Legal

This page explains the terms of use for Scoreba's services and how we handle personal data.

1. Service Agreement / Terms of Use

Parties: This agreement is between [Company legal name / registration number / registered address to be inserted] ("Scoreba", "we") and the individual or entity purchasing the service ("Customer").

Scope of service: Scoreba provides: (a) a free, automated Pre-Analysis scan; (b) a Full Audit combining automated scanning (axe-core-based) with AI-assisted analysis (including image alt-text and link-text evaluation); and (c) a continuous Monitoring service that detects site changes. AI-assisted analysis is performed via Anthropic's Claude models.

EXPLICIT SCOPE LIMIT: This service does NOT guarantee full compliance with WCAG or any official accessibility checklist. Automated tools (axe-core-class scanners) can reliably detect only a subset of WCAG success criteria (commonly estimated at roughly 30-40%); AI-assisted analysis extends this coverage somewhat, but a substantial portion of criteria — contextual keyboard usability, screen-reader experience, cognitive accessibility, and the semantic correctness of forms/workflows — can only be evaluated through an EXPERT, HUMAN-CONDUCTED MANUAL AUDIT. Reports from Scoreba are a starting point and prioritization aid, not a definitive legal compliance determination.

Accessibility conformance mark/logo: Where an official accessibility conformance mark or logo exists (e.g. under Turkish regulation), it is ISSUED BY THE RELEVANT GOVERNMENT MINISTRY/AUTHORITY. Scoreba does NOT issue this mark; it provides only a technical preparation service to help the customer qualify for that application.

Customer responsibilities: The Customer is responsible for (i) IMPLEMENTING remediations for reported findings via its own development team/agency, and (ii) completing the required allowlist/whitelist setup (see `/kurulum`) so that our scanning traffic is not blocked by the site's security layer (WAF/CDN) before a Full Audit runs. A failed scan due to missing allowlist setup is not a service defect.

Limitation of liability: To the maximum extent permitted by applicable law, Scoreba's total liability under this agreement is CAPPED AT THE FEES PAID by the Customer for the relevant service. We accept no liability for indirect damages (lost profits, reputational harm, third-party claims) or for ADMINISTRATIVE FINES levied against the Customer.

Termination and refunds: The Customer may cancel an order and receive a full refund before a Full Audit scan begins. Once scanning has started (real server/API costs have been incurred), no refund is issued. Monthly Monitoring may be cancelled at any time effective at the next billing cycle; no refund is issued for the current cycle.

2. Data Protection Disclosure Notice

Data controller: [Company legal name / registration number / registered address to be inserted]

Personal data processed: (a) account email address and password (stored hashed); (b) the scanned site URL and scan results (accessibility findings, screenshot/DOM content samples); (c) name, email, and message submitted via the contact/quote form; (d) order metadata related to payment (card details are NOT stored by us — they are processed directly by the payment provider); (e) IP address (for rate limiting and security, retained briefly).

Purposes and legal basis: Performance of the service (contract performance), compliance with legal obligations, and legitimate interest (fraud/abuse prevention, rate limiting).

International transfer (EXPLICITLY DISCLOSED): During the Full Audit's AI-assisted analysis step, visual/text content of scanned pages (the site URL, screenshots, link text) is sent to and processed by Anthropic, PBC's API, based in the United States. This transfer relies on an appropriate safeguard mechanism (e.g. Standard Contractual Clauses, where applicable — see §6 for EU customers). Transferred data is used SOLELY for accessibility analysis (alt-text/link-text evaluation).

Retention period: Account data is retained for as long as the account is active plus the applicable statutory limitation period. Scan results/reports may be retained for up to 24 months (to support historical comparison). AI cost logs are retained for 12 months for operational purposes.

Data subject rights: You have the right to learn whether your personal data is being processed, request information about it, request correction or deletion, learn to whom it has been transferred, and claim compensation for damages. Requests can be sent to [email protected].

3. Data Processing Addendum (DPA)

Role split: Scoreba does NOT scan or process any personal data belonging to the Customer's own site visitors (e.g. data collected via the Customer's forms) — scanning examines only the site's publicly accessible HTML/DOM structure, visual content, and accessibility attributes. In this respect, Scoreba acts as a data CONTROLLER only for its own account data, not as a data PROCESSOR of the Customer's site-visitor data. No integration requiring access to the Customer's visitor data (e.g. live chat, form integrations) is offered.

Sub-processors: (1) Anthropic, PBC — AI-assisted visual/text analysis (the transfer described in §2 above); (2) hosting/infrastructure provider — [Company legal name / registration number / registered address to be inserted] (server hosting); (3) transactional email provider (Resend or equivalent) — sending transactional emails.

Security measures: Passwords are stored using a one-way, salted hash (scrypt); API keys are randomly generated and revocable; database access is restricted to in-process connections; production `.env` values are kept outside the source code repository.

Breach notification: In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours and affected data subjects within a reasonable time, as required by applicable law.

4. Privacy Policy

This policy summarizes, in consumer-facing language, the data processing activities described in the Disclosure Notice (§2) above: what data we collect, why we collect it, who we share it with (including the Anthropic API), and how you can exercise your rights. See §5 for cookie details.

Your data is never SOLD or rented to third parties for marketing purposes.

6. Note for EU Customers

For customers established in the EU, the transfer of personal data to Türkiye and to the United States (Anthropic API) may be subject to the rules of Chapter V of the General Data Protection Regulation (GDPR). Such transfers SHOULD rely on the European Commission's Standard Contractual Clauses (SCCs) or an equivalent safeguard mechanism — the exact mechanism must be confirmed by legal counsel before this section can be treated as final; until then it remains a DRAFT.

Last updated: the date this page was created. Questions: [email protected]