Vizuem
PrivacyData useEvidence gated

Privacy & Data Use

This Privacy Policy explains how Vizuem collects, uses, protects, and retains data to provide WCAG-informed scan intelligence, evidence review, Digital Risk signals, assets visibility, exports, and reporting.

Policy summary
Customer data sale
No
Cross-customer sharing
No
AI training on customer data
No
Last updated
September 14, 2026
Plain-language summary: customer operational scan data stays workspace-scoped. Anonymized platform intelligence may support scoring calibration and benchmark context, but it is designed not to identify a customer, site, workspace, user, or scan.

Overview

Vizuem is designed to minimize sensitive data collection while preserving the information customers need to review scan results, export records, monitor posture over time, and understand digital accessibility signals.

We distinguish customer operational scan data, account and contact data, and anonymized platform intelligence. Customer operational scan data supports the customer workspace. Account and contact data supports account administration, authorized workspace access, billing, support, and service communications. Platform intelligence supports aggregate analytics, scoring calibration, and benchmark context when thresholds are met.

Data Classes

Operational Scan Data
Workspace-scoped

Customer-scoped operational data required to run scans, review evidence, generate reports, and support workspace workflows.

  • Scan targets and configured scan scope.
  • Evidence, rule results, severity, implementation context, and scan telemetry.
  • Digital Risk signals, discovered assets, reports, exports, and scan settings.
  • Access-controlled within the customer workspace.
Platform Intelligence Data
Anonymized

Anonymized, aggregated signal data used to support product analytics, scoring calibration, and benchmark context.

  • Aggregated rule prevalence, severity distributions, and score bands.
  • Eligible benchmark snapshots when sample thresholds are met.
  • Excludes URLs, domains, page paths, HTML/content, scan IDs, user IDs, and workspace identifiers.
  • Designed to be non-attributable to any customer or site.
Account and Contact Data
Operational

Information used to create and administer accounts, customer relationships, workspace access, billing, support, and service communications.

  • Account email addresses and authenticated-user identifiers.
  • Organization, contact, billing, and workspace membership information.
  • Invitation, account-access, legal-acceptance, and communication-preference records.
  • Contact and support information submitted when communicating with Vizuem.
Retention note: operational scan data is time-limited by default. Platform intelligence may be retained longer if it remains anonymized, aggregated, and non-attributable.

How Data Is Used

  • Provide scans, evidence review, reports, exports, scan history, and workspace functionality.
  • Administer accounts and workspaces, verify authorized access, process invitations, and provide account, security, billing, support, legal, and other service-related communications.
  • Maintain reliability, security, abuse prevention, billing controls, support, and platform operations.
  • Send optional product news, educational content, announcements, and offers by email only when you explicitly choose to receive marketing email.
  • Improve scoring calibration and benchmark context using anonymized platform intelligence.
  • Enforce plan limits, access controls, and export authorization.

AI Training Policy

Vizuem does not use customer URLs, page content, evidence, reports, exports, or other customer operational scan data to train public or general-purpose AI models.

Allowed use: anonymized platform intelligence may be used for product analytics, benchmark context, scoring calibration, and service improvement when it remains aggregated and non-attributable.

Data Sharing

We do not sell customer operational scan data. We do not share customer operational scan data across customer accounts.

Customer operational scan data and account and contact data may be processed by subprocessors engaged to provide the Services, subject to confidentiality and security obligations, or disclosed when required by law.

Platform intelligence is anonymized and aggregated. It is not intended to be attributable to a customer, workspace, scan, user, or site.

Retention

Data
Default
Notes
Operational scan data
18 months
Evidence, telemetry, Digital Risk, assets, and workspace context.
Exported reports
5 years
Report artifacts for procurement and documentation workflows.
Account and Contact Data
Active relationship + 90 days
Routine account and contact records are deleted or irreversibly anonymized after the account or workspace has been closed for 90 days.
Routine business correspondence
24 months
Routine support, sales, general inquiry, affiliate, and similar correspondence. Billing and accounting, legal and privacy, security and operational, and other specialized records follow separate retention schedules.
Revalidation audit records
90 days
Operational history for revalidation activity.
Internal administrative action history
5 years
Internal support and platform-administration action history.

Retention defaults may vary by plan, feature, or written agreement. Billing and accounting records, legal and privacy records, security and investigation records, legal-acceptance history, communication-preference and suppression evidence, legal-hold records, and other records subject to a separately defined retention schedule are handled independently from the routine Account and Contact Data lifecycle. When an applicable retention period expires, data is deleted or irreversibly anonymized in the ordinary course unless a separate retention requirement applies.

Customer Controls

  • Customers define scan targets and configured scan scope.
  • Workspace access controls determine who can view scans, evidence, reports, and exports.
  • Exports are customer-initiated and may be subject to plan limits.
  • Authenticated workspace access is required for full evidence, scan history, and downloadable records.
  • Necessary and functional browser storage remains available for authentication, security, accessibility preferences, and product operation.
  • Optional first-party analytics are off until you choose to allow Analytics.
  • Vizuem stores a first-party anonymous browser identifier for up to 90 days when Analytics is allowed to measure product usage and funnel activity. The identifier is not used for marketing.
  • You can change your Analytics choice at any time using Analytics Preferences in the site footer. Rejecting Analytics removes the analytics identifier and suppresses optional analytics events.
  • Promotional and marketing email is off unless you explicitly choose to receive it.
  • If you opt in to marketing email, Vizuem uses your account email address and records your preference change so the current choice can be honored.
  • You can change your marketing email preference at any time in Settings → Communications. Marketing opt-out does not suppress account, security, billing, support, or other service-related messages.
Claim boundary: Vizuem provides WCAG-informed scan intelligence and evidence context. It provides informational scan context only. Final decisions remain with your team and advisors.

Contact

For privacy, retention, procurement, or data-handling questions, use your account support channel or contact contact our privacy team.

Vizuem
This Privacy Policy describes how Vizuem handles data. Formal terms are governed by the applicable agreement.
Last updated: September 14, 2026