Legal
Privacy policy
How we handle personal data in the Kaveia service.
Effective from:
1. Who processes your data
The data controller is CETUSPRO SP. Z O.O., ul. Adama Matuszczaka 14, 35-083 Rzeszów, Poland, KRS 0000877163, NIP 8133850782, REGON 387860607.
For data protection matters write to kontakt@kaveia.com.
We have not appointed a data protection officer. We are not required to, and every request reaches the address above.
2. What we process
- Your account data
- Your e-mail address, which is also your login. A password hash: we do not store and cannot read your password. An optional display name, your role and your organization.
- An account event record
- We log account and organization events, for example account creation, role changes, password resets, suspension and deletion. The record includes the e-mail address of the person who performed the action and the organization name.
- Data from the sites you scan
- We store the address of the scanned page, the audit result and visual material: full page screenshots, crops of individual elements and vision simulations.
- Please note that a screenshot of an ordinary website often contains personal data, for example staff names, e-mail addresses, phone numbers or photographs of people. You decide which sites we scan.
- Technical data
- We use the visitor IP address in server memory only, to rate limit requests and prevent abuse. We do not write it to the database.
- Server error logs record the route, the method and a short error identifier. We deliberately do not log request headers or query strings, because they would contain session data and the addresses of scanned sites.
3. Why, and on what legal basis
- Providing the service and running your account
- Performance of the contract, GDPR art. 6(1)(b).
- Service security, abuse prevention, error diagnosis
- Our legitimate interest, GDPR art. 6(1)(f).
- The account event record, as proof of what was done
- Our legitimate interest in accountability, GDPR art. 6(1)(f).
- Billing and tax obligations
- Legal obligation, GDPR art. 6(1)(c).
- Establishing or defending legal claims
- Our legitimate interest, GDPR art. 6(1)(f).
Personal data found on the sites we scan is processed on our client instructions. For that data the client is the controller and we are the processor. We sign a data processing agreement on request.
4. Who else receives the data
- Railway
- Application and database hosting.
- European Union, Amsterdam region.
- Cloudflare R2
- Storage of screenshots and other files.
- European Union.
- Anthropic PBC
- AI judgment on selected accessibility criteria.
- United States.
Data may also reach our accountants and public authorities where the law requires it.
Transfers outside the European Economic Area: when the AI pass is enabled for a scan, fragments of the scanned page travel to Anthropic PBC in the United States. These are page text, the page title, headings, link text and link destinations, image alt text, form error messages, and for two criteria also image crops taken from the page. The transfer relies on the standard contractual clauses approved by the European Commission, GDPR art. 46(2)(c).
The AI pass can be turned off per scan. With it off, no page content leaves our infrastructure, at the cost of some results.
5. How long we keep it
Account data for as long as the contract lasts.
Audit results and visual material for 90 days. Image files are removed from storage automatically on a separate schedule, so an older report may still be readable with its screenshots already gone. The report says so explicitly when that happens.
Server error logs for no longer than 30 days, and we keep no archive of our own.
The account event record indefinitely. This is deliberate: the record is meant to outlive the deletion of an organization, because otherwise deleting data would destroy the proof that the deletion was carried out. It contains the e-mail address of the person who acted.
What survives the deletion of an organization: deleting an organization removes user accounts, scans, schedules and every image file. Two things are kept. The first is the event record described above. The second is a technical cache of AI judgments. It holds fragments of publicly published content from scanned pages, that is text, headings, alt text, link destinations and the page path, together with the judgment itself. The cache holds no account data and does not identify who requested the scan. We keep it so the same content is never judged twice and no repeat cost is incurred. We state this plainly, because we would rather describe what we actually do than promise an erasure we do not perform.
6. Security
We apply technical and organizational measures meeting GDPR art. 32. In particular, each organization data is separated at the database query level, passwords are stored only as cryptographic hashes, all communication runs over HTTPS, and screenshots are not publicly reachable and are served only through cryptographically signed addresses valid for one hour.
Deletion after the retention period runs automatically, and the deletion process is guarded against running against the wrong database. The full list of measures is an annex to the data processing agreement, which we sign on request.
7. Your rights
You have the right to access your data, to rectify it, to erase it, to restrict processing and to data portability.
The right to object: you may object at any time to processing of your data based on our legitimate interest. We state it separately because this right must be presented clearly and separately from the others.
Write to kontakt@kaveia.com.
You also have the right to lodge a complaint with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland.
Providing an e-mail address is necessary to create an account. Without it we cannot provide the service.
8. Cookies
Kaveia uses four cookies and all four are strictly necessary to deliver the service you asked for. We therefore ask for no consent and show no consent banner. Basis: art. 361(3) of the Polish Electronic Communications Law.
- wcag_session
- Keeps you signed in.
- Until sign out or session expiry.
- locale
- Remembers your chosen language.
- 12 months.
- kv_org
- Remembers which organization you are viewing.
- Until sign out.
- kv_menu
- Remembers whether the sidebar is collapsed.
- 12 months.
We use no cookies for analytics, profiling or advertising, and we embed no third party scripts.
9. Artificial intelligence
Some criteria are judged with the help of a language model. Those results are clearly labelled in the report together with the model reasoning, so that you can check them rather than take them on trust.
An AI judgment is not a decision producing legal effects for any person and is not used to evaluate people. Kaveia is not an automated decision making tool within the meaning of GDPR art. 22.
10. Changes
We will announce material changes in the application or by e-mail at least 14 days in advance. The current version is always available at this address, and previous versions are available on request.