← Back to AAI

Legal

Privacy Statement

Last updated: 05 June 2026

This Privacy Statement explains how Accessibility Assurance Institute collects, uses, stores, shares, and protects personal data when you use our website, public scan tools, customer portal, widgets, reports, manual testing workflow, developer workflow, support services, emails, billing processes, and related services.

1. Who we are

AAI is operated by Accessibility Assurance Institute, with address at 6 Quay Street, Skerries, County Dublin, Ireland.

For privacy and data protection questions, contact us at legal@aa-i.ie.

2. Our role

Where applicable, we act as a data controller for personal data we use for our own business purposes, such as account management, billing, marketing, security, and support.

Where we process personal data on behalf of a customer as part of scans, evidence, reports, uploaded materials, or managed workflows, we may act as a data processor for that customer.

3. Personal data we collect

We may collect and process the following types of personal data:

  • Account and user data, such as name, email address, role, organisation, login details, preferences, and communication settings.
  • Organisation and billing data, such as organisation name, billing contact details, subscription plan, payment status, invoice references, and tax information where required.
  • Website, scan, and workflow data, such as domain names, page URLs, scan results, accessibility findings, manual audit notes, developer actions, evidence attachments, reports, and support configuration.
  • Technical and usage data, such as IP address, browser and device information, log data, session information, security events, cookie identifiers, pages visited, feature usage, and error reports.
  • Communications data, such as emails, support tickets, demo requests, contact form messages, and our responses.

4. How we collect data

We collect data when you visit our website, use the public scan feature, create an account, add an organisation or domain, run scans, create reports, install or configure a widget, upload evidence or notes, purchase or manage a subscription, contact us, or when our systems automatically generate logs, scan results, and security records.

5. Why we use personal data

We use personal data to:

  • Provide, operate, secure, and improve AAI.
  • Create and manage accounts, organisations, domains, pages, scans, reports, widgets, and workflows.
  • Process subscriptions, invoices, payments, add-ons, and cancellations.
  • Provide support and respond to enquiries.
  • Send service messages, security notices, invoices, and product updates.
  • Prevent misuse, abuse, fraud, unauthorised scanning, and security incidents.
  • Meet legal, accounting, tax, regulatory, and audit obligations.
  • Send marketing communications where permitted.

6. Legal bases for processing

Where GDPR applies, we rely on one or more legal bases, including contract, legitimate interests, consent, and legal obligation.

We rely on contract where processing is needed to provide the platform and services. We rely on legitimate interests to operate, secure, improve, and promote AAI, prevent misuse, and manage customer relationships. We rely on consent where required, such as for certain cookies or optional marketing. We rely on legal obligation where processing is needed for accounting, tax, compliance, regulatory, or legal requirements.

7. Cookies and similar technologies

We may use cookies and similar technologies for essential website and login functionality, security, user preferences, analytics, product improvement, and marketing where permitted.

Where required, we will ask for consent before using non-essential cookies. You can manage cookie preferences through our cookie banner or browser settings.

8. Public scans

If you use a public preview scan, we may process the URL or domain submitted, same-domain URLs discovered, scan results, technical logs, IP address, browser information, and abuse prevention data.

Public scans are limited and may be rate-limited or blocked to prevent misuse. Public scans should only be run against websites you own or are authorised to assess.

9. Customer-controlled data

Customers may upload or generate data within AAI, including accessibility findings, notes, screenshots, evidence, reports, user assignments, and developer actions.

Where this data contains personal data, the customer is responsible for ensuring that the data is lawful, personal data is not uploaded unnecessarily, users are authorised to access it, and appropriate notices and lawful bases are in place.

10. Sharing personal data

We may share personal data with hosting and infrastructure providers, payment processors, email and communication providers, authentication providers, analytics and monitoring providers, professional advisers, regulators, authorities, courts, law enforcement where required, and business successors if AAI is sold, merged, reorganised, or transferred.

We do not sell personal data.

11. International transfers

Some service providers may process personal data outside Ireland, the EEA, or the UK. Where this occurs, we will use appropriate safeguards where required, such as adequacy decisions, standard contractual clauses, or equivalent protections.

12. Retention

We keep personal data only for as long as needed for the purposes described in this Privacy Statement. Retention periods may depend on account status, subscription and billing requirements, legal and tax obligations, security needs, customer instructions, and the need to preserve reports, evidence history, and operational records.

13. Security

We use appropriate technical and organisational measures designed to protect personal data, including access controls, authentication, logging, backup processes, and security monitoring.

No system is completely secure. Customers and users are responsible for keeping account credentials secure and controlling access within their organisations.

14. Your data protection rights

Depending on where you are located and the law that applies, you may have rights to access, correct, delete, restrict, object to processing, receive a portable copy of your data, withdraw consent, and complain to a data protection authority.

In Ireland, the relevant authority is the Data Protection Commission. To exercise rights, contact us at legal@aa-i.ie.

15. Marketing communications

We may send marketing communications where permitted by law. You can opt out at any time by using the unsubscribe link in our emails or contacting us.

Even if you opt out of marketing, we may still send service, billing, security, and account-related messages.

16. Children

AAI is intended for use by organisations, professionals, website owners, developers, auditors, and authorised users. It is not intended for children, and we do not knowingly collect personal data from children through the platform.

17. Changes to this Privacy Statement

We may update this Privacy Statement from time to time. The updated version will be posted on our website or made available through the platform. Where changes are material, we will take reasonable steps to notify affected users.

18. Contact

Accessibility Assurance Institute
6 Quay Street, Skerries, County Dublin, Ireland.
Email: legal@aa-i.ie