AccessPreflight is designed to minimize source retention and keep technical evidence separate from the customer content that produced it. This policy describes our current intended data practices and is subject to any more specific data-processing agreement, order form, or enterprise agreement.
1. Scope, controller, and processor roles
This Privacy Policy applies to the AccessPreflight marketing website, application, APIs, accounts, support communications, and related services (the “Service”). It does not govern third-party websites or integrations that have their own privacy policies.
AccessPreflight is the controller of personal data used to operate the website, administer accounts, communicate with users, bill customers, secure the Service, and improve our operations. If an order form identifies another AccessPreflight contracting entity, that entity is the controller for the relationship described there.
When a customer submits website content, HTML, documents, or other material containing personal data and determines why and how that material is processed, the customer is normally the controller and AccessPreflight acts as its processor. The applicable data-processing agreement governs that processing.
Controller address: "Dunajska cesta 106, Ljubljana, Slovenia".
2. Personal data we collect
| Category | Examples | Source |
|---|---|---|
| Account and identity | Name, work email, organization, role, authentication and membership records | You, your organization, or an identity provider |
| Commercial and billing | Plan, usage, invoices, tax information, billing contacts, and payment status | You and our payment provider |
| Service and device | IP address, browser and device information, request time, routes, API activity, security events, and diagnostic logs | Your browser, client, and use of the Service |
| Customer Content | Submitted URLs, HTML, PDF or DOCX files, metadata, file names, extracted structure, and supplied configuration | You or an integration you configure |
| Technical outputs | Findings, evidence locators, reports, hashes, profile and engine versions, gate decisions, and audit records | Generated while providing the Service |
| Communications | Support requests, demo inquiries, product feedback, and administrative or marketing preferences | You |
| Optional website analytics | Consent-state and cookieless measurements while storage is denied; fuller page, engagement, device, referrer, approximate-location, and identifier data after you allow analytics | Google Analytics through advanced Consent Mode |
3. How and why we use personal data
We process personal data to:
- provide, administer, support, and bill for the Service;
- accept and orchestrate scans, create reports, deliver webhooks, and maintain configured evidence and audit records;
- authenticate users, enforce permissions and limits, prevent abuse, investigate incidents, and protect customers and the Service;
- respond to inquiries, provide requested demos, and send essential service or account communications;
- understand website use and improve public content when you have consented to optional analytics;
- comply with legal, accounting, tax, sanctions, and regulatory obligations; and
- establish, exercise, or defend legal claims and enforce our terms.
Depending on the context and applicable law, our legal bases include performing a contract, taking requested pre-contract steps, complying with legal obligations, pursuing legitimate interests in operating and securing the Service, and your consent. Where we rely on consent, you may withdraw it at any time without affecting earlier processing.
4. Customer Content and accessibility scan data
We do not use customer files, supplied HTML, extracted text, or private scan content to train AccessPreflight or third-party machine-learning models.
Customer Content can contain confidential information, personal data, special-category data, or information about children. Customers must decide what is appropriate to submit, configure suitable retention, and provide required notices or obtain required permissions. Standard operational logs are designed not to contain raw document content, full submitted HTML, or sensitive identifiers.
The Service creates technical outputs such as findings, evidence locators, hashes, reports, and version information. These outputs may themselves contain personal data, especially where source text, file names, URLs, or metadata identify a person. Customers should apply access controls and retention settings accordingly.
The public website checker processes one submitted public URL to perform the requested scan. We also process the requester’s IP address and Cloudflare Turnstile result to prevent abuse. The temporary public preview is not transferred into a customer workspace, and the submitted URL, checker token, scan identifier, and finding content are not sent to website analytics.
The public PDF checker processes one uploaded PDF, its filename, and basic source metadata to perform the requested scan. The public checker accepts files up to 10 MiB and 25 pages and retains the source for 24 hours. We also process the requester’s IP address and Cloudflare Turnstile result to prevent abuse. The filename, checker token, scan identifier, source content, and finding content are not sent to website analytics.
7. Regions and international transfers
AccessPreflight’s initial production service is designed for EU data processing. Some providers, support activities, billing services, or optional analytics may involve processing in other countries. Where required, we use an approved transfer mechanism and supplementary safeguards, such as an adequacy decision or standard contractual clauses.
The applicable order form, data-processing agreement, or subprocessor information describes service-specific processing and backup regions. Google may process analytics data in countries where it and its subprocessors operate under Google’s applicable transfer arrangements.
8. Retention and deletion
We retain personal data only for as long as needed for the purposes described here, the customer’s configured policy, contractual obligations, security, and applicable law. Different records have different lifecycles.
- Raw uploads and supplied HTML are designed for short retention; the standard service target is deletion within 24 hours after terminal processing, with shorter or zero-retention modes where available.
- Native engine output is short-lived and separated from longer-lived findings, reports, hashes, profile versions, and evidence metadata.
- Findings, reports, audit records, billing records, and signed deletion evidence may be retained for the plan, project policy, legal requirement, or period agreed with the customer.
- Account and support records are retained while needed to provide the Service, resolve issues, enforce agreements, and satisfy legal obligations.
- Optional analytics data follows the Google Analytics property retention settings and your consent choice.
Deletion from primary systems and derived artifacts may be asynchronous. Encrypted backups expire according to their configured lifecycle and are not restored to extend ordinary retention. We may retain minimal deletion, fraud-prevention, billing, or legal records where necessary and permitted.
9. Security
We use administrative, technical, and organizational measures designed to protect personal data, including access controls, encryption in transit and at rest where appropriate, tenant isolation, private storage, log redaction, credential controls, vulnerability management, retention monitoring, and incident procedures. No security measure can eliminate every risk.
If you believe you have found a security or privacy issue, do not include sensitive Customer Content in an ordinary email. Contact info@accesspreflight.com so we can provide an appropriate reporting channel.
10. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of your personal data; object to certain processing; withdraw consent; or complain to a supervisory authority. You may also have the right to know the categories, sources, purposes, and recipients of personal data and to appeal a denied request.
Send a request to info@accesspreflight.com. We may need to verify your identity and authority. If your data was submitted by an AccessPreflight customer, contact that customer first; we will assist the customer with requests as required by the applicable data-processing agreement and law. Authorized agents may submit requests where local law permits.
You may withdraw website analytics consent at any time using “Cookie settings” in the footer. You may unsubscribe from optional marketing messages through the link in the message, while essential account, security, billing, and service communications will continue.
11. Children
The Service is intended for organizations and professionals and is not directed to children. We do not knowingly collect personal data directly from children through the marketing website. Customers must not submit children’s data unless authorized by the applicable agreement and law and appropriate safeguards are in place.
12. Changes to this policy
We may update this policy as the Service, providers, or law changes. We will publish the revised policy with a new effective date and, where required, provide additional notice. Material changes to processor terms or subprocessors follow the applicable agreement and change-notice process.
13. Contact and complaints
Contact AccessPreflight at info@accesspreflight.com with privacy questions or requests.
Postal address: "Dunajska cesta 106, Ljubljana, Slovenia".
You may also lodge a complaint with the data-protection authority in your country or the authority responsible for the AccessPreflight controller. We encourage you to contact us first so we can try to resolve the issue.