Privacy Policy
Last updated: July 2026
1. Who we are
Aulys ("we", "us") is the data controller for personal data processed through this website and the Aulys accessibility scanning platform. Our full legal identity is published in our Impressum. An EU representative under Art. 27 GDPR / Art. 4(2) EAA is in the process of being appointed; this page will be updated with their contact details once appointed.
2. Data we collect
- Identity data — name, username.
- Contact data — email address, billing address.
- Technical data — IP address, browser type/version, time zone.
- Usage data — how you use the dashboard and scanner, scan history.
- Scan content — the URLs, page HTML, and screenshots of the sites you submit for scanning.
3. Lawful basis for processing (Art. 6 GDPR)
- Performance of a contract — running scans, generating reports, billing.
- Legitimate interest — securing the service, preventing abuse, product analytics you've consented to.
- Legal obligation — tax and accounting records.
- Consent — non-essential cookies and analytics (see Section 7).
4. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Request erasure of your data ("right to be forgotten").
- Request a portable copy of your data.
- Restrict or object to certain processing.
- Lodge a complaint with your local data protection supervisory authority.
To exercise any of these rights, contact privacy@aulys.com.
5. Sub-processors
We use the following sub-processors to run the service:
- Supabase — authentication.
- Neon — primary database (hosted on AWS
us-east-1, United States). - Dodo Payments — billing and payment processing (merchant of record).
- Railway — API hosting.
- Vercel — web application hosting.
- PostHog — product analytics (only after you accept cookies, see Section 7).
- Google Gemini / Groq — AI-generated remediation suggestions for accessibility issues found in your scans.
A full Data Processing Agreement covering these sub-processors is available at /dpa.
6. International data transfers
Our primary database is hosted in the United States. Where personal data originating in the EEA is transferred outside the EEA, we rely on our sub-processors' Standard Contractual Clauses (SCCs) or equivalent safeguards under Chapter V GDPR.
7. Cookies
We use strictly necessary cookies (authentication session) at all times, and analytics cookies (PostHog) only if you accept them via the cookie banner shown on your first visit. Analytics are opted out by default until you accept, and you can change your choice at any time by clearing your browser's local storage for this site.
8. Data security
We use industry-standard security measures — encrypted transport (TLS), access controls, and least-privilege credentials — to protect your data from unauthorized access, alteration, or disclosure.
9. Contact us
Questions about this privacy policy or our data practices: privacy@aulys.com.