Privacy Policy

Last updated:

Who we are

AccessifyAI is a Shopify-installable application operated by Ensomedia (sole proprietorship, Poland), the data controller for personal data processed through this app. For privacy enquiries contact contact@ensomedia.pl. We have not appointed a designated Data Protection Officer because our processing activities do not cross the thresholds in GDPR Art. 37; privacy requests are handled directly by the controller at the email above.

Lawful basis for processing (GDPR Art. 6)

What data we collect

When a merchant installs AccessifyAI we receive and store:

What we do not collect

How AI processing works (EU AI Act Art. 50(1))

Pro-tier AI fix suggestions, alt-text generation, and report narratives are produced by sending a redacted accessibility issue payload to Groq, our AI inference provider. We pass only the minimum required: the WCAG criterion, an HTML element selector, and a short HTML snippet (after PII scrubbing). Groq's privacy and data-retention terms apply to that processing — groq.com/privacy-policy. AccessifyAI does not retain the AI provider's input or output beyond the scope of returning the fix to the requesting merchant.

AI-generated content is labelled as such in the AccessifyAI admin UI before any merchant decision to apply it. Merchants always preview a unified diff in a Monaco editor and click an explicit confirmation before any AI-generated code is written to their theme.

Data retention

Scan results, issue lists, AI fix suggestions, and audit logs are retained for as long as the app is installed, plus 30 days after uninstall to allow re-install without data loss. After 30 days post-uninstall we permanently delete the merchant's data. Merchants on the Pro plan can configure a shorter retention window (down to 30 days) in app settings; we honour that setting through an automated weekly purge of records older than the configured window.

AutoFix snapshots created when a fix is applied are retained for the rollback window the merchant sets (default 30 days). Report exports are retained 90 days then permanently deleted.

Your rights under the GDPR

Merchants and their end customers can exercise the following rights:

Email contact@ensomedia.pl from the email associated with the Shopify shop owner. We respond within 30 days as required by Art. 12(3). Shopify also automatically delivers GDPR compliance webhooks to AccessifyAI when a customer or shop requests data export or deletion, and we honour those automatically.

California residents (CCPA / CPRA)

If you are a California resident or your shop's end-customers are California residents, you have the following rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act:

California residents can exercise these rights by emailing contact@ensomedia.pl. We verify the request against the shop owner's Shopify-registered email. Authorised agents may submit requests on behalf of a consumer with documented authorisation under §1798.135(c).

Sub-processors

The following sub-processors are used to operate AccessifyAI:

Security

All traffic is TLS-encrypted. Access tokens are stored encrypted at rest by the underlying Google Cloud SQL provider. We do not use third-party analytics inside the merchant admin app. The storefront widget runs entirely client-side and sends only widget-configuration ping requests to our domain, no end-customer telemetry.

International data transfers

Our primary infrastructure runs in the European Union (europe-central2). Groq processes inference requests on infrastructure outside the EU. We rely on the EU Standard Contractual Clauses published in Commission Implementing Decision (EU) 2021/914 to legitimise that transfer, plus the technical safeguards described above (redaction before transmission, no end-customer PII).

Changes to this policy

We will post any material changes to this policy on this page and update the "Last updated" date. Material changes that affect existing data processing will additionally be sent to merchants by email at least 14 days before they take effect.

Contact

Ensomedia
Email: contact@ensomedia.pl

Terms of Service