Snapshot 18557
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Data Processing Agreement (DPA)
This Data Processing Agreement ("DPA") is entered into between Skynet Technologies USA
LLC, 9045 SW 79th Avenue, Gainesville, FL 32608, ("Processor") and the customer identified in
the applicable order, subscription or account registration for the All in One Accessibility
Services ("Controller" or "Customer").
This DPA forms part of, and is incorporated by reference into, the Skynet Technologies Terms &
Conditions. It takes effect on the date the Customer accepts the Terms & Conditions or first
uses the Services, whichever is earlier (the "Effective Date"), and remains in force for as long as
Skynet Technologies USA LLC processes personal data on behalf of the Customer.
Where the Customer has entered into a separate written agreement with Skynet Technologies
USA LLC that expressly incorporates this DPA, the Effective Date is the effective date of that
agreement.
1. Definitions
For the purposes of this Agreement:
• “Personal Data” means any information relating to an identified or identifiable natural
person.
• “Processing” means any operation performed on Personal Data, such as collection,
storage, use, disclosure, or deletion.
• “Sub-processor” means any third party engaged by the Processor to process Personal
Data.
• “Data Protection Laws” means applicable laws including the EU GDPR, UK GDPR, Swiss
FADP, CCPA/CPRA, and other relevant privacy regulations.
• “Services” means the provision of the All in One Accessibility solution by Skynet
Technologies.
2. Subject Matter and Duration
This Agreement governs the Processing of Personal Data by the Processor on behalf of the
Controller in connection with the provision of the Services. The Agreement remains in effect for
as long as the Processor processes Personal Data on behalf of the Controller.
DPA version 2.0 Effective Date: September 07, 2026
3. Nature and Purpose of Processing
The Processor processes Personal Data of visitors to the Controller's website(s) solely for the
purpose of:
• Delivering the All in One Accessibility widget script and the Controller's widget
configuration to the visitor's browser;
• Providing the accessibility features requested by a visitor (including screen-reader voice
synthesis and language translation);
• Generating, storing and serving alternative text for images on the Controller's website
that lack it; and
• Securing and troubleshooting the Services.
The Processor does not use such Personal Data for its own purposes, including analytics,
marketing or the training of AI models.
4. Types of Personal Data
• IP address, user agent and page URL, transmitted when the widget loads and when a
visitor uses a feature (the IP address is not stored by the Processor);
• Text selected by a visitor for the screen-reader (text-to-speech) feature;
• Page text, where a visitor activates the translation or sign-language feature (transmitted
from the visitor's browser directly to the third-party service, see Annex I Part B);
• Page URLs and image paths of the Controller's website, and the alternative text
generated for those images, where these contain Personal Data.
Accessibility preferences chosen by a visitor are stored only in the visitor's browser and are not
transmitted to the Processor. No special categories of Personal Data are intended to be
processed; the Controller shall not deploy feature services on pages where such data would be
transmitted.
DPA version 2.0 Effective Date: September 07, 2026
5. Categories of Data Subjects
Visitors to the Controller's website(s) on which the All in One Accessibility widget is installed.
6. Obligations of the Data Processor
The Processor shall:
1. Instructions – Process Personal Data only on documented instructions from the
Controller.
2. Confidentiality – Ensure all persons authorized to process Personal Data are bound by
confidentiality obligations.
3. Security – Implement appropriate technical and organizational measures to protect
Personal Data (see Annex II).
4. Assistance – Assist the Controller in responding to data subject rights requests.
5. Breach Notification – Notify the Controller without undue delay, and no later than 72
hours, upon becoming aware of a Personal Data Breach.
6. Data Deletion/Return – At the end of services, delete or return all Personal Data unless
retention is required by law.
7. Records – Maintain records of Processing activities as required by law.
8. Data protection impact assessments – Assist the Controller, taking into account the
nature of the Processing and the information available to the Processor, in carrying out
data protection impact assessments and prior consultations with supervisory
authorities under Articles 35 and 36 GDPR.
9. Information and audits – Make available to the Controller all information necessary to
demonstrate compliance with the obligations laid down in Article 28 GDPR and this
DPA, and allow for and contribute to audits, including inspections, conducted by the
Controller or an auditor mandated by the Controller. The Processor shall first satisfy
audit requests by providing its current SOC 2 Type 2 report and written responses to
reasonable questionnaires. Where these are insufficient to demonstrate compliance,
the Controller may conduct an on-site or remote audit once per twelve (12) months, or
additionally following a Personal Data Breach or at the request of a supervisory
authority, on at least thirty (30) days' written notice, during normal business hours,
DPA version 2.0 Effective Date: September 07, 2026
subject to reasonable confidentiality obligations and without unreasonable disruption
to the Processor's operations. Each party bears its own costs.
10. Unlawful instructions – Immediately inform the Controller if, in the Processor's opinion,
an instruction infringes the GDPR or other Data Protection Laws.
7. Sub-processors
The Controller gives the Processor general authorisation to engage the sub-processors listed in
Annex I Part A. The Processor shall ensure that each sub-processor is bound by data-protection
obligations no less protective than those in this DPA, whether by written contract or by the sub-
processor's standard data-processing terms accepted by the Processor, and remains fully liable
to the Controller for the performance of the sub-processor's obligations.
The Processor shall give the Controller at least thirty (30) days' prior notice of any intended
addition or replacement of a sub-processor, by e-mail to the Controller's registered account e-
mail address, and shall publish the updated Annex I in the DPA on its website. The Controller
may object in writing within that period on reasonable, documented data-protection grounds. If
the parties cannot resolve the objection in good faith within thirty (30) days of the objection, the
Controller may terminate the affected Services without penalty, and the Processor shall refund
any prepaid fees for the period after termination.
Annex I Part B lists third-party services that are not sub-processors of the Processor: they are
contacted directly by the visitor's browser, only after the visitor activates the relevant feature,
and the Controller may disable each of them at any time through the widget settings or by
request to the Processor.
8. International Data Transfers
Any transfer of Personal Data to a third country outside the EEA, UK, or Switzerland shall be
subject to appropriate safeguards such as Standard Contractual Clauses (SCCs), the EU-U.S.
Data Privacy Framework, the UK Extension, or the Swiss-U.S. Data Privacy Framework, as
applicable.
9. Security Measures
The Processor applies a layered security program including, but not limited to:
• Data encryption in transit (TLS) and at rest.
DPA version 2.0 Effective Date: September 07, 2026
• Strong access controls and 2FA.
• Regular backups and disaster recovery planning.
• Staff training on data protection and security.
Details are provided in Annex II – Security Measures.
10. Data Subject Rights
The Processor shall assist the Controller by appropriate technical and organizational measures,
insofar as possible, in fulfilling the Controller’s obligation to respond to requests from Data
Subjects (e.g., access, correction, erasure, portability, objection).
11. Termination
Upon termination of the Services, the Processor shall, at the Controller’s choice:
• Delete all Personal Data, or
• Return all Personal Data in a commonly used format.
The Processor will confirm deletion in writing, unless retention is required by law.
12. Governing Law
This Agreement is governed by and construed in accordance with the laws of the State of
Florida, United States, unless otherwise required by applicable Data Protection Laws.
DPA version 2.0 Effective Date: September 07, 2026
Annex I:
Part A — Sub-processors of Customer visitor data
Sub- Description Data processed Location Transfer mechanism
processor
InMotion Hosting of Widget requests (IP EU customers: Amsterdam, NL. EU customers data
Hosting widget API, address, page URL, user Other than EU & India remains in the EU.
configuration agent), stored page URLs, customers: Los Angeles /
and image paths, alt text Ashburn, USA.
database Indian Customer: Mumbai
Cloudflare CDN, DNS Request metadata incl. IP Global edge network; EU-U.S. DPF
and web address, in transit; (Cloudflare, Inc. is
security in certified) and
front of the Cloudflare Customer
widget DPA with SCCs.
servers
Google Cloud Text-to- Selected text of the page Global; EU-U.S. DPF; Google
( Text-to- Speech (TTS) Only when a visitor Cloud DPA with
Speech) and AI activates the screen reader SCCs.
services for feature from the widget.
Screen-
reader voice
synthesis
Microsoft Generation Image URLs and image Global EU-U.S. DPF
Corporation of alt text for content from the (Microsoft
AI Azure images Customer's website (not Corporation);
missing it visitor data unless images Microsoft Products
depict people) - At crawl and Services Data
time, server-side; not Protection
triggered by visitors Addendum
incorporating EU
Standard Contractual
Clauses
DPA version 2.0 Effective Date: September 07, 2026
Part B — Third-party services contacted directly by the visitor's browser (not sub-
processors).
Service Description Data processed Location Transfer mechanism
VLibras Page text to For the selected text only Brazil only. N/A
(vlibras.gov.br) be signed; when user enable the Libras
— Brazilian Only when a feature.
Sign Language visitor
activates the
Libras
feature
Google LLC Live Page text, IP address Global; EU-U.S. Data Privacy
(Language language Framework (Google
Translate) translation LLC). Google acts as
- Only when an independent
Live site controller.
translation
add-ons
purchased
by website
owner and
the visitor
selects a
language.
DPA version 2.0 Effective Date: September 07, 2026
Annex II – Security Measures
Skynet Technologies implements the following security measures:
1. Organizational Security
• Designated Data Protection Officer (DPO).
• Staff confidentiality agreements.
• Regular data protection and security training.
2. Technical Security
• TLS encryption for all data in transit.
• AES-256 encryption for stored data.
• Role-based access with least-privilege principle.
• Multi-factor authentication (MFA).
• Regular vulnerability scanning and penetration testing.
3. Operational Security
• Daily system monitoring and log review.
• Intrusion detection and prevention systems.
• Regular backups with secure storage.
• Business continuity and disaster recovery planning.
Execution. This DPA is binding on both parties from the Effective Date by virtue of its
incorporation into the Terms & Conditions and does not require signature to be effective. At the
Customer's request, the parties may additionally execute this DPA by signing below; a signed
copy confirms the agreement already in effect and, where the parties complete the fields below,
identifies the Customer entity and Effective Date for the Customer's records.
DPA version 2.0 Effective Date: September 07, 2026
Skynet Technologies USA LLC (Processor)
Name: __________________________
Title: __________________________
Signature: __________________________
Date: __________________________
For Controller (Client)
Legal entity name: ____________________________________________________
Name: __________________________
Title: __________________________
Signature: __________________________
Date: __________________________
DPA version 2.0 Effective Date: September 07, 2026