Who we are

Usable Access is an accessibility compliance consultancy working with organisations whose consumer-facing digital services fall within the scope of the European Accessibility Act. We are a United States registered business serving clients in Ireland and elsewhere in the European Union. Because we offer services to people and organisations in the EU, the General Data Protection Regulation applies to how we handle personal data, and this notice sets out how we do that.

You can contact us about anything in this notice at hello@usableaccess.io.

Visitors to this website

We use Google Analytics to understand how the site is used, in aggregate. This tells us which pages people read and how they arrived, not who they are. If you book a call with us, that booking is handled by Calendly and the details you give are used to hold the call and to follow it up.

How we contact businesses

We contact people in a professional capacity at organisations whose consumer-facing digital services fall within the scope of the European Accessibility Act.

What we hold: name, job title, employer, work email address, and publicly stated professional responsibilities. We do not hold home addresses, personal email addresses, or any special category data.

Where it comes from: the organisation’s own website, publicly available professional profiles, and business contact discovery services. We do not buy scraped contact lists.

Why: to describe a specific accessibility issue we have identified on that organisation’s own service, and to offer our assistance with it.

Our lawful basis is legitimate interests. We have assessed the balance between our interest in making contact and the recipient’s interests and rights: the data is business context only, contact is low volume and personalised, it relates directly to the recipient’s stated professional responsibilities, and every message offers an immediate way to stop. That assessment is available on request.

You can stop it at any time. Reply to any message, or email us, and we will not contact you again. We do not ask for a reason. If you would also like the details we hold deleted, tell us and we will do it and confirm.

Clients

When we carry out work for a client we hold the contact details of the people we work with, and the material needed to do the work. Where we test a client’s service, our findings are about the service, not about individuals.

Where an engagement includes research sessions with disabled participants, we handle that separately and more carefully, because information about a person’s access needs is special category data. Those sessions run on explicit, recorded consent; participants can stop at any time without giving a reason and are paid regardless; notes and findings are anonymised at the point of capture; and recordings are deleted at an agreed point after the work concludes. We collect only the access needs relevant to the test, and never a diagnosis.

How long we keep things

  • Business contact details: up to two years from our last meaningful contact, then deleted.
  • If you ask us not to contact you: we keep the minimum needed to honour that request — your name and organisation, and the date — so that we do not contact you again by mistake.
  • Client records: as agreed in the engagement terms. Material containing personal data is deleted when the work concludes unless the client asks otherwise.
  • Research recordings: deleted at the point agreed with participants.

Who we share it with

We do not sell personal data and we do not share it for anyone else’s marketing. We use a small number of service providers to run the business — email hosting, scheduling, analytics, and payment processing — and they process data only to provide those services to us.

Because we are based in the United States, personal data we hold is processed outside the European Economic Area. We rely on the standard contractual clauses and equivalent safeguards offered by our service providers for those transfers.

Your rights

If you are in the EU or the UK you have the right to ask what we hold about you, to have it corrected, to have it deleted, to restrict how we use it, and to object to our use of it — including our use of legitimate interests to contact you. Ask us and we will act on it, and in any event within one month.

We would rather sort out any concern directly, but you also have the right to complain to a supervisory authority. In Ireland that is the Data Protection Commission.

Contact us about your data

Email hello@usableaccess.io and tell us what you would like us to do. If you find any part of this notice unclear, or you need it in a different format, tell us that too and we will sort it out.