Privacy Policy
How ADA Fix protects your documents and compliance data
We Understand the Sensitivity of Government Data
ADA Fix is designed specifically for government, education, and regulated industries. We only record the minimum metadata required to maintain compliance audits, and we never persistently store your document content.
Last Updated: December 22, 2025
In-Memory Streaming
All PDF/Office remediations are completed in RAM. The remediation package is destroyed from memory immediately after delivery.
No Persistent Storage
We do not persistently store any original or remediated document content. Audit logs contain only processing result metadata.
Data Sovereignty
Organization administrators can export Evidence Packs or request the destruction of all compliance records for a specific tenant at any time.
Information We Process
- Account Data: Email address, encrypted identifiers, and subscription status.
- Compliance Metadata: File names (anonymization recommended), processing duration, and the types and number of WCAG errors identified.
- Payment Information: Transaction IDs and billing metadata processed securely via our payments provider.
How We Use Information
- User authentication and compliance task quota management.
- Generating Evidence Packs to provide auditable proof of an organization's compliance efforts.
- Optimizing remediation algorithm accuracy (based solely on anonymized structural metadata, without sensitive content).
Document Processing Security
- Server-side Remediation: Runs in controlled container environments with TLS 1.3 data transfer encryption.
- Local Browser Mode: For extremely sensitive documents, we support remediation entirely within the local browser's Web Worker, where data never leaves the server.
- Standard DPA (Data Processing Agreement) provided to meet government cloud security and compliance requirements.
Third-Party Service Providers
We only partner with suppliers that meet strict compliance requirements:
- Supabase – Provides authentication and core compliance metadata storage.
- Creem.io – Acts as the Merchant of Record for payment processing, compliant with PCI-DSS standards.
- Vercel / AWS – Provides underlying computing infrastructure with SOC2 Type II compliance certification.
Your Rights
Depending on applicable data protection laws, you may have the right to:
- Access and export your compliance audit history.
- Request the removal of cloud-based remediation caches for specific assets.
- Close your account and delete all metadata not required to be retained by law.
For any privacy-related requests, please contact: [email protected]. We will respond within 7 business days.