Portal Privacy Notice

Last updated: 28 September 2026

Notice version: 2026-09-28

1. Who we are

This notice covers the client portal at portal.mywebaccess.co.uk and the admin portal at admin.mywebaccess.co.uk. MyWeb Access is an accessibility audit service operated by MyVision Oxfordshire Ltd, a charity registered in England and Wales (charity number 1140556) and a company limited by guarantee (company number 07465300).

Registered office: MyVision Oxfordshire, Bradbury Lodge, Gordon Woodward Way, Oxford, OX1 4XL. We are registered with the Information Commissioner’s Office under reference Z2824840. You can contact us about anything in this notice at support@mywebaccess.co.uk, or by post at the address above.

2. Our role

For your account and the running of the portal, MyVision is the controller. That covers your sign-in details, the records that keep sign-in secure, the emails we send you about your account and the service, and administering the service.

For personal data we hold for a client’s engagement — for example in test accounts, audited websites, screenshots, evidence, findings or reports, or in the deliverables the portal hosts for them — we act on that client’s behalf, as their processor, under our contract with them. The client’s own privacy information applies to that data, and questions about it are best sent to them. If you send one to us, we will pass it on.

3. What we process for your account

Your name, email address, organisation and role, so that you can sign in and use the portal on your organisation’s behalf. If you use the client portal as part of an organisation, its authorised portal administrator can see and manage the account details of people in that organisation’s portal team.

When you sign in, reset or change your password, or something about your account’s security changes, we record the event with your email address, IP address and browser details. We keep these records for 90 days. Each signed-in session also keeps the IP address and browser it started from until the session expires. We use them only to keep accounts secure and to investigate misuse.

We email you about your account (setting it up, resetting or changing your password) and about the service (for example, when a dashboard is published or an invoice is issued). If you email us, we keep routine messages for 12 months after the last message in the conversation; a message that becomes part of a client engagement, a complaint or a rights request is kept with that record.

We keep a client portal account while your organisation keeps its portal account open, and an admin account while its holder works on the service. Our lawful basis is legitimate interests (Article 6(1)(f)): providing the portal to your organisation under its contract with us, and keeping it secure.

4. Cookies and your device

When you sign in, the portal sets three cookies that keep you signed in: a sign-in token, your role, and a token that renews your session. On the client portal they are named myaccess_agency_token, myaccess_agency_role and myaccess_agency_refresh_token; on the admin portal, myaccess_admin_token, myaccess_admin_role and myaccess_admin_refresh_token. Page scripts cannot read them, they are sent only to the portal that set them, and they last 7 days or until you sign out.

The portal also stores a few settings in your browser, so that it looks and works the way you left it: your light or dark theme, and the sidebar’s layout (whether it is open, and its width). The sidebar setting is stored under a name that includes your account’s identifier, and it stays in that browser after you sign out. On the admin portal, the last few websites selected on the scan-upload page are remembered to save retyping. A one-time “password updated” message uses your browser’s session storage, which is not kept beyond your browser session. There is no advertising or analytics.

You can stop the portal remembering these settings. In Settings, untick “Remember these settings on this device”. The portal removes them from your browser straight away and stops saving them. Your choices then last only until you reload, and some only until you open another page. So that your choice lasts, your browser keeps a small note of it, which ticking the box again removes. The client and admin portals each keep their own choice, and clearing your browser’s data removes the note too.

Our network provider, Cloudflare, runs a short automated security check in your browser on the portal’s pages, which sends Cloudflare information about your browser, to protect the service from abuse. It normally sets one cookie, cf_clearance, which records the result of the check, applies to mywebaccess.co.uk and its subdomains, and lasts up to a year. If Cloudflare decides a visit needs a closer look it may show a check page and set further security cookies. We do not use it for anything else. Cloudflare also uses information about traffic on its network to run, secure and improve its services, under its own terms and privacy policy.

5. Who else is involved

The portal is hosted by Railway Corporation, which also holds its database and encrypted backups, and is delivered through Cloudflare, Inc. Our emails to you are sent through Brevo (Sendinblue SAS, Paris). Apart from authorised users at your organisation, these providers, and anyone we are required by law to tell, we do not share your personal data, and we never sell it.

Processing outside the UK. Railway and Cloudflare are United States companies, so using them involves transferring personal data to the United States, wherever their servers are. Those transfers rely on the UK’s adequacy regulations for the United States (the UK Extension to the EU-US Data Privacy Framework), under which each of them is currently certified. Brevo is based in France, which the UK recognises as providing adequate protection. Where Brevo’s own providers process data outside Europe, Brevo’s terms provide for standard contractual clauses or, for the United States, the EU-US Data Privacy Framework. You can ask us for details at the address in section 1.

6. Your rights

You have the right to ask what we hold about you, to have it corrected, to have it erased, to restrict or object to how we use it, and to receive it in a portable form where that applies.

Your right to object. Where we use your personal data on the basis of legitimate interests, you can object at any time. We will stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims.

Write to support@mywebaccess.co.uk or to the postal address in section 1. We respond within one month, or tell you within that month if we need up to two more months and why. For personal data we hold as a client’s processor (section 2), we will help that client answer your request.

If you want to complain about how we have handled your personal data, write to the same address or to the postal address in section 1. We will acknowledge your complaint within 30 days of receiving it and tell you the outcome. If you are not satisfied, you can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint.