Skip to content

Legal

Privacy Policy

Effective / last updated: July 14, 2026· Connectivo, Inc.

Connectivo builds accessibility technology, and we hold ourselves to the same high standard for privacy that our customers expect of us. This Privacy Policy explains what information Connectivo, Inc. (“Connectivo,” “we,” “us”) collects, how we use and share it, and the choices and rights you have. It applies to our website at connectivo.ai and to the Connectivo Accessibility Platform (the “Platform”).

Privacy at a glance. We collect the minimum data needed to deliver accessibility services. We do not sell or share your personal information for advertising, and we do not track end users of the websites we help remediate. For web pages, we remediate through a real-time proxy and do not modify your source pages or source code or persistently store the page content we process. To make documents and multimedia accessible (Microsoft Office files, PDFs, audio, and video), we access and remediate the files themselves, under the security and retention controls described below. We do not collect student education records, health records, payment-card data, or biometric data.

1. Scope & our role

Connectivo provides an AI-powered accessibility platform that scans, remediates, and helps maintain digital accessibility (WCAG 2.1/2.2 and Section 508) across websites, documents, and other content, delivered through modules including Connectivo Discover, Scan, AI Remediation, Proxy, Governance, and LMS.

Our role under data-protection law depends on the context:

  • As a data controller, for personal information we collect directly — for example, when you visit our website, request a demo, correspond with us, or an administrator creates an account.
  • As a data processor / service provider, for institutional data we handle on behalf of a customer under our customer agreement and Data Processing Addendum. In that role, the customer (for example, a university) is the controller and directs how the data is used.

2. Information we collect

Information you provide

  • Contact & account data: name, business/institutional email, phone, organization, role, and account credentials (passwords are stored only as salted hashes).
  • Sales & support communications: the content of demo requests, inquiries, and support tickets.

Information we process to deliver the Platform

  • Web page content (processed transiently): the Platform renders and analyzes web pages within your configured scope at the proxy layer. Web page content is processed in memory and is not persistently stored, and we do not modify your source pages or source code. Any personal information that a customer chooses to publish on its own site and that the Platform incidentally encounters is handled with the same security controls; customers control what content is exposed.
  • Documents and multimedia (remediated at the file level): to make documents (Microsoft Office, PDF) and multimedia (audio, video) accessible, the Platform accesses and remediates the files themselves and produces remediated versions. Where you connect storage or learning systems (for example SharePoint, Google Drive, OneDrive, NAS, or Canvas), the Platform reads source files and writes back remediated versions, handled under the security, retention, and deletion controls in this policy.
  • Accessibility findings & remediation records: issue inventories, WCAG mappings, remediation recipes, and status — describing pages and elements, not individuals.

Information collected automatically

  • Website & product usage:pages viewed on our own site, feature usage within the Platform, and standard log data (such as the administrator’s IP address, browser type, and timestamps) used for security, troubleshooting, and service improvement.

What we do not collect

  • No disability or accessibility data about individuals. The Platform evaluates the accessibility of content, not the characteristics of the people who use it. We do not collect, use, or share information about any individual’s disability or accessibility needs.
  • No end-user tracking on the sites we remediate. We do not track the browsing behavior of, build profiles of, or set tracking cookies on visitors to the websites we help remediate, and we do not track users across sites.
  • We do not collect FERPA-protected education records, protected health information (PHI/HIPAA), payment-card (PCI) data, government identifiers such as SSNs, or biometric data.

3. How we use information

We use personal information to:

  • provide, operate, secure, and improve the Platform and our website;
  • authenticate users, administer accounts, and enforce role-based access;
  • detect, prevent, and respond to security incidents, fraud, and abuse;
  • respond to demo requests, questions, and support tickets;
  • send service and administrative communications (such as security or change notices);
  • comply with legal obligations and enforce our agreements.

We do not use institutional data for advertising, and we do not train our AI models on your data by default (institutions may voluntarily opt in). See our Responsible AI & Transparency Statement for how AI processing works and how to opt out.

Automated decision-making. We do not use automated decision-making, including profiling, that produces legal or similarly significant effects concerning individuals. Our AI proposes accessibility fixes to content; it does not make decisions about people, and human review can be required before changes are applied.

Marketing communications. If you receive marketing emails from us, you can unsubscribe at any time using the link in that email; you will still receive transactional messages related to your account and the Services.

4. Legal bases for processing (GDPR / UK GDPR)

Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (to provide the Platform and respond to requests); legitimate interests (to secure, operate, and improve our services, balanced against your rights); consent (for non-essential activities, where required, which you may withdraw at any time); and legal obligation (to comply with applicable law). When we act as a processor, we process personal data on the documented instructions of our customer.

5. Cookies & similar technologies

Our authenticated application uses strictly necessary cookies (for example, session and security cookies) that are required for the service to function. We do not use advertising or cross-site tracking cookies, and we do not use tracking pixels to profile end users. Our public website may use limited, privacy-respecting analytics to understand aggregate usage; where required by law, we present a cookie choice. Our website honors Do Not Track (DNT)browser signals — when a DNT signal is detected, our analytics do not record that visit. You can control cookies through your browser settings, though disabling strictly necessary cookies may prevent parts of the service from working.

Any analytics or marketing technologies on our own website are notdeployed on the customer websites that the Platform remediates. The Platform’s remediation layer is designed not to set tracking cookies on, or track the visitors of, those sites.

6. How we share information

We share personal information only as needed to run our business and deliver the service:

  • Sub-processors. Vetted service providers process data on our behalf under written data-processing agreements. See our current Sub-processor List.
  • Professional advisors. Auditors, lawyers, and accountants under confidentiality obligations.
  • Legal & safety. When required by valid legal process, or to protect the rights, safety, and security of Connectivo, our customers, or the public. We require valid legal process (such as a subpoena or warrant) before disclosing institutional data to law enforcement and, where permitted, notify the affected customer.
  • Corporate transactions. In connection with a merger, acquisition, or financing, subject to this policy and applicable law.

We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA.

7. International data transfers

By default, institutional data for U.S. customers is stored and processed in the United States. Where a customer requires EU data residency, we can store data in EU regions. When personal data is transferred across borders, we use appropriate safeguards, including the European Commission’s Standard Contractual Clauses, and we make these available through our Data Processing Addendum.

8. Data retention

We retain institutional data for the duration of the customer agreement and then for up to 90 days, after which it is securely deleted by cryptographic erasure (destroying the encryption keys so the data is unrecoverable), unless a longer period is required by law. Security and audit logs are retained for approximately one year. We retain website and account contact data only as long as needed for the purposes described above or as required by law. If you request deletion of your individual account, we complete deletion within 30 days, a window that allows for data retrieval requests before removal.

9. How we protect information

We protect personal information with encryption in transit (TLS 1.2/1.3) and at rest (AES-256), role-based access controls, multi-factor authentication, least-privilege administration, continuous monitoring, and an independently tested security program. For details, see our Security & Trust Overview. No method of transmission or storage is perfectly secure, but we work continuously to protect your information and to notify affected parties promptly if an incident occurs (within our 72-hour breach-notification commitment for confirmed breaches of institutional or personal data).

10. Your privacy rights

California residents (CCPA/CPRA)

Subject to the law’s limits, you may request to know what personal information we collect and how we use and disclose it; access or receive a copy; correct inaccurate information; and delete personal information. You have the right to opt out of the sale or sharingof personal information — although Connectivo does not sell or share personal information — and the right not to receive discriminatory treatment for exercising your rights. Where we act as a service provider to an institution, we handle personal information only as permitted by our customer contract and will refer consumer requests to the relevant institution.

In the preceding 12 months, we have collected the following categories of personal information as defined by the CCPA:

Categories of personal information collected (CCPA)
CategoryExamples
IdentifiersName, email address, phone number, IP address, account name.
California Customer Records (Cal. Civ. Code § 1798.80(e))Name, phone number, company name, job title.
Commercial informationRecords of services purchased or considered, subscription history.
Internet or network activityBrowsing activity on our website, interactions with the Services.
Professional or employment informationJob title, company name.
InferencesInferences drawn from the above to reflect preferences or characteristics.

EEA / UK residents (GDPR / UK GDPR)

You may have the right to access, rectify, erase, restrict or object to processing, and to data portability, as well as the right to withdraw consent and to lodge a complaint with a supervisory authority. Where we act as a processor, we will assist our customer (the controller) in responding to such requests.

Other jurisdictions

Residents of other U.S. states and countries may have similar rights under applicable law; we honor those rights consistent with the law that applies to you.

11. How to exercise your rights

To exercise any right, email [email protected]. We confirm requests within 2 business days and respond within the timeframe required by applicable law (generally within 30–45 days). We take reasonable steps to verify your identity before acting, and you may use an authorized agent where the law allows. If you are an end user or student whose data is controlled by an institution using Connectivo, please contact that institution; we will support them in fulfilling your request.

12. Student data & FERPA

Connectivo does not store or process education records protected by the Family Educational Rights and Privacy Act (FERPA). Where an institution engages us in a manner that implicates FERPA, Connectivo will act as a “school official” with a legitimate educational interest under the institution’s direct control, use the data only for the authorized purpose, and not re-disclose it except as permitted. These commitments are reflected in our Data Processing Addendum.

13. Children's privacy

Connectivo is a business-to-business service intended for institutions and their authorized administrators. It is not directed to children, and we do not knowingly collect personal information from children under 13 (or the applicable age in your jurisdiction). If you believe a child has provided us personal information, contact [email protected] and we will delete it.

14. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version here with a new “last updated” date and, for material changes, provide additional notice as required by law or our customer agreements.

15. Contact us & our Data Protection Officer

Questions, requests, or complaints about privacy can be sent to our privacy team, which includes our Data Protection Officer–equivalent:

Privacy team / DPO[email protected]
General inquiries[email protected]
Phone+1 (888) 800-5938
Mailing addressConnectivo, Inc., Southern California, United States (full mailing address available on request)

If you are in the EEA or UK and are not satisfied with our response, you may contact your local data-protection supervisory authority.