Skip to main content
AccessPreflight
Free checkers
Check a source nowNo account required
Website checkerOne public page against the WCAG 2.2 web profilePDF checkerOne private PDF with a PDF/UA-1 technical preview
Pricing
Policies
Scanning policies15 versioned profiles

Web standards

  • WCAG 2.1 AAwcag-2.1-aa-web
  • WCAG 2.2 AAwcag-2.2-aa-web
  • EN 301 549 weben-301-549-v3.2.1-web

Document standards

  • EN 301 549 documentsen-301-549-v3.2.1-nonweb-document
  • PDF/UA-1pdfua-1-machine
  • PDF/UA-2pdfua-2-machine

Legal mappings

  • European Accessibility Acteu-eaa-preflight
  • EU Web Accessibility Directiveeu-wad-current
  • Slovenia ZDPSIsi-zdpsi-current
  • Slovenia ZDSMAsi-zdsma-current
  • ADA Title IIus-ada-title-ii-2026
  • EAA e-commerceeu-eaa-ecommerce-service
  • US Section 508us-section-508-ict
  • UK public sectoruk-psbar-current
  • UK Equality Actuk-equality-act-digital-context
Compare profiles, inputs, and coverage boundaries.View all policies
Resources
Explore AccessPreflightProduct, guidance, and support
ProductPlatform and result modelFeaturesAPIs, gates, reports, and webhooksUse casesPublishing and delivery workflowsHow it worksScan lifecycle and evidenceBlogPractical accessibility field notesFAQAnswers about scans and coverage
API docs ↗Sign inTry it free
Free checkers

Choose a source

Website checkerPDF checker
ProductFeaturesUse casesHow it worksPricing
Policies

Web standards

WCAG 2.1 AAWCAG 2.2 AAEN 301 549 web

Document standards

EN 301 549 documentsPDF/UA-1PDF/UA-2

Legal mappings

European Accessibility ActEU Web Accessibility DirectiveSlovenia ZDPSISlovenia ZDSMAADA Title IIEAA e-commerceUS Section 508UK public sectorUK Equality Act
View all policies
BlogFAQAPI docs ↗Sign inTry it free
Legal

Privacy Policy

This policy explains how AccessPreflight handles personal data on the website and in the accessibility preflight service.

Effective
August 17, 2026
Privacy contact
info@accesspreflight.com
On this pageScope and rolesData we collectHow we use dataCustomer contentAnalytics and cookiesSharing and providersRetention and deletionYour rightsContact

AccessPreflight is designed to minimize source retention and keep technical evidence separate from the customer content that produced it. This policy describes our current intended data practices and is subject to any more specific data-processing agreement, order form, or enterprise agreement.

1. Scope, controller, and processor roles

This Privacy Policy applies to the AccessPreflight marketing website, application, APIs, accounts, support communications, and related services (the “Service”). It does not govern third-party websites or integrations that have their own privacy policies.

AccessPreflight is the controller of personal data used to operate the website, administer accounts, communicate with users, bill customers, secure the Service, and improve our operations. If an order form identifies another AccessPreflight contracting entity, that entity is the controller for the relationship described there.

When a customer submits website content, HTML, documents, or other material containing personal data and determines why and how that material is processed, the customer is normally the controller and AccessPreflight acts as its processor. The applicable data-processing agreement governs that processing.

Controller address: "Dunajska cesta 106, Ljubljana, Slovenia".

2. Personal data we collect

CategoryExamplesSource
Account and identityName, work email, organization, role, authentication and membership recordsYou, your organization, or an identity provider
Commercial and billingPlan, usage, invoices, tax information, billing contacts, and payment statusYou and our payment provider
Service and deviceIP address, browser and device information, request time, routes, API activity, security events, and diagnostic logsYour browser, client, and use of the Service
Customer ContentSubmitted URLs, HTML, PDF or DOCX files, metadata, file names, extracted structure, and supplied configurationYou or an integration you configure
Technical outputsFindings, evidence locators, reports, hashes, profile and engine versions, gate decisions, and audit recordsGenerated while providing the Service
CommunicationsSupport requests, demo inquiries, product feedback, and administrative or marketing preferencesYou
Optional website analyticsConsent-state and cookieless measurements while storage is denied; fuller page, engagement, device, referrer, approximate-location, and identifier data after you allow analyticsGoogle Analytics through advanced Consent Mode

3. How and why we use personal data

We process personal data to:

  • provide, administer, support, and bill for the Service;
  • accept and orchestrate scans, create reports, deliver webhooks, and maintain configured evidence and audit records;
  • authenticate users, enforce permissions and limits, prevent abuse, investigate incidents, and protect customers and the Service;
  • respond to inquiries, provide requested demos, and send essential service or account communications;
  • understand website use and improve public content when you have consented to optional analytics;
  • comply with legal, accounting, tax, sanctions, and regulatory obligations; and
  • establish, exercise, or defend legal claims and enforce our terms.

Depending on the context and applicable law, our legal bases include performing a contract, taking requested pre-contract steps, complying with legal obligations, pursuing legitimate interests in operating and securing the Service, and your consent. Where we rely on consent, you may withdraw it at any time without affecting earlier processing.

4. Customer Content and accessibility scan data

Customer Content is not training data.

We do not use customer files, supplied HTML, extracted text, or private scan content to train AccessPreflight or third-party machine-learning models.

Customer Content can contain confidential information, personal data, special-category data, or information about children. Customers must decide what is appropriate to submit, configure suitable retention, and provide required notices or obtain required permissions. Standard operational logs are designed not to contain raw document content, full submitted HTML, or sensitive identifiers.

The Service creates technical outputs such as findings, evidence locators, hashes, reports, and version information. These outputs may themselves contain personal data, especially where source text, file names, URLs, or metadata identify a person. Customers should apply access controls and retention settings accordingly.

The public website checker processes one submitted public URL to perform the requested scan. We also process the requester’s IP address and Cloudflare Turnstile result to prevent abuse. The temporary public preview is not transferred into a customer workspace, and the submitted URL, checker token, scan identifier, and finding content are not sent to website analytics.

The public PDF checker processes one uploaded PDF, its filename, and basic source metadata to perform the requested scan. The public checker accepts files up to 10 MiB and 25 pages and retains the source for 24 hours. We also process the requester’s IP address and Cloudflare Turnstile result to prevent abuse. The filename, checker token, scan identifier, source content, and finding content are not sent to website analytics.

5. Analytics, cookies, and local storage

When a measurement ID is configured, the marketing website loads Google Analytics 4 using Google’s advanced Consent Mode. Before you make a choice, analytics storage, advertising storage, advertising user data, and advertising personalization default to denied. Google signals and advertising personalization remain disabled in our configuration even if you allow analytics.

While analytics storage is denied, the Google tag does not write analytics cookies, but Google may receive consent-state signals and measurements without cookies, including functional request data and limited page or event context. If you choose “Allow analytics,” analytics storage becomes granted and Google may receive analytics identifiers, page and engagement information, referrer, device and browser data, approximate location derived from network information, and related usage data. Google acts under its own terms and privacy disclosures; learn more in Google’s Privacy Policy and its Google Analytics privacy information.

We store your analytics choice in browser local storage under accesspreflight.analytics-consent and in the functional first-party cookie ap_analytics_consent. The cookie shares the choice with the AccessPreflight application and expires after 180 days. These records prevent the consent panel from appearing on every page. You can change your choice through “Cookie settings” in the footer. Withdrawing consent changes analytics storage to denied, attempts to remove AccessPreflight analytics cookies from the current domain, and limits subsequent Google measurements to the cookieless denied state described above. Clearing browser storage resets the choice.

If analytics is allowed, we also measure interactions with sign-up, sign-in, and demo links and selected service milestones such as completed registration, confirmed demo booking, first completed scan, and confirmed paid subscription. These events contain product context such as CTA placement, scan asset type, plan, currency, and invoice transaction ID; they do not include names, email addresses, submitted content, or scanned URLs. The application may keep first-party event-deduplication markers so milestone events are not sent repeatedly from the same browser.

Essential browser storage may also be used by the application for authentication, security, session continuity, preferences, and other features you request. Essential storage is not used for advertising.

6. When personal data is shared

We may share personal data with:

  • infrastructure, database, object-storage, queue, security, observability, transactional-email, support, and similar providers that help operate the Service;
  • payment, invoicing, tax, and fraud-prevention providers for paid plans;
  • Google Analytics for denied-consent, cookieless website measurement and, when you allow optional analytics, fuller analytics measurement;
  • integrations and webhook destinations that you direct us to use;
  • professional advisers, auditors, insurers, and financing or transaction counterparties under appropriate confidentiality; and
  • public authorities or other parties when required by law or reasonably necessary to protect rights, safety, security, and the integrity of the Service.

We do not sell personal data or share it for cross-context behavioral advertising. Service providers may process data only for the agreed purpose and under applicable contractual safeguards. The current subprocessor list and change-notice process are made available to customers before production processing of Customer Content and may also be included with the applicable data-processing agreement.

7. Regions and international transfers

AccessPreflight’s initial production service is designed for EU data processing. Some providers, support activities, billing services, or optional analytics may involve processing in other countries. Where required, we use an approved transfer mechanism and supplementary safeguards, such as an adequacy decision or standard contractual clauses.

The applicable order form, data-processing agreement, or subprocessor information describes service-specific processing and backup regions. Google may process analytics data in countries where it and its subprocessors operate under Google’s applicable transfer arrangements.

8. Retention and deletion

We retain personal data only for as long as needed for the purposes described here, the customer’s configured policy, contractual obligations, security, and applicable law. Different records have different lifecycles.

  • Raw uploads and supplied HTML are designed for short retention; the standard service target is deletion within 24 hours after terminal processing, with shorter or zero-retention modes where available.
  • Native engine output is short-lived and separated from longer-lived findings, reports, hashes, profile versions, and evidence metadata.
  • Findings, reports, audit records, billing records, and signed deletion evidence may be retained for the plan, project policy, legal requirement, or period agreed with the customer.
  • Account and support records are retained while needed to provide the Service, resolve issues, enforce agreements, and satisfy legal obligations.
  • Optional analytics data follows the Google Analytics property retention settings and your consent choice.

Deletion from primary systems and derived artifacts may be asynchronous. Encrypted backups expire according to their configured lifecycle and are not restored to extend ordinary retention. We may retain minimal deletion, fraud-prevention, billing, or legal records where necessary and permitted.

9. Security

We use administrative, technical, and organizational measures designed to protect personal data, including access controls, encryption in transit and at rest where appropriate, tenant isolation, private storage, log redaction, credential controls, vulnerability management, retention monitoring, and incident procedures. No security measure can eliminate every risk.

If you believe you have found a security or privacy issue, do not include sensitive Customer Content in an ordinary email. Contact info@accesspreflight.com so we can provide an appropriate reporting channel.

10. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of your personal data; object to certain processing; withdraw consent; or complain to a supervisory authority. You may also have the right to know the categories, sources, purposes, and recipients of personal data and to appeal a denied request.

Send a request to info@accesspreflight.com. We may need to verify your identity and authority. If your data was submitted by an AccessPreflight customer, contact that customer first; we will assist the customer with requests as required by the applicable data-processing agreement and law. Authorized agents may submit requests where local law permits.

You may withdraw website analytics consent at any time using “Cookie settings” in the footer. You may unsubscribe from optional marketing messages through the link in the message, while essential account, security, billing, and service communications will continue.

11. Children

The Service is intended for organizations and professionals and is not directed to children. We do not knowingly collect personal data directly from children through the marketing website. Customers must not submit children’s data unless authorized by the applicable agreement and law and appropriate safeguards are in place.

12. Changes to this policy

We may update this policy as the Service, providers, or law changes. We will publish the revised policy with a new effective date and, where required, provide additional notice. Material changes to processor terms or subprocessors follow the applicable agreement and change-notice process.

13. Contact and complaints

Contact AccessPreflight at info@accesspreflight.com with privacy questions or requests.

Postal address: "Dunajska cesta 106, Ljubljana, Slovenia".

You may also lodge a complaint with the data-protection authority in your country or the authority responsible for the AccessPreflight controller. We encourage you to contact us first so we can try to resolve the issue.

AccessPreflight

Accessibility quality control for web and document publishing workflows.

Free checkerProductFeaturesUse casesHow it worksPricingPoliciesBlogFAQAboutAccessibility APIsAPI documentation ↗
Check a website freeSign inCreate an accountBook a demo

© 2026 AccessPreflight.

Preflight evidence, not automated certification.

AccessibilityTermsPrivacy
Optional analytics

Google Analytics runs with storage denied unless you allow analytics. Advertising storage and personalization always stay disabled. Read our privacy policy.