Third Party Index

Snapshot 18557

Document
Data processing addendum
URL
https://www.skynettechnologies.com/sites/default/files/dpa.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
554835 bytes
SHA-256 (raw)
f33ffb15c5c3b3d803218cc542f24a4e7d6ee055a29d75f5dd1d80fe8bbeec43
SHA-256 (normalized text)
97b1e3dbf2d5f9a855b5d54cd9f4f0c1dff92def0720672c94e54cb015d450ca

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Data Processing Agreement (DPA)

This Data Processing Agreement ("DPA") is entered into between Skynet Technologies USA
LLC, 9045 SW 79th Avenue, Gainesville, FL 32608, ("Processor") and the customer identified in
the applicable order, subscription or account registration for the All in One Accessibility
Services ("Controller" or "Customer").

This DPA forms part of, and is incorporated by reference into, the Skynet Technologies Terms &
Conditions. It takes effect on the date the Customer accepts the Terms & Conditions or first
uses the Services, whichever is earlier (the "Effective Date"), and remains in force for as long as
Skynet Technologies USA LLC processes personal data on behalf of the Customer.

Where the Customer has entered into a separate written agreement with Skynet Technologies
USA LLC that expressly incorporates this DPA, the Effective Date is the effective date of that
agreement.

1. Definitions

For the purposes of this Agreement:

   •   “Personal Data” means any information relating to an identified or identifiable natural
       person.

   •   “Processing” means any operation performed on Personal Data, such as collection,
       storage, use, disclosure, or deletion.

   •   “Sub-processor” means any third party engaged by the Processor to process Personal
       Data.

   •   “Data Protection Laws” means applicable laws including the EU GDPR, UK GDPR, Swiss
       FADP, CCPA/CPRA, and other relevant privacy regulations.

   •   “Services” means the provision of the All in One Accessibility solution by Skynet
       Technologies.

2. Subject Matter and Duration

This Agreement governs the Processing of Personal Data by the Processor on behalf of the
Controller in connection with the provision of the Services. The Agreement remains in effect for
as long as the Processor processes Personal Data on behalf of the Controller.

DPA version 2.0                                                Effective Date: September 07, 2026
3. Nature and Purpose of Processing

The Processor processes Personal Data of visitors to the Controller's website(s) solely for the
purpose of:

   •   Delivering the All in One Accessibility widget script and the Controller's widget
       configuration to the visitor's browser;

   •   Providing the accessibility features requested by a visitor (including screen-reader voice
       synthesis and language translation);

   •   Generating, storing and serving alternative text for images on the Controller's website
       that lack it; and

   •   Securing and troubleshooting the Services.

The Processor does not use such Personal Data for its own purposes, including analytics,
marketing or the training of AI models.

4. Types of Personal Data

   •   IP address, user agent and page URL, transmitted when the widget loads and when a
       visitor uses a feature (the IP address is not stored by the Processor);

   •   Text selected by a visitor for the screen-reader (text-to-speech) feature;

   •   Page text, where a visitor activates the translation or sign-language feature (transmitted
       from the visitor's browser directly to the third-party service, see Annex I Part B);

   •   Page URLs and image paths of the Controller's website, and the alternative text
       generated for those images, where these contain Personal Data.

Accessibility preferences chosen by a visitor are stored only in the visitor's browser and are not
transmitted to the Processor. No special categories of Personal Data are intended to be
processed; the Controller shall not deploy feature services on pages where such data would be
transmitted.

DPA version 2.0                                               Effective Date: September 07, 2026
5. Categories of Data Subjects

 Visitors to the Controller's website(s) on which the All in One Accessibility widget is installed.

6. Obligations of the Data Processor

The Processor shall:

   1. Instructions – Process Personal Data only on documented instructions from the
      Controller.

   2. Confidentiality – Ensure all persons authorized to process Personal Data are bound by
      confidentiality obligations.

   3. Security – Implement appropriate technical and organizational measures to protect
      Personal Data (see Annex II).

   4. Assistance – Assist the Controller in responding to data subject rights requests.

   5. Breach Notification – Notify the Controller without undue delay, and no later than 72
      hours, upon becoming aware of a Personal Data Breach.

   6. Data Deletion/Return – At the end of services, delete or return all Personal Data unless
      retention is required by law.

   7. Records – Maintain records of Processing activities as required by law.

   8. Data protection impact assessments – Assist the Controller, taking into account the
      nature of the Processing and the information available to the Processor, in carrying out
      data protection impact assessments and prior consultations with supervisory
      authorities under Articles 35 and 36 GDPR.

   9. Information and audits – Make available to the Controller all information necessary to
      demonstrate compliance with the obligations laid down in Article 28 GDPR and this
      DPA, and allow for and contribute to audits, including inspections, conducted by the
      Controller or an auditor mandated by the Controller. The Processor shall first satisfy
      audit requests by providing its current SOC 2 Type 2 report and written responses to
      reasonable questionnaires. Where these are insufficient to demonstrate compliance,
      the Controller may conduct an on-site or remote audit once per twelve (12) months, or
      additionally following a Personal Data Breach or at the request of a supervisory
      authority, on at least thirty (30) days' written notice, during normal business hours,

DPA version 2.0                                                Effective Date: September 07, 2026
        subject to reasonable confidentiality obligations and without unreasonable disruption
        to the Processor's operations. Each party bears its own costs.

   10. Unlawful instructions – Immediately inform the Controller if, in the Processor's opinion,
       an instruction infringes the GDPR or other Data Protection Laws.

7. Sub-processors

The Controller gives the Processor general authorisation to engage the sub-processors listed in
Annex I Part A. The Processor shall ensure that each sub-processor is bound by data-protection
obligations no less protective than those in this DPA, whether by written contract or by the sub-
processor's standard data-processing terms accepted by the Processor, and remains fully liable
to the Controller for the performance of the sub-processor's obligations.

The Processor shall give the Controller at least thirty (30) days' prior notice of any intended
addition or replacement of a sub-processor, by e-mail to the Controller's registered account e-
mail address, and shall publish the updated Annex I in the DPA on its website. The Controller
may object in writing within that period on reasonable, documented data-protection grounds. If
the parties cannot resolve the objection in good faith within thirty (30) days of the objection, the
Controller may terminate the affected Services without penalty, and the Processor shall refund
any prepaid fees for the period after termination.

Annex I Part B lists third-party services that are not sub-processors of the Processor: they are
contacted directly by the visitor's browser, only after the visitor activates the relevant feature,
and the Controller may disable each of them at any time through the widget settings or by
request to the Processor.

8. International Data Transfers

Any transfer of Personal Data to a third country outside the EEA, UK, or Switzerland shall be
subject to appropriate safeguards such as Standard Contractual Clauses (SCCs), the EU-U.S.
Data Privacy Framework, the UK Extension, or the Swiss-U.S. Data Privacy Framework, as
applicable.

9. Security Measures

The Processor applies a layered security program including, but not limited to:

   •    Data encryption in transit (TLS) and at rest.

DPA version 2.0                                                 Effective Date: September 07, 2026
   •   Strong access controls and 2FA.

   •   Regular backups and disaster recovery planning.

   •   Staff training on data protection and security.

Details are provided in Annex II – Security Measures.

10. Data Subject Rights

The Processor shall assist the Controller by appropriate technical and organizational measures,
insofar as possible, in fulfilling the Controller’s obligation to respond to requests from Data
Subjects (e.g., access, correction, erasure, portability, objection).

11. Termination

Upon termination of the Services, the Processor shall, at the Controller’s choice:

   •   Delete all Personal Data, or

   •   Return all Personal Data in a commonly used format.

The Processor will confirm deletion in writing, unless retention is required by law.

12. Governing Law

This Agreement is governed by and construed in accordance with the laws of the State of
Florida, United States, unless otherwise required by applicable Data Protection Laws.

DPA version 2.0                                               Effective Date: September 07, 2026
           Annex I:
           Part A — Sub-processors of Customer visitor data
Sub-              Description       Data processed                Location                           Transfer mechanism
processor
InMotion          Hosting of        Widget requests (IP           EU customers: Amsterdam, NL. EU customers data
Hosting           widget API,       address, page URL, user       Other than EU & India        remains in the EU.
                  configuration      agent), stored page URLs,     customers: Los Angeles /
                  and               image paths, alt text         Ashburn, USA.
                  database                                        Indian Customer: Mumbai

Cloudflare         CDN, DNS          Request metadata incl. IP     Global edge network;               EU-U.S. DPF
                  and web           address, in transit;                                             (Cloudflare, Inc. is
                  security in                                                                        certified) and
                  front of the                                                                       Cloudflare Customer
                  widget                                                                             DPA with SCCs.
                  servers

Google Cloud      Text-to-          Selected text of the page     Global;                            EU-U.S. DPF; Google
( Text-to-        Speech (TTS)      Only when a visitor                                              Cloud DPA with
Speech)           and AI            activates the screen reader                                      SCCs.
                  services for      feature from the widget.
                  Screen-
                  reader voice
                  synthesis

Microsoft         Generation        Image URLs and image          Global                             EU-U.S. DPF
Corporation       of alt text for   content from the                                                 (Microsoft
AI Azure          images            Customer's website (not                                          Corporation);
                  missing it        visitor data unless images                                       Microsoft Products
                                    depict people) - At crawl                                        and Services Data
                                    time, server-side; not                                           Protection
                                    triggered by visitors                                            Addendum
                                                                                                     incorporating EU
                                                                                                     Standard Contractual
                                                                                                     Clauses

           DPA version 2.0                                                 Effective Date: September 07, 2026
          Part B — Third-party services contacted directly by the visitor's browser (not sub-
          processors).
Service            Description     Data processed                Location                         Transfer mechanism

VLibras            Page text to    For the selected text only    Brazil only.                     N/A
(vlibras.gov.br)   be signed;      when user enable the Libras
— Brazilian        Only when a     feature.
Sign Language      visitor
                   activates the
                   Libras
                   feature

Google LLC         Live            Page text, IP address         Global;                          EU-U.S. Data Privacy
(Language          language                                                                       Framework (Google
Translate)         translation                                                                    LLC). Google acts as
                   - Only when                                                                    an independent
                   Live site                                                                      controller.
                   translation
                   add-ons
                   purchased
                   by website
                   owner and
                   the visitor
                   selects a
                   language.

          DPA version 2.0                                               Effective Date: September 07, 2026
Annex II – Security Measures

Skynet Technologies implements the following security measures:

   1. Organizational Security

               •   Designated Data Protection Officer (DPO).
               •   Staff confidentiality agreements.
               •   Regular data protection and security training.

   2. Technical Security

             • TLS encryption for all data in transit.
             • AES-256 encryption for stored data.
             • Role-based access with least-privilege principle.
             • Multi-factor authentication (MFA).
             • Regular vulnerability scanning and penetration testing.
   3. Operational Security

               •   Daily system monitoring and log review.
               •   Intrusion detection and prevention systems.
               •   Regular backups with secure storage.
               •   Business continuity and disaster recovery planning.

Execution. This DPA is binding on both parties from the Effective Date by virtue of its
incorporation into the Terms & Conditions and does not require signature to be effective. At the
Customer's request, the parties may additionally execute this DPA by signing below; a signed
copy confirms the agreement already in effect and, where the parties complete the fields below,
identifies the Customer entity and Effective Date for the Customer's records.

DPA version 2.0                                              Effective Date: September 07, 2026
Skynet Technologies USA LLC (Processor)

Name: __________________________

Title: __________________________

Signature: __________________________

Date: __________________________

For Controller (Client)

Legal entity name: ____________________________________________________

Name: __________________________

Title: __________________________

Signature: __________________________

Date: __________________________

DPA version 2.0                                         Effective Date: September 07, 2026