Data processing
Who handles your data, and where
Written for the person at an agency who has to answer this about their own client. Everything here is the real list, not a category.
Which of us is responsible for what
For your own account, we are the controller. Your email, what you bought, what you saved: we decide what to keep and why, and the privacy page says so.
For a site you measure on somebody else's behalf, you are the controller and we are the processor. You decide which pages get checked and what we do with the result. We act on your instructions, which in practice means the pages you save and the schedules you set. If your client asks who else is involved, this page is the answer.
Who we use
Two groups. The first is what runs the product, for everybody. The second is who takes the money, which depends on the currency you pay in.
Running the product
| Who | What for | Where |
|---|---|---|
| Cloudflare | Serving the site, DNS, protection against abuse | Global network |
| OVH | The server that runs the checks, the database, saved reports | Canada |
| SendByte | Sign in links, finished reports, outage alerts | Their processing region |
| Vemetric | Counting visits, no advertising trackers | European Union |
Taking payments
Card details never reach us either way.
| Who | What for | Who it applies to |
|---|---|---|
| Bachs | Card payments in US dollars | Everyone paying in dollars |
| Paystack | Card payments in Naira | Customers paying in Naira |
That is the whole list. If it changes we update this page, and if you are on a paid plan we email you before it takes effect.
Data leaving its home country
Our server is in Canada, so information about your account and the pages you measure is held there. Cloudflare serves the site from wherever you are. Payment information goes to whichever payment company took your money and stays with them.
If that is a problem for your client, tell us before you put their site in. We would rather have the conversation than surprise you.
What we actually hold about a page you measure
- The address, and what we measured: scores, findings, the files we named.
- The page's own HTML and network log from the run, because that is what the findings are derived from.
- For a watched page, when it stopped answering and when it came back.
- For a page behind a login, one session you gave us, encrypted. See below.
We do not scrape a page for personal information, and we do not look at what is on it beyond measuring how it loads. But a page's HTML is a page's HTML: if your client's page shows a customer name to a signed in user, and you gave us a session, that name is in what we stored. That is the honest version, and it is the reason for the next section.
The session you give us for a page behind a login
This is the most sensitive thing we hold and it deserves its own answer.
- It is encrypted before it is stored. The key lives on our server, not in the database.
- It is only ever sent to the host it belongs to. A redirect anywhere else drops it.
- We only accept one for a domain the account has proved it controls.
- It is never shown back, to you or to us.
- Revoking deletes it immediately, on your word alone.
- We ask for a throwaway account with ordinary access, not an admin login, and that is the single most useful thing you can do to limit what any of this touches.
How long we keep it
- Reports and what we measured: while the account exists, or while a public report link still works.
- Outage history: kept, because uptime figures over 30 days need it.
- Payment records: as long as the law requires.
- A login session: until you revoke it or delete the page.
- Everything else: gone when you ask us to delete the account.
Getting your data, or getting rid of it
Email us and we will send you what we hold, or delete it. No form, no reason required, and we do not charge for it. If you are acting for a client and they have asked you, that is enough for us.
If something goes wrong
If data we hold is exposed, we will tell the affected accounts within 72 hours of knowing, say what happened in plain words, and say what we are doing about it. We will not wait until we have a comfortable version of the story.
A written agreement
If your client needs a signed data processing agreement, email us and we will sign one. PafCore is a small product and we do not pretend to have a procurement department, but this is a normal thing to ask for and we will not make it difficult.
Contact
Questions, requests, or an agreement to sign: hello@pafcore.site.
Last updated: 15 September 2026. Also see Privacy and Terms. This page is written to be read and is not legal advice.