Skip to content
a11yfy
How it works Pricing Compliance Certificate
Log in Start free Start

Legal

Privacy Policy

Effective date: 11 July 2026 Last updated: 13 July 2026 Version: 1.1

This Privacy Policy explains how the a11yfy platform ("a11yfy", "we", "us") collects, uses, and protects personal data. We keep it deliberately plain: we collect only what is needed to run the Service, we do not sell personal data, and we do not use your documents to train AI models.


1. Data controller

Field Value
Controller Zoltan Csordas E.V. (operating the a11yfy platform)
Registered seat Malom utca 11/1, 2367 Újhartyán, Hungary
Contact for privacy matters support@a11yfy.com

Where you upload documents that themselves contain personal data, you (or your organisation) are the controller of that content and we process it on your behalf, solely to provide the Service (see Section 4).


2. What we collect and why

Category Details Purpose Legal basis (GDPR Art. 6)
Account data Email address, name, password hash, language preference Authentication, account management, service notifications Performance of contract — 6(1)(b)
Organisation data Organisation name, membership, roles Team collaboration, access control Performance of contract — 6(1)(b)
Billing data Subscription status, credit balance, transaction references received from Paddle Billing, credit accounting, support Performance of contract — 6(1)(b); legal obligation — 6(1)(c)
Uploaded documents and outputs PDF files you upload and the accessible files we generate Providing the document-remediation service Performance of contract — 6(1)(b)
Usage and job data Processing history, credit consumption, API usage Billing, support, abuse prevention Performance of contract — 6(1)(b); legitimate interest — 6(1)(f)
Technical data IP address, session identifiers, security and audit logs Security, fraud and abuse prevention Legitimate interest — 6(1)(f)
Support communication Emails you send to support@a11yfy.com Handling your requests Legitimate interest — 6(1)(f)
Signup attribution Campaign parameters (utm_*), referring URL, and landing page from your first visit, recorded when you create an account Measuring which marketing channels work — first-party only, never shared with third parties Legitimate interest — 6(1)(f)

We do not collect more data than listed here, and we do not use your data for advertising or profiling.


3. Payments — Paddle

Payments are processed by Paddle (Paddle.com Market Limited, UK / Paddle.com Inc., USA), our Merchant of Record. When you make a purchase, Paddle acts as an independent data controller of the personal data you provide at checkout — such as your name, email address, billing address, payment card details, IP address, and transaction records. Paddle's processing is governed by its own Privacy Policy.

Paddle shares limited order data with us (transaction references, subscription status, billing country) for order fulfilment, credit accounting, fraud prevention, and support. We never receive or store your full payment card details.


4. Uploaded documents

Documents you upload are processed exclusively to provide the Service: analysis, remediation, validation, certificate issuance, and delivery of the output file.

  • We do not read, review, or use your documents for any other purpose.
  • We do not use your documents or the generated outputs to train generalised AI models.
  • Access to stored documents is restricted and protected by technical and organisational measures.

During processing, document content is transmitted to the specialised document-analysis and AI providers listed in Section 6, strictly for the purpose of performing the conversion.


5. Retention

Data Retention period
Uploaded input documents Deleted automatically 7 days after upload
Generated output files (and certificates' downloadable copies) Deleted automatically 30 days after completion
Processing caches (intermediate document-analysis results used to avoid re-processing the same file) Deleted automatically no later than 7 days after creation
Account data Until account deletion (7-day grace period, then permanent erasure)
Signup attribution (campaign parameters recorded at account creation) For the lifetime of your account; deleted when your account is deleted
Credit ledger and transaction records Retained as required by applicable tax and accounting law (typically up to 8 years)
Security and audit logs Up to 12 months
Session data Until session expiry or sign-out

You can delete uploaded documents earlier at any time. When you delete your account, a 7-day grace period applies (during which you can undo the deletion by logging in); after it, your account data and all stored documents are permanently erased.


6. Recipients and international transfers

We use the following categories of service providers ("recipients") to operate a11yfy:

Recipient Role Location Safeguard
Cloudflare, Inc. Hosting, storage, CDN, security EU data centres (with US parent) EU Standard Contractual Clauses (SCCs); EU Data Boundary controls
Google Cloud (Google Ireland Ltd.) Document-conversion compute EU (europe-west1, Belgium) GDPR-compliant EU processing; SCCs where applicable
Specialised document-analysis and AI service providers Layout analysis, OCR, AI-generated descriptions during processing EU and USA EU Standard Contractual Clauses (SCCs); data processed transiently, not retained for training
Functional Software, Inc. (Sentry) Error diagnostics — technical error reports so we can detect and fix failures EU ingest endpoint (US parent) EU Standard Contractual Clauses (SCCs); configured to exclude personal data (no PII sent)
Paddle Payment processing (Merchant of Record) UK / USA Independent controller — see Section 3

To protect the free document scanner on our website from automated abuse, we use Cloudflare Turnstile (a privacy-preserving bot-detection service by Cloudflare, Inc.). Turnstile evaluates browser signals to distinguish humans from bots; it does not track you across sites and does not build advertising profiles. See the Cookie Policy for details.

All transfers of personal data outside the European Economic Area take place under Standard Contractual Clauses approved by the European Commission, or another valid transfer mechanism under Chapter V GDPR. A current, detailed list of processors engaged for document processing is available on request at support@a11yfy.com.

We do not sell personal data, and we do not share it with any third party for their own marketing purposes.


7. Your rights (GDPR)

Under Articles 15–22 GDPR you have the right to:

  • Access your personal data and receive a copy;
  • Rectify inaccurate data;
  • Erase your data ("right to be forgotten") — account deletion is available self-serve in the account settings;
  • Restrict processing;
  • Data portability — a self-serve export of your account data is available in the account settings;
  • Object to processing based on legitimate interest.

To exercise any right, use the self-serve controls in the application or contact support@a11yfy.com. We respond within one month.

Complaints

If you believe our processing infringes the GDPR, you may lodge a complaint with a data protection supervisory authority — in particular in the EU/EEA member state of your habitual residence, your place of work, or the place of the alleged infringement. A list of all EU/EEA supervisory authorities is available on the European Data Protection Board website.


8. Users outside the EEA

United Kingdom

For users in the UK, the UK GDPR applies with the same lawful bases and rights as described above. You may lodge complaints with the Information Commissioner's Office (ico.org.uk).

California (CCPA/CPRA)

California residents have the right to know what personal information we collect (see Section 2), to request deletion, and to non-discrimination for exercising these rights. We do not sell or share personal information within the meaning of the CCPA/CPRA. Submit requests to support@a11yfy.com; we respond within 45 days.


9. Security

We protect personal data with industry-standard measures, including encryption in transit (TLS) and at rest, access controls, audit logging, scoped API keys, and the automatic deletion schedules described in Section 5.


10. Cookies

We use only strictly necessary cookies plus cookieless analytics; details are in the Cookie Policy.


11. Children

The Service is not directed at children under 16, and we do not knowingly collect their data.


12. Changes to this policy

If we make material changes to this policy, we will post the updated version here and notify registered users by email before the changes take effect.

Questions? Contact us at support@a11yfy.com.

Product

  • Pricing
  • How it works
  • Try it free
  • API & SDKs
  • WordPress plugin

Resources

  • API reference
  • Compliance
  • Security & data protection
  • GitHub
  • Help

Legal

  • Imprint
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Refund Policy
  • Data Processing Agreement
  • Accessibility statement
  • support@a11yfy.com
a11yfy Accessible PDF generator. PDF/UA-1 and WCAG compliance, EAA-ready.
© 2026 a11yfy. All rights reserved.

a11yfy produces PDF/UA-1 tagged PDFs — the technical foundation required by EN 301 549 (the EAA and the EU Web Accessibility Directive) and referenced by US Section 508 and ADA guidance. Accessibility regulations also cover process and content-quality requirements that no tool can fully automate; our reports show exactly what was fixed and what needs human judgment. a11yfy is a technology provider, not a law firm; this site is not legal advice.

Referenced frameworks: EAA (Directive (EU) 2019/882) · Web Accessibility Directive (EU) 2016/2102 · EN 301 549 · WCAG 2.1 AA · PDF/UA-1 (ISO 14289-1) · ADA Title II · Section 508