Skip to main content
Back to homepage

Privacy Policy

Last updated: April 27, 2026
v1.3

How VexNexa handles your personal data and protects your privacy.

Privacy at a glance
The most important points in one overview.

✅ What we DO

  • Only scan publicly accessible pages
  • Store data securely in the EU
  • Data minimization & transparency
  • Clear rights and settings

❌ What we DON'T do

  • Store personal data from page content
  • Sell data to third parties
  • Non-essential cookies without consent
  • Unsecured transfers outside the EU

1. Who we are

VexNexa is an accessibility-scanning service developed in the Netherlands. We help website owners make their sites more accessible by testing WCAG compliance.

Contact details (data controller)

Address: Provencialeweg 46B, 1562TB Krommenie, Netherlands
Chamber of Commerce: 94848262  |  Establishment Number: 000060294744
Email: info@vexnexa.com | Website: vexnexa.com

2. What data we collect

Scan data

  • URL of the scanned page
  • Technical metadata about accessibility issues
  • Scan timestamps
  • IP address for rate-limiting and abuse prevention

Important: we do not store personal data from page content (such as names, emails, phone numbers); we only analyze HTML structure and accessibility.

Account data (optional)

  • Email address
  • Name (if provided)
  • Hashed password
  • Account preferences

Contact

  • Name and email address
  • Message content
  • Submission timestamp

Sign in with Google (OAuth)

When you choose to sign in with your Google account, we receive only the following information from your Google profile via the Google OAuth integration:

  • Your email address (required for account identification)
  • Your full name as registered with Google
  • A unique Google account ID (sub) to link future logins

Payment data

Important: VexNexa does not store credit card or bank account numbers itself. All payment data is processed exclusively by our payment service provider Mollie B.V. within their PCI-DSS certified environment.

  • We receive only a payment reference (payment ID), the status (success/failure), the amount, and the payment-method type (e.g. iDEAL, SEPA, card) from Mollie — never the card number itself.
  • For legally required invoicing we retain invoice details (company name, address, VAT number, invoice number, amount).
  • You can revoke a stored payment method at any time by canceling your subscription or contacting support.

3. Legal basis (Art. 6 GDPR)

  • Performance of contract – scans, results, account management.
  • Legitimate interest – security (rate-limiting, abuse detection), basic improvements.
  • Consent – analytics/marketing cookies and any opt-in communication.
  • Legal obligation – retention requirements and requests from authorities.

4. Cookies and tracking

Functional cookies (necessary)

  • Session for logged-in users
  • Preferences (language, theme)
  • Cookie consent status

Analytics cookies (optional)

With consent, we may use privacy-friendly analytics (e.g., Vercel Analytics or alternative). We measure aggregated statistics, not individual profiles.

  • Visitor statistics (aggregated/anonymous)
  • Popular pages and features
  • Technical performance

You can manage consent through the cookie settings.

UTM parameters

We may temporarily store UTM parameters to understand origin. These contain no personal data.

5. How and why we use data

  • Performing scans and displaying results
  • Account management and login
  • Customer service and support
  • Service improvement (with consent for analytics)
  • Compliance with laws and regulations

We do not sell or rent your data to third parties for marketing purposes.

6. Recipients and processors

We share data only with service providers that process it on our behalf under a Data Processing Agreement (DPA) compliant with Art. 28 GDPR. Per category, the current processors are:

  • Hosting & edge: Vercel Inc. — application hosting and edge routing. Any data transfers to the United States are covered by EU Standard Contractual Clauses (SCCs) and supplementary technical measures.
  • Database & storage: Supabase (hosted on AWS in the EU, Frankfurt region) — primary storage for account and scan data. Data remains within the EU.
  • Authentication: Supabase Auth for email/password login, and Google LLC for the optional Google OAuth integration. With Google OAuth we receive only your email address, full name, and a Google account ID.
  • Payments: Mollie B.V. (Keizersgracht 313, 1016 EE Amsterdam) — handles all payments and is independently PCI-DSS certified. VexNexa does not store any card data.
  • Email (transactional): Resend (Resend Inc.) — sends transactional email such as verification, password reset, and invoice/report notifications. Data transfers are covered by SCCs.

7. Transfers outside EU/EEA

If transfers outside the EU take place (e.g., edge-routing or support logs), we use appropriate safeguards such as EU Standard Contractual Clauses and additional measures.

8. Data storage, security & retention

Storage locations

  • Database/compute in EU data centers
  • Backups within Europe

Security measures

  • TLS/HTTPS end-to-end
  • Hashed passwords
  • Least-privilege access control & monitoring
  • Regular patches/updates
  • Data minimization

Retention periods

  • Scan data: 1 year (Free); longer for paid accounts (configurable in your account)
  • Account data: until account deletion or as long as legally required
  • Contact messages: up to 2 years
  • Analytics: up to 24 months (aggregated/anonymized where possible)
  • Invoice data is retained for 7 years in accordance with the statutory tax retention obligation of the Dutch Tax Administration (Belastingdienst).

We delete or anonymize earlier when data is no longer needed, unless retention is legally required (such as the fiscal retention obligation for invoice data).

9. Your rights (GDPR/AVG)

🔍 Right of access

Request what data we have about you.

✏️ Rectification

Have incorrect data corrected.

🗑️ Erasure

Have data deleted.

⏸️ Restriction

Restrict processing (temporarily).

📦 Data portability

Receive data in a common format.

❌ Objection

Object to processing based on legitimate interest.

Je rechten uitoefenen? Mail info@vexnexa.com. We respond within 30 days.

10. Children

Not directed at children under 16 years. Contact us if data has been collected; we will delete it.

11. Data breaches

We immediately investigate the impact, limit risks and report if required to the Dutch Data Protection Authority and affected parties.

12. Automated decision-making

We do not make decisions based solely on automated processing with legal effects for you.

13. Changes to this policy

We communicate significant changes via email (if applicable), a notification on the site and update of the date.

14. Contact & complaints

Get in touch

Email: info@vexnexa.com

Or use the contact form.

Not satisfied? File a complaint with the Dutch Data Protection Authority via autoriteitpersoonsgegevens.nl.

Last updated: April 27, 2026