Skip to content

Privacy policy

Last updated: 18 July 2026

Attesta B.V. ("Attesta", "we") provides automated web-accessibility scanning. This policy explains what personal data we process, why, and your rights under the GDPR. Short version: we process as little as possible, entirely within the EU.

What we process

  • Account data: your name, email address and password hash, to operate your account.
  • Scan data: URLs you submit, pages we crawl on those public sites, and the accessibility findings — no visitor data from your site is collected, ever.
  • Operational logs: IP-derived rate-limiting counters and request logs, kept briefly for abuse prevention and debugging.
  • Emails you send us (support, contact form).

What we deliberately don't do

  • No advertising, no sale of data, no third-country transfers of your account data.
  • No cookies beyond the strictly-necessary session cookie — which is why you see no cookie banner.
  • Anonymous free scans are retained for 7 days, then deleted automatically.

Legal bases & your rights

We process account data to perform our contract with you (Art. 6(1)(b) GDPR) and operational logs under legitimate interest in service security (Art. 6(1)(f)). You can access, correct, export or delete your data at any time — email privacy@attesta.example. You may lodge a complaint with your supervisory authority; ours is the Dutch Autoriteit Persoonsgegevens.

Processors

We use EU-region infrastructure providers as sub-processors under GDPR-compliant data processing terms; the current list is available on request and in our DPA.