, detected tool names and the URL — never page HTML, never captured tracking payloads or the personal data described in section 2
NeoSending sign-in emailsEUNo — account email only (controller-side; listed for completeness)

Paddle (our merchant of record) processes billing data as described in our Privacy Policy and is not a sub-processor of scan data.

7. Helping you with your obligations

8. Deletion and return

9. Showing you we comply

We will make available the information reasonably necessary to demonstrate compliance with this agreement — starting with this document, our Privacy Policy, and our processor list. If that is genuinely not enough, we will allow an audit, conducted reasonably: on notice, during business hours, no more than once a year, under confidentiality, and at your cost unless it uncovers a material breach.

10. International transfers

Where a sub-processor is outside the EEA, transfers rely on the European Commission's Standard Contractual Clauses.

11. Liability and precedence

Liability under this agreement follows section 11 of our Terms of Service. If this agreement and the Terms conflict about the processing it covers, this agreement wins. If this agreement conflicts with mandatory data protection law, the law wins.

12. Duration and law

This agreement applies for as long as we process scan data for you, and is governed by the law of Estonia, like our Terms.

Edwin OÜ, Jüri tee 18f, Karla küla, Rae vald, Harjumaa 75326, Estonia · Registry code 14178279 · privacy@analyticsdom.com