Legal
Privacy policy
Version: July 6, 2026
This is an English convenience translation. In case of discrepancies, the German version (linked in the footer of the German site) prevails.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is SSL Fruitly AI GmbH & Co. KG, Inkustraße 1–7/Stiege 2/Haus C/1. OG/Top 2109, 3400 Klosterneuburg, Austria, email: info@accessibility-check.ai, phone: +43 650 37 50 530. Further details in the legal notice.
2. The essentials first
- We use no tracking or marketing cookies.
- We sell no data and show no advertising.
- Uploaded PDF files are processed only in memory for the duration of the check and discarded afterwards.
- Accounts are passwordless; your email address is enough to sign in.
3. Hosting and server logs
When you access the website, our server automatically processes technical access data (IP address, date and time, requested page, browser identifier). This data is required for the operation, stability and protection of the Services (Art. 6(1)(f) GDPR) and is deleted after a short time unless it is needed to investigate misuse.
Operation takes place at an external hosting provider within a data processing agreement under Art. 28 GDPR.
4. Cookies
We use only one technically necessary session cookie (“ac_session”) that keeps you signed in after login (lifetime: 30 days, HttpOnly). The legal basis is Art. 6(1)(b) and (f) GDPR. Since we use no cookies requiring consent without your consent, we show no cookie banner. For the consent-based additional features of our analytics (section 4a) we obtain separate consent.
4a. Analytics and error diagnostics with Pivty
For usage analysis, error diagnostics and reach measurement we use Pivty (pivty.com). Pivty is a service operated by us (SSL Fruitly AI GmbH & Co. KG) ourselves and serves to improve this website and to trace technical problems faster. Processing and storage take place on servers within the European Union.
Without consent, Pivty sets no cookies, writes nothing to your device, stores no persistent browser identifier and records no sessions. In this mode Pivty only measures data-minimizing, content-free usage and quality data (Art. 6(1)(f) GDPR). To recognize a visitor within a single day, Pivty forms a short-lived hash from a daily rotating random value, the IP address and a browser signature. The IP address and browser signature are not stored in clear text; the random value is deleted after 24 hours. As a result, no cross-site and no cross-day tracking takes place without consent.
With consent, Pivty stores a stable, random identifier in browser local storage to recognize visits to this website across several days, to measure usage events and to replay sessions for error analysis (Art. 6(1)(a) GDPR). The identifier applies only to this website and not across sites. If you are signed in to your accessibility-check.ai account, usage data may be linked to your account insofar as this is necessary for error analysis and product improvement.
For session replays, inputs, form fields, passwords, payment data and sensitive content are technically hidden or masked in the browser before any data is transmitted. Forms are evaluated without input contents; at most whether a form was submitted or abandoned and which field was last touched is recorded.
If you decline Pivty, that decision is respected and no consent-based tracking takes place. You can change your settings at any time via the link at the end of this section and withdraw consent with effect for the future. After withdrawal the browser identifier is deleted and any ongoing recording is ended. The daily random value for anonymous counting is deleted after 24 hours; analytics data and any session recordings are deleted once they are no longer required for the stated purposes.
Without consent, in particular the following may be processed:
- pages and paths visited, timestamps, referrer domain, UTM parameters and 404 hits with the referring page;
- approximate location data (country, region, city) derived locally from the IP address, without storing the IP address itself;
- technical characteristics such as browser, operating system, device type, screen size, language, connection type and preferred color scheme;
- content-free interactions such as clicks, rage clicks, scroll depth, dwell time, frantic scrolling, quick back navigation, zoom gestures, form abandonment and last touched field;
- anonymous click coordinates for aggregated heatmaps;
- search terms from the on-site search taken from the URL (entries that look like personal data are discarded);
- short copied text snippets, exclusively from page content and not from input fields;
- technical quality data such as load times, layout stability, JavaScript errors and failed server requests with path and status code, but no request or response contents.
The following are not collected:
- raw IP addresses, browser signatures in clear text, form contents, passwords and payment data;
- cross-site tracking, ad network data and data sales;
- automated decisions within the meaning of Art. 22 GDPR.
5. Account and sign-in codes
To unlock full reports we create an account with your email address. Sign-in works via 6-digit one-time codes we send you by email; codes are valid for 10 minutes and are stored on our side only as a hash. We process your email address and the times of sign-in (Art. 6(1)(b) GDPR). You can have your account deleted at any time by emailing us.
6. Website check and monitoring
When you enter a website address for a check, our audit system requests the publicly reachable pages of that website and analyzes them automatically. We store the checked address, the audit results and screenshots of the checked views as part of the report (Art. 6(1)(b) and (f) GDPR). Reports are assigned to your account once you sign in.
For monitoring, we additionally store the address you selected and the check interval in order to run recurring checks and send you the reports by email.
To prevent misuse we limit the number of requests per IP address; these counters are only held briefly in memory (Art. 6(1)(f) GDPR).
7. PDF check
Uploaded PDF files are processed exclusively for the automated accessibility analysis. The analysis runs in an isolated environment; the file is held only in memory and discarded after the check. Only the audit report, the file name and a preview image of the first page are stored permanently so you can retrieve the report later (Art. 6(1)(b) GDPR).
Please only upload documents you are authorized to process. If documents contain personal data of third parties, you are responsible for the lawfulness of the processing.
7a. Alt text generator (AI image description)
Uploaded images are processed exclusively to generate the image description you requested. The analysis is performed by a self-hosted AI model on our own infrastructure; no data is transferred to external AI providers. The image is held only in memory and discarded after the description has been generated. It is neither stored nor used to train models. So you can find your results in your account, we store a usage counter for your allowance, the generated description text, the context you entered and the image metadata (type and size, not the image content). You can remove this account history at any time by deleting your account (Art. 6(1)(b) GDPR).
Please only upload images you are authorized to process. If images contain personal data of third parties (such as identifiable people), you are responsible for the lawfulness of the processing.
8. Accessibility statement generator
We use the information you enter (such as organization name, description of the offering, contact email and phone number) exclusively to generate the statement and send it to you by email (Art. 6(1)(b) GDPR).
9. Email delivery
We send you sign-in codes, reports (including PDF attachments) and content you requested by email. Delivery takes place via our email service provider (currently Hostinger) within a data processing agreement. We do not send promotional emails without your consent.
9a. Support requests
When you contact us via the support form in the dashboard or by email, we process your details (category, subject, message, account email and your current plan) exclusively to handle the request (Art. 6(1)(b) GDPR). Support requests are deleted once they are resolved and no statutory retention obligations apply.
10. Assistance widget on customer websites
The embeddable assistance widget runs in the browser of the respective website's visitors. Selected settings (such as font size or contrast) are stored locally in the browser and not transmitted to us. When the widget loads, our server merely checks whether the domain key is valid; the technical access data described in section 3 arises in the process. The operator of the respective website is the controller for the use of the widget on that website.
10a. Payment processing with Stripe (paid plans)
For paid plans we use the payment provider Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. This involves processing your name, email address, billing address, VAT ID where applicable, payment data (e.g. card details, directly with Stripe) and transaction and subscription data. The purpose is contract performance and billing; the legal basis is Art. 6(1)(b) GDPR and, for retaining invoice data, Art. 6(1)(c) GDPR.
Stripe processes payment data partly under its own responsibility, including through Stripe, Inc. in the USA; transfers are based on EU standard contractual clauses and the EU-US Data Privacy Framework. We retain invoice data for up to ten years under commercial and tax law. Details: stripe.com/privacy.
11. Recipients and third-country transfers
We pass your data only to the named processors (hosting, email delivery) to the extent required for operating the Services, and to authorities where we are legally obliged. No transfer to third countries outside the EU/EEA takes place unless it occurs in individual cases on the basis of suitable safeguards (Art. 44 et seq. GDPR).
12. Storage periods
- Sign-in codes: 10 minutes, then invalid and deleted.
- Sessions: 30 days or until sign-out.
- Reports and account data: until your account is deleted or you request deletion.
- Server logs: short-term, unless misuse is suspected.
- Uploaded PDF files: only for the duration of the check.
- Uploaded images (alt text generator): only for the duration of the description, never stored.
13. Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object to processing based on legitimate interests (Art. 21). To exercise them, simply contact info@accessibility-check.ai.
You also have the right to lodge a complaint with a data protection supervisory authority, in Austria with the Data Protection Authority (www.dsb.gv.at), alternatively with the authority responsible for your place of residence.
14. No automated decision-making
Our reports and assessments are technical analyses without legal effect towards you; no automated decision-making within the meaning of Art. 22 GDPR takes place.
15. Changes to this policy
We adapt this privacy policy when our Services or the legal situation change. The version published here at the time applies.
