Includoc, home

Data Processing Addendum

How Includoc processes personal data for customers: roles, instructions, security, subprocessors, breach notice, deletion, audits and data transfers.

Last updated

Not legal advice

Includoc provides evidence of automated and human accessibility checks. It is not legal advice and does not certify legal compliance.

This Data Processing Addendum ("DPA") is part of the Terms of Service or other written agreement between Includoc and the customer that uses the Service (the "Agreement"). It applies whenever Includoc processes Customer Personal Data on the customer's behalf. If this DPA conflicts with the Agreement about the processing of personal data, this DPA controls.

This DPA applies automatically when the customer accepts the Agreement. If your organization needs a signed copy, contact us.

1. Definitions

Capitalized terms not defined here have the meanings given in the Agreement.

  • "Customer" means the organization or person that has agreed to the Agreement.
  • "Customer Content" means documents, images, text and other materials that Customer or its users upload, link to or submit to the Service, materials collected from websites Customer has verified, and the fixed files, reports and other results produced from them.
  • "Customer Personal Data" means personal data or personal information in Customer Content that Includoc processes on Customer's behalf.
  • "Data Protection Laws" means all laws that apply to the processing of Customer Personal Data under the Agreement, including US state privacy laws such as the California Consumer Privacy Act, and, where they apply, the EU General Data Protection Regulation ("GDPR"), the UK GDPR and the Swiss Federal Act on Data Protection.
  • "Security Incident" means a breach of security that leads to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data.
  • "Subprocessor" means a third party that Includoc engages to process Customer Personal Data.
  • "Standard Contractual Clauses" means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914.
  • "UK Addendum" means the International Data Transfer Addendum to the Standard Contractual Clauses issued by the UK Information Commissioner.

Terms such as "controller," "processor," "data subject," "processing," "business" and "service provider" have the meanings given in Data Protection Laws.

2. Roles and scope

Customer is the controller of Customer Personal Data, or a processor acting for its own controller. Includoc is Customer's processor and service provider.

Includoc is a controller only for the personal data it uses to run its own business, such as account, billing, security and website analytics data, as described in its Privacy Policy. This DPA doesn't apply to that data.

Annex 1 describes the processing.

3. Customer's instructions

Includoc will process Customer Personal Data only on Customer's documented instructions. Those instructions are:

  • The Agreement and this DPA
  • Customer's use and configuration of the Service, such as uploading files, choosing a retention period, adding a website or ordering human verification
  • Other reasonable written instructions that are consistent with the Agreement

Includoc will tell Customer if it believes an instruction violates Data Protection Laws, unless the law prevents it from doing so. Includoc may process Customer Personal Data where the law requires it, after telling Customer where the law allows.

Customer's responsibilities. Customer is responsible for having a lawful basis for the processing, giving any notices and getting any permissions Data Protection Laws require for the Customer Personal Data it submits. Customer won't submit protected health information unless a business associate agreement is in place, and will avoid submitting sensitive personal data the Service doesn't need.

4. US privacy law commitments

As a service provider, Includoc will not:

  • Sell or share Customer Personal Data, as "sell" and "share" are defined in the California Consumer Privacy Act
  • Retain, use or disclose Customer Personal Data for any purpose other than providing the Service under the Agreement, or outside the direct business relationship with Customer
  • Combine Customer Personal Data with personal information it receives from other sources, except as Data Protection Laws allow

Includoc will comply with the obligations Data Protection Laws place on service providers and give Customer Personal Data the level of privacy protection those laws require. Includoc will tell Customer if it can no longer meet these obligations, and Customer may then take reasonable steps to stop and remedy any unauthorized processing. Includoc certifies that it understands and will comply with the restrictions in this section.

5. Confidentiality

Includoc will ensure that everyone it authorizes to process Customer Personal Data, including employees, contractors and the accessibility specialists who perform human verification, is bound by confidentiality obligations and has access only as needed to provide the Service.

6. Security

Includoc will put in place and maintain appropriate technical and organizational measures to protect Customer Personal Data, including those described in Annex 2. Includoc may update these measures, as long as the update doesn't materially reduce the overall protection of Customer Personal Data.

7. Subprocessors

Authorization. Customer gives Includoc general authorization to use the Subprocessors listed on the subprocessors page.

Notice of changes. Before a new Subprocessor starts processing Customer Personal Data, Includoc will update the subprocessors page and notify Customer by email at least 30 days in advance.

Objections. Customer may object to a new Subprocessor on reasonable data protection grounds during the notice period. Includoc will work with Customer in good faith to resolve the objection, for example by offering a way to use the Service without that Subprocessor. If we can't resolve it, Customer may end the affected part of the Service, and Includoc will refund any prepaid fees for the period after it ends.

Contracts. Includoc will have a written agreement with each Subprocessor that requires data protection no less protective than this DPA, to the extent it applies to the Subprocessor's service. Includoc remains responsible for its Subprocessors' performance of those obligations.

8. Assistance

  • Data subject requests. If Includoc receives a request from a data subject about Customer Personal Data, it will pass the request to Customer, unless the law prohibits that, and won't respond itself except to direct the person to Customer. The Service lets Customer delete and export Customer Content. Includoc will provide reasonable additional help where Customer can't respond using the Service alone.
  • Assessments and consultations. Includoc will give reasonable help with data protection impact assessments and consultations with authorities, taking into account the nature of the processing and the information available to Includoc.
  • Records. Includoc will keep the records of processing that Data Protection Laws require of it.

9. Security Incidents

Includoc will notify Customer without undue delay, and within 72 hours, after confirming a Security Incident that affects Customer Personal Data. The notice will describe, as far as the information is available:

  • What happened, and when
  • The categories and approximate amount of data and data subjects affected
  • The likely consequences
  • What Includoc has done and plans to do to address the incident and reduce harm
  • A contact for more information

If not all of the information is available at first, Includoc will provide it as it becomes available. Includoc will take reasonable steps to contain, investigate and remedy the incident and will cooperate with Customer's reasonable requests. Notice of a Security Incident is not an admission of fault or liability.

10. Deletion and return

During the Agreement. Customer can download its fixed files and reports and delete files at any time. Customer Content is deleted automatically under Customer's retention setting.

At the end of the Agreement. Includoc will delete Customer Personal Data within 30 days after the Agreement ends, unless the law requires Includoc to keep it. Customer can export its files and reports before then. Copies in backups are deleted as the backups expire on their normal schedule, and stay protected under this DPA until then. Records that don't contain document content, such as audit logs, may be kept for up to one year after the Agreement ends for audit and legal purposes.

11. Audits

Includoc will make available the information reasonably needed to show that it complies with this DPA. That includes its security overview, answers to reasonable security questionnaires (such as the HECVAT or SIG) and summaries of relevant policies. If Includoc obtains third-party certifications or audit reports, it will share them on request under confidentiality terms.

If that information isn't enough to show compliance, or a regulator requires it, Customer may audit Includoc's compliance with this DPA, subject to these conditions:

  • No more than once in any 12 months, unless after a Security Incident or at a regulator's request
  • With at least 30 days' written notice and an agreed scope and timing
  • During normal business hours, without unreasonably disrupting Includoc's operations
  • By Customer or an independent auditor bound by confidentiality
  • Without access to other customers' data
  • At Customer's own cost

12. International transfers

Includoc stores and processes Customer Personal Data in the United States.

European Economic Area. Where Customer's transfer of Customer Personal Data to Includoc is subject to the GDPR and isn't covered by another valid transfer mechanism, the Standard Contractual Clauses are incorporated into this DPA as follows:

  • Module Two (controller to processor) applies where Customer is a controller, and Module Three (processor to processor) applies where Customer is a processor.
  • Customer is the data exporter and Includoc is the data importer.
  • The optional docking clause in Clause 7 applies.
  • Under Clause 9, option 2 (general written authorization) applies, with the notice period in section 7 of this DPA.
  • The optional language in Clause 11 doesn't apply.
  • Under Clause 13, the competent supervisory authority is determined by Customer's establishment or representative under the GDPR.
  • Annex I is completed with the information in Annex 1 of this DPA, Annex II with Annex 2, and Annex III with the subprocessors page.

United Kingdom. Where the transfer is subject to the UK GDPR, the UK Addendum is incorporated into this DPA, with its tables completed using the information in this section and the Annexes.

Switzerland. Where the transfer is subject to the Swiss Federal Act on Data Protection, the Standard Contractual Clauses apply with the changes Swiss law requires, including treating the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority.

If the Standard Contractual Clauses or the UK Addendum conflict with this DPA, they control.

13. Health information

Includoc is not a business associate under HIPAA unless it has signed a business associate agreement with Customer. Customer won't submit protected health information unless a business associate agreement is in place. If one is signed, it controls for protected health information.

14. Education records

If Customer is an educational agency or institution subject to the Family Educational Rights and Privacy Act (FERPA) and submits education records, Includoc acts under Customer's direct control with respect to their use and maintenance, uses them only to provide the Service, and won't disclose them except as the Agreement and FERPA allow.

15. Liability and term

Each party's liability under this DPA is subject to the limitations in the Agreement, unless Data Protection Laws or the Standard Contractual Clauses provide otherwise.

This DPA stays in effect for as long as Includoc processes Customer Personal Data.

Annex 1: Description of the processing

ItemDescription
Subject matterProviding the Service under the Agreement
DurationThe term of the Agreement, plus the deletion period in section 10
Nature and purposeStoring, checking and analyzing documents for accessibility; adding text with OCR; AI-assisted suggestions for structure, reading order and alt text; tagging and repairing files; producing reports; human verification when ordered; crawling websites Customer has verified; and support
Data subjectsPeople whose personal data appears in Customer Content, such as residents, applicants, students, employees, officials and meeting participants; and Customer's authorized users
Personal dataWhatever appears in Customer Content, such as names, contact details, addresses, signatures, photographs and other information in public records; and the names and email addresses of Customer's users in reports and audit logs
Sensitive dataNot intended. Customer won't submit protected health information without a business associate agreement and should avoid submitting other sensitive data the Service doesn't need. Safeguards: short retention, isolated processing, access controls and the measures in Annex 2
FrequencyContinuous, for the duration of the Agreement
RetentionUnder Customer's retention setting: 7, 30, 90 or 365 days, with 30 days as the default, or until Customer deletes a file. Reports and records without document content are kept for Customer's audit trail
SubprocessorsAs listed on the subprocessors page

Annex 2: Security measures

  • Encryption: TLS for data in transit; encryption at rest for file storage and the database.
  • Storage: private storage buckets with no public access; upload and download links are signed and expire after 5 minutes.
  • Isolated processing: documents are parsed only inside isolated containers that run one job at a time as a non-root user, with a read-only file system apart from temporary space, limits on processing time and memory, and network access restricted to Includoc's storage and backend.
  • Credentials: no API keys in processing containers; each job gets short-lived, job-specific access; messages between containers and the backend are signed.
  • Malware scanning: every upload is scanned before processing.
  • Secrets management: all API keys are held in the backend's secret store, never in the browser or container images; keys are separate for each environment and rotated on a schedule; code is scanned for leaked secrets.
  • Access control: multi-factor authentication on all vendor and administrative accounts; least-privilege access; quarterly access reviews; support access to customer accounts is read-only and logged.
  • Audit logging: an append-only audit log records uploads, fixes, approvals, exception decisions and deletions.
  • AI processing: AI requests are routed only to Anthropic's Claude models through OpenRouter, with zero-data-retention routing, data collection refused, prompt logging off and training opted out. Customer Content is never used to train AI models.
  • Retention and deletion: automatic deletion under the retention schedule; "Delete now" removes stored files and document content on request.
  • Secure development: code review, automated dependency and code scanning, and automated accessibility and functional tests before changes are released.
  • Incident response: a documented incident response plan, with customer notice within 72 hours of confirming a Security Incident.
  • Monitoring: error monitoring, uptime monitoring and a public status page.

Annex 3: Subprocessors

The current list of Subprocessors, with what each does and where it processes data, is on the subprocessors page.

  • Terms of Service

    The terms that apply when you use Includoc to check, fix and report on the accessibility of PDF and Office documents.

  • Privacy Policy

    What personal information Includoc collects, why we collect it, how long we keep it, who processes it for us, and the choices and rights you have.

  • Subprocessors

    The providers Includoc uses to run its service, what each one does, the data it handles, where it processes data, and how we notify you of changes.

  • Trust and security

    How Includoc stores, protects and deletes your documents: US storage, encryption, short retention, isolated processing and no AI training on your files.