Privacy Policy
How VexNexa handles your personal data and protects your privacy.
✅ What we DO
- Only scan publicly accessible pages
- Store data securely in the EU
- Data minimization & transparency
- Clear rights and settings
❌ What we DON'T do
- Store personal data from page content
- Sell data to third parties
- Non-essential cookies without consent
- Unsecured transfers outside the EU
1. Who we are
VexNexa is an accessibility-scanning service developed in the Netherlands. We help website owners make their sites more accessible by testing WCAG compliance.
Contact details (data controller)
Address: Provencialeweg 46B, 1562TB Krommenie, Netherlands
Chamber of Commerce: 94848262 | Establishment Number: 000060294744
Email: info@vexnexa.com | Website: vexnexa.com
2. What data we collect
Scan data
- URL of the scanned page
- Technical metadata about accessibility issues
- Scan timestamps
- IP address for rate-limiting and abuse prevention
Important: we do not store personal data from page content (such as names, emails, phone numbers); we only analyze HTML structure and accessibility.
Account data (optional)
- Email address
- Name (if provided)
- Hashed password
- Account preferences
Contact
- Name and email address
- Message content
- Submission timestamp
Sign in with Google (OAuth)
When you choose to sign in with your Google account, we receive only the following information from your Google profile via the Google OAuth integration:
- Your email address (required for account identification)
- Your full name as registered with Google
- A unique Google account ID (sub) to link future logins
Payment data
Important: VexNexa does not store credit card or bank account numbers itself. All payment data is processed exclusively by our payment service provider Mollie B.V. within their PCI-DSS certified environment.
- We receive only a payment reference (payment ID), the status (success/failure), the amount, and the payment-method type (e.g. iDEAL, SEPA, card) from Mollie — never the card number itself.
- For legally required invoicing we retain invoice details (company name, address, VAT number, invoice number, amount).
- You can revoke a stored payment method at any time by canceling your subscription or contacting support.
3. Legal basis (Art. 6 GDPR)
- Performance of contract – scans, results, account management.
- Legitimate interest – security (rate-limiting, abuse detection), basic improvements.
- Consent – analytics/marketing cookies and any opt-in communication.
- Legal obligation – retention requirements and requests from authorities.
5. How and why we use data
- Performing scans and displaying results
- Account management and login
- Customer service and support
- Service improvement (with consent for analytics)
- Compliance with laws and regulations
We do not sell or rent your data to third parties for marketing purposes.
6. Recipients and processors
We share data only with service providers that process it on our behalf under a Data Processing Agreement (DPA) compliant with Art. 28 GDPR. Per category, the current processors are:
- Hosting & edge: Vercel Inc. — application hosting and edge routing. Any data transfers to the United States are covered by EU Standard Contractual Clauses (SCCs) and supplementary technical measures.
- Database & storage: Supabase (hosted on AWS in the EU, Frankfurt region) — primary storage for account and scan data. Data remains within the EU.
- Authentication: Supabase Auth for email/password login, and Google LLC for the optional Google OAuth integration. With Google OAuth we receive only your email address, full name, and a Google account ID.
- Payments: Mollie B.V. (Keizersgracht 313, 1016 EE Amsterdam) — handles all payments and is independently PCI-DSS certified. VexNexa does not store any card data.
- Email (transactional): Resend (Resend Inc.) — sends transactional email such as verification, password reset, and invoice/report notifications. Data transfers are covered by SCCs.
7. Transfers outside EU/EEA
If transfers outside the EU take place (e.g., edge-routing or support logs), we use appropriate safeguards such as EU Standard Contractual Clauses and additional measures.
8. Data storage, security & retention
Storage locations
- Database/compute in EU data centers
- Backups within Europe
Security measures
- TLS/HTTPS end-to-end
- Hashed passwords
- Least-privilege access control & monitoring
- Regular patches/updates
- Data minimization
Retention periods
- Scan data: 1 year (Free); longer for paid accounts (configurable in your account)
- Account data: until account deletion or as long as legally required
- Contact messages: up to 2 years
- Analytics: up to 24 months (aggregated/anonymized where possible)
- Invoice data is retained for 7 years in accordance with the statutory tax retention obligation of the Dutch Tax Administration (Belastingdienst).
We delete or anonymize earlier when data is no longer needed, unless retention is legally required (such as the fiscal retention obligation for invoice data).
9. Your rights (GDPR/AVG)
🔍 Right of access
Request what data we have about you.
✏️ Rectification
Have incorrect data corrected.
🗑️ Erasure
Have data deleted.
⏸️ Restriction
Restrict processing (temporarily).
📦 Data portability
Receive data in a common format.
❌ Objection
Object to processing based on legitimate interest.
Je rechten uitoefenen? Mail info@vexnexa.com. We respond within 30 days.
10. Children
Not directed at children under 16 years. Contact us if data has been collected; we will delete it.
11. Data breaches
We immediately investigate the impact, limit risks and report if required to the Dutch Data Protection Authority and affected parties.
12. Automated decision-making
We do not make decisions based solely on automated processing with legal effects for you.
13. Changes to this policy
We communicate significant changes via email (if applicable), a notification on the site and update of the date.
14. Contact & complaints
Not satisfied? File a complaint with the Dutch Data Protection Authority via autoriteitpersoonsgegevens.nl.
Last updated: April 27, 2026