Privacy policy

Last updated: July 25, 2026

This document contains two parts. Part A is the privacy policy. Part B is the terms of service.

Complaudax is a product of DemtiliWorks, a business based in Ontario, Canada. By using Complaudax, the browser extension, the web application, and the public website, you agree to both parts below. If you do not agree, do not use the Service.

Complaudax is a tool that helps you find, track, and document web accessibility issues. It does not make any website compliant on its own, and it does not guarantee that a website meets any legal standard.

This document is provided in English. It is a general template aligned with common industry practice. It is not legal advice. You should have it reviewed by a qualified lawyer before relying on it, in particular the data protection sections if you serve users in the European Union or the United Kingdom.

Part A: Privacy Policy

A1. Who we are

Complaudax is operated by DemtiliWorks, based in Ontario, Canada. For any privacy question, or to exercise the rights described below, contact us at[email protected].

A2. The short version

  • We collect the minimum needed to run the Service: your account details, the accessibility audit results you generate, and basic product usage analytics.
  • We do not store the full content of the web pages you audit. Page text is stripped inside your browser before anything is sent to us.
  • We do not sell your personal information, and we do not sell the data of the websites you audit.
  • We use a small number of third party providers to operate the Service, listed in section A7.
  • You can export or delete your data at any time.

A3. What we collect

Account information. When you create an account, we collect your name, email address, and authentication identifier from your chosen sign in method. If you subscribe to a paid plan, our payment processor collects your billing details. We do not receive or store your full payment card number.

Content you create in the Service. This includes the clients and sites you set up, and the accessibility audit results you generate. Audit results consist of metadata about accessibility issues: the rule identifier, the affected element identified by a stable non reversible hash, the impact level, the relevant WCAG success criteria, and a short redacted code snippet.

What we deliberately do not collect. We do not store the full HTML or the visible text content of the pages you audit. Before an audit result leaves your browser, text nodes are removed and only accessibility relevant attributes are retained, and code snippets are truncated. This means personal data belonging to your clients or their website visitors is not transmitted to us or stored on our servers through normal use of the Service.

The public scanner. If you use the free public scanner on our website, we scan the single public URL you provide. The result of that scan, including the URL, is held for thirty minutes so that you can ask for it by email, and is then deleted automatically. Beyond that window we keep only aggregate information: the host name, the issue counts, and a timestamp. We never store the content of the page we scanned. If you choose to receive the result by email, we store the email address you provide for that purpose, and every such email carries a working unsubscribe link.

Abuse prevention on the public scanner. The scanner is free and unauthenticated, so we limit how many scans one visitor can run. To count them we store a one-way cryptographic hash of the network address the request came from, never the address itself, and those records are deleted after one hour.

Usage analytics. We collect basic product analytics to understand how the Service is used and to improve it, such as which features are used and whether an audit or a report completed. We identify these events by your account identifier only. We do not send your clients' website URLs, your clients' names, or any redacted snippet content to our analytics provider.

Technical data. Like most online services, our systems automatically log basic technical information such as IP address, browser type, and timestamps, for security, fraud prevention, and reliability.

A4. How we use it

We use the information above to:

  • provide, maintain, and secure the Service;
  • generate the audit history, trends, and reports you request;
  • process payments and manage subscriptions;
  • communicate with you about your account, security, and material changes;
  • understand and improve product usage;
  • detect, prevent, and address fraud, abuse, and technical issues;
  • comply with legal obligations.

We rely on the following legal bases where applicable: performance of our contract with you, our legitimate interests in operating and improving the Service, your consent, and compliance with law.

We do not use your content to train machine learning models.

A5. Your role and our role for client data

You are responsible for having the right to audit the websites you choose to audit, including any staging environment or page behind a login. When you use the Service in connection with websites belonging to your own clients, you are responsible for your relationship with those clients and for any notices or agreements required between you and them.

Because the Service is designed so that page content is redacted in your browser before transmission, we act primarily as a provider of tools to you rather than as a processor of your clients' end user personal data. Where we do process personal data on your behalf, we do so in accordance with this Privacy Policy. If you require a separate data processing agreement to meet your obligations under the GDPR, the UK GDPR, or similar laws, contact us at [email protected].

A6. Sharing

We do not sell your personal information. We share information only in these situations:

  • Service providers. With the third parties listed in section A7, strictly to operate the Service, under contracts that limit their use of the data.
  • Legal. When required by applicable law, regulation, legal process, or a valid governmental request, or to protect the rights, safety, and property of the Company, our users, or the public.
  • Business transfer. If the Company or the Complaudax product is involved in a merger, acquisition, financing, or sale of assets, in which case we will take reasonable steps to ensure this Privacy Policy continues to apply.

A7. Third party providers

We rely on a small number of providers to run the Service. Each processes only what is needed for its function:

  • Cloud hosting and database, for running the application and storing your data.
  • Payment processing, for subscriptions and billing.
  • Product analytics, for usage measurement, receiving account level events only.
  • Email delivery, for transactional and, where you consent, marketing email.
  • Bot protection, for the public scanner.
  • The automated accessibility detection engine, axe-core, is bundled and runs locally in your browser or on our server for the public scanner; it does not transmit your data to Deque Systems.

We will keep this list current. A specific, up to date list of subprocessors is available on request.

A8. International transfers

We are based in Canada and process data in Canada and other jurisdictions where our providers operate. Canada benefits from an adequacy decision from the European Commission for commercial organizations. Where personal data of individuals in the European Union or the United Kingdom is transferred, we rely on that adequacy decision or on appropriate safeguards such as standard contractual clauses.

A9. Retention

We keep your account and content data for as long as your account is active. On free plans, audit history may be retained for a limited period as described in the Service. When you delete your account, we delete or anonymize your personal data within a reasonable period, except where we must retain certain records to comply with legal, tax, accounting, or security obligations, or to resolve disputes.

A10. Your rights

Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, to object to certain processing, and to withdraw consent. Canadian users have rights under applicable Canadian privacy law, and users in the European Union and the United Kingdom have rights under the GDPR and UK GDPR.

To exercise any of these rights, contact[email protected]. We will respond within the time required by applicable law. You also have the right to complain to your local data protection authority.

A11. Security

We take reasonable technical and organizational measures to protect your data, including encryption in transit, access controls, and data minimization by design. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

A12. Children

The Service is a business tool and is not directed to individuals under the age of majority in their jurisdiction. We do not knowingly collect personal data from children.

A13. Changes

We may update this Privacy Policy from time to time. When we make material changes, we will update the date at the top and, where appropriate, notify you. Your continued use of the Service after an update means you accept the revised policy.