Skip to content
How it worksPricingAbout
Sign inStart seven-day trial

Data processing agreement

You are the controller of what the Service sees inside your application. The Operator processes it for you, on your documented instructions, and this agreement says on what terms.

Revision 3, effective from 2026-09-12

1. Parties, scope and precedence

Controller
You, the customer holding the account (the Customer), for the personal data contained in or derived from the applications you ask the Service to check.
Processor
Tomáš Pilař, a sole trader (self-employed natural person) registered in the Czech Republic, Škroupova 564, 537 01 Chrudim – Chrudim III, Czech Republic, identification number 88527069 (the Operator).
Notices under this agreement
legal@stillworks.watch for contractual matters; privacy@stillworks.watch for data-subject requests and incidents.

This agreement forms part of the terms of service and applies to the processing of personal data that the Operator carries out on your behalf as your processor within the meaning of Article 28 of Regulation (EU) 2016/679 (the GDPR). For your own account data, your billing data and the Operator's security and operational records, the Operator is the controller and the privacy notice applies instead; this agreement does not cover that processing. If this agreement conflicts with the terms, this agreement prevails for the processing it covers.

You accept this agreement by ticking the acceptance box the first time you sign in. The Service records the moment of acceptance and the revision accepted, and asks again, by name and by revision, whenever a new revision takes effect. Where you act for a company or another legal person, you warrant that you are authorised to bind it.

2. Subject matter, duration, nature and purpose

Subject matter. Opening the addresses you name in a browser, on the schedule you choose and after each deploy the Service detects; performing the steps and verifying the conditions of each check you configure; running the probes you enable; receiving visitor-error events from the optional snippet you install; receiving an email sent by your application to a configured email step; operating the recorder while you record a check; and recording, storing, presenting and alerting on the outcome.

The subject matter also includes measuring, while a check of yours runs, how long its pages and its steps took and how many requests and bytes they needed. Those measurements are whole numbers, counts and fixed words produced by the browser that ran the check. They hold no page address, no content of a page, no header, no cookie, no body of a request or a reply and no field value, so they add no category of personal data to section 3. They are kept with the record of the run they belong to, are deleted with it, and are used for nothing except showing you how your application behaved during your own checks.

Duration. For as long as your account exists, and then for the deletion period in section 11.

Nature. Automated collection, storage, transmission to the subprocessors in section 8 to the extent each one is used, display to you and to the recipients you verify, and deletion.

Purpose. Telling you whether your application still works, and showing you what the Service saw when it did not. The Operator does not process this data for any other purpose, does not use it to train any model, and does not derive anything from it about the individuals it concerns.

3. Categories of data subjects and personal data

Data subjects may include, depending on what your application displays and on the checks you configure:

  • you, the account holder, and the persons acting on your behalf;
  • the alert recipients you nominate and who verify their address;
  • employees, contractors and users of your application, including the account whose credentials a check uses;
  • end users, visitors and customers of your application, including visitors whose browser reports an error through the optional snippet;
  • senders and recipients of an email that a configured email step receives.

Categories of personal data may include:

  • names, email addresses, usernames and other account identifiers rendered by your application;
  • any other data your application displays on a page while a check runs, as captured in screenshots, recordings and the page structure a step needed;
  • HTTP request and response metadata retained in a network trace, which can include tokens and identifiers;
  • authentication credentials for your application that you configure for a check;
  • server-rendered page content and links collected once to propose checks;
  • browser and runtime error messages, stack traces, URL paths and viewport category reported by the optional visitor-error snippet;
  • the sender, sender domain and extracted link of an email received by a configured email step;
  • the page addresses and element crops of a recorder session;
  • any other information you choose to render in your application or submit to the Service.

Not every run contains these data. This is the possible scope; what actually appears depends on your application and your instructions.

Special categories. The Service is not designed for the intentional or targeted processing of special categories of personal data under Article 9 GDPR, or of data relating to criminal convictions under Article 10. You will not deliberately instruct the Service to process such data unless you have an appropriate lawful basis and the processing is necessary for the check. Incidental capture can nevertheless occur, for example where a screen of your application displays such information at the moment a screenshot or recording is taken; the Operator does not represent that incidental capture is technically impossible and applies the measures in section 7 to such data in the same way as to any other.

4. Processing on your documented instructions

The Operator processes personal data only on your documented instructions. Your instructions are: this agreement, the terms of service, and the configuration you make in the Service, that is, the projects you create, the checks, probes, schedules, credentials, email steps and recipients you configure, the snippet you install, the recorder sessions you start, and the settings you choose. A further instruction may be given in writing to the contractual contact and takes effect when the Operator confirms it can be carried out.

The Operator may depart from your instructions only where Union or Czech law requires it, in which case the Operator informs you of that requirement before processing unless the law prohibits such information on important grounds of public interest. If the Operator considers that an instruction infringes the GDPR or other data-protection law, it will tell you immediately and may suspend the instruction until it is resolved.

You are responsible for the lawfulness of the processing you instruct, including your authority over each application you add, the lawful basis for the data your application displays, the information you give your own users, and the lawful use of any credential or email address you configure. A domain owner's valid request that the Operator stop checking that domain overrides your instruction, as the terms of service provide.

5. What travels by email

When a check breaks twice in a row the Service sends an alert by email, and the screenshot of the failure travels with it as an attachment rather than as a link, because a link would expire before the message is read. That screenshot is a picture of your application and can therefore contain personal data of your users: names, email addresses, order details, the contents of a half-filled form. It reaches the Operator's mail provider and then the recipients you nominated, each of whom has confirmed they want the messages.

This is an instruction you give by verifying a recipient. The picture travels with every email alert; an alert to Slack, Discord or a webhook you connect carries the text only. You are responsible for nominating only recipients who are entitled to see what the screenshot shows.

6. Confidentiality

The Operator keeps the personal data confidential, uses it only as this agreement allows, and ensures that every person authorised to process it, today the Operator alone, has committed to confidentiality or is under an appropriate statutory obligation of confidentiality. The Operator does not disclose the data to a third party other than a subprocessor under section 8 or a public authority where the law requires it, and in the latter case tells you beforehand unless the law prohibits it.

7. Security measures

The Operator implements the technical and organisational measures below, which are the measures the Service actually applies, and keeps them appropriate to the risk under Article 32 GDPR. The Operator may improve a measure at any time and will not reduce the overall level of protection during the term. The security page describes the same measures for a general reader.

Isolated runs
Each run opens your application in a browser container created for that run and destroyed after it, with a read-only filesystem, no extra privileges, a memory limit and a hard timeout. The container holds no credential to the Operator's database, object storage or AI provider, cannot reach the Operator's internal network, and returns results through one signed endpoint whose input is validated before anything is stored.
Credentials
Credentials you configure are encrypted at rest with envelope encryption. The master key is held only by the control plane and never reaches a runner; a runner receives only the ciphertext and data key of the values the current run references and opens them in memory for that run.
Secrets and logs
Decrypted credentials, session tokens and values marked secret are never written to a log, an error report or an alarm. A run that carries a credential or an email step records no video and no network trace, and sign-in fields are blanked out of step screenshots. Tokens in sign-in, alert and deploy links are stripped from the access log before it is written.
Artefact storage
Screenshots and recordings are written to private buckets through one-off signed URLs issued for one run, and read back the same way. No bucket is public.
Internal authentication
Internal channels between the control plane, the runner agent, the inbox and the runner are authenticated with HMAC signatures; a runner signs with a per-run key that expires with the run.
AI requests
Requests to the pinned AI provider carry instructions to deny data collection and to require zero retention, allow no fallback to another provider, and fail rather than route elsewhere. Prompt logging is switched off on the routing account.
Backups
The database is backed up daily into a separate private bucket with separate credentials, encrypted with a key held only by the backup process, retained for 30 days, and restored into an empty database every month to prove the backup can be read. A backup that has not been proven restorable is not treated as a backup.
Retention enforcement
Recordings and screenshots expire after 30 days on every plan; raw visitor-error events after two weeks; recorder crops and inbound-email links within hours. Expiry is enforced by a scheduled job, not by policy alone.
Access
Access to production systems is limited to the Operator, over authenticated administrative channels; the Operator is bound by the confidentiality obligation in section 6.

The Operator holds no certification such as ISO 27001 or SOC 2 and does not represent otherwise. The measures above are contractual commitments; a certification is not.

8. Subprocessors

You give the Operator general authorisation to engage the subprocessors listed on subprocessors. That page is rendered from the configuration actually in use rather than from a list somebody maintains by hand, and it states for each subprocessor its legal entity, what reaches it, where it is and whether it is in use in the current configuration. The Operator imposes on each subprocessor, by contract, data-protection obligations that provide at least the level of protection required by this agreement, and remains fully liable to you for the subprocessor's performance.

Adding or replacing a subprocessor. The Operator informs you by email before a new subprocessor starts processing your data. You may object on reasonable data-protection grounds by writing to the contractual contact before the change takes effect. If the objection cannot be resolved, for example by not using that subprocessor for your account, you may terminate the terms of service with respect to the affected service without penalty, and the Operator deletes the data it holds for you under section 11.

The AI chain. The two AI requests are routed through OpenRouter, Inc., a United States company, to the inference provider pinned in the Operator's configuration, which is currently Azure in the EU. The developer of the pinned model is named on the subprocessors page for transparency and is not a recipient of your data where the pinned endpoint is operated by another party. The Operator does not hold an individual written zero-retention undertaking from OpenRouter or from the inference provider; instead, every request carries instructions to deny data collection and to require zero retention, allows no fallback to another provider, and fails if no compliant provider is available; prompt logging is switched off on the routing account; and the Operator relies on the providers' published retention and training commitments, which it reviews before each deployment and periodically. If the pinned provider ceases to satisfy those commitments, the Operator stops that AI path until a compliant provider is configured.

Stripe is listed on the subprocessors page because your email address and subscription identifiers reach it; for the payment itself and its own regulatory duties it acts as an independent controller, as the privacy notice explains, and it never receives data covered by this agreement.

9. International transfers

Core infrastructure is hosted in the European Union: the servers, database, object storage, backups and outgoing email are in Germany and the Czech Republic. A transfer of personal data covered by this agreement to a country outside the European Economic Area takes place only through the routing layer of the AI requests described in section 8, whose provider is a United States company, and only where you have not opted out of the visual fallback and a check-proposal or fallback request is made. Where the pinned inference provider is outside the EU, the subprocessors page says so.

Any such transfer rests on the European Commission's standard contractual clauses or another transfer mechanism under Chapter V GDPR, together with the request-level restrictions in section 8. The Operator does not transfer data covered by this agreement outside the EEA for any other purpose and will tell you before any new transfer, which you may object to under section 8.

10. Assistance, incidents and audits

Data-subject requests. If a person whose data your application displays exercises a right under Chapter III GDPR, the Operator, taking into account the nature of the processing, assists you with appropriate technical and organisational measures so that you can respond within your own deadline. The Operator does not answer such a person directly, tells you without undue delay if a request reaches it, and does not charge for assistance that takes reasonable effort.

Security, impact assessments and consultations. The Operator assists you in complying with Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to it, including by providing the information in section 7 and on the security page for a data-protection impact assessment or a prior consultation with a supervisory authority.

Personal data breaches. The Operator notifies you without undue delay after becoming aware of a personal data breach affecting data processed on your behalf, at the email address on your account, and gives you the information reasonably available at that time, including the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed, and supplements it as further information becomes available. The Operator does not promise notification within a fixed number of hours; it promises to notify without undue delay and in time for you to meet your own 72-hour obligation where that is within its control.

Information and audit. The Operator makes available to you the information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by you or by an auditor you mandate who is bound by confidentiality. An audit is carried out at reasonable notice of at least 30 days, at most once in any twelve-month period unless a supervisory authority requires it or a personal data breach has occurred, during business hours, and in a manner proportionate to a service of this size: first by written questions and documents, then remotely, and on the Operator's premises or systems only where that is necessary. You bear your own costs; the Operator may charge reasonable costs for an audit that exceeds one working day of its time.

11. Deletion and return

Recordings, screenshots and network traces are deleted after 30 days on every plan, without you asking. Raw visitor-error events are deleted after two weeks. The record of what happened is kept for the period your plan states and then deleted. Recorder crops and session records are deleted within 24 hours of the session ending, and a link extracted from an inbound email within one hour.

When the account ends, whether because you asked for it to be deleted, because a frozen account reached its deletion date, or because the terms of service were terminated, the Operator deletes all personal data covered by this agreement within 30 days, including the objects in storage, and confirms deletion on request. Before deletion you may retrieve what the product lets you download; the Operator provides a copy of the data covered by this agreement in a commonly used format on request where that is technically reasonable. A copy of deleted data can remain in an encrypted backup until that backup expires, at most 30 days later; such a copy is not restored except to recover the Service from a disaster and is not treated as active data.

Deletion of your account does not require the Operator to delete records it must keep under accounting, tax or other mandatory law, or records that Stripe keeps under its own obligations as an independent controller. Those records are kept for their statutory period and for no other purpose.

12. Liability, term and law

The limitation of liability in the terms of service applies to this agreement, except where the GDPR or other mandatory law does not allow liability to be limited. Each party is liable towards data subjects as Article 82 GDPR provides.

This agreement runs for as long as the terms of service and section 11 survives its end. It is governed by the laws of the Czech Republic, with disputes heard by the courts of the Czech Republic, with local jurisdiction determined under applicable procedural law. A new revision is asked for again, by name and by revision, the next time you sign in; the Service records the moment you accepted and which revision you accepted.

The last thing to remember

Someone should be checking. It's me.

Know someone with more side projects than time? Send stillworks.watch their way.

You give me one URL. I keep checking it while you’re away.

stillworks.watch

A second look at the things you ship.

Product

  • How it works
  • Pricing
  • Help

Trust & support

  • About
  • Security
  • Status
  • Report abuse

Legal

  • Terms
  • Privacy
  • Data processing
  • Subprocessors