Legal
Privacy Policy
Effective date: 1 January 2025 | Last updated: 26 February 2026
1. Introduction
Inclusivy ("Company", "we", "us", or "our") is committed to protecting your privacy and ensuring transparency about how we collect, use, and protect your personal data. This Privacy Policy explains our data processing practices in connection with our website accessibility assessment service ("Service").
We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable data protection legislation.
By using our Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our data practices, please do not use our Service.
2. Data Controller
Inclusivy is the data controller responsible for your personal data processed through the Service. For questions or concerns regarding data protection, please contact:
Inclusivy
Trading name of Avuro (sole proprietorship)
Registered Address:
Handelsstraat 3
5391 KE Nuland
The Netherlands
Registration Details:
Chamber of Commerce (KvK): 82137765
VAT Number (BTW): NL003644696B08
Contact:
Privacy enquiries: privacy@inclusivy.com
General enquiries: support@inclusivy.com
3. Personal Data We Collect
3.1 Information You Provide Directly
We collect personal data that you voluntarily provide when using our Service:
| Data Category | Purpose | Legal Basis |
|---|---|---|
| Email address | Report delivery, account identification, customer support | Contract performance |
| Website URL | Service delivery (assessment execution) | Contract performance |
| Contact form submissions | Responding to enquiries | Legitimate interest |
3.2 Information Collected Automatically
When you access our website, we automatically collect certain technical information:
| Data Category | Purpose | Legal Basis |
|---|---|---|
| IP address | Security, fraud prevention, service operation | Legitimate interest |
| Browser type and version | Service optimisation, compatibility | Legitimate interest |
| Device information | Service optimisation | Legitimate interest |
| Access timestamps | Security monitoring, service analytics | Legitimate interest |
| Referring URLs | Understanding service discovery | Legitimate interest |
3.3 Payment Information
Payment card details and financial information are processed directly by our payment processor, Lemon Squeezy (Lemon Squeezy, LLC). We do not receive, store, or have access to your complete payment card numbers. We receive only transaction confirmation data including transaction reference numbers, payment status, and the email address associated with your purchase.
3.4 Analytics Data
We use analytics services to understand how visitors use our website:
- Google Analytics: Collects anonymised data about page views, session duration, traffic sources, and user interactions to help us improve our website and service
- Microsoft Clarity: Records anonymised session data including mouse movements, clicks, and scrolling behaviour to help us understand user experience and identify usability issues
Both services use cookies and may collect IP addresses (anonymised where possible). You can opt out of analytics tracking via your browser settings or by using browser extensions. See our Cookie Policy for more details.
4. How We Use Your Personal Data
We process your personal data for the following purposes:
4.1 Service Delivery (Contract Performance)
- Executing accessibility assessments on submitted URLs
- Generating and delivering assessment reports
- Processing verification rescans
- Providing customer support and technical assistance
4.2 Legitimate Business Interests
- Maintaining service security and preventing fraud
- Analysing service usage to improve functionality
- Diagnosing technical issues and errors
- Protecting our legal rights and interests
4.3 Legal Compliance
- Maintaining records required by tax and accounting regulations
- Responding to lawful requests from public authorities
- Establishing, exercising, or defending legal claims
5. Legal Basis for Processing
Under GDPR, we process your personal data based on the following legal grounds:
- Contract performance (Article 6(1)(b)): Processing necessary to deliver the Service you have purchased
- Legitimate interests (Article 6(1)(f)): Processing necessary for our legitimate business interests, where these are not overridden by your rights and interests
- Legal obligation (Article 6(1)(c)): Processing necessary to comply with applicable laws
We do not rely on consent as a legal basis for processing your personal data in connection with the Service. Where consent is required (e.g., for certain cookies), we will obtain it separately.
6. Data Sharing and Recipients
We may share your personal data with the following categories of recipients:
6.1 Service Providers
| Provider | Purpose | Location |
|---|---|---|
| Lemon Squeezy, LLC | Payment processing and order management | United States* |
| Google LLC (Google Analytics) | Website analytics and traffic analysis | United States* |
| Microsoft Corporation (Clarity) | User experience analytics and session recording | United States* |
| Hosting provider | Website and data hosting | European Union |
| Email service provider | Transactional email delivery | European Union |
* US-based providers operate under the EU-US Data Privacy Framework or Standard Contractual Clauses to ensure adequate protection of personal data transferred outside the EEA.
6.2 Legal and Regulatory Authorities
We may disclose personal data to law enforcement agencies, regulatory bodies, or other public authorities when required by law or when necessary to protect our rights or the rights of third parties.
6.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity. We will notify you of any such change and any choices you may have regarding your data.
We do not sell your personal data to third parties for marketing purposes.
7. International Data Transfers
We primarily process and store personal data within the European Economic Area (EEA). However, some of our service providers are located in the United States, including:
- Lemon Squeezy (payment processing)
- Google (analytics)
- Microsoft (user experience analytics)
Where data transfers outside the EEA are necessary, we ensure appropriate safeguards are in place, including:
- Transfers to the United States under the EU-US Data Privacy Framework
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Transfers to countries with an adequacy decision from the European Commission
- Other legally approved transfer mechanisms
You may request information about safeguards for specific transfers by contacting us.
8. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected:
| Data Category | Retention Period | Basis |
|---|---|---|
| Assessment reports and email | 2 years from last activity or deletion request | Service provision, rescan functionality |
| Payment records | 7 years | Tax and accounting obligations |
| Server logs (IP addresses) | 90 days | Security monitoring |
| Support correspondence | 2 years from resolution | Customer service quality |
9. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction:
- TLS/SSL encryption for all data transmitted between your browser and our servers
- Encryption of personal data at rest
- Access controls limiting data access to authorised personnel only
- Regular security assessments and updates
- Secure hosting infrastructure within the European Union
- Monitoring for suspicious activity and potential security incidents
While we implement robust security measures, no method of transmission or storage is completely secure. We cannot guarantee absolute security of your data.
10. Your Rights Under GDPR
As a data subject under GDPR, you have the following rights:
10.1 Right of Access
You have the right to obtain confirmation of whether we process your personal data and to receive a copy of that data.
10.2 Right to Rectification
You have the right to request correction of inaccurate personal data or completion of incomplete data.
10.3 Right to Erasure
You have the right to request deletion of your personal data in certain circumstances, including when the data is no longer necessary for its original purpose or when you withdraw consent.
10.4 Right to Restriction of Processing
You have the right to request that we restrict processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
10.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
10.6 Right to Object
You have the right to object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
10.7 Exercising Your Rights
To exercise any of these rights, please contact us at privacy@inclusivy.com. We will respond to your request within 30 days. We may request verification of your identity before processing your request.
11. Cookies and Tracking Technologies
We use cookies and similar technologies on our website, including:
- Essential cookies: Required for the website to function properly (session management, security)
- Analytics cookies: Google Analytics cookies to understand website traffic and user behaviour
- User experience cookies: Microsoft Clarity cookies to analyse how users interact with our website
- Payment cookies: Lemon Squeezy cookies during the checkout process
For detailed information about the cookies we use, their purposes, and your choices, please refer to our Cookie Policy.
12. Children's Privacy
Our Service is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 16 without appropriate consent, we will take steps to delete that information.
13. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our data practices or legal requirements. Material changes will be communicated by posting a notice on our website and updating the "Last updated" date above.
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.
14. Complaints and Supervisory Authority
If you have concerns about our data practices, please contact us first so we can address your concerns. You also have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your residence, place of work, or place of the alleged infringement.
In the Netherlands, the supervisory authority is:
Autoriteit Persoonsgegevens
15. Contact Information
For questions about this Privacy Policy or our data practices, please contact:
Inclusivy
Trading name of Avuro (sole proprietorship)
Registered Address:
Handelsstraat 3
5391 KE Nuland
The Netherlands
Registration Details:
Chamber of Commerce (KvK): 82137765
VAT Number (BTW): NL003644696B08
Contact:
Privacy enquiries: privacy@inclusivy.com
General enquiries: support@inclusivy.com