Privacy policy
Last updated: 23 July 2026. Written to be read, not to hide behind.
Who we are
Able (able.cat) is an accessibility benchmarking company that audits websites for businesses. It is operated from Barcelona, Spain by its founder, who is the data controller for the processing described here. Contact for anything on this page, including exercising your rights: hello@able.cat.
What we collect, and why
- If you buy an audit: your URL, your name, a billing email address, and payment records. Legal basis: performing our contract with you, plus legal (tax) obligations for invoices. Kept for as long as Spanish tax law requires invoice records, then deleted.
- If you email us: your email and what you wrote, kept so we can reply and keep context. Deleted on request.
- If we contacted you first: we research prospective business customers using public sources only (company websites, public directories) and write to role addresses or named business contacts about their own website. Legal basis: legitimate interest in business-to-business outreach about a service relevant to their role. Every message identifies us and includes a working opt-out; opting out puts you on a suppression list we check before any future send, which is the one list we never delete you from, because it is what stops us contacting you again.
- Scan data: audits and research scans run against publicly reachable pages only. Results about your site belong to your report. Aggregated, anonymised statistics (no company names) feed our published EU Accessibility Baseline.
- If you use the free scanner: we store the address you submit, the time, a coarse rate-limiting record of the requesting connection, and the scan result. That powers the service, prevents abuse, and feeds the same anonymised aggregates. Scans load one public page, once, in a normal browser.
What we do not do
- No cookies and no cross-site tracking. We measure visits with Plausible, a privacy-first analytics tool we run on our own European server and serve from our own domain. It sets no cookies, stores no personal data, never fingerprints you and never follows you to other websites: only aggregate counts such as page views, referrer and country. That is why this site has no cookie banner, and why there is nothing here to opt out of. The server also keeps ordinary technical access logs (IP, path, time) for security, rotated on a short schedule.
- We never sell personal data, and we do not use your data to train external AI systems without your explicit permission.
- We do not scan behind logins and we do not collect special-category data. If a customer wants a logged-in journey audited, that happens only by written agreement with credentials you create for the purpose and revoke after.
Where it lives and who touches it
Data is stored on our server in the EU (Hetzner, Germany) and in our EU-hosted email (Zoho). State-of-the-art automated analysis, including AI models, does the heavy lifting of scanning and drafting; the founder reviews outputs before they reach you. Where AI providers process content for us, they act as processors and content is limited to what the task needs, which for audits is your public pages.
Your rights
GDPR applies. You can ask for access, correction, deletion, restriction, portability, and you can object to legitimate-interest processing, including outreach, at any time. Email hello@able.cat and it is handled within a month, usually much faster. If you are unhappy with how we handle it, you can complain to the Spanish supervisory authority (AEPD, aepd.es) or your local one.
Changes
If this policy changes materially, the change and its date are noted here. We keep the old versions available on request.