Legal
Data Processing Addendum
Last updated September 23, 2026
This addendum supplements the Terms of Service for Launch Ready (uselaunchready.com, https://uselaunchready.com) and applies whenever we process personal data on your behalf. Where it conflicts with the Terms on data protection, this addendum governs. It is written in plain language and is not legal advice.
Scope and roles
You are the controller of the personal data you put into Launch Ready and of the websites you ask us to scan. We — Péter Kiss, who operates Launch Ready from Calle Las Huertas 15, 29788 Frigiliana (Málaga), Spain — are the processor, acting only on your documented instructions; using the product is that instruction. The sub-processors listed below act on our behalf.
For our own account, billing and security records we are the controller; that processing is described in the Privacy Policy.
Subject matter and duration
Subject matter: providing pre-launch website QA — crawling the sites you submit, scoring launch readiness, and producing reports, share links and PDFs.
Duration: for as long as your account is active, plus the limited operational period in which backups and logs age out. Deleting a project or your account starts deletion immediately.
Nature and purpose
We fetch pages from the URLs you submit, extract structured metadata from them, apply deterministic checks, store the resulting findings and scores, and deliver them to you and to the recipients you choose (share links, PDFs, email, Slack or webhook alerts). We do not use your data to train models and we do not sell it.
Categories of data
- Crawled public website content: HTML, headers, redirect chains, page metadata, and any personal data that happens to be published on the pages you scan
- Account data: email addresses, optional names, authentication records
- Workspace data: workspace and client names, contact names and emails you enter
- Finding data: scores, findings and their evidence excerpts, states, assignees, notes and sign-offs
- Operational data: scan progress events, audit log entries (actor, action, target, IP), email delivery records, error logs
- Credentials you choose to store: HTTP basic auth for staging sites, encrypted at rest
Data subjects
- Your staff: the people you invite into the workspace
- Your clients’ contacts: the names and emails you enter against a client
- Visitors and individuals named on the sites you scan — only to the extent that the content was already public (or reachable with credentials you supplied). We do not submit forms, do not log in as a user, and do not collect visitor behaviour from the sites we crawl
Our obligations as processor
- Process personal data only on your instructions, and tell you if we believe an instruction is unlawful
- Keep personnel with access bound to confidentiality
- Apply the technical and organisational measures described below
- Engage sub-processors only under equivalent obligations, and keep the list below current
- Help you respond to data subject requests — export and deletion are available in the product, and we assist with anything the product cannot do
- Help you with impact assessments and regulator consultations where relevant
- Delete or return personal data at the end of the engagement
Your obligations as controller
- Have a lawful basis for the data you put into the product
- Only submit URLs you own or are authorised to test, including staging sites whose credentials you supply
- Keep your own notices and records up to date, and manage who you invite
- Choose where alerts and share links go, and revoke them when an engagement ends
Sub-processors
We use the following sub-processors. We will give notice before adding one, so you can object.
| Sub-processor | Purpose | Data | Location |
|---|---|---|---|
| Vercel | Web application hosting and edge delivery | Account session traffic, request logs | EU (Frankfurt, fra1) |
| Supabase | Postgres database and authentication | Accounts, workspaces, projects, scans, findings, share links | EU |
| Railway | Long-running scan worker that processes the job queue | Scan jobs and crawl results in transit | Region of the worker deployment |
| Stripe | Subscription payments and the billing portal | Billing contact, customer and subscription identifiers | Global |
| Resend | Transactional email (magic links, invites, scan and alert notices) | Recipient email address and message content | Global |
| Cloudflare | Turnstile bot protection on signup and login, when enabled | Request IP and challenge token | Global |
| Sentry | Error monitoring, when enabled | Error payloads, scrubbed of secrets before sending | Global |
| Slack and customer-configured webhooks | Monitoring alert delivery, only to endpoints the workspace configures | Alert summaries: project name, score, finding counts | Determined by the endpoint you configure |
Cloudflare, Sentry, Slack and customer-configured webhooks are only engaged when that feature is enabled for your workspace or deployment.
International transfers
The web application runs in Vercel’s Frankfurt region (fra1) and the database and authentication run on Supabase in the EU. Where a sub-processor above operates globally, any transfer out of the EEA relies on that processor’s standard contractual clauses and its own supplementary measures.
Security measures
- TLS in transit for the application, the API, and outbound crawls
- Row-level security policies on workspace data, so a workspace’s rows are reachable only through its membership
- API keys stored as SHA-256 digests — the plaintext is shown once and never stored, logged, or written to the audit log
- Staging HTTP basic credentials encrypted at rest with a key derived from our server secret
- Role-based access inside a workspace (viewer, member, admin, owner), enforced on the server
- An append-only audit log of privileged actions, readable by workspace owners and admins
- SSRF protection on every outbound hop: private, loopback and reserved addresses are refused, and DNS is pinned for the request that follows the lookup
- Rate limits and optional bot protection on authentication and scan creation
- Error payloads scrubbed of secrets before they reach error monitoring
Incident notification
If we become aware of a personal data breach affecting your data, we will notify you without undue delay with what we know: what happened, which data and workspaces are affected, what we have done, and what we recommend you do.
Audit and information rights
On reasonable notice, and no more than once a year unless a regulator or an incident requires otherwise, we will answer a written security questionnaire and provide the information you need to demonstrate compliance with this addendum. We are a small team and do not hold a third-party certification today; we will say so rather than imply one.
Return and deletion
You can export your account data and delete individual projects or your whole account from the product at any time; export is available before delete. Deleting a project removes its scans, findings, and share links. Backups and operational logs may retain residual copies for a limited period before they age out.
Requesting a signed copy
Request a signed copy, ask about a sub-processor, or raise a data protection question at privacy@uselaunchready.com.
Also see our Privacy Policy and How we scan.