Data Processing Agreement
Last updated: September 2026
This Data Processing Agreement ("DPA") supplements the Audityxe Terms of Service and applies to the extent Audityxe processes personal data on your behalf as part of the audit tool.
1. Roles
For account data (email, plan tier, usage counters) you are the data controller and Audityxe is the data processor. For the URLs you submit for auditing, you are responsible for having the right to request an audit of that domain.
2. Scope of processing
- Account identifiers and authentication data, processed via Firebase Authentication.
- Usage and rate-limit counters, stored in Firestore.
- Submitted URLs and the public HTTP/HTML response fetched from them at request time.
3. Sub-processors
Audityxe uses Vercel for hosting and Google Firebase for authentication and data storage. See the Third-Party Services page for the full list.
4. Security measures
Data in transit is encrypted via TLS. Access to Firestore is restricted by security rules scoped to the authenticated account. Audit fetches are outbound-only and do not execute submitted page content.
5. Data deletion
Deleting your account removes your user and usage documents. Audit results are not retained after a response is returned, so there is nothing further to delete on that front.
6. Contact
For DPA questions, contact us via the Contact page.