← Back

Privacy Policy

Last updated: 7 February 2026

1. Who We Are

AccessyAI is operated by Biiig.Studio (ABN 62 549 755 047), based in Australia.

In this policy, “Biiig.Studio”, “we”, “us”, and “our” refer to the operator of AccessyAI trading as Biiig.Studio.

For the purposes of EU and UK data protection laws, the data controller is Biiig.Studio (ABN 62 549 755 047), contactable at info@accessyai.com.

2. What We Collect

We collect only the information necessary to provide and improve the Service:

DataDetailsPurpose
Email addressProvided via waitlist signup formBeta access and communication
Role & company sizeOptional, provided via waitlist formUnderstanding our user base
URLs submittedWeb addresses you enter for auditingPerforming accessibility audits
Crawled page dataPage title, HTML snippets of violations, screenshots, bounding boxesGenerating audit reports
IP addressFrom request headers, not stored persistentlyRate limiting only

3. How We Collect It

  • Waitlist form — email, role, and company size
  • Audit form — URL submitted for scanning
  • Automated crawling — page data collected when you initiate an audit

4. Why We Collect It

  • To provide the accessibility auditing service
  • To manage beta access
  • To improve and develop the Service
  • To communicate with you about your account or the Service

5. Legal Basis

Australian Privacy Act 1988: Although we may qualify for the small business exemption under the Privacy Act, we voluntarily commit to handling your personal information in accordance with the Australian Privacy Principles (APPs). We collect only information that is reasonably necessary for our functions and activities, and only by lawful and fair means.

EU/UK GDPR: For users in the European Union and United Kingdom, we process personal data on the basis of legitimate interests (Article 6(1)(f)) for providing the Service, and consent where applicable.

6. Third-Party Disclosure

We do not sell your personal information.

We share limited data with the following third parties only as necessary to provide the Service:

  • Anthropic (Claude API) — United States. When you click “Enhance with AI”, violation details (rule, description, HTML snippet, severity, WCAG criteria, category, impact groups) are sent to the Anthropic Claude API to generate remediation suggestions. This is user-initiated only.
  • Turso — Australia (Sydney). Database hosting for storing audit results.

7. Cookies & Local Storage

Cookies are small text files placed on your device by websites you visit. Local storage is a similar browser mechanism that stores data on your device. AccessyAI uses a single essential cookie and one local storage item. We do not use any third-party cookies, advertising cookies, or analytics tracking cookies.

Cookie:

NameTypePurposeDurationAttributes
accessy_betaEssentialAuthenticates your beta access session using a unique token1 yearhttpOnly, secure (production), sameSite lax

Local storage:

KeyTypePurposeNotes
accessy-selected-roleFunctionalRemembers your selected role preference in the UIStored locally only, never sent to our servers

You can control and delete cookies through your browser settings. If you delete the accessy_beta cookie, you will lose access to the beta and will need to be re-approved through the waitlist.

8. Data Retention

  • Audit results — stored until you request deletion
  • Waitlist data — stored while your account is active or until you request removal
  • IP addresses — used transiently for rate limiting and not stored persistently

9. Data Security

We implement appropriate technical measures to protect your data, including SSRF protection for URL scanning, Content Security Policy (CSP) headers, rate limiting, and httpOnly secure cookies. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

10. Data Breach Notification

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users without undue delay. Where required by applicable law (including the EU/UK GDPR), we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach.

11. Your Rights (Australian Privacy Principles)

In line with our commitment to the Australian Privacy Principles, you have the right to:

  • Access — request access to the personal information we hold about you (APP 12)
  • Correction — request correction of inaccurate or outdated information (APP 13)
  • Complaint — lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the APPs

12. Your Rights (EU/UK GDPR)

If you are located in the European Union or United Kingdom, you have additional rights under the GDPR, including the right to:

  • Access your personal data
  • Rectification of inaccurate data
  • Erasure (“right to be forgotten”)
  • Restriction of processing
  • Data portability
  • Object to processing
  • Withdraw consent at any time (where processing is based on consent)

To exercise any of these rights, contact us at info@accessyai.com. We will respond within 30 days.

AccessyAI generates accessibility scores and violation reports through automated analysis. These results are informational only and do not have legal or similarly significant effects on you. No decisions about your access to the Service are made solely by automated means.

13. Children

AccessyAI is not directed at children under 16 years of age. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

14. International Transfers

Your data may be processed outside Australia in connection with third-party services we use, including the Anthropic Claude API and Turso database hosting. Where data is transferred internationally, we take reasonable steps to ensure it is handled in accordance with the Australian Privacy Principles and applicable data protection laws.

15. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated “Last updated” date. We encourage you to review this policy periodically.

16. Contact & Complaints

If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at:

info@accessyai.com

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).