Legal

Data Processing Addendum

Last updated September 23, 2026

This addendum supplements the Terms of Service for Launch Ready (uselaunchready.com, https://uselaunchready.com) and applies whenever we process personal data on your behalf. Where it conflicts with the Terms on data protection, this addendum governs. It is written in plain language and is not legal advice.

Scope and roles

You are the controller of the personal data you put into Launch Ready and of the websites you ask us to scan. We — Péter Kiss, who operates Launch Ready from Calle Las Huertas 15, 29788 Frigiliana (Málaga), Spain — are the processor, acting only on your documented instructions; using the product is that instruction. The sub-processors listed below act on our behalf.

For our own account, billing and security records we are the controller; that processing is described in the Privacy Policy.

Subject matter and duration

Subject matter: providing pre-launch website QA — crawling the sites you submit, scoring launch readiness, and producing reports, share links and PDFs.

Duration: for as long as your account is active, plus the limited operational period in which backups and logs age out. Deleting a project or your account starts deletion immediately.

Nature and purpose

We fetch pages from the URLs you submit, extract structured metadata from them, apply deterministic checks, store the resulting findings and scores, and deliver them to you and to the recipients you choose (share links, PDFs, email, Slack or webhook alerts). We do not use your data to train models and we do not sell it.

Categories of data

  • Crawled public website content: HTML, headers, redirect chains, page metadata, and any personal data that happens to be published on the pages you scan
  • Account data: email addresses, optional names, authentication records
  • Workspace data: workspace and client names, contact names and emails you enter
  • Finding data: scores, findings and their evidence excerpts, states, assignees, notes and sign-offs
  • Operational data: scan progress events, audit log entries (actor, action, target, IP), email delivery records, error logs
  • Credentials you choose to store: HTTP basic auth for staging sites, encrypted at rest

Data subjects

  • Your staff: the people you invite into the workspace
  • Your clients’ contacts: the names and emails you enter against a client
  • Visitors and individuals named on the sites you scan — only to the extent that the content was already public (or reachable with credentials you supplied). We do not submit forms, do not log in as a user, and do not collect visitor behaviour from the sites we crawl

Our obligations as processor

  • Process personal data only on your instructions, and tell you if we believe an instruction is unlawful
  • Keep personnel with access bound to confidentiality
  • Apply the technical and organisational measures described below
  • Engage sub-processors only under equivalent obligations, and keep the list below current
  • Help you respond to data subject requests — export and deletion are available in the product, and we assist with anything the product cannot do
  • Help you with impact assessments and regulator consultations where relevant
  • Delete or return personal data at the end of the engagement

Your obligations as controller

  • Have a lawful basis for the data you put into the product
  • Only submit URLs you own or are authorised to test, including staging sites whose credentials you supply
  • Keep your own notices and records up to date, and manage who you invite
  • Choose where alerts and share links go, and revoke them when an engagement ends

Sub-processors

We use the following sub-processors. We will give notice before adding one, so you can object.

Sub-processorPurposeDataLocation
VercelWeb application hosting and edge deliveryAccount session traffic, request logsEU (Frankfurt, fra1)
SupabasePostgres database and authenticationAccounts, workspaces, projects, scans, findings, share linksEU
RailwayLong-running scan worker that processes the job queueScan jobs and crawl results in transitRegion of the worker deployment
StripeSubscription payments and the billing portalBilling contact, customer and subscription identifiersGlobal
ResendTransactional email (magic links, invites, scan and alert notices)Recipient email address and message contentGlobal
CloudflareTurnstile bot protection on signup and login, when enabledRequest IP and challenge tokenGlobal
SentryError monitoring, when enabledError payloads, scrubbed of secrets before sendingGlobal
Slack and customer-configured webhooksMonitoring alert delivery, only to endpoints the workspace configuresAlert summaries: project name, score, finding countsDetermined by the endpoint you configure

Cloudflare, Sentry, Slack and customer-configured webhooks are only engaged when that feature is enabled for your workspace or deployment.

International transfers

The web application runs in Vercel’s Frankfurt region (fra1) and the database and authentication run on Supabase in the EU. Where a sub-processor above operates globally, any transfer out of the EEA relies on that processor’s standard contractual clauses and its own supplementary measures.

Security measures

  • TLS in transit for the application, the API, and outbound crawls
  • Row-level security policies on workspace data, so a workspace’s rows are reachable only through its membership
  • API keys stored as SHA-256 digests — the plaintext is shown once and never stored, logged, or written to the audit log
  • Staging HTTP basic credentials encrypted at rest with a key derived from our server secret
  • Role-based access inside a workspace (viewer, member, admin, owner), enforced on the server
  • An append-only audit log of privileged actions, readable by workspace owners and admins
  • SSRF protection on every outbound hop: private, loopback and reserved addresses are refused, and DNS is pinned for the request that follows the lookup
  • Rate limits and optional bot protection on authentication and scan creation
  • Error payloads scrubbed of secrets before they reach error monitoring

Incident notification

If we become aware of a personal data breach affecting your data, we will notify you without undue delay with what we know: what happened, which data and workspaces are affected, what we have done, and what we recommend you do.

Audit and information rights

On reasonable notice, and no more than once a year unless a regulator or an incident requires otherwise, we will answer a written security questionnaire and provide the information you need to demonstrate compliance with this addendum. We are a small team and do not hold a third-party certification today; we will say so rather than imply one.

Return and deletion

You can export your account data and delete individual projects or your whole account from the product at any time; export is available before delete. Deleting a project removes its scans, findings, and share links. Backups and operational logs may retain residual copies for a limited period before they age out.

Requesting a signed copy

Request a signed copy, ask about a sub-processor, or raise a data protection question at privacy@uselaunchready.com.

Also see our Privacy Policy and How we scan.