Privacy policy
Privacy policy
How Wexlo handles personal data: what a scan collects, why, how long it is kept and what rights you have under the GDPR.
Last updated: 17 September 2026
Version 2026-09-17
This is the version that currently applies.
Language
This page is a translation. The source text is the English version: wexlo.eu/privacy.
Who we are
- Trade name
- Wexlo
- Business
- Rybier Consulting
- Address
- President Allendelaan 263
1068 VM Amsterdam - KvK number
- 66637694
- VAT number
- NL001677588B25
- Contact
- hello@wexlo.eu
We are the controller for the processing described on this page.
The short version
- We collect the minimum needed to scan websites, deliver reports and invoice, and from the automated scan we deliberately do not store screenshots or HTML of scanned pages. Only a manual assessment keeps screenshots, as evidence for the findings.
- Our infrastructure runs in the EU. One step in the report pipeline (the AI text generation) currently runs via a US supplier; we state that honestly below instead of hiding it.
- No advertising cookies, no cross-site tracking, no cookie banner needed. One functional session cookie on login, cookie-free analytics.
- You can unsubscribe from any email with one click and request deletion of your data at any time.
What we process, and why
- Free scan. You enter a website URL and your email address. We scan the publicly reachable page, store the findings and email you the results. We only send follow-up emails about the full product (up to four) if you tick the box on the form for that. Every follow-up email contains an unsubscribe link; one click immediately stops all further follow-up emails. Legal basis for the follow-up emails: your consent (art. 6(1)(a) GDPR), which you can withdraw at any time; withdrawal does not affect the lawfulness of processing before the withdrawal.
- Scan results. We only store structured findings: the rule, the WCAG criterion, the severity and a CSS selector. From the automated scan we deliberately do not store screenshots or HTML fragments of scanned pages, so that any personal data that may appear on those pages does not end up in our database.
- Customer accounts and orders. When you take out a subscription, we store your company name, contact email address, VAT number, country and the domains you have registered, in order to run your scans and invoice you. Legal basis: performance of the contract (art. 6(1)(b)) and legal (tax) obligations for invoices (art. 6(1)(c)).
- Reports. Your scan reports and PDF files are kept so that you can download them in your portal. Legal basis: performance of the contract.
- Evidence from a manual assessment. When one of our assessors reviews pages by hand, we take screenshots of them, including one per step of the keyboard pass, and we keep the raw measurement output. That lets us substantiate a finding and hand over the full set on request, to you or to the agency doing the fix. The screenshots show the page as a visitor sees it without logging in; personal data visible on the page itself therefore also appears on the screenshot. We keep this for at most 12 months after the measurement date. Legal basis: performance of the contract, and for a free assessment our legitimate interest in being able to substantiate what we report.
- Payments and invoicing. Payments run via Mollie; we never see or store your full payment details. Invoices are created in our accounting system (Jortt) with your company name, address and VAT number, as tax legislation requires.
- Order and consent record. At checkout, we record which version of our terms you agreed to, when, and the IP address and browser characteristics (user agent) of the request. We use this only to prevent fraud and to support or rebut payment disputes (chargebacks). Legal basis: legitimate interest (art. 6(1)(f): fraud prevention and legal claims).
- How you found us. If you arrive via a campaign link, we record the campaign parameters (UTM tags) and the referring page with your lead or order. This is read from the page address; no cookies and no cross-site tracking are involved. Legal basis: legitimate interest (measuring which channels work).
- Customer portal login. We use one-time login links to your email address and one functional session cookie. We do not store passwords for customers: we do not offer password login. Optionally, you can log in with your Google account. Google's consent screen shows what is shared in that process: your name, your profile picture and your email address. We store only the name and the email address; the picture is discarded on arrival and is not stored in our database. We ask for nothing further: no contacts, no calendar, no files, no other access to your Google account. The login attempt is linked to the account already associated with that email address. Google processes the login attempt itself as an independent controller under its own privacy policy, and therefore knows that you are logging in with us at that moment. If you would rather not do that, use the login link instead; that remains available at all times. Legal basis: performance of the contract.
- Abuse prevention. We limit the number of requests per IP address (rate limiting). These technical counters expire automatically and are used only to keep the service available. Legal basis: legitimate interest.
- Support correspondence. If you email us or ask a question through the portal, we keep that conversation: your email address, the messages themselves, and when they were sent. We use this only to reply to you and to be able to look back if you return to the same question later. We keep support conversations for up to 24 months after the last message and delete them afterwards. Legal basis: our legitimate interest in replying to the people who contact us, and performance of the contract if you are a customer.
- Business contacts. If we approach your organisation about Wexlo (business-to-business prospecting), we process business contact details from public sources such as your company website, and findings from a scan of your public web pages. Legal basis: legitimate interest (direct marketing to businesses, within each country's channel rules). You can object at any time via hello@wexlo.eu; we then stop immediately.
- Newsletter. If you subscribe to our newsletter, we store your email address, your language, where you subscribed and when you confirmed. Legal basis: your consent. We first send a confirmation email; if you do not confirm, we delete your address after 30 days. You can unsubscribe via the link in every email; 30 days after unsubscribing we anonymise your data. We use Mailjet, a processor in the EU, to send it.
What we deliberately do not store
Scanning a page inevitably means our scanner loads it briefly, including everything visible on it. By design, we retain almost none of that: from the automated scan no screenshots, no HTML, no continuous page text, only the structured findings described above, which may include a short quote from the element being assessed. Retaining is not the same as sending: during the run, the AI assessment step does send bounded page fragments along, as the transfer section below sets out. This is our main safeguard against collecting personal data of people who appear on scanned websites.
Controller or processor?
For your account, orders, invoices and this website, we are the data controller. When we scan the websites you designate under a paid subscription, we act as your processor for personal data that appears on those pages: you determine what we scan, we process it only to produce your reports. That processing falls under our data processing agreement (DPA), which is part of our terms: no separate signature is required.
AI processing
Scan findings are summarised by an Anthropic AI model (Claude) into plain-language reports, and on paid scans that same model assesses five textual WCAG criteria. For the report text, we send only the structured findings. For the assessment, bounded fragments of the scanned page are also sent: the title, the headings, the alt text of images, the link text, a short piece of surrounding text per element, and sentences that point to a sensory instruction. No account data is sent with these AI calls. The fragments sent are not stored; we do retain the structured findings that result from them, and these may include a short quote from the assessed element. Under our API agreement, Anthropic does not use this data to train its models. Anthropic is a US supplier; see the transfer section below. We do not use AI for automated decision making about you with legal effects or similarly significant effects (Article 22 GDPR): the scan analyses websites, not people.
If image analysis has been switched on (an optional feature that is off by default), then for paid scans we also send the meaningful images from the scanned pages, their alt text and a short excerpt of the surrounding page text to Anthropic, solely to assess those images for accessibility. The images are used only to carry out the analysis and are, as a rule, deleted by Anthropic within 30 days (longer only where needed for abuse prevention or legal obligations); they are never used to train AI models. The transfer to the United States takes place on the basis of the standard contractual clauses approved by the European Commission (see the transfers section below), and Wexlo itself keeps no copies of the images. No images are sent without this explicit consent. Where you give that consent depends on what you buy: with a one-off order there is an optional tick box in the checkout that is off by default, and with a subscription the owner makes that choice in the portal, when setting up a domain and requesting a scan. You can withdraw at any time: with a subscription the owner switches the setting off again in the portal, and with a one-off order you email us at hello@wexlo.eu. A withdrawal applies to what comes after it, not to a scan that has already run. Legal basis: consent.
Recipients and sub-processors
- Scalingo: application hosting (EU)
- Fly.io: scan-worker, CRM and analytics hosting (lead and customer contact data; visitor statistics) (EU region; US company)
- Neon: database (EU region; US company)
- Cloudflare: report and evidence storage (R2, EU jurisdiction), DNS and firewall (US company)
- Upstash: rate limiting and job queue (EU region; US company)
- Mailjet: email delivery (EU; Sinch group)
- Google (Workspace): our customer service mailbox, so every email you send us passes through it and stays there (EU region; US company)
- Mollie: payment processing (EU)
- Jortt: invoicing and bookkeeping (EU)
- vatverify.dev: VAT number validation (receives only the VAT number you enter)
- Anthropic: AI report text, AI assessment of page text and, only with the owner's image-analysis opt-in, page images (United States; our API agreement records that this data is not used for training)
- Sentry: error monitoring (EU data residency region)
Plausible is not on this list because nothing goes to it. Plausible is open-source software that we install and run on our own servers in the EU; the company behind it receives no data about your visit whatsoever. The supplier of those servers (Fly.io) is listed above.
We also measure which pages are visited within your logged-in environment. That happens in the same cookieless way, with one extra measure the public site does not need. Addresses in the portal can contain an identifier, for example for a domain, a support query or an invitation. We strip that identifier out before anything is recorded: our statistics only show that a settings page was visited, never which domain or query it concerned. We measure that a page was visited, not who was there.
We share personal data with these parties solely for the purposes above, under the agreements the law requires for each party: a data processing agreement where the party acts as our processor. We never sell personal data. If you choose to log in with Google, you authenticate with Google itself, and Google is an independent controller for its own processing, not our processor. From that login we retain only your name and email address. The same list, with the processor roles spelled out, is part of our DPA.
International transfer
Our infrastructure is EU-hosted: application, scanner, database, storage, queue, email, payments and invoicing all run in EU regions. Two honest caveats. First, the AI text in our reports is currently generated via Anthropic's API in the United States; that transfer is covered by the EU Standard Contractual Clauses, and we limit it: the reporting step sends only structured findings, and the assessment step sends bounded fragments of the scanned page rather than the page itself. Your account data is not included in either. Second, some of our EU-region suppliers (Neon, Fly.io, Cloudflare, Upstash, Google) are US companies; your data stays in their EU regions, but as US companies they may fall under US law. Where a transfer to the US does take place, it relies on the EU-US Data Privacy Framework for entities certified under it, and otherwise on the EU Standard Contractual Clauses. You can request a copy of the applied Standard Contractual Clauses via hello@wexlo.eu; the model clauses themselves are published on the European Commission's website. If you want the fully precise picture, the sub-processor list above names every party and location.
How long we retain data
- Orders, invoices and consent records: 7 years, the Dutch statutory retention period for financial records.
- Customer account data: for as long as your account exists. On a deletion request, we erase or anonymise everything except what tax law requires us to retain.
- Paid scan results and reports: for as long as your account exists, or until you ask us to delete them.
- Evidence from a manual assessment (screenshots and raw measurement output): at most 12 months after the measurement date, then deleted automatically. Ask us to delete it sooner and we will.
- Free scan data (email address and results): until you unsubscribe or ask us to delete it, and for a maximum of 12 months after your last scan. After unsubscribing, we retain only what is needed to honour the unsubscribe.
- Support conversations: a maximum of 24 months after the last message. We do not delete conversations that are still open on age alone.
- Security and audit logs: a maximum of 24 months, unless an ongoing security incident or dispute requires longer.
- Rate-limit counters: expire automatically within a few hours.
- Login links: single-use, valid for 15 minutes, cleaned up automatically.
Analytics
We use Plausible Analytics to see how our marketing pages are used. We run it ourselves: it is open-source software hosted on our own servers in the EU, served from analytics.wexlo.eu, so your visit never reaches the company behind Plausible.
Alongside page views we record a small number of anonymous interaction events (that a scan was started, that an order was completed, that a contact form was submitted) so we can see where visitors get stuck. Those events contain no personal data: no email address, no scanned website, no order details.
Our analytics stores nothing on your device: no cookies, no local storage. The only cookie we place anywhere is one functional session cookie in the customer portal, and only when you log in (see Cookies above). To be able to distinguish repeat visits within one day, the software calculates a hash from your IP address, your browser and the date, using a key that is destroyed and replaced every 24 hours. Your IP address itself is never stored, and once that key is gone, the hash can no longer be linked to you or to the following day.
Because our analytics does not store or read anything on your device (Article 5(3) of the ePrivacy Directive, Article 11.7a of the Dutch Telecommunications Act), we do not ask for consent for it. Legal basis for the analysis itself: legitimate interest (Article 6(1)(f) GDPR) in understanding how our own site performs.
How we protect your data
All traffic is encrypted in transit (TLS, enforced with HSTS) and data is encrypted at rest with our database and storage providers. We minimise by design what we collect, use one-time login links instead of passwords, restrict internal access on a least-privilege basis and log security-relevant events. No system is perfectly secure; if a data breach ever affects your rights, we will inform you and the supervisory authority as the GDPR requires.
Your rights
You have the right to access, correct, delete and receive a copy (portability) of your personal data, to restrict and object to processing, and you can withdraw consent at any time without affecting processing carried out before that. Customers can request deletion directly from the portal; anyone can email hello@wexlo.eu. We respond within one month. You can also file a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl) or with the supervisory authority in your own EU country.
Changes
If this policy changes, we update this page and the date at the top; for material changes we inform customers by email. The current version is always at https://wexlo.eu/nl/privacy.