Privacy & Security
Your trust is our priority. Learn how we protect your data and maintain the highest security standards.
Last updated: December 2024
Encrypted Data
All data is encrypted in transit (TLS 1.3) and at rest (AES-256).
SOC 2 Compliant
Our infrastructure and processes meet SOC 2 Type II standards.
GDPR & CCPA
Full compliance with global privacy regulations.
Privacy Policy
1. Information We Collect
We collect information you provide directly to us, including:
- Account Information: Name, email address, company name, and password when you create an account.
- Billing Information: Payment details processed securely through Stripe. We do not store full credit card numbers.
- Usage Data: Information about how you use our service, including URLs scanned, test results, and feature usage.
- Communications: Messages you send us through support channels or contact forms.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our accessibility testing services
- Process transactions and send related information
- Send technical notices, updates, and security alerts
- Respond to your comments, questions, and support requests
- Analyze usage patterns to enhance our platform
- Detect, prevent, and address technical issues or fraud
3. Cookies and Tracking
We use essential cookies to maintain your session and preferences. We also use analytics cookies to understand how our service is used. You can control cookie preferences through your browser settings.
4. Third-Party Services
We work with trusted, industry leading third-party services to operate sensitive platform features:
- Secure authentication and identity management
- Payment processing (PCI DSS compliant)
- Secure database hosting
- Industry leading application hosting and content delivery
5. Data Retention
We retain your data for as long as your account is active or as needed to provide you services. Test results and scan history are retained for 12 months by default. You can request earlier deletion at any time. Upon account deletion, we remove your personal data within 30 days, except where required by law.
6. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your personal data
- Portability: Export your data in a machine-readable format
- Objection: Object to certain processing of your data
To exercise these rights, contact us at privacy@accessible.com.
Security Practices
Infrastructure Security
Our infrastructure is designed with security as a foundational principle:
- Hosted on enterprise-grade cloud infrastructure with 99.99% uptime SLA
- Regular security audits and penetration testing
- Automated vulnerability scanning and patch management
- Network segmentation and firewall protection
- DDoS protection and rate limiting
Data Encryption
All data is protected using industry-standard encryption:
- In Transit: TLS 1.3 encryption for all network communications
- At Rest: AES-256 encryption for stored data
- Secrets: Secure key management with regular rotation
Access Controls
We implement strict access controls to protect your data:
- Role-based access control (RBAC) for all systems
- Multi-factor authentication required for employee access
- Regular access reviews and least-privilege principles
- Comprehensive audit logging of all access
Incident Response
We maintain a comprehensive incident response plan:
- 24/7 security monitoring and alerting
- Defined incident response procedures and escalation paths
- Customer notification within 72 hours of confirmed data breach
- Regular incident response drills and plan updates
Compliance
We adhere to recognized security standards and regulations:
- GDPR compliant
- CCPA compliant
- Regular third-party security assessments
Contact Us
If you have questions about this Privacy & Security policy, please contact us:
Email: privacy@accessible.com
Security Issues: security@accessible.com
Address: Accessible, Inc.