An initiative by Proper Access, an accessibility audit firm

v2.46.12 · 50 checks · WCAG 2.1 & 2.2 AA

Privacy statement

Last updated:

Who we are

WCAG Toolkit is a free online tool that checks websites against WCAG 2.1 and 2.2 AA. The tool is published by Proper Access B.V. (Chamber of Commerce 95350985), Keizersgracht 520 H, 1017 EK Amsterdam, the Netherlands, and reachable at testtoegankelijkheid.nl. The older addresses wcag-scan.nl and wcag-scan.eu redirect to this domain. For questions about your data: info@properaccess.nl.

What data do we process?

Scan

  • The URL of the website you scan.
  • The HTML scan results (findings, scores, screenshot metadata).
  • Your IP address (only short-lived for rate-limiting; not retained).

Full report by email (optional)

  • Name, job title and business email.
  • Your answers to the EAA questions (B2C, revenue, FTE).

Quote request (optional)

  • Organisation type (government / B2C / B2B / culture / etc.).
  • Name, job title, business email; optional organisation, website, notes.

WCAG Radar

The Radar runs entirely in your own browser. What it sees on a page stays there: no finding is ever sent to us.

  • The browser extension ships with its code and fetches nothing from us while you test. If you have entered a licence key, that key is the only thing the extension ever sends: it goes to us to check that the licence still runs, roughly once a day. With no key entered, nothing ever leaves your device.
  • The bookmarklet fetches the script from us each time it starts. From that request we count one thing: how often the Radar was loaded on a given day, split by language.

Checking your key leaves nothing behind: we look up whether the key belongs to a running licence and send back a signed proof that lasts seven days. The key and that proof stay on your own device. The proof says only which licence it is for and how long it holds, no name and no address. In Firefox we ask your permission separately before the key is sent.

That counter is a number per day, not a list of requests. It carries no IP address, no browser details and no cookie, so nothing can be traced back to a person or to the site you are testing. Your IP address does reach our server, as it does with any request on the internet, but we do not record it.

Seats in a licence

When an administrator hands a seat to a colleague, we store that colleague's email address, plus a name and a note if the administrator fills them in. Those two exist to make an address recognisable; they are not in the email the colleague receives and we never ask the colleague for them. The key itself is stored only as a hash. If the administrator withdraws the seat, the row stays as withdrawn, so it remains traceable who had access when.

Signing in to your account

  • Your email address, and the date you last signed in.
  • The sign-in link and the code from the email, as a hash only. What we store cannot be turned back into the link itself.
  • A session in your browser so you stay signed in. That too is stored only as a hash.

There is no password, so there is none to leak. We do not record which device or IP address you sign in from.

Before we send a sign-in link, your browser runs a small calculation using ALTCHA. There is nothing for you to do: no traffic-light images, no code to copy. That check runs on our own server, so no extra company is involved and no data leaves. We also do not measure how you move your mouse or scroll; that ALTCHA feature is switched off.

Why we process this data

  • Scan URL and results: to run the WCAG check and make the report available at a unique link.
  • Lead / quote contact info: to email the report and to follow up with relevant advice or a quote.
  • IP address: to limit abuse (automated requests) via rate-limiting.
  • Radar load count: to see whether the tool is used and in which language, so we know what to work on.
  • Email address and session: to let you sign in and to show you your licence.

Legal basis: legitimate interest (rate-limiting and the load count), consent (lead and quote data via explicit checkboxes), and performance of the requested service (the scan itself).

How long do we keep data?

  • Scan results and scanned URL: up to 7 days, then automatically deleted.
  • Lead data (report email opt-in): as long as the conversation is relevant, up to 24 months.
  • Quote request data: as long as the engagement is current, or up to 24 months for records.
  • IP addresses for rate-limiting: 1 hour in server memory. For sign-in we store a hash of the address instead of the address itself, and that is gone after a day.
  • Radar load count: indefinitely, as these are numbers containing no personal data.
  • Sign-in links and codes: valid for fifteen minutes, deleted within a day.
  • Sessions: 30 days after your last visit, or immediately when you sign out.
  • Your account: as long as you use it. Ask us to remove it and it goes.

Who we share data with

We use a few processors, all EU-based or with an EU data residency option:

  • Hetzner Online (German company, servers in Helsinki, Finland): app hosting, database and backups.
  • AhaSend (Netherlands): sending report and quote confirmation emails.
  • Mollie (Netherlands): handling licence payments. Mollie receives your organisation’s name, the billing address and the amount. Your bank account and card details stay with Mollie; we never see them.
  • Plausible Analytics (EU): privacy-friendly visitor analytics without cookies, personal data or cross-site tracking.

If you enter a VAT number from outside the Netherlands, we check it with VIES, the European Commission’s register. We have to: without that check we may not reverse charge the VAT. We keep the outcome as evidence with your account.

We never sell data to third parties and we use no tracking cookies or ad networks.

Cookies

We set one functional cookie (wcag_locale) to remember your language choice (NL/EN). This cookie is technically necessary for site functionality, contains no personal data and is not shared.

When you sign in, one more cookie is added (ta_session) that remembers it is you. Scripts cannot read it, it only goes to the domain you signed in on, and it disappears when you sign out. It carries no tracking.

Your rights

Under the GDPR you have the right to:

  • access your data;
  • correction or deletion;
  • restriction or objection to processing;
  • portability;
  • file a complaint with the Dutch Data Protection Authority.

Send your request to info@properaccess.nl. We respond within 30 days.

Security

All traffic uses HTTPS. Storage sits in an EU data centre in Helsinki, Finland, with encrypted connections between the application and the processors. Raw data access is limited to the operator.

Changes

We may update this statement when legislation or our practices change. The current version is always on this page.