WebAbility Privacy Policy
Effective Date: July 18, 2024
Welcome to WebAbility! This Privacy Policy outlines how we handle your personal information when you use our services, which include our standalone service accessible through our website, webability.io (collectively referred to as the “Service”).
Information We Collect and Receive
We collect various types of information, including Personal Information, when a Customer or a Visitor (including anyone acting on their behalf) accesses or uses our Services as more fully set forth below.
a. Information You Provide
- Account Information: When you register or update an account, we collect full name, email address, and phone number. You may edit these at any time via your account or by emailing us at support@webability.io.
- Payment Details: To purchase a license, you may provide billing information (name, card number, expiration date, CVV, billing address) which is handled by our secure third-party payment processor.
- Device & Technical Information: We automatically collect your IP address, referring URL, device type and ID, operating system and version, browser type/version, and screen resolution.
- Support Information: When you use our chatbot or contact support, we collect any Personal Information you share (for example, your name, email, and message content) and may combine it with other data we hold.
- Marketing Communication: If you request a demo, a scan, or register for events, we collect your name, email, phone number, job title, and company details to fulfill your request and send follow-up materials.
b. Information Collected from Other Sources
- WebAbility Communication: Signing up for an WebAbility report requires your name and email, which we may also use for marketing follow-up.
- Usage Information: When our accessibility widget is installed, we receive image URLs, link URLs, HTML/CSS structure, clicks, interactions, and page views.
- Log Information: Server logs capture your IP address, approximate geolocation, referring page, browser type/settings, and cookie data.
- Cookies: We use cookies (excluding widget-only cookies) to operate the Service, measure ad performance, and analyze traffic (only on the landing page). See our Cookie Policy for details.
c. Information from Social Media
We collect publicly posted data (e.g., feedback, reviews, social handles) from our official social pages. If you’d like content removed, email support@webability.io.
d. Data Obtained through Analytics Tools
We use tools like Google Analytics to track site visits, page interactions, session frequency, non-precise geolocation, and referral sources.
e. Information We Collect from Third Parties
We may obtain data from referral partners, service providers (e.g., payment processors, social media), publicly available sources, and marketing providers. Combined with our data, this helps us improve and personalize the Service.
f. Information Collected in Accordance with Applicable Law
We also collect any data required to verify your identity or comply with legal obligations under applicable laws.
Communications
We may contact you via email, telephone, or other means about changes to the Service, updates to your account, billing issues, and important security or account-related notices (“Essential Communications”). You cannot opt out of these Essential Communications.
Additionally, we may send newsletters, feature updates, event invitations, and other marketing or promotional emails. You may opt out of these by clicking the unsubscribe link included in those messages.
How We Use Your Data
WebAbility uses the collected data for various purposes, including:
- Operating and maintaining our Service
- Notifying you about changes to our Service
- Allowing you to participate in interactive features when you choose
- Providing customer care and support
- Conducting analysis to improve the Service
- Monitoring usage of the Service
- Detecting, preventing, and addressing technical issues
Data Transfer
Your information, including Personal Data, may be transferred to and maintained on servers located outside your state, province, country, or other governmental jurisdiction where data protection laws may differ from your own. If you are located outside the United States and choose to provide information to us, note that we transfer the data to the United States for processing. By using our Service, you consent to this transfer.
We take reasonable steps to ensure that your data is secure and treated in accordance with this Privacy Policy. No transfer of your Personal Data will occur to an organization or country unless adequate controls are in place.
Disclosure of Data
WebAbility may disclose your Personal Data in good faith if necessary to:
- Comply with legal obligations
- Protect and defend the rights or property of WebAbility
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect the personal safety of users or the public
- Protect against legal liability
Security of Data
The security of your data is important to us, but remember that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
Data Privacy Framework Notice
WebAbility complies with the EU–U.S. Data Privacy Framework (EU–U.S. DPF), the UK Extension to the EU–U.S. DPF, and the Swiss–U.S. DPF as set forth by the U.S. Department of Commerce. We rely on the European Commission’s adequacy decision for the EU–U.S. DPF to transfer data from the EEA. WebAbility has certified adherence to the DPF Principles for processing Personal Information from the EU, UK (including Gibraltar), and Switzerland.
If there is any conflict between this Privacy Policy and the DPF Principles, the DPF Principles shall govern. Learn more about the Data Privacy Framework and view our certification at dataprivacyframework.gov.
Under the DPF Principles, we’re responsible for Personal Information we receive under the Framework and any onward transfers to service providers. For questions or complaints about our compliance, contact support@webability.io.
If you have an unresolved complaint regarding data received under the DPF, you may contact JAMS at JAMS DPF Dispute Resolution. You may also invoke binding arbitration under the Framework rules. WebAbility is subject to the investigatory and enforcement powers of the U.S. FTC.
How Long We Retain Personal Information
We retain Personal Information tied to an active account for as long as the account remains active, to resolve disputes, and to comply with legal obligations. After you request account closure, we may keep your data for up to 30 days to properly close the account (or longer if required by law or to protect our rights).
Once that period ends, we may retain certain information as necessary for purposes described in this policy—such as audits, legal compliance, dispute resolution, and enforcing our Terms.
If you don’t have an account, we keep your Personal Information only as long as needed to fulfill legal obligations, resolve disputes, and enforce our rights, whichever is shorter. Afterward, your data is deleted.
Aggregated, anonymized data used for business insights is retained indefinitely, as it cannot identify you.
How We Protect Your Information
The security of your Personal Information is important to us. We implement physical, technical, and organizational safeguards—such as encryption, access controls, and secure development practices—to protect your data from misuse, damage, and unauthorized access.
However, no system is entirely foolproof. While we strive to use industry-standard measures, we cannot guarantee absolute security for information transmitted over the Internet or stored on our servers or those of our third parties.
Your Rights as a Visitor from the EEA, UK or Switzerland
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, the GDPR, UK GDPR, and Swiss FADP apply. In addition to the rights in this policy, you have the additional rights listed below.
We process your Personal Information on these lawful grounds:
- Consent: Where required, based on your consent.
- Contractual necessity: To perform our agreement with you.
- Legal obligation: To comply with laws and protect vital interests.
- Legitimate interests:
- Communications & direct marketing
- Cybersecurity & fraud prevention
- Support, customer relations, and service operations
- Enhancements & improvements to the Service
- Analytics & feature optimization
You have the right to:
- Access the Personal Information we hold about you and learn how it’s processed.
- Rectify inaccurate or incomplete Personal Information.
- Erase your Personal Information (“right to be forgotten”).
- Restrict or object to processing of your Personal Information.
- Port your data to another service provider.
- Withdraw consent at any time (without affecting prior processing).
- Not be subject to decisions based solely on automated processing.
- File a complaint with your local Data Protection Authority.
For a full summary of your EU data protection rights, visit ec.europa.eu/info/law/law-topic/data-protection/reform/rights-citizens_en.
To exercise these rights, contact us at support@webability.io. We may request information to verify your identity and will respond within 30 days.
When we act as an independent data controller, you may contact us directly. If we process data on behalf of another controller, please contact that controller to exercise your rights.
If you’re unsatisfied with our response, you may lodge a complaint with your local Data Protection Authority. Find contacts at ec.europa.eu/justice/data-protection/article-29/structure/data-protection-authorities/index_en.htm.
Specific Provisions for California Residents
a. Categories of Personal Information Collected
In the past 12 months, we have collected:
- Identifiers (e.g., name, email address, IP address)
- Commercial information (e.g., payment details)
- Internet or network activity (e.g., site and mobile usage, session info, search history)
- Inferences drawn from other personal information
b. Business Purposes for Collection
We collect this information to provide, maintain, and improve the Service, as described in Section 4.
c. Sources of Information
We obtain Personal Information directly from you, from your use of the Service, and from third-party providers.
d. Sharing of Personal Information
We share your data with service providers and affiliates (see Section 5). We do not “sell” your data under CCPA, but we do share it with certain ad tech partners. To opt out of such sharing, click here.
e. Categories of Disclosed Information
In the past 12 months, we have disclosed for business purposes:
- Identifiers (name, email, IP)
- Commercial information (payment details)
- Internet or network activity
- Inferences drawn from Personal Information
We have not sold Personal Information in the past 12 months.
f. Your Rights as a California Resident
You may:
- Request the categories and specific pieces of Personal Information we collected in the past 12 months.
- Request the sources and business purposes for that collection.
- Request categories of third parties with whom data was shared.
- Receive your data by mail or electronically, and request its transfer to another entity.
- Correct or update incorrect Personal Information.
- Request deletion of your Personal Information, subject to legal exceptions.
- Not be discriminated against for exercising these rights.
g. How to Exercise Your Rights
To submit a request, email us at support@webability.io. Only you or an authorized agent may make a request. You may make two requests per 12 months. We will verify your identity and respond within 45 days (possible extension of 45 more days with notice). We do not charge a fee unless the request is excessive or unfounded.
Service Providers
We may employ third-party companies and individuals to facilitate our Service (“Service Providers”), provide the Service on our behalf, perform Service-related services, or assist us in analyzing how our Service is used.
These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.
Analytics
We may use third-party Service Providers to monitor and analyze the use of our Service.
Links to Other Sites
Our Service may contain links to other sites that are not operated by us. If you click on a third-party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
GDPR Compliance
If you are located in the European Economic Area (EEA), the following additional provisions apply:
Data Controller
WebAbility is the data controller responsible for your personal data under the GDPR.
Contact:
WebAbility
Email: support@webability.io
Lawful Basis for Processing
We process your personal data only where we have a lawful basis to do so, such as:
- Consent: you have given us (e.g., marketing communications)
- Contractual necessity: to deliver the Service you request
- Legal obligation: compliance with applicable laws
- Legitimate interests: to improve our Service, prevent fraud
Your GDPR Rights
Under the GDPR, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Ask us to correct any inaccurate or incomplete data.
- Erasure (“Right to be Forgotten”): Request deletion where no lawful basis exists.
- Restriction of Processing: Request that we restrict how we use your data.
- Data Portability: Obtain and reuse your personal data across different services.
- Object: Object to processing based on legitimate interests or direct marketing.
- Withdraw Consent: You may withdraw consent at any time.
To exercise any of these rights, please contact us at support@webability.io. We will respond within one month, or sooner if required by law.
Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.
We will let you know via email and/or a prominent notice on our Service, prior to the change becoming effective and update the “Effective Date” at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Contact Us
If you have any questions about this Privacy Policy, please contact us:
By email: support@webability.io