Vai al contenuto

Legal

Privacy Policy

Effective date: 24 August 2026. This policy is available in English only at this time.

1. Who we are

Cluesia (“Cluesia”, “we”, “us”) is operated by Ignion Apps, registered in Rajkot, Gujarat, India as a small business under India’s Udyam (MSME) registration scheme. We are the data controller for account data described in Section 2, and a data processor for the scan data described in Section 3 — see our Data Processing Addendum for that relationship. Questions about this policy: [email protected].

2. Data we collect about you, our customer

  • Account data: the email address and organisation name you sign up with, and any Google account identifiers if you sign in via Google OAuth.
  • Site data: the URLs you submit for scanning, and the domain ownership verification token/method you choose.
  • Billing data: our payment provider, Dodo Payments Inc., acts as Merchant of Record and handles your payment method, invoicing, and VAT directly — we never receive or store your card number. We do receive the transaction record (amount, tier purchased, timestamp).
  • Campaign link clicks: when you follow a cluesia.com/go/… short link from one of our posts, we record the click — the link’s slug, the referring site’s domain, and a timestamp — to see which content brings people here. No cookie is set, and we do not store your IP address or any identifier; the counts are aggregate only.

3. Data we process on your behalf (scan data)

When you submit a URL, our automated scanner (a sandboxed, non-interactive browser) visits the pages you designate and captures, per page: the rendered DOM, CSS selectors, a screenshot, and any accessibility findings against WCAG 2.1 AA / EN 301 549. Because this is your own website’s content, it can incidentally include personal data of your site’s visitors — for example a name in a testimonial, or a photo in a screenshot. We do not scan pages behind a login, and we do not target or profile individual visitors; the scan exists to find accessibility defects, not people.

DOM snippets are sanitised (scripts and event handlers stripped) before storage, purely as a security measure against stored XSS — this does not remove incidental personal data from the captured markup.

4. Legal basis

Account and billing data: performance of our contract with you (GDPR Art. 6(1)(b)). Scan data: performed on your instructions as our customer, under the Data Processing Addendum (Art. 6(1)(b), with you as controller for that data). Security logging and fraud/abuse prevention: our legitimate interest (Art. 6(1)(f)).

5. How long we keep it

  • Account data: for as long as your account is active, deleted on request thereafter.
  • Report findings and generated reports: kept indefinitely — the report is the deliverable you purchased, and re-generating it would require re-scanning your site.
  • Raw screenshots: purged automatically after 90 days by a scheduled job. Only the screenshot is deleted; the finding record (severity, citation, remediation text) is kept.

6. Who we share data with (sub-processors)

Sub-processorPurposeLocation
SupabaseDatabase, authenticationEU (Frankfurt)
Cloudflare (R2)Report/screenshot storageEU jurisdiction bucket
Dodo Payments Inc.Payments, billing, VAT (Merchant of Record)US / UK
Google (Gemini API)AI-assisted remediation text and alt-text generationMay process outside the EEA
ResendTransactional email deliveryEU/US

Where a sub-processor operates outside the EEA, transfers are made under appropriate safeguards (Standard Contractual Clauses or an equivalent adequacy mechanism). We do not sell your data or your visitors’ data, and we do not use scan content for advertising.

7. Your rights

Under GDPR you have the right to access, correct, delete, restrict, or export your account data, and to object to processing based on legitimate interest. To exercise any of these, contact [email protected]. If you believe we haven’t handled your request properly, you can lodge a complaint with your local data protection authority.

8. If you are a visitor to one of our customers’ websites

We don’t collect data about you directly — we’re processing our customer’s website on their instructions, as described in Section 3. Requests concerning your data should go to the website operator (our customer); we assist them in fulfilling such requests under our Data Processing Addendum.

9. Security

Scans run in a sandboxed, non-privileged browser with no host network access. We validate every user-submitted URL against private/loopback/link-local address ranges before fetching (including on every redirect hop) to prevent server-side request forgery. Traffic is encrypted in transit (HTTPS/HSTS), and our application enforces a restrictive Content-Security-Policy.

10. Cookies

We use only strictly-necessary cookies: to keep you signed in (set by Supabase Auth), remember your language choice, and remember your cookie preference. We do not use advertising or cross-site tracking cookies. See our Cookie Policy for the full list.

11. Children

Cluesia is a B2B service and is not directed at, or knowingly used by, children under 16.

12. Changes to this policy

We’ll post material changes here with an updated effective date, and notify active customers by email for changes that affect how we handle their data.

13. Contact

[email protected] — Ignion Apps, Rajkot, Gujarat, India.

Privacy Policy — Cluesia