Sub-processors
This document is complete in substance but still carries placeholders in square brackets for the registered entity, address and governing law. It has not yet been reviewed by a qualified lawyer in the relevant jurisdiction, and it is not legal advice.
In short: Six parties can technically see anything: Apple (purchases), our CDN (website traffic), our host (the API and queue), the model provider (screen content), our email relay (notification and support mail), and our own audit machine. Your build binary reaches only the last of those — it is never transmitted to the model provider or anyone else. We give 30 days' notice before adding a sub-processor, and you can object.
1. What this page is
Where we process personal data on your behalf (see Privacy Policy, section 12), Article 28(4) GDPR requires us to tell you who else is involved. This is that list. It is exhaustive: if a company is not named here, it has no access to customer data in the AccessProof pipeline.
2. The boundary that matters most
Your build binary never leaves the audit machine. The
.ipa travels from the macOS app to our API, is queued, and is
installed on a machine we own and control. It is not uploaded to the model
provider, not stored with a cloud object store, and not shared with any
party in the table below other than our host, which stores the bytes at
rest while the job is queued.
What the model provider receives is screen content: the accessibility tree of the screen currently on display, control labels and roles, and — where a judgement must be made visually — an image of that screen. That is a narrower surface than the build, and it is the minimum an audit can work from. Whatever your app renders during the run can be part of it, which is exactly why the Terms require a disposable demo account and non-production data.
3. The list
| Party | Role | What it can see | Location & transfer basis |
|---|---|---|---|
| Apple Inc. | App distribution, payment processing, merchant of record. | Your Apple Account, payment method and purchase history — none of which we see. We receive only a transaction identifier and a verification result. | United States and worldwide. Apple's own terms and transfer mechanisms apply; Apple is an independent controller for your purchase, not our processor. |
| Cloudflare, Inc. | DNS, TLS and static hosting for accessproof.dev. | Website request metadata: IP address, requested path, user agent. The site is static, so there is nothing else to see — no form data, no account, no analytics. | Global edge network. EU Standard Contractual Clauses and the UK Addendum, under Cloudflare's Data Processing Addendum. |
| [HOSTING_PROVIDER] | Hosts the API, the job queue and the encrypted build at rest while queued. | Everything stored server-side: the uploaded build, the encrypted demo credentials, audit records, access logs. | [HOSTING_REGION]. Processed within the EEA where the region is in the EEA; otherwise SCCs. |
| [MODEL_PROVIDER] | Language model API used for the judgement layer of the audit. | Screen content only, as described in section 2 — accessibility tree, labels, roles, and screen images. Not the build. Not your credentials. Not your identity. | Commercial API tier, never a consumer subscription, configured so that never is what happens in respect of model training. SCCs where the transfer leaves the EEA or UK. |
| [EMAIL_PROVIDER] | Transactional email relay. | The recipient address and the body of the one notification email per audit, and the text of a support message you send. Nothing else — no build, no findings, no credentials. | [HOSTING_REGION] where available, otherwise SCCs. The notification address is erased on our side the moment the send is attempted. |
| Our own audit machine | Runs the build and captures evidence. Hardware we own, in [WORKER_LOCATION]. | Everything, for the duration of the run: the installed build, the screens, the credentials, the recordings. | Not a third party — listed because a sub-processor page that omits the machine with the most access is not honest. Physically controlled by us; no third-party administrative access. |
4. Who is not on this list
We use no analytics provider, no advertising or attribution network, no
customer data platform, no CRM holding customer records, no session-recording
tool, no chat widget, no crash reporter that transmits off-device, and no
cloud object store for evidence. Evidence is
embedded_in_report and server-side artifact
retention is 0 days, so
there is nothing to store and therefore no storage provider to name.
5. How we choose them
Before engaging a sub-processor we check that it offers a data processing agreement with terms at least as protective as ours, a lawful transfer mechanism where relevant, and a security posture appropriate to what it will hold. Each is bound by a written contract imposing the Article 28 obligations on it, and we remain liable to you for its performance.
6. Changes and your right to object
We give 30 days' notice on this page before a new sub-processor starts processing customer data, and we move the effective date at the top when we do. If you object on reasonable data protection grounds, write to info@accessproof.dev within those 30 days. We will try to offer an alternative; if we cannot, you may stop using the service and we will return the value of any unspent credits through the process in the Refunds & purchases policy.
There is no email list to subscribe to for this — deliberately, since that would mean holding your address. Check this page, or ask us and we will tell you the current state.
An emergency replacement — a provider failing, or a security incident forcing a migration — may have to happen faster than 30 days. If that occurs we will say so here, explain why, and your objection right still applies after the fact.
Contact
[LEGAL_ENTITY], [REGISTERED_ADDRESS], [COUNTRY]. Registration [COMPANY_REGISTRATION_NUMBER] · Tax ID [TAX_ID].
One address handles everything — legal notices, privacy and data subject requests, support, security disclosure and accessibility feedback: info@accessproof.dev. Put the subject in the first line and it reaches the right person.