pixmoat / legal
Data processing addendum
Last updated: 12 August 2026
This page describes the intended data-processing arrangement for organisations using pixmoat. A customer requiring a signed data processing agreement should contact info@pixmoat.com before uploading customer data.
Roles
For customer project data processed to provide the service, the customer is generally the controller and pixmoat is generally the processor. For pixmoat account, billing, security, and website data, pixmoat may act as controller. The exact roles depend on the processing activity.
Processing scope
Processing may include hosting, storing, transmitting, comparing, displaying, backing up, securing, and deleting screenshots, baselines, build metadata, project configuration, account information, and integration data. The duration is the term of the service plus the deletion and backup period applicable to the account.
Processor commitments
- Process customer data only to provide, secure, maintain, and support the service, or on documented customer instructions.
- Apply appropriate technical and organisational security measures.
- Require confidentiality from people authorised to access customer data.
- Assist with data-subject requests, security incidents, and legally required cooperation where reasonably possible.
- Use subprocessors listed on the Subprocessors page and provide notice of material changes where required.
- Delete or return customer data after termination, subject to legal retention and ordinary backup rotation.
Customer instructions
The customer is responsible for giving lawful instructions, providing notices to its own users, and ensuring that its use of pixmoat has an appropriate legal basis. A signed agreement can define the details for a specific customer.