DIRECTIVE (EU) 2019/882 · IN FORCE SINCE 28 JUNE 2025 EU-HOSTED · GDPR-CLEAN
EAA Compliance

LEGAL

Privacy notice

VERSION 1.0 · EFFECTIVE 1 May 2026 · WE WILL DATE EVERY REVISION

We monitor public web pages and hold the evidence that monitoring produces. This notice says exactly what that means for personal data — including the parts that are genuinely uncomfortable to write down.

Who we are

The controller for the data described here is EAACompliance.org, The Bradfield Centre, Cambridge Science Park Road, Cambridge, CB4 0GA, United Kingdom, operating eaacompliance.org. Contact us at [email protected].

We are established in the United Kingdom and serve customers across the European Union, so two regimes apply to us: the UK GDPR for our UK processing, and the EU GDPR where we offer services to people in the EU. Where they differ, we apply the stricter obligation rather than the more convenient one.

An honest gap, stated rather than hidden. A controller outside the EU offering services into it is generally required to designate a representative in the Union under Article 27 GDPR. Ours is being appointed; until this notice names one, treat that requirement as outstanding on our side, and write to us if it affects your procurement.

When you use the platform to scan your own websites, the roles reverse: for the scan results and evidence relating to your sites, you are the controller and we are your processor, on the terms of our data processing agreement.

What we process

CategoryWhat it isWhere it comes from
Account dataYour name, email address and Google account identifierGoogle, when you sign in — we never receive or store a password
Organization dataOrganization name, plan, seats, notification address, billing detailsYou, and Stripe for payment records
Scan dataURLs, rendered page structure, rule identifiers, CSS selectors and short markup snippets from the pages we scanOur scanner, on domains you have verified
Journey dataRule identifiers, selectors, URLs, step names and timestamps from recorded authenticated flowsThe journey recorder, in your tester’s own browser
Evidence recordsThe append-only ledger: verifications, scans, sign-offs, exports and who made themGenerated by the platform as you use it
Technical dataIP address and user agent attached to a sign-in session, and rate-limit countersYour browser, when you sign in or call the API
Page requestsOne row per page you request: the time, the path, the referring site’s host name, your user agent, your IP address, the country your request arrived from, the status we answered with, and a short value derived from your address and user agent so that several requests can be recognised as one visitYour browser, on every page of this site
Two things we deliberately do not collect. The journey recorder strips form values, cookies, credentials, page HTML and screenshots inside your browser before anything is uploaded — we could not produce them if asked. And a scan of a public page can incidentally encounter personal data published on that page; we store selectors and short snippets, never full page content, and never build a profile from them.

Legal bases

  • Performance of a contract (Art. 6(1)(b) GDPR) — running the platform, scanning your domains, producing your evidence and documents, and taking payment.
  • Legitimate interests (Art. 6(1)(f)) — securing the service, rate limiting, preventing abuse, and keeping the operational records that let us diagnose failures. We keep these to what a reasonable customer would expect.
  • Legal obligation (Art. 6(1)(c)) — retaining invoices and tax records for the statutory period.

Where it is processed

Scanning runs on infrastructure located in the European Union. The web application and its database are currently hosted in Singapore, which means account data, organization data and evidence records are transferred outside the EEA. That transfer is covered by the European Commission’s Standard Contractual Clauses, and we have assessed the transfer as required.

We would rather tell you plainly than bury it. A company selling European accessibility compliance should be direct about where its own servers are. If EU-only hosting for the application is a requirement for you, say so — it is on our roadmap and we will tell you honestly where it stands rather than implying it is already done.

Sub-processors

ProviderPurposeLocation
EU scanning hostScanner infrastructureEuropean Union
Application hostWeb application and databaseSingapore
CloudflareDNS, TLS termination and protection against abuseGlobal edge, EU data centres for European visitors
GoogleSign-in (OpenID Connect) only — we receive your email, name and account identifierGlobal
StripePayments, invoices and tax handling. Card details go to Stripe and never reach usEU / US, SCCs in place

We will list changes to this table on our changelog before they take effect, so you can object if a new sub-processor does not suit you.

How long we keep it

  • Evidence records — for the retention period of your plan (3 to 60 months). Ledger entries are never edited or deleted within that period; that is what makes them evidence.
  • Raw scan pages — pruned earlier than the ledger, since the finding and its selector are the durable part.
  • Account and organization data — while your organization exists, and then removed on request. Deletion is a request we confirm with you, not a button that silently destroys an audit trail you may need.
  • Invoices — for the statutory retention period, regardless of account deletion.
  • Sign-in sessions — 30 days, or until you sign out.

Your rights

You have the rights to access, rectification, erasure, restriction, portability and objection under the GDPR, and the right to complain to a supervisory authority. Write to [email protected] and we will respond within one month.

One honest limitation: erasing evidence records erases the very thing that demonstrates your monitoring history. We will always do it if you ask, and we will tell you what you are giving up first.

Cookies

One first-party cookie, eaa_s, holds your sign-in session for 30 days. There are no analytics cookies, no advertising cookies, and no third-party trackers anywhere on this site — which is why you are not being asked to dismiss a consent banner.

We do count page requests, and we are specific about it because the previous version of this notice was not. Every page you request writes one row holding the time, the path, the referring site’s host name, your user agent, your IP address, the two-letter country Cloudflare reports, the status we answered with, and a short hash of your address and user agent that lets us tell one visit from two. Rows are kept for 90 days and then deleted.

What that does not include: no cookie is set for it, nothing is loaded from a third party to do it, no identifier follows you to another site, and we do not use it to build a profile or to advertise. You are not asked to dismiss a consent banner because the cookie we set is the sign-in one and nothing else, not because we keep nothing.

We rely on legitimate interests for this: running a site we can see the shape of, and telling real visitors apart from crawlers. If you would rather we did not, write to [email protected] and we will remove your rows.

Changes to this notice

Every version of this notice is dated, and material changes are announced on the changelog. We do not quietly rewrite a privacy notice, for the same reason we do not quietly rewrite a ledger.