Privacy policy
Last updated:
This policy explains what personal data EqualSense collects through its website and its application, why we collect it, who processes it for us and where, how long we keep it, and the rights you have.
Who we are
EqualSense is provided by Hurix Digital Inc., 5700 Tennyson Pkwy, Suite 300, Plano, TX 75024, USA. You can reach us at equalsense.support@hurix.com. Hurix Digital Inc. is the controller of the personal data this policy describes.
Organizations that use EqualSense upload their own documents, which can contain personal data about other people, such as staff or students named in course materials. We process the personal data in those documents on the organization's behalf, as its processor, under our agreement with the organization.
What we collect and why
Your account
You sign in on a page hosted by our authentication provider, WorkOS. We do not receive your password. When you sign in, WorkOS confirms who you are, and we store your email address, your name and the address of your profile picture as WorkOS provides them, your WorkOS user ID, and when you last signed in. We also store the organizations you belong to and your role in each. We use this to give you access to your organization in EqualSense and to record who did what in it.
Your organization
For each customer organization we store its name and legal name, its interface language, the email addresses its administrators add to receive audit notifications, and its ID at WorkOS. We send the organization's name to WorkOS to set up sign-in for it. When an administrator invites someone, we store the invited email address, the role offered and a random invitation token, and we send the invitation email ourselves.
Documents and what we produce from them
Your organization's users upload PDF, Word (DOCX), PowerPoint (PPTX) and EPUB files. We store each file and its versions, and we produce from them page and slide images, extracted text and structure, accessibility findings, suggested fixes, remediated files, and reports in JSON, CSV, HTML and PDF. Administrators can also upload their organization's own accessibility guidelines, which we read so that audits can apply them.
If an administrator connects a learning management system (Canvas or Moodle), we store the connection's credentials in encrypted form.
Audit results and activity
We keep each audit's findings, the decisions reviewers make on suggested fixes, and an audit log of actions in your organization: who did what, and when.
If an administrator of your organization opts in, we also keep the reading-order corrections your reviewers make — the order of the elements on a page or slide, never their text — to improve how EqualSense detects reading order. This is off unless your organization turns it on.
Emails and notifications
We send service emails: invitations, notices that an audit has completed or failed, notices that fixes were applied or could not be applied, and set-up emails for a new organization's owner. Audit notices also go to the extra addresses your administrators list. Notifications inside the application are stored with your account.
Support access
EqualSense staff can open your organization in EqualSense only when one of your administrators grants support access. A grant lasts at most seven days and allows viewing only. The start and end of each support session are recorded in your organization's audit log, and we record the staff member's IP address and browser for each session. To operate the service, our platform administrators can see your organization's member list and the names of recently audited files without a grant.
The contact form
When you send us a message through the contact form, we store your email address and message, your name and company if you give them, when you agreed to be contacted, your browser's user-agent string (its first 200 characters), and a keyed hash of your IP address. We do not store the IP address itself. We use this to reply to you, and we use the hash and your email address to limit how many messages can be sent in a day. Your message is emailed to our sales team.
To protect the form from automated abuse, the contact page loads Cloudflare Turnstile from Cloudflare's servers, and when you send a message we pass the Turnstile result and your IP address to Cloudflare to check it. Turnstile collects only the signals it needs to detect bots, such as your IP address and browser details, and does not read what you type into the form.
Cookies and browser storage
We use only the cookies the service needs to work. We use no analytics, advertising or tracking cookies, and no analytics or tracking scripts.
| Cookie | What it does | How long it lasts |
|---|---|---|
| wos-session | Keeps you signed in. Set by the sign-in library from WorkOS. | Until you sign out, or up to 400 days |
| wos-auth-verifier | Protects the sign-in exchange with WorkOS. | 10 minutes |
| eqs_canvas_oauth | Protects the step that connects a Canvas account to your organization. | 10 minutes |
The application also keeps two display preferences in your browser's storage: whether you dismissed the workbench introduction (kept until you clear it) and whether page overlays are shown (cleared when you close the tab). Our fonts are served with the site, not loaded from a third party. The contact page loads Cloudflare Turnstile, as described above; Cloudflare's Turnstile privacy addendum describes what it collects.
How AI models process your documents
To draft alternative text for images and titles for slides, to judge findings that need visual or language understanding (such as text contrast, reading order and slide content), to detect math, and to read the guideline documents your organization uploads, EqualSense sends page and slide images, image crops, and text extracted from your documents, including slide notes, to generative AI models provided by Google through Google Cloud's Vertex AI service, in the us-central1 region (United States). AI output is only a suggestion: no fix is applied to a file until a reviewer in your organization approves it. Under Google Cloud's terms, Google does not use this data to train its models.
Who processes data for us, and where
- Google Cloud runs the application and its background processing, stores files and reports, runs the job queue, and provides the AI models described above, in the us-central1 region (United States).
- Neon hosts our database, in the United States.
- WorkOS provides sign-in, single sign-on and organization identity, in the United States.
- Resend sends our emails and processes them in the United States.
- Cloudflare runs the Turnstile check on the contact form, on its global network, which includes data centers outside the United States.
International transfers
We process personal data in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, transfers of your personal data to the United States are protected by Standard Contractual Clauses.
How long we keep data
- Account, organization and document data: we keep it for as long as your organization uses EqualSense. Archiving a file in the application removes it from view but keeps the file and its audit history. We delete an organization's data within 90 days after its agreement ends, or sooner if it asks us in writing at equalsense.support@hurix.com.
- Contact-form messages: we keep them for 24 months, then delete them. Deleting one erases the name, email address, company, message, IP hash and browser string it holds.
- Service logs: Google Cloud keeps our request logs, which include IP addresses, for 30 days.
- Copies held by our service providers, such as sent emails, are kept under those providers' own retention terms.
How we protect data
- Each organization's data is kept separate. Every page of an organization checks that you are an active member of that organization, records are checked against the organization before they are shown or changed, and each organization's files are stored under a path of their own.
- Roles decide what each member of an organization can do.
- Credentials for connected learning management systems are encrypted with AES-256-GCM before they are stored. API keys are stored only as SHA-256 hashes, never in readable form.
- IP addresses from the contact form are stored only as a keyed hash.
- Staff access to an organization needs a grant from its administrators, as described above.
- Connections to EqualSense use HTTPS, and our hosting providers encrypt stored data at rest.
Your rights
Depending on where you live, the law gives you rights over your personal data. Subject to the conditions and exceptions of the applicable law, you can ask us:
- to confirm whether we process your personal data and to give you a copy of it (access);
- to correct personal data that is inaccurate or incomplete (correction);
- to delete it (deletion);
- to give it to you, or to another organization, in a structured, commonly used and machine-readable format (portability);
- to stop or restrict using it, or to object to our using it (objection).
If your request is about personal data in an organization's EqualSense account, such as documents it uploaded, we refer your request to that organization, which decides how that data is used.
If you are in the European Economic Area or the United Kingdom
The General Data Protection Regulation (GDPR) and the UK GDPR give you the rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and objection (Article 21), and the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you (Article 22). Where we rely on your consent, such as your agreement to be contacted when you use the contact form, you can withdraw it at any time; withdrawing it does not affect processing that took place before. You have the right to lodge a complaint with a supervisory authority, in particular in the country where you live or work or where you believe your rights were infringed (Article 77).
Our legal bases for processing are: our contract with your organization, for accounts and documents; our legitimate interests in keeping EqualSense secure and preventing abuse; and your consent, for following up on a message you send through the contact form.
If you are a California resident
The California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the right to know what personal information we collect, use and disclose, and to access it; to delete it; to correct it; to opt out of its sale or sharing; to limit the use and disclosure of sensitive personal information; and not to be discriminated against for exercising these rights. You can make a request through an authorized agent. We do not sell or share personal information, as the CCPA defines those terms, and the website and application contain no advertising or analytics trackers.
How to make a request
Contact us at equalsense.support@hurix.com.
Changes to this policy
When we change this policy, we update the date at the top of this page. Before a material change takes effect, we email the owners of each organization that uses EqualSense.