Legal
Privacy notice
We collect little, we sell nothing, and this page tells you everything: what data we process, on what legal basis, who touches it, how long we keep it, and how to exercise your rights.
Last updated: July 19, 2026.
1. Who is responsible
The data controller is Jivaseva OÜ, registry code 12142627, Lootuse tn 1-6, Kiili alev, 75401 Harju maakond, Estonia, operating as AuditRush. For anything in this notice, use the contact form and pick the data request topic; we answer in writing. We are an EU company and apply the GDPR to everyone we serve, wherever you are. Our processing does not require a data protection officer; the controller answers data questions directly.
2. What we process, why, and on what legal basis
- Order and delivery data: your email address, the site URL, your page selection, and what you type into the order or contact form. We use it to deliver the audit you ordered and answer questions about it. Legal basis: performance of a contract (GDPR art 6(1)(b)).
- Payment data: processed by Stripe as payment processor; we receive confirmation of payment and the billing details Stripe shows us, never your card number. Legal basis: performance of a contract, and legal obligation for the accounting records (art 6(1)(c)).
- Audit artifacts: screenshots, page structure, and findings we generate about the audited public pages. These pages can incidentally show personal data that is publicly visible on them (for example a staff page). We process that content only to produce the audit. Legal basis: performance of a contract with the customer, and our legitimate interest in documenting the evidence behind each finding (art 6(1)(f)).
- Correspondence: messages you send us, kept so that answers given in writing stay accountable. Legal basis: legitimate interest (art 6(1)(f)).
- Site visits: when you visit this website, Cloudflare, our host, processes connection data such as your IP address to serve the pages and protect them against abuse. We do not build visitor profiles from it. Legal basis: legitimate interest in running a secure website (art 6(1)(f)).
- Aggregate usage measurement: we run PostHog, hosted in the European Union and served from our own domain, which counts page views and a few actions on this site, for example how many free scans were run and how many people opened the order page, together with the country your IP address points to. It stores nothing on your device and reads nothing from it, sets no cookie, and cannot recognise you across visits: each visit counts as a new one. Alongside it we keep our own daily tallies of the same actions, numbers only, with nothing attached that could identify a visitor. Legal basis: legitimate interest in knowing whether the site works (art 6(1)(f)).
- Free scan: the address you submit is used to load and test that one page, and the result is returned to your browser. We do not store the address or the result.
- Shopify app: if you install our app, we store your shop's domain and the access token Shopify issues us, which is what lets the app run inside your admin, plus a record of any audit you buy there. The check itself runs against your public storefront. If your storefront is password protected and you choose to enter that password in the app, it is used for that one check and never stored. No customer, order, or product data from your shop is read or kept. Legal basis: performance of a contract (art 6(1)(b)).
This website sets no cookies and carries no advertising, no third-party trackers, and no third-party fonts. Measurement is limited to the cookieless aggregate counting described above. We do not sell personal data, and we make no automated decisions about people that have legal or similarly significant effects.
Providing the order data is necessary to deliver the audit: without an email address and a site URL there is nothing to deliver. None of our processing relies on consent, so there is no consent to withdraw. For everything we base on legitimate interest we have documented the balancing test; you can request a summary through the contact form.
Sensitive and children's data: we never seek either, but an audited page can incidentally show them. The two cases are legally distinct, with the same practical outcome. Special categories of personal data (GDPR art 9, for example a staff biography mentioning disability): where the person manifestly made the information public themselves, art 9(2)(e) applies, and in every other case we redact it from the audit artifacts as soon as we become aware of it or on request. Children's data (for example pupils shown on a school site) is not an art 9 category, but children are vulnerable data subjects whose interests weigh heavier in our legitimate interest balancing, so we apply the same redaction on awareness or on request. Redaction never weakens a finding: findings concern the page's markup, not the people shown on it.
3. Who processes data for us
We use a small set of service providers, each only for what it says:
- Stripe for payments, invoices, and receipts. For fraud prevention and its own legal obligations Stripe also acts as an independent controller under its own privacy policy
- Cloudflare for website hosting, email routing, and the free scan's page rendering
- PostHog (PostHog EU, hosted in the European Union) for the cookieless aggregate usage measurement described above
- Brevo for delivering transactional email
- Shopify where you install our app from the Shopify App Store: Shopify issues the access token, handles the purchase, and is the source of the shop domain we store
- Google (Gmail) as our mailbox provider
- AI analysis providers: captured content of the audited public pages is analyzed with large language models accessed via OpenRouter (Anthropic models). We send page evidence, not your correspondence, the content is used only to produce the analysis, and the provider agreements we use do not permit it to be used for training the providers' models.
- The named reviewer: an independent certified accessibility specialist reviews each audit under written confidentiality obligations before it ships.
4. International transfers
Some of these providers process data in the United States, and the named reviewer may work from outside the EEA. Provider transfers rely on the EU-US Data Privacy Framework or on the European Commission's Standard Contractual Clauses, per each provider's data processing agreement; the reviewer's written confidentiality obligations include data protection duties. You can request details of the applicable safeguards through the contact form.
5. How long we keep things
- Accounting records (orders, invoices): 7 years, as the Estonian Accounting Act requires.
- Audit reports and artifacts: 2 years after delivery, so we can answer follow-up questions from you or your attorney and honor our correction commitment; deleted earlier on your request where no legal obligation requires keeping them.
- Correspondence: up to 2 years after the matter is closed.
- Shopify app records: the shop domain and access token are deleted when Shopify tells us the shop was redacted after an uninstall, and immediately on request.
6. Confidentiality
Customer identities, orders, and report contents are confidential, as the terms state: no marketing use of customer audits, no publishing customer names, disclosure only where law or a binding order requires it. Many customers are in active legal disputes and we treat everything accordingly.
7. Your rights
You can ask for access to the personal data we hold about you, have it corrected or deleted, restrict or object to processing based on legitimate interest, and receive data you gave us in a portable format. Send the request through the contact form; we respond within a month. If you think we handle personal data unlawfully, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or to the supervisory authority of your own country.
If you are not our customer but personal data about you is visible on pages we audited, the same rights apply to the audit artifacts. The source of that data is the audited website itself, where it was publicly visible; we collected it as part of the page evidence, not from you. Contact us and we will respond the same way.
8. Security
The site and all delivery channels run over TLS, we collect the minimum the service needs, access to audit data is limited to the people producing the audit, and secrets are not stored in the website's code. If a personal data breach ever occurs, we notify the supervisory authority within 72 hours of becoming aware of it where the GDPR requires notification, and we tell you without undue delay when the breach is likely to put you at high risk.
9. Changes to this notice
The date at the top tells you the current version. If we change what we process or who processes it, we update this page before the change takes effect; the version that applies to an order is the one published when you ordered.