Privacy Policy
What we collect, why we collect it, how long we keep it, and who else touches it.
Last updated: 8 August 2026
Who we are
AccessPulse is an accessibility toolbar that website owners embed on their sites. This policy covers two different groups of people, and it matters which one you are:
- Customers — the businesses who buy AccessPulse and install it on their websites.
- Visitors — people browsing a website that has AccessPulse installed.
For visitor data collected through the widget, the website owner is the data controller and AccessPulse acts as a processor on their behalf. For customer account data, AccessPulse is the controller.
What we collect from website visitors
When the widget loads on a page, it records how the accessibility tools are used. This is deliberately minimal.
| Data | Why |
|---|---|
| Which accessibility tool was used, and the type of event | So customers can see which tools their visitors actually need |
| The page address the widget loaded on | To attribute usage to the right page |
| Browser user-agent string | Compatibility and troubleshooting |
| A short-lived session identifier | To group one visit's actions together |
| A one-way hash of the IP address | To count unique visits without storing who they are |
We do not store a visitor's IP address for widget analytics. It is hashed before it is written, and the hash cannot be reversed to recover the address. We do not build advertising profiles, we do not sell data, and we do not track visitors across different websites.
The widget stores a visitor's chosen settings (contrast, text size, and so on) in their own browser so the choice persists between pages. That stays on their device.
What we collect when you contact us
Demo requests and sign-ups
Name, email address, company name, your message, and the IP address the request came from — the last of these to detect abuse of the form.
The AI assistant
If you use the chat assistant on this website, we store the conversation so we can answer follow-up questions and respond to enquiries. That record includes any name, email address or phone number you give us, the page you started from, your IP address, your user-agent, and the full message history.
Chat conversations are deleted after 180 days. Please do not put sensitive personal information into the chat.
Customer accounts
Company name, email address, phone number, and a password stored only as a bcrypt hash — never in a form we can read. For partners we also hold billing details and tax registration.
Who else processes your data
| Provider | What for | Where |
|---|---|---|
| Amazon Web Services | Hosting, database, email delivery | Mumbai, India (ap-south-1) |
| Amazon Bedrock | Powers the AI chat assistant | AWS region as configured |
| Microsoft Clarity | Usage analytics on this marketing website — only if you accept analytics cookies | Microsoft infrastructure |
| Let's Encrypt | TLS certificates for our domains | — |
Our infrastructure runs in AWS's Mumbai region, so customer and visitor data is stored in India. Chat messages are processed by Amazon Bedrock, which may run in another AWS region.
How long we keep things
- Chat conversations — 180 days, then deleted automatically.
- Widget usage analytics — kept while the customer's account is active. Contains no identifying data, only hashed values.
- Customer account records — for as long as the account exists, and afterwards only as long as tax and accounting law requires.
- Demo requests — retained while we follow up on the enquiry.
- Database backups — up to 90 days.
How we protect it
- All traffic is encrypted in transit with TLS, and the database is encrypted at rest.
- The database is not reachable from the internet at all. It sits in a private network and accepts connections only from our application servers.
- Each part of the application connects to the database with its own least-privilege credentials, so a fault in one component cannot reach data belonging to another.
- Passwords are stored only as bcrypt hashes.
- Administrative access is logged in an audit trail.
No system is perfectly secure, and we will not claim otherwise. If a breach affects your data we will tell you.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, or stop using it in a particular way. Write to us and we will respond within 30 days. If your data was collected through a widget on somebody else's website, ask that website owner first — they control it, and we will act on their instruction.
Depending on where you live you may also have rights under India's Digital Personal Data Protection Act, the EU/UK GDPR, or other local law.
Cookies and local storage
We do not use advertising cookies and we do not sell data to advertisers.
Essential — always on
These are needed for the site to work at all, so they are not optional:
- A session cookie when you are signed in to the customer portal or admin panel, so you stay signed in.
- Browser local storage for your accessibility-widget preferences, your currency and billing-period choice on the pricing page, and your cookie choice itself.
Analytics — only with your consent
We would like to use Microsoft Clarity to understand how the site is used so we can improve it. It records page interactions and may record a session replay.
Nothing is loaded and no request is made to Microsoft until you click Accept. If you decline, or simply ignore the banner, Clarity never runs. Declining is remembered, so we will not keep asking.
You can change your mind at any time: open cookie settings. Clearing your browser storage also resets the choice, and you will be asked again.
Children
AccessPulse is sold to businesses and is not directed at children. We do not knowingly collect data from anyone under 18.
Changes
If we change this policy we will update the date at the top. For material changes affecting customers, we will also email you.
Contact
Questions, or a request about your data: kavithalayaventures@gmail.com