PRIVACY POLICY – Accessi
Effective Date: July 30, 2026
Company Name: Accessi LLC
Company Address: 30 N Gould St, Sheridan, WY 82801, United States
Website: https://accessi.biz/
Email: lazar@accessi.biz
1. Introduction
Accessi LLC (“Accessi”, “we”, “us”, or “our”) is a limited liability company organized under the laws of the State of Wyoming, United States. We provide digital accessibility services, including accessibility auditing, usability testing with assistive technology users, accessibility training, and accessibility consulting support.
This Privacy Policy explains how we collect, use, disclose, transfer, retain, and protect personal information, and describes the rights and choices available to individuals whose personal information we process. It applies to our website located at https://accessi.biz/ (the “Website”), to our services (the “Services”), and to our business communications with prospective clients, clients, vendors, testers, and other individuals who interact with us.
We are committed to handling personal information lawfully, fairly, and transparently. Because our clients and Website visitors are located in the United States and in other countries, this Privacy Policy is written to address both United States privacy laws and the data protection laws of the European Economic Area, the United Kingdom, and Canada. Where a specific law grants you rights that exceed what is described in this Privacy Policy, that law governs to the extent of the difference.
Please read this Privacy Policy carefully. If you do not agree with it, please do not use the Website or the Services.
2. Who We Are and How to Contact Us
For the purposes of the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) and the United Kingdom General Data Protection Regulation (“UK GDPR”), Accessi LLC is the controller of the personal information described in this Privacy Policy, except where this Privacy Policy expressly states that we act as a processor on behalf of a client.
You may contact us regarding this Privacy Policy or any privacy matter using the following details:
Company Name: Accessi LLC
Company Address: 30 N Gould St, Sheridan, WY 82801, United States
Email: lazar@accessi.biz
Website: https://accessi.biz/
We do not currently maintain an establishment within the European Economic Area or the United Kingdom. Where we are required to appoint a representative under Article 27 of the GDPR or Article 27 of the UK GDPR, we will publish the representative’s contact details in this Privacy Policy. Until such details are published, individuals in the European Economic Area and the United Kingdom may contact us directly using the email address above, and we will respond within the timeframes required by applicable law.
3. Scope of This Policy
This Privacy Policy applies to personal information we process in the following contexts:
- Visitors to the Website, including individuals who submit contact forms, request information, or book a call or consultation.
- Prospective clients and their personnel who communicate with us during sales, scoping, or proposal discussions.
- Clients and their personnel who engage us to deliver Services, and who exchange information with us during an engagement.
- Participants in accessibility training sessions, including individuals who register for or attend training and receive completion certificates.
- Testers, contractors, consultants, and other individuals who perform work on our behalf.
- Vendors, suppliers, and professional advisors who provide goods or services to us.
- Individuals who contact us to report an accessibility barrier on the Website or on a client digital property, or to exercise a privacy right.
This Privacy Policy does not apply to:
- Personal information processed by our clients on their own websites, applications, or systems, including personal information relating to their own users, customers, or employees. Those activities are governed by the privacy notices of the relevant client.
- Third-party websites, platforms, or services that we do not control, even where those services are linked from the Website or used in connection with an engagement.
- Information that has been aggregated, de-identified, or anonymized such that it can no longer reasonably be associated with an identified or identifiable individual./li>
4. Definitions
The following terms are used throughout this Privacy Policy:
- “Personal information” (also referred to as “personal data”) means any information relating to an identified or identifiable natural person, or any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household, as those terms are defined under applicable law.
- “Sensitive personal information” and “special categories of personal data” mean the categories of personal information afforded heightened protection under applicable law, including information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for the purpose of uniquely identifying a natural person, data concerning health, and data concerning a natural person’s sex life or sexual orientation, as well as those categories designated as sensitive under United States state privacy laws.
- “Controller” means the entity that determines the purposes and means of processing personal information. “Business” has a corresponding meaning under United States state privacy laws.
- “Processor” means an entity that processes personal information on behalf of and under the documented instructions of a controller. “Service provider” has a corresponding meaning under United States state privacy laws.
- “Client” means a natural or legal person that engages Accessi LLC to provide Services under a written agreement, order form, statement of work, or accepted proposal.
- “Client Materials” means any information, content, files, credentials, documentation, source code, design assets, staging environments, or systems made available to us by a client for the purpose of delivering the Services.
- “Processing” means any operation performed on personal information, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, restriction, erasure, or destruction.
5. Our Role: Controller and Processor
Our role with respect to personal information depends on the context in which we process it.
5.1 Where We Act as a Controller
We act as a controller when we determine the purposes and means of processing. This includes personal information collected through the Website, personal information exchanged during sales and marketing activities, contact details of client personnel used for engagement administration and communication, billing and payment records, training registration and attendance records, and personal information relating to our own contractors and vendors.
5.2 Where We Act as a Processor
We act as a processor when we process personal information contained within Client Materials or accessible within a client environment, on behalf of and under the instructions of the client. This most commonly occurs when we are granted access to a client website, application, staging environment, content management system, or administrative interface in order to perform an accessibility audit, remediation review, or quality assurance testing, and that environment contains personal information relating to the client’s own users, customers, or employees.
In these circumstances, the client is the controller and remains responsible for the lawfulness of the processing, for providing any required notices to affected individuals, and for obtaining any required consents. We process such personal information only to the extent necessary to deliver the Services and in accordance with the applicable engagement agreement and, where applicable, a Data Processing Addendum.
We instruct clients to provide access to non-production, anonymized, or test data wherever technically feasible, and to avoid exposing live personal information to us unless it is strictly necessary for the accessibility assessment. We do not require access to live personal information in order to perform accessibility testing, and we will not knowingly extract, copy, export, or retain personal information from a client environment except where such information is captured incidentally within screenshots, recordings, or issue documentation for the sole purpose of illustrating an accessibility defect.
5.3 Joint Responsibility
Where we and a client jointly determine the purposes and means of a specific processing activity, the allocation of responsibilities will be set out in the applicable engagement agreement or Data Processing Addendum. Absent such an agreement, each party is independently responsible for its own compliance obligations.
6. Personal Information We Collect
6.1 Information You Provide Directly
We collect personal information that you voluntarily provide to us, including:
- Identity and contact information: full name, job title, employer or organization name, business email address, business telephone number, business postal address, and country or region.
- Enquiry and booking information: the content of messages you submit through contact forms, the subject of your enquiry, the services you are interested in, information about your website or mobile application, and any scheduling details you provide when you book a call or consultation through a third-party scheduling provider.
- Engagement information: information exchanged during scoping, proposals, statements of work, kick-off calls, project correspondence, remediation discussions, and consultation sessions.
- Training information: registration details, attendance records, participant names for the purpose of issuing completion certificates, role or job function, accessibility or dietary requirements you choose to disclose for the purpose of accommodating your participation, and any feedback you submit.
- Billing and payment information: billing name, billing address, tax or registration identifiers where required, purchase order references, invoice records, and payment status. We do not collect or store full payment card numbers. Card payments are processed by Stripe. Where payment is made by wire transfer or ACH, we receive the transaction details supplied by the sending bank, which may include the remitter name and account reference.
- Accessibility feedback: information you provide when you report an accessibility barrier on the Website or on a digital property we have assessed, including your description of the barrier, the assistive technology and browser you use, and your contact details where you request a response.
- Recruitment and contractor information: where you apply to work with us or engage with us as a contractor, we collect the information you submit, including curriculum vitae, professional history, certifications, references, and any information required to onboard and remunerate you.
- Any other information you choose to provide: including information contained in emails, attachments, shared documents, or recorded calls where recording has been disclosed and, where required, consented to.
6.2 Information Collected Automatically
When you visit the Website, certain information is collected automatically by our hosting infrastructure and by cookies and similar technologies:
- Technical and device information: Internet Protocol (IP) address, browser type and version, operating system, device type, screen resolution, language preference, and, where relevant to accessibility diagnostics, assistive technology signals voluntarily exposed by your browser configuration.
- Usage information: pages viewed, time and date of access, duration of visit, referring and exit pages, navigation paths, links clicked, files downloaded, and error events.
- Approximate location: a general geographic location inferred from your IP address, typically at the country, region, or city level. We do not collect precise geolocation data.
- Cookie and identifier information: cookie identifiers, session identifiers, and similar identifiers placed by us or by third-party providers, subject to the consent requirements described in Section 10 and in our Cookie Policy.
6.3 Information from Third Parties
We may receive personal information about you from sources other than you, including:
- Your employer or the organization you represent, where that organization engages us and identifies you as a project contact, stakeholder, or training participant.
- Third-party scheduling providers, when you book a call or meeting with us.
- Payment processors and financial institutions, in connection with the processing, reconciliation, refund, or dispute of a payment.
- Professional networks, business directories, conference organizers, and publicly available sources, where we conduct proportionate business-to-business outreach or verify a business contact.
- Referral sources and partners who introduce you to us, where they have a lawful basis to do so.
6.4 Client Environments and Client End-User Data
In the course of performing an accessibility audit, remediation review, or quality assurance testing, we may be granted access to a client environment that contains personal information relating to the client’s users, customers, employees, or other individuals. This may include names, contact details, account information, order or transaction records, support tickets, uploaded content, or any other data present in the environment to which we are given access.
We do not seek out such information, and we access it only to the extent that it is incidentally visible while assessing the accessibility of the relevant interface. We process such information solely as a processor on behalf of the client, as described in Section 5.2.
6.5 Usability Testing Recordings and Tester Information
Our usability testing service involves an accessibility tester who is a native user of assistive technology navigating a client digital property while their interaction is recorded. These recordings typically consist of a screen capture accompanied by an audio narration in which the tester describes what they encounter, and in some engagements may include webcam video of the tester.
A tester’s voice and, where webcam video is used, image constitute personal information relating to the tester. Testers are informed in advance that sessions are recorded, are informed of the purposes for which recordings will be used, and provide their agreement prior to recording. Testers may withdraw their agreement to future recordings at any time, although withdrawal does not affect the lawfulness of processing carried out before withdrawal, and does not require us to withdraw a recording already delivered to a client under a licence.
Recordings are delivered to the client through a secure link. We do not publish, broadcast, or use a recording for marketing, case study, or promotional purposes without the prior written consent of both the client and the tester appearing in the recording.
Where a client requests that its own users, employees, or customers participate as test participants rather than our testers, the client is responsible for identifying and recruiting those participants, for providing them with any required privacy notice, and for obtaining any required consent to recording. We will act as a processor with respect to those participants’ personal information.
6.6 Special Category and Sensitive Personal Information
Because of the nature of our Services, we may come into contact with information relating to disability, which constitutes data concerning health under the GDPR and the UK GDPR and sensitive personal information under certain United States state privacy laws. This may occur in the following ways:
- A tester or trainer who works with us may be a person with a disability, and the fact of that disability may be evident from the nature of the assistive technology they use or from statements they make during a recorded session.
- An individual who reports an accessibility barrier may disclose information about their disability or assistive technology in the course of describing the barrier.
- A training participant may disclose an accommodation requirement in order to participate effectively.
- A client end user’s disability-related information may be incidentally visible within a client environment.
We do not solicit disability information beyond what is necessary for the purpose for which it is provided, and we do not use disability information to infer characteristics about an individual, to build profiles, or for advertising or marketing purposes.
Where we process special category data as a controller under the GDPR or the UK GDPR, we rely on Article 9(2)(a) (explicit consent) or Article 9(2)(f) (establishment, exercise, or defence of legal claims), as applicable to the circumstances.
Under the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), we use and disclose sensitive personal information only for the purposes permitted by Section 7027(m) of the CCPA regulations, which do not require us to offer a right to limit its use. We do not use sensitive personal information to infer characteristics about a consumer.
6.7 Information We Do Not Collect
We do not intentionally collect the following categories of information:
- Full payment card numbers, card verification values, or card expiry dates.
- Government-issued identification numbers, including Social Security numbers, driver’s licence numbers, and passport numbers, except where legally required for tax reporting in respect of a contractor or vendor.
- Biometric information processed for the purpose of uniquely identifying a natural person.
- Precise geolocation data.
- Information relating to racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life, or sexual orientation.
- Personal information relating to children, as described in Section 24.
If you provide information of a type we do not require, we will delete it within a reasonable period unless we are required to retain it by law.
7. Categories of Personal Information Collected and Disclosed
The following table summarizes the categories of personal information we have collected in the preceding twelve months, using the category descriptions set out in the CCPA. It is provided to satisfy the notice at collection requirement under California law and is equally informative for individuals in other jurisdictions.
| Category | Examples | Disclosed To |
|---|---|---|
| Identifiers | Name, business email address, business telephone number, business postal address, IP address, cookie and session identifiers | Hosting, email, scheduling, CRM, and analytics providers; professional advisors |
| Customer records information | Billing name, billing address, invoice and payment records, tax or registration identifiers | Payment processor, banking provider, accounting and tax advisors |
| Commercial information | Services enquired about or purchased, proposals, statements of work, engagement history, training registrations | CRM, document storage, and accounting providers |
| Internet or other electronic network activity information | Pages viewed, session duration, referring pages, links clicked, error events | Hosting and analytics providers, subject to consent where required |
| Geolocation data | Approximate country, region, or city inferred from IP address | Hosting and analytics providers |
| Audio, electronic, or visual information | Screen recordings with audio narration produced during usability testing, and in some engagements webcam video; recorded calls where disclosed | The commissioning client; secure file delivery and storage providers |
| Professional or employment-related information | Job title, employer, role or function, professional history and certifications where submitted | CRM and document storage providers |
| Sensitive personal information | Disability or health-related information voluntarily disclosed in the contexts described in Section 6.6 | Not disclosed except to the commissioning client where inherent in a deliverable, and to secure storage providers |
We have not sold or shared personal information for cross-context behavioural advertising in the preceding twelve months, and we do not do so.
8. How We Use Personal Information
We use personal information for the following purposes:
- To respond to enquiries, provide information about our Services, prepare proposals, and schedule and conduct calls and consultations.
- To deliver the Services, including performing accessibility audits, conducting usability testing, preparing reports and remediation guidance, providing engineering support during an engagement, delivering quality assurance testing, providing accessibility consulting support, and preparing accessibility conformance documentation.
- To deliver and administer accessibility training, including registration, attendance tracking, distribution of materials, and issuance of completion certificates.
- To administer and manage the client relationship, including project communication, scheduling, scope management, change requests, and status reporting.
- To process payments, issue invoices, manage collections, process refunds, and respond to payment disputes and chargebacks.
- To operate, maintain, secure, and improve the Website, including diagnosing technical faults and monitoring performance.
- To improve the accessibility of the Website and of our own materials, and to respond to accessibility feedback.
- To send service and transactional communications, including engagement updates, scheduling confirmations, invoices, security notices, and changes to our terms or policies.
- To send marketing communications where you have consented to receive them or where we are otherwise permitted to do so under applicable law, subject at all times to your right to opt out.
- To maintain business records, including accounting records, contracts, and correspondence, and to comply with tax, accounting, and corporate record-keeping obligations.
- To establish, exercise, or defend legal claims, to enforce our terms, to investigate suspected misuse, and to protect the rights, property, and safety of Accessi LLC, our clients, our personnel, and the public.
- To comply with applicable law, regulation, court order, or lawful request from a public authority.
- To conduct internal analysis, quality control, and business planning, using aggregated or de-identified information wherever practicable.
We do not use personal information for purposes that are incompatible with the purposes for which it was collected. If we intend to use personal information for a new and incompatible purpose, we will provide notice and, where required, obtain your consent.
9. Legal Bases for Processing Under the GDPR and UK GDPR
Where the GDPR or the UK GDPR applies, we process personal information on one or more of the following legal bases:
- Performance of a contract (Article 6(1)(b)): to deliver the Services, administer an engagement, deliver training, and process payments, where you are a party to the contract or where processing is necessary in order to take steps at your request prior to entering into a contract.
- Legitimate interests (Article 6(1)(f)): to communicate with client personnel, to operate and secure the Website, to maintain business records, to conduct proportionate business-to-business marketing, to improve our Services, and to establish, exercise, or defend legal claims. Where we rely on legitimate interests, we have assessed that our interests are not overridden by the interests, rights, and freedoms of the individuals concerned. You may object to this processing as described in Section 18.
- Consent (Article 6(1)(a)): to place non-essential cookies and similar technologies, to send marketing communications where consent is required, and to record sessions where consent is the appropriate basis. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- Legal obligation (Article 6(1)(c)): to comply with tax, accounting, corporate, and other legal obligations to which we are subject.
- Explicit consent (Article 9(2)(a)) or the establishment, exercise, or defence of legal claims (Article 9(2)(f)): where we process special category data as described in Section 6.6.
Where we act as a processor on behalf of a client, the client is responsible for identifying and documenting the legal basis for the processing.
10. Cookies and Similar Technologies
The Website uses cookies and similar technologies, which may include local storage, pixels, and software development kits. These technologies fall into the following categories:
- Strictly necessary cookies, which are required for the Website to function, to maintain session integrity, to balance load, and to provide security. These cannot be disabled through our consent tool.
- Functional cookies, which remember your preferences, including language, display, and accessibility settings.
- Analytics cookies, which help us understand how the Website is used so that we can improve it.
- Marketing cookies, which may be used to measure the effectiveness of campaigns or to deliver relevant content.
Where required by the GDPR, the UK GDPR, the ePrivacy Directive as implemented in your jurisdiction, or comparable law, we obtain your consent before placing any cookie that is not strictly necessary, and we provide a means to withdraw that consent at any time. Where United States state privacy law applies, we honour opt-out preference signals as described in Section 26.
Full details of the categories of cookies used, their purposes, and how to manage your preferences are set out in our Cookie Policy, which forms part of this Privacy Policy.
11. How We Disclose Personal Information
We disclose personal information only as described below. We do not disclose personal information to third parties for their own independent marketing purposes.
- Service providers and processors: we engage third parties to provide website hosting, email, calendar and scheduling, customer relationship management, document storage and collaboration, secure file delivery, video conferencing and recording, analytics, payment processing, accounting, and information security services. These providers process personal information only on our documented instructions and are bound by written agreements imposing confidentiality and security obligations.
- Contractors, testers, and consultants: we engage individuals and firms to perform testing, auditing, training, and consulting work. They are bound by written confidentiality obligations and process personal information only as necessary to perform their assigned work.
- Clients: where personal information is inherent in a deliverable, including the voice and, where applicable, image of a tester within a usability testing recording, that information is disclosed to the commissioning client under the licence terms set out in our Terms of Service.
- Payment and financial providers: Stripe processes card payments on our behalf. Our banking provider processes wire transfer and ACH payments. These providers handle payment information in accordance with their own privacy notices and applicable payment industry standards.
- Professional advisors: legal counsel, accountants, tax advisors, auditors, and insurers, where necessary for the provision of their professional services and subject to professional duties of confidentiality.
- Legal and regulatory disclosures: where we are required to disclose personal information by applicable law, regulation, subpoena, court order, or binding request from a public authority, or where disclosure is necessary to establish, exercise, or defend legal claims, to investigate suspected fraud or misuse, or to protect the rights, property, or safety of any person.
- Business transfers: in connection with a merger, acquisition, reorganization, financing, sale of assets, or insolvency proceeding, personal information may be transferred to a successor or acquirer, subject to the recipient continuing to handle it in accordance with this Privacy Policy or providing notice of any material change.
- With your direction or consent: where you ask us to share your personal information with a third party, or where you otherwise consent to the disclosure.
12. Sub-processors and Service Providers
We maintain a record of the third parties that process personal information on our behalf, including the nature of the processing and the locations in which processing occurs.
Where we act as a processor for a client, we will not engage a sub-processor without the client’s general or specific written authorization. Where general authorization is given, we will provide notice of any intended addition or replacement of a sub-processor, giving the client a reasonable opportunity to object. Sub-processors are bound by written terms imposing data protection obligations no less protective than those to which we are subject.
A current list of sub-processors is available to clients on written request to lazar@accessi.biz.
13. No Sale or Sharing of Personal Information
We do not sell personal information, and we have not sold personal information in the preceding twelve months, as “sell” is defined under the CCPA and comparable United States state privacy laws.
We do not share personal information for cross-context behavioural advertising, and we have not done so in the preceding twelve months.
We do not sell or share the personal information of individuals we know to be under sixteen years of age.
14. International Data Transfers
We are established in the United States, and personal information we process is stored on and accessed from servers located in the United States. In addition, members of our team, including testers, trainers, consultants, and contractors, may be located outside the United States and outside the European Economic Area and the United Kingdom, including in countries that have not been the subject of an adequacy decision by the European Commission or the United Kingdom government.
Where we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland to a country that does not benefit from an adequacy decision, we implement an appropriate transfer mechanism, which is ordinarily the Standard Contractual Clauses approved by the European Commission, supplemented by the United Kingdom International Data Transfer Addendum where the transfer is from the United Kingdom. Where appropriate, we carry out a transfer impact assessment and apply supplementary technical, organizational, and contractual measures.
You may request a copy of the relevant transfer safeguards by contacting us at lazar@accessi.biz. We may redact commercially confidential terms from any copy we provide.
Personal information transferred internationally may become subject to the laws of the destination country, including laws permitting access by public authorities. We assess the risk of such access and apply mitigating measures where we consider it necessary and proportionate.
15. Data Retention
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, tax, or reporting requirements, and to establish, exercise, or defend legal claims. The criteria we use to determine retention periods include the nature and sensitivity of the information, the purpose of the processing, the duration of the relationship, and any applicable limitation period.
Our general retention practices are as follows:
| Category of Information | Retention Period |
|---|---|
| Website enquiry and contact form submissions that do not result in an engagement | Up to twenty-four months from the last communication, unless you request earlier deletion |
| Client engagement records, correspondence, and deliverables | For the duration of the engagement and for six years following its conclusion, in line with applicable limitation periods |
| Usability testing recordings and associated raw testing materials | Twelve months from delivery, after which they are deleted from our systems unless the client has requested extended retention in writing |
| Training registration and attendance records, and certificate records | Three years from the date of the training session |
| Invoices, payment records, and accounting documentation | Seven years, or such longer period as required by applicable tax and accounting law |
| Marketing contact records and consent records | Until you withdraw consent or object, and thereafter a suppression record retained indefinitely to honour your opt-out |
| Website server logs and security logs | Up to twelve months |
| Privacy rights request records | Twenty-four months from the date of the request, as required to demonstrate compliance |
| Personal information within client environments processed as a processor | Deleted or returned on conclusion of the engagement in accordance with the client’s instructions, subject to any legal retention obligation |
Where personal information is retained beyond the periods above because it is subject to a legal hold, a pending dispute, or a regulatory requirement, we restrict processing to what is necessary for that purpose. Where continued retention is no longer necessary, we securely delete the information or irreversibly de-identify it.
16. Data Security
We implement technical and organizational measures designed to protect personal information against unauthorized or unlawful processing and against accidental loss, destruction, alteration, or damage. These measures include:
- Encryption of data in transit using industry-standard transport layer security, and encryption of data at rest where supported by the underlying service.
- Access control on a least-privilege basis, so that personnel and contractors are granted access only to the information necessary to perform their assigned work.
- Multi-factor authentication on business-critical accounts.
- Written confidentiality obligations binding all personnel, contractors, and sub-processors.
- Secure delivery of deliverables and recordings through access-controlled links rather than unprotected email attachments.
- Use of reputable third-party providers with recognized security practices for hosting, storage, and payment processing.
- Periodic review of access rights, and prompt revocation of access on conclusion of an engagement or termination of a working relationship.
- Segregation of client environments and credentials, and a policy against reuse of client credentials outside the scope of the relevant engagement.
Where a client grants us access to its systems, the client is responsible for issuing credentials scoped to the minimum access necessary, for monitoring the use of those credentials, and for revoking them promptly on conclusion of the engagement. We will request that credentials be revoked at the end of an engagement, but we cannot revoke access issued by a client.
No method of transmission over the internet and no method of electronic storage is completely secure. While we take reasonable steps to protect personal information, we cannot guarantee absolute security, and any transmission of information to us is at your own risk. You are responsible for maintaining the confidentiality of any credentials you use to communicate with us or to access materials we provide.
17. Data Breach Notification
We maintain procedures for identifying, escalating, investigating, containing, and remediating suspected personal data breaches.
Where we act as a controller and a personal data breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the competent supervisory authority without undue delay and, where feasible, within seventy-two hours of becoming aware of the breach. Where the breach is likely to result in a high risk to those rights and freedoms, we will also notify the affected individuals without undue delay.
Where we act as a processor, we will notify the relevant client without undue delay after becoming aware of a personal data breach affecting personal information processed on that client’s behalf, and will provide the information reasonably required for the client to meet its own notification obligations.
We will also comply with applicable breach notification requirements under United States federal and state law, and under Canadian law, where they apply.
18. Your Rights Under the GDPR and UK GDPR
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights in relation to personal information for which we are the controller:
- Right of access: to obtain confirmation of whether we process your personal information and, if so, to receive a copy of it together with information about the processing.
- Right to rectification: to have inaccurate personal information corrected and incomplete personal information completed.
- Right to erasure: to have your personal information deleted where one of the grounds set out in Article 17 applies, including where it is no longer necessary for the purpose for which it was collected or where you withdraw consent and no other legal basis applies.
- Right to restriction of processing: to have processing restricted in the circumstances set out in Article 18, including where you contest the accuracy of the information or object to the processing pending verification.
- Right to data portability: to receive personal information you have provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible, where processing is based on consent or contract and carried out by automated means.
- Right to object: to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests. Where you object to processing for direct marketing purposes, we will stop that processing without further assessment.
- Right to withdraw consent: to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
- Right not to be subject to automated decision-making: to not be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you. As set out in Section 23, we do not carry out such processing.
- Right to lodge a complaint: to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement. In the United Kingdom, the relevant authority is the Information Commissioner’s Office.
To exercise any of these rights, contact us at lazar@accessi.biz. We will respond without undue delay and in any event within one month of receipt of your request. That period may be extended by up to two further months where necessary, taking into account the complexity and number of requests, in which case we will inform you of the extension and the reasons for it.
We may request information reasonably necessary to verify your identity before acting on a request. We will not charge a fee for responding to a request unless the request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act, and will explain our reasons.
Where a request relates to personal information we process as a processor on behalf of a client, we will refer the request to the relevant client without undue delay and will assist that client in responding, as required under Article 28 of the GDPR.
19. Your Rights Under California Law
If you are a California resident, the CCPA provides you with the following rights in relation to personal information for which we are the business.
- Right to know: to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which it was collected, the business or commercial purpose for collecting it, the categories of third parties to whom we disclose it, and the categories of personal information disclosed for a business purpose.
- Right to delete: to request deletion of personal information we have collected from you, subject to the exceptions set out in the CCPA, including where retention is necessary to complete a transaction, detect security incidents, comply with a legal obligation, or exercise or defend legal claims.
- Right to correct: to request correction of inaccurate personal information we maintain about you.
- Right to opt out of the sale or sharing of personal information: as stated in Section 13, we do not sell or share personal information, so there is nothing to opt out of. We nonetheless honour opt-out preference signals as described in Section 26.
- Right to limit the use and disclosure of sensitive personal information: we use and disclose sensitive personal information only for purposes permitted without a right to limit under the CCPA regulations, and we do not use it to infer characteristics.
- Right to non-discrimination: we will not discriminate against you for exercising any of your rights under the CCPA. We will not deny you goods or services, charge you a different price, provide a different level or quality of service, or suggest that you will receive a different price or quality of service because you exercised your rights. We do not offer financial incentives in exchange for the retention or sale of personal information.
To submit a request, contact us at lazar@accessi.biz with the subject line “California Privacy Request”. We will acknowledge receipt within ten business days and respond within forty-five days, which may be extended by a further forty-five days where reasonably necessary, in which case we will notify you of the extension.
We will verify your identity before responding to a request to know or delete, using information reasonably available to us, which may include matching the information you provide against information already held in our records. For requests concerning specific pieces of personal information, we apply a higher standard of verification.
An authorized agent may submit a request on your behalf. We will require the agent to provide written proof of authorization, and we may require you to verify your own identity directly with us or to confirm that you have granted the agent permission to submit the request.
California Civil Code Section 1798.83 permits California residents to request information about disclosures of personal information to third parties for those third parties’ direct marketing purposes. We do not make such disclosures.
20. Your Rights Under Other United States State Privacy Laws
A number of United States states have enacted comprehensive consumer privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island. Where such a law applies to you, you generally have the right to:
- Confirm whether we process your personal data and access that data.
- Correct inaccuracies in your personal data.
- Delete personal data you provided to us or that we obtained about you.
- Obtain a copy of your personal data in a portable and readily usable format, where processing is carried out by automated means.
- Opt out of the processing of personal data for the purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects. We do not engage in any of these activities.
To exercise these rights, contact us at lazar@accessi.biz. We will respond within forty-five days, which may be extended by a further forty-five days where reasonably necessary.
If we decline to act on your request, you may appeal that decision by replying to our response with the subject line “Privacy Appeal” and stating the basis for your appeal. We will respond to an appeal within sixty days, and if the appeal is denied we will provide you with a method to contact your state attorney general to submit a complaint.
Nevada residents may submit a request that we not sell certain personal information. We do not sell personal information as defined under Nevada law.
21. Your Rights Under Canadian Law
If you are located in Canada, the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and applicable provincial privacy legislation may apply to our processing of your personal information.
Under PIPEDA, you have the right to access the personal information we hold about you, to request correction of inaccurate or incomplete information, and to withdraw consent to processing, subject to legal and contractual restrictions and reasonable notice. We collect, use, and disclose personal information only for purposes that a reasonable person would consider appropriate in the circumstances.
We may transfer personal information to service providers located outside Canada, including in the United States. While personal information is in the custody of a service provider in another country, it may be subject to the laws of that country, including lawful access by public authorities. We use contractual and other means to provide a comparable level of protection while the information is being processed by a service provider.
To exercise your rights under PIPEDA, contact us at lazar@accessi.biz. If you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada.
Under Canada’s Anti-Spam Legislation, we send commercial electronic messages only where we have express or implied consent, and every such message identifies us and provides an unsubscribe mechanism that takes effect within ten business days.
22. Marketing Communications and Opt-Out
Where we send marketing communications, we do so only where you have consented or where we are otherwise permitted to do so under applicable law. Every marketing email we send includes an unsubscribe link, and we act on unsubscribe requests promptly.
You may also opt out at any time by emailing lazar@accessi.biz with the subject line “Unsubscribe”.
Opting out of marketing communications does not affect service and transactional communications relating to an active engagement, including scheduling confirmations, project correspondence, invoices, security notices, and notices of changes to our terms or policies. These communications are necessary for the performance of our contract with you and cannot be opted out of while the engagement remains active.
Where you opt out, we retain a minimal suppression record consisting of your email address and the fact of your opt-out, so that we can honour your preference. This record is retained indefinitely for that purpose and is not used for any other purpose.
23. Automated Decision-Making and Profiling
We do not carry out automated decision-making that produces legal effects concerning you or that similarly significantly affects you, and we do not carry out profiling for the purpose of such decision-making.
Automated tooling is used in the delivery of accessibility audits to scan digital properties for technical accessibility defects. Such tooling assesses code and interface behaviour, not individuals, and does not evaluate personal characteristics or make decisions about individuals.
24. Children’s Privacy
The Website and the Services are directed to businesses and to professionals acting in a business capacity. They are not directed to children, and we do not knowingly collect personal information from children under the age of sixteen, or under such higher age as may apply in your jurisdiction.
If you believe that a child has provided personal information to us, please contact us at lazar@accessi.biz. If we become aware that we have collected personal information from a child without appropriate consent, we will delete that information promptly.
Where a client engages us to assess a digital property directed to children, the client remains the controller of any personal information relating to children within that environment and is responsible for compliance with applicable children’s privacy law, including the Children’s Online Privacy Protection Act where relevant.
25. Third-Party Websites and Services
The Website may contain links to third-party websites, resources, and services that we do not own or control, including scheduling providers, professional networks, industry resources, and client digital properties. This Privacy Policy does not apply to those third parties.
We are not responsible for the privacy practices, content, or security of any third-party website or service. We encourage you to review the privacy notice of any third party before providing personal information to it.
Where a third-party service is embedded in the Website, including a scheduling tool or video player, that service may set cookies or collect technical information when the embedded content loads. Where such collection is not strictly necessary, it is subject to your consent as described in Section 10 and in our Cookie Policy.
26. Do Not Track Signals and Opt-Out Preference Signals
Some browsers transmit a “Do Not Track” signal. There is no common industry standard for interpreting or responding to such signals, and we do not currently respond to them.
Where required by United States state privacy law, we recognize and honour opt-out preference signals transmitted by a browser or extension, including the Global Privacy Control, as a valid request to opt out of the sale or sharing of personal information and of targeted advertising. As stated in Section 13, we do not engage in these activities, but we will process such a signal as a valid opt-out request in any event.
Because an opt-out preference signal is transmitted at the browser and device level, it applies only to the browser and device from which it is sent.
27. Client Responsibilities
Where we deliver Services to a client, the client is responsible for the following:
- Providing any privacy notice required to be given to its own users, customers, employees, or test participants, and obtaining any consent required under applicable law.
- Determining the lawful basis for any processing of personal information within its environment that we carry out on its behalf.
- Issuing credentials scoped to the minimum access necessary, and revoking them promptly on conclusion of the engagement.
- Using non-production, anonymized, or test data wherever technically feasible, and not exposing live personal information to us unless strictly necessary.
- Ensuring that any transfer of personal information to us is lawful, including implementing an appropriate international transfer mechanism where required.
- Responding to privacy rights requests submitted by its own users, customers, employees, or test participants, with our reasonable assistance.
Where required, we will enter into a Data Processing Addendum with a client governing the processing of personal information carried out on that client’s behalf. In the event of a conflict between this Privacy Policy and an executed Data Processing Addendum in respect of processing carried out as a processor, the Data Processing Addendum prevails.
28. Accessible Formats of This Policy
We are committed to making this Privacy Policy available in a format you can use. If you require this Privacy Policy in an alternative accessible format, including plain text, large print, or a structured document optimized for a specific assistive technology, contact us at lazar@accessi.biz and we will provide it at no cost.
If you encounter an accessibility barrier that prevents you from reading this Privacy Policy or from exercising a privacy right, contact us and we will provide an alternative means of exercising that right.
29. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our Services, the technologies we use, or applicable law.
When we make changes, we will revise the Effective Date at the top of this Privacy Policy and publish the updated version at https://accessi.biz/. Where a change is material, we will provide additional notice by email to clients with an active engagement and to individuals who have provided us with an email address for that purpose, or by a prominent notice on the Website, before the change takes effect.
Where a change requires your consent under applicable law, we will obtain that consent before applying the change to personal information already collected. Your continued use of the Website or the Services after an updated Privacy Policy takes effect constitutes your acknowledgement of the updated Privacy Policy, except where consent is required.
We encourage you to review this Privacy Policy periodically. Prior versions are available on request to lazar@accessi.biz.
30. Contact and Complaints
If you have any question, concern, or complaint about this Privacy Policy or about how we handle personal information, contact us using the details below. We take all privacy concerns seriously and will investigate and respond.
Company Name: Accessi LLC
Company Address: 30 N Gould St, Sheridan, WY 82801, United States
Email: lazar@accessi.biz
Website: https://accessi.biz/
If you are located in the European Economic Area or the United Kingdom and you are not satisfied with our response, you have the right to lodge a complaint with the supervisory authority in the country of your habitual residence, place of work, or place of the alleged infringement. In the United Kingdom, the relevant authority is the Information Commissioner’s Office.
If you are located in Canada and you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada.
If you are a resident of a United States state with a comprehensive consumer privacy law and we decline to act on your request, you may appeal that decision as described in Section 20, and if the appeal is denied you may submit a complaint to your state attorney general.