GDPR Compliance
How WCAG Scanner protects your personal data and respects your privacy rights under EU law.
This document explains how WCAG Scanner complies with the General Data Protection Regulation (GDPR) (EU) 2016/679. It applies to all users in the European Economic Area (EEA).
1. Data Controller
WCAG Scanner is the data controller for the personal data we collect. If you have any questions about this notice or your data rights, contact us at reports@wcagscannerr.com.
2. Personal Data We Collect
We collect only the minimum personal data necessary to provide our service:
- Account data: Email address and name (required for account creation and login).
- Scan data: URLs you submit for scanning. We do not store the full content of scanned pages.
- Payment data: Processed entirely by Stripe — we never see or store your payment details.
- Usage data: Anonymous product usage data to improve the service.
3. Legal Basis for Processing
We process your personal data under the following legal bases:
- Contract (Article 6(1)(b)): Account creation, service delivery, and billing.
- Consent (Article 6(1)(a)): Marketing emails (you can opt out anytime).
- Legitimate interests (Article 6(1)(f)): Service improvement, security monitoring, and fraud prevention.
4. Your Rights Under GDPR
As a data subject in the EEA, you have the following rights:
- Right of access (Art. 15): Request a copy of all personal data we hold about you.
- Right to rectification (Art. 16): Correct inaccurate or incomplete data via your account settings.
- Right to erasure (Art. 17): Request deletion of your account and associated data.
- Right to restrict processing (Art. 18): Limit how we use your data in certain circumstances.
- Right to data portability (Art. 20): Receive your data in a machine-readable format (CSV).
- Right to object (Art. 21): Object to processing based on legitimate interests.
To exercise any of these rights, email reports@wcagscannerr.com. We will respond within 30 days as required by GDPR.
5. Data Processing & Sub-processors
We use the following sub-processors who may access personal data:
- Supabase (AWS) — Database hosting. SOC 2 compliant. Data stored in us-east-1 (Virginia, USA).
- Stripe — Payment processing. PCI DSS Level 1 certified. Data stored in accordance with Stripe's DPA.
- Vercel — Application hosting. Data processed in the region closest to the user.
- Resend — Transactional email delivery. Data processed in us-east-1.
We have Data Processing Agreements (DPAs) in place with each sub-processor as required by Article 28 of the GDPR.
6. International Data Transfers
Your personal data is primarily stored and processed in the United States. We rely on the following safeguards for international data transfers:
- EU-US Data Privacy Framework — for transfers to certified sub-processors.
- Standard Contractual Clauses (SCCs) — adopted by the European Commission.
7. Data Retention
- Account data: Retained for the duration of your account plus 90 days after deletion.
- Scan data: Retained according to your plan's scan history duration (30 days for Starter, 90 days for Growth, 1 year for Enterprise).
- Payment records: Retained for 7 years as required by tax law.
8. Data Security
We implement the following technical and organizational security measures:
- All data encrypted in transit (TLS 1.3) and at rest (AES-256).
- Row-Level Security (RLS) ensures users can only access their own data.
- Passwords are hashed using bcrypt — we cannot see them.
- Regular security audits and penetration testing.
9. Data Breach Notification
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours as required by Article 33 of the GDPR. Affected data subjects will be notified without undue delay.
10. Complaints
If you believe we have not complied with data protection laws, you have the right to lodge a complaint with your local supervisory authority. Contact us first at reports@wcagscannerr.com and we will do our best to resolve your issue promptly.
11. Data Processing Agreement (DPA)
Enterprise customers who require a signed Data Processing Agreement (DPA) can request one by emailing reports@wcagscannerr.com. Our DPA incorporates the EU Standard Contractual Clauses (Module 2: Controller-to-Processor) and covers all sub-processors listed in Section 5.
Questions? Email us at reports@wcagscannerr.com