Data Processing Agreement

Last updated: 14 August 2026

This agreement covers the personal data you put into CatchLeak — whatever sits inside the workflow you paste. Under UK GDPR you are the controller of that data and we are your processor. Article 28 requires those terms to be in writing, so here they are.

It forms part of our Terms and applies automatically when you use CatchLeak — there is nothing to sign. For our own site, your payment and your emails to us, see the Privacy Policy, where we are the controller.

1. The basics

Do not paste special category data(health, biometrics, race, religion, politics, sex life), criminal offence data, children’s data, or financial account details. CatchLeak is not built for it and you must not send it.

2. Your credentials never travel

This is the part that matters most, and it is architecture rather than a promise: credentials are replaced with placeholders in your own browser, before anything is sent. The map that turns them back into real values stays on your machine and is applied to the repaired workflow after it comes back. API keys, tokens and passwords in your workflow therefore never reach our servers, and cannot reach anyone we work with.

3. We act only on your instructions

We process your workflow only to give you what you asked for. We will not use it for our own purposes. In particular we do not:

If the law ever required us to process your data otherwise, we would tell you first unless that law forbids it. If we think an instruction of yours breaches data protection law, we will say so.

4. Confidentiality

Access is limited to the people who need it to run the service — today that is one person — under a duty of confidentiality.

5. Security

6. Sub-processors

You give general authorisation for the sub-processors below. We stay responsible for what they do with your data, and we will give you notice of any addition or replacement with a reasonable opportunity to object.

Where a sub-processor operates outside the UK, transfers rely on appropriate safeguards (UK adequacy, the UK IDTA or the Addendum to the EU SCCs).

We deliberately do not list Polar, or Microsoft 365 here. They never receive your workflow: Polar is the Merchant of Record and an independent controller of the payment relationship; Microsoft 365 carries our email. Those are providers of our own business, where we are the controller — a different role, described in our Privacy Policy. Naming them here would wrongly suggest your workflow travels to them.

7. Deletion and return

There is nothing to return at the end of the contract, because we keep nothing. Your workflow is discarded as soon as your report or repair is produced. We hold no library of scanned workflows, and technical logs never contain their contents.

8. Helping you meet your obligations

9. Audit

On reasonable written request we will provide the information needed to demonstrate compliance with this agreement, and allow an audit or inspection — at a mutually agreed time, no more than once a year unless a breach or a regulator requires otherwise, and subject to confidentiality.

10. Liability and general

The liability provisions of our Terms apply to this agreement. If any term here conflicts with the Terms on the handling of your workflow, this agreement wins. It is governed by the law of England and Wales.

11. Contact

The processor under this agreement is Luis Cristian Aurrecoechea Di Giacomo, 6 Southgate Drive, Towcester, Northamptonshire, NN12 6JQ. Questions, notices, or a request under this agreement: hello@catchleak.com. You can also complain to the UK ICO (ico.org.uk).