Legal

Data Processing Agreement

Last updated June 25, 2026Effective June 25, 2026Version 2.0

The short version: When HelpBob scans the sites you connect and generates accessibility fixes, we process that data on your behalf— you stay the controller, we are the processor. Our footprint is deliberately small: we scan your page content, generate JavaScript-based fixes and recommendations, and serve them from our CDN. We don’t collect your visitors’ form inputs and we don’t build profiles. This DPA sets out how we handle that data under GDPR Article 28: our obligations, our sub-processors, security, breach notification, the Standard Contractual Clauses for international transfers, and US state-privacy terms (including CCPA).

HelpBob is a product of Luna And The Stars LLC, a Delaware limited liability company. On this page, “HelpBob,” “we,” “us,” and “our” refer to Luna And The Stars LLC.

01Scope & roles

This Data Processing Agreement (“DPA”) forms part of the agreement between you (“Customer”) and Luna And The Stars LLC (a Delaware limited liability company) for your use of the Service (the “Agreement”), and governs our processing of personal data on your behalf. It applies where data-protection law — including the EU and UK General Data Protection Regulation (“GDPR”), the Swiss Federal Act on Data Protection (“FADP”), and applicable US state privacy laws — applies to that processing.

Who is whoFor the personal data contained in the sites you connect and in your end-users’ interactions, you are the controller and HelpBob is the processor. For data about you and your staff as our customer (your account, billing, and support data), HelpBob acts as an independent controller under its Privacy Policy; that data is outside the scope of this DPA. Where terms conflict, this DPA prevails over the Terms on data-protection matters, and the Standard Contractual Clauses prevail over this DPA.

02Definitions

“Personal data,” “processing,” “controller,” “processor,” “data subject,” and “personal data breach” have the meanings given in the GDPR. “Sub-processor” means any third party engaged by HelpBob to process personal data on Customer’s behalf. “Standard Contractual Clauses” (“SCCs”) means the clauses approved by the European Commission in Implementing Decision (EU) 2021/914 for the transfer of personal data to third countries. “UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under s.119A of the UK Data Protection Act 2018. Capitalized terms not defined here have the meaning given in the Agreement or, for the US state-privacy terms, in Annex IV.

03Details of the processing

The subject matter, duration, nature, purpose, types of personal data, and categories of data subjects are described in Annex I and summarized here:

  • Subject matter: provision of the HelpBob accessibility scanning, remediation, and audit-trail Service.
  • Duration: for the term of the Agreement, plus the retention period set out in Section 11 and the Privacy Policy.
  • Nature & purpose:periodically scanning (crawling) the web pages you connect, detecting accessibility barriers, generating JavaScript-based fixes and written recommendations, serving those fixes from HelpBob’s content delivery network (“CDN”), and maintaining a tamper-evident record of changes.
  • Types of personal data:(a) personal data that happens to be contained in the markup and content of the pages you connect (which may include identifiers, contact details, or other data your pages display); and (b) technical and log data generated when our CDN serves fixes to your visitors, including IP addresses, request metadata, user-agent strings, and timestamps. HelpBob does not collect end-user form submissions, does not set cookies on your visitors’ browsers through the fix code, and does not profile your visitors.
  • Categories of data subjects: your website visitors, customers, and other individuals whose data appears on the sites you connect.

04HelpBob's obligations as processor

HelpBob will:

  • Process personal data only on your documented instructions, including the Agreement and your configuration of the Service, unless required to act otherwise by law (in which case we will inform you, where legally permitted).
  • Immediately inform you if, in our opinion, an instruction infringes the GDPR or other applicable data-protection law (Article 28(3), final paragraph).
  • Ensure that persons authorized to process personal data are bound by appropriate confidentiality obligations.
  • Implement and maintain the technical and organizational measures set out in Annex II, appropriate to the risk.
  • Assist you, taking into account the nature of the processing and the information available to us, in responding to data-subject requests (Section 9) and in meeting your obligations on security, breach notification, data protection impact assessments, and prior consultation (Articles 32–36).
  • At your choice, delete or return personal data at the end of the provision of the Service, as set out in Section 11, except where retention is required by law.
  • Make available the information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, as set out in Section 12.

05Sub-processors

You provide general written authorizationfor HelpBob to engage sub-processors to deliver the Service. Each sub-processor is bound by data-protection obligations no less protective than those in this DPA, and HelpBob remains fully responsible for each sub-processor’s performance of its obligations.

A current list of sub-processors is maintained at helpbob.ai/subprocessors, where you can subscribe to email notifications of changes. We will give you at least 30 days’ prior notice of any intended addition or replacement of a sub-processor before that sub-processor begins processing your data, and you may object on reasonable data-protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the Service. The current sub-processors are listed in Annex III.

06Security measures

HelpBob maintains the technical and organizational measures set out in Annex II, including encryption of personal data in transit and at rest, access controls and least-privilege practices, segregation of environments, logging and monitoring, secure development practices, vulnerability management, and regular review of these measures. We will not materially decrease the overall protection of personal data during the term of the Agreement.

07Personal data breaches

HelpBob will notify you without undue delay after becoming aware of a personal data breach affecting personal data processed on your behalf. The notification will, to the extent reasonably available to us, describe the nature of the breach (including, where possible, the categories and approximate number of data subjects and records concerned), the likely consequences, and the measures taken or proposed to address it. We will provide further information as it becomes available so you can meet your own notification obligations. Our notification is not an acknowledgement of fault or liability.

08International transfers

All personal data processed under this DPA is stored within the European Economic Area (EEA) (see Annex III). Where processing nevertheless involves a transfer of personal data to, or remote access from, a country outside the EEA, the UK, or Switzerland without an adequacy decision — including access by HelpBob from the United States — the following apply:

  • EEA transfers. The SCCs are incorporated into this DPA by reference, with HelpBob as data importer and Customer as data exporter. Module Two (Controller to Processor) applies, with the following selections:
    • Clause 7 (docking clause): applies.
    • Clause 9(a): Option 2 (general written authorisation), with the 30-day notice period in Section 5.
    • Clause 11(a) optional independent dispute-resolution language: does not apply.
    • Clause 17 (governing law): the law of Ireland.
    • Clause 18(b) (forum and jurisdiction): the courts of Ireland.
    • Annexes I, II, and III to the SCCs are populated by Annexes I, II, and III of this DPA.
  • UK transfers. The UK Addendum applies, with the SCCs as its base, the version of the Approved Addendum in force, Customer as exporter and HelpBob as importer, and the UK as the governing jurisdiction for UK data.
  • Swiss transfers. The SCCs apply with the amendments necessary under the FADP: references to the GDPR also refer to the FADP, the competent authority is the Swiss Federal Data Protection and Information Commissioner, and the Clauses also protect the data of legal entities until the FADP no longer requires it.
  • Future adequacy / Data Privacy Framework. If and when HelpBob self-certifies under the EU-US Data Privacy Framework (and its UK Extension and Swiss-US framework), transfers to HelpBob will primarily rely on that framework, and the SCCs and UK Addendum will continue to apply as a fallback. No amendment to this DPA is required for that change to take effect.

Where there is a conflict between this DPA and the SCCs or UK Addendum, the SCCs or UK Addendum prevail.

09Assistance with data-subject requests

Taking into account the nature of the processing, HelpBob will assist you by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, and objection). If we receive such a request directly relating to your data, we will not respond to it ourselves except on your instructions or as legally required, and will instead direct the individual to you without undue delay.

10Customer's responsibilities

You, as controller, represent and warrant that:

  • you have a valid legal basis for the processing of the personal data contained in the sites you connect, and have provided all notices and obtained all consents required for HelpBob to process that data as described in this DPA;
  • your instructions to HelpBob comply with applicable data-protection law; and
  • you are responsible for the personal data present in the markup and content of the sites you connect, including ensuring that connecting them to the Service is lawful.

HelpBob is not responsible for personal data that you place, or permit third parties to place, on your connected sites, beyond processing it in accordance with this DPA.

11Return & deletion of data

On termination or expiry of the Agreement, HelpBob will, at your choice, delete or return the personal data processed on your behalf and delete existing copies, unless storage is required by law. You may make that choice at any time up to 30 days after termination; absent a choice, we will delete the data after that period.

The tamper-evident audit trail — which you may need to demonstrate past conformance — is retained for up to 12 months after termination and then deleted, unless you instruct earlier deletion or longer retention is required by law.

12Audits

HelpBob will make available the information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to the following:

  • audits take place no more than once in any 12-month period, except where required by a supervisory authority or following a personal data breach;
  • you give at least 30 days’ prior written notice;
  • audits occur during business hours, without unreasonable disruption, and subject to reasonable confidentiality and security conditions;
  • HelpBob may satisfy an audit request by providing third-party audit reports, certifications, or a completed security questionnaire (such as SOC 2 or ISO/IEC 27001) where these are available, in lieu of an on-site audit; and
  • each party bears its own costs, unless the audit reveals a material non-compliance by HelpBob, in which case HelpBob bears the reasonable costs of the audit.

13Aggregated & de-identified data

HelpBob may create aggregated, anonymized, or de-identified data from the processing and use it, as an independent controller, to operate, develop, secure, and improve the Service — including training and improving its accessibility-detection and remediation models, benchmarking, and analytics — provided such data does not identify, and cannot reasonably be used to identify, you or any data subject. Such data is not personal data and is outside the scope of this DPA, and HelpBob will not attempt to re-identify it.

14US state privacy terms

Where the California Consumer Privacy Act (CCPA/CPRA) or another applicable US state privacy law governs personal information HelpBob processes on your behalf, the terms in Annex IV apply. In summary, HelpBob acts as your service provider(or “processor” / “contractor” under the relevant law), processes personal information only for the limited purposes of providing the Service, and does not sell or share personal information.

15Liability & precedence

Each party’s liability under this DPA and the SCCs is subject to the limitations and exclusions of liability set out in the Terms, and any amounts payable under this DPA count toward — and do not increase — the aggregate liability cap in the Terms. Nothing in this section limits any data subject’s rights under the SCCs. This DPA is the parties’ complete agreement on the processing of personal data on Customer’s behalf and supersedes any prior data-processing arrangements between them for the Service.

16Government & law-enforcement requests

If HelpBob receives a legally binding request from a public authority or law-enforcement body for personal data processed on your behalf, HelpBob will, unless legally prohibited: notify you before disclosure (or as soon as permitted); review the legality of the request and challenge it where it appears unlawful or overbroad; and disclose only the minimum amount of personal data necessary to respond. HelpBob does not grant any government or authority direct or unfettered access to personal data processed on your behalf.

17Accepting this DPA

This DPA is incorporated into and forms part of the Agreement; by using the Service you accept it (click-acceptance). If your organization requires a countersigned copy or has specific data-protection requirements, contact [email protected] and we will be glad to provide one.

18Annex I — Description of processing

(populates Annex I of the SCCs)

A. List of parties

Data exporter (controller):the Customer identified in the Agreement. Contact: the account or billing contact in the Customer’s account. Role: controller.

Data importer (processor): Luna And The Stars LLC, 8 The Green, Suite B, Dover, DE 19901, United States. Contact: [email protected]. Role: processor.

B. Description of the transfer

  • Categories of data subjects:the Customer’s website visitors, customers, and other individuals whose personal data appears on, or interacts with, the sites the Customer connects to the Service.
  • Categories of personal data:(a) personal data contained in the markup and content of the connected pages (which may include names, contact details, and other identifiers the Customer’s pages display); and (b) technical and log data, including IP addresses, user-agent strings, request metadata, and timestamps generated when the CDN serves fixes.
  • Special categories of data: none are intended to be processed. The Customer must not connect sites whose content is designed to expose special-category data to the Service without first contacting HelpBob.
  • Frequency of the transfer: on a continuous basis (periodic scans plus on-request delivery of fixes) for the term of the Agreement.
  • Nature and purpose of processing: scanning connected pages, detecting accessibility barriers, generating and serving JavaScript-based fixes and recommendations, and maintaining a tamper-evident audit trail — for the purpose of providing the Service.
  • Retention:for the term of the Agreement; the audit trail for up to 12 months after termination (Section 11); otherwise deleted or returned at the Customer’s choice.
  • Sub-processors: as listed in Annex III; the subject matter, nature, and duration of their processing is the hosting, storage, and CDN delivery described above.

C. Competent supervisory authority

Consistent with Clause 13 SCCs and the Customer’s place of establishment, the competent supervisory authority is the lead EEA supervisory authority for the Customer; where the Customer is not established in the EEA but falls within the GDPR, the supervisory authority of the EEA member state of the Customer’s Article 27 representative.

19Annex II — Technical and organizational measures

(populates Annex II of the SCCs)

HelpBob maintains the following measures. They are reviewed periodically and updated as the Service evolves; HelpBob will not materially reduce the overall level of protection during the term.

  • Encryption. Personal data is encrypted in transit using TLS 1.2 or higher. Personal data stored by HelpBob is encrypted at rest.
  • Access control. Access to systems and personal data follows least-privilege and role-based principles, with unique accounts and multi-factor authentication for administrative access. Access is reviewed periodically and revoked promptly on role change or departure.
  • Environment segregation. Production, staging, and development environments are logically separated; production personal data is not used in non-production environments.
  • Network & infrastructure security. Firewalls and restricted network access protect the hosting environment; administrative access is limited to authorized personnel over secured channels.
  • Logging & monitoring. Relevant system and access events are logged and monitored to detect and respond to anomalies and security events.
  • Secure development. Changes follow a secure development lifecycle, including peer code review and dependency/patch management.
  • Vulnerability management. Systems are patched on a risk-based schedule; HelpBob performs or commissions periodic security testing.
  • Resilience & backups. Personal data is backed up regularly; backups are stored within the EEA and restoration is tested periodically.
  • Pseudonymization & minimization. HelpBob limits the personal data it processes to what is necessary for the Service and applies pseudonymization where feasible.
  • Personnel. Personnel with access to personal data are bound by confidentiality obligations and receive security awareness guidance.
  • Sub-processor management. Sub-processors are subject to data-protection obligations no less protective than those in this DPA and are assessed before engagement.
  • Physical security. Physical and environmental security of the hosting and CDN infrastructure is provided by the sub-processors in Annex III under their respective certifications.
  • Incident response. HelpBob maintains a process to identify, investigate, escalate, and remediate security incidents and to notify the Customer in accordance with Section 7.

20Annex III — Sub-processors

The following sub-processors process personal data on the Customer’s behalf. The current list, with a subscription option for change notifications, is at helpbob.ai/subprocessors.

Sub-processorRole / serviceLocation of processing
Hetzner Online GmbHCloud hosting and storage of application and scan dataGermany (EEA)
Webdock ApSCloud hosting and storageDenmark (EEA)
Cloudflare, Inc.Content delivery network (serving fixes; processes visitor IP addresses and request metadata)Global edge network; US-headquartered. Cloudflare is self-certified under the EU-US Data Privacy Framework and engaged under SCCs; EU data-localization options apply where configured.

21Annex IV — US state privacy terms

(CCPA and other US state laws)

This Annex applies to personal informationthat HelpBob processes on the Customer’s behalf where the CCPA or another applicable US state privacy law (including the Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, and successor or comparable laws) governs that processing. Capitalized terms used and not defined in this DPA have the meaning given in the applicable law.

  1. Roles. With respect to such personal information, the Customer is the Business (or controller) and HelpBob is the Service Provider(or processor/contractor). HelpBob processes personal information only on the Customer’s behalf to provide the Service.
  2. Limited purpose. HelpBob will process personal information solely for the Business Purpose(s) of providing, securing, and improving the Service as set out in the Agreement and this DPA, and for no other purpose.
  3. No sale or sharing. HelpBob will not Sell and will not Share personal information, and will not retain, use, or disclose personal information (a) for any purpose other than the Business Purposes specified above, including outside the direct business relationship between the parties, or (b) for its own commercial purposes other than performing the Service — except as permitted by the applicable law.
  4. No combining. HelpBob will not combine personal information received under the Agreement with personal information it receives from, or on behalf of, others, or collects from its own interactions with individuals, except as permitted by the applicable law to perform a Business Purpose.
  5. Certification. HelpBob certifies that it understands the restrictions in this Annex and will comply with them.
  6. Compliance & remediation.HelpBob will provide the level of privacy protection required by the applicable law. The Customer may take reasonable and appropriate steps to confirm HelpBob’s compliance and, on notice, to stop and remediate unauthorized use of personal information. HelpBob will notify the Customer without undue delay if it determines it can no longer meet its obligations under the applicable law.
  7. Assistance & consumer requests.HelpBob will assist the Customer, taking into account the nature of the processing, in responding to verifiable consumer requests (such as access, deletion, correction, and opt-out) and in meeting the Customer’s obligations under the applicable law.
  8. De-identified data. Where HelpBob uses de-identified data (Section 13), it will maintain and use that data in de-identified form and will not attempt to re-identify it, consistent with the applicable law.
Need a countersigned copy or have specific requirements? Write to [email protected]. Luna And The Stars LLC · 8 The Green, Suite B, Dover, DE 19901, United States.

Compliance you can prove, not just promise.

Start a free scan and see every accessibility issue on your site in under two minutes — with the paper trail to back it up.

No credit card · 30-day money-back guarantee