DATA GOVERNANCE · GDPR · INDIA DPDP ACT 2023 · ZERO VISITOR PII

DATA PRIVACY & PROTECTION POLICY

Privacy Policy.

A11yGo is engineered with privacy-by-design principles. We protect personal information, maintain zero visitor telemetry on client websites, and uphold global privacy regulations.

Zero PII Client Site Visitors
GDPR & DPDP Compliance Baseline
AES-256 Encrypted Data In Transit
01

Privacy Overview & Scope

This Privacy Policy governs how A11yGo ("A11yGo", "we", "our", or "us") collects, stores, processes, and protects information across our marketing website, license management platform, and customer portals.

By accessing our website, creating an account, or purchasing a subscription, you consent to the data practices described in this Privacy Policy.
02

Zero-Visitor-PII Architecture

Client-Side Isolation Guarantee

When an organization embeds the A11yGo Toolbar on their website, the toolbar operates entirely within the end-user's local browser. We do NOT track individual website visitors, record browsing habits, capture biometric data, or store Personally Identifiable Information (PII) of your visitors.

User preferences (such as high contrast mode, chosen font size, or dyslexia adjustments) are persisted strictly in the visitor's local browser storage (localStorage) and are never transmitted to our remote servers.

03

Information We Collect

3.1 Information You Provide Directly

We collect information directly when you register an account, request a free assessment, or purchase a subscription:

  • Account Details: Full name, corporate email address, contact phone number, company/organization name.
  • Billing & Commercial Data: Billing address, GST number (if applicable), transaction IDs, and plan selections.
  • Support Communications: Inquiries, tickets, and correspondence submitted via email or contact forms.
3.2 Information Collected Automatically

When accessing the A11yGo marketing website or customer dashboard, our servers automatically log technical metadata such as browser version, operating system, approximate geographic location (country/city level via IP), and referral URLs for security and diagnostic purposes.

04

How We Use Information

We process collected information solely for legitimate business and contractual purposes:

  • Service Fulfillment: Generating license keys, validating authorized domains, and managing subscriptions.
  • Diagnostic Reporting: Crawling public web pages to produce complimentary WCAG/IS 17802 assessment PDF reports.
  • Customer Support: Responding to inquiries and troubleshooting integration questions.
  • Security & Fraud Prevention: Protecting administrative portals from brute-force attempts and abuse.
05

Data Protection & Security Standards

A11yGo employs enterprise-grade technical, operational, and organizational security controls:

TLS 1.3 & AES-256

All data in transit is encrypted using modern TLS 1.3 ciphers, and databases are encrypted at rest.

Role-Based Access

Strict least-privilege employee access controls with mandatory multi-factor authentication (MFA).

06

Third-Party Data Sharing

We do not sell, rent, or trade your personal data. We disclose data only to trusted subprocessors essential for delivering the Service:

  • Cloud Infrastructure & CDN: High-security hosting providers for web delivery and API endpoints.
  • Payment Gateways: PCI-DSS certified payment processors for secure transaction settlement.
  • Transactional Email: SMTP gateways for delivering license confirmations, PDF assessments, and password resets.
07

Your Statutory Privacy Rights

Under applicable privacy frameworks (including GDPR, Indian Digital Personal Data Protection Act 2023, and CCPA), you possess the following rights:

Right to Access / Inquire
Right to Rectification / Correction
Right to Erasure / "Be Forgotten"
Right to Data Portability

To exercise any of these statutory rights, submit a written request to [email protected]. We respond within 30 days.

08

Data Retention Policies

We retain personal information only for as long as your account remains active or as required to fulfill tax, statutory accounting, and legal obligations (typically 5 to 7 years for financial transaction records). Inactive lead records and temporary assessment scans are purged on a rolling 90-day cycle.

09

Cross-Border Data Transfers

Where data is transferred across international boundaries, we ensure that transfers comply with applicable data protection laws through Standard Contractual Clauses (SCCs) and robust technical safeguards.

10

Privacy Desk & Data Protection Officer

If you have questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact our Privacy Desk:

Official Privacy Email [email protected]
Customer Support Portal Submit Privacy Ticket

A11yGo Privacy Office: We are committed to resolving data protection inquiries swiftly and transparently.

PRIVACY-FIRST ACCESSIBILITY

Enhance accessibility without compromising visitor privacy.

Discover how A11yGo delivers WCAG and IS 17802 compliance with 100% zero visitor tracking.