Skip to content
Back to Home

Privacy Policy

Last updated: January 21, 2026

Effective date: January 21, 2026


1. Who We Are

GDPR Scanner ("we", "us", "our") is a privacy compliance scanning service operated by:

GDPR Scanner
Finland

Business ID: 1803004-8
VAT ID: FI1803004-8

Data Protection Contact: contact@gdprscanner.eu


2. What This Policy Covers

This Privacy Policy explains how we collect, use, store, and protect your personal data when you:

  • Visit our website
  • Use our scanning service
  • Create an account
  • Subscribe to VIP plans
  • Contact us

3. Data We Collect

3.1 All Visitors (No Account Required)

DataPurposeCollected When
IP addressRate limiting, abuse prevention, securityEvery visit
URLs submittedProvide scanning serviceWhen you scan
Scan resultsDisplay results to youWhen you scan
TimestampService logsEvery request
Browser typeCompatibility, debuggingEvery visit

3.2 Registered Users (Free Account)

In addition to the above:

DataPurposeCollected When
Email addressAccount login, notificationsRegistration
PasswordAccount security (stored hashed)Registration
Display namePersonalization (optional)Registration
Scan historyYour dashboard, history featureWhen you scan
Account settingsYour preferencesWhen you change settings

3.3 VIP Subscribers

In addition to the above:

DataPurposeCollected When
Payment methodProcess subscriptionCheckout
Billing addressInvoices, tax complianceCheckout
Subscription statusAccess controlSubscription changes
Invoice historyYour records, legal complianceEach payment
CountryVAT calculationCheckout

3.4 Data We Do NOT Collect

  • ❌ Full credit card numbers (handled by Stripe)
  • ❌ Government ID or passport
  • ❌ Precise location / GPS
  • ❌ Contacts or address book
  • ❌ Data from scanned websites (only metadata)

4. How We Use Your Data

4.1 To Provide the Service

  • Process your scan requests
  • Display scan results
  • Maintain your account
  • Process payments
  • Send transactional emails (receipts, password resets)

4.2 To Protect the Service

  • Prevent abuse and fraud
  • Enforce rate limits
  • Detect and block malicious activity
  • Maintain security

4.3 To Improve the Service

  • Analyze usage patterns (anonymized)
  • Fix bugs and errors
  • Develop new features

4.4 To Communicate With You

  • Respond to support requests
  • Send service announcements
  • Send marketing emails (only with your consent)

5. Legal Basis for Processing

Under GDPR, we process your data based on:

Data TypeLegal BasisGDPR Article
IP address, scan logsLegitimate interestArt. 6(1)(f)
Account data (email, password)Contract performanceArt. 6(1)(b)
Payment and billing dataContract + Legal obligationArt. 6(1)(b), 6(1)(c)
Invoice retention (7 years)Legal obligationArt. 6(1)(c)
Marketing emailsConsentArt. 6(1)(a)

Legitimate Interest Assessment

For data processed under legitimate interest, we have balanced our interests against your rights:

  • Our interest: Operating a secure, abuse-free service
  • Your rights: Privacy, data minimization
  • Balance: We collect minimal data, retain it briefly, and anonymize where possible

6. Data Sharing

6.1 We Do NOT Sell Your Data

We never sell, rent, or trade your personal data to third parties for marketing purposes.

6.2 Service Providers

We share data with these processors who help us operate:

ProviderPurposeData SharedLocation
StripePayment processingEmail, billing address, payment methodUSA (GDPR compliant)
RailwayServer hostingAll service dataEU (Germany)
SMTP2GOTransactional emailsEmail addressEU

All processors are bound by Data Processing Agreements (DPAs) and are GDPR compliant.

6.3 Legal Requirements

We may disclose data if required by:

  • Court order or legal process
  • Law enforcement request
  • Protection of our legal rights
  • Emergency situations involving safety

We will notify you unless legally prohibited.


7. Data Retention

Data TypeRetention PeriodReason
IP addresses14 daysAbuse prevention
Anonymous scan logs12 monthsService improvement
Scan history (logged-in)Until account deletionUser feature
Account dataUntil account deletionService provision
Payment records7 yearsTax/legal requirement
Support conversations2 yearsService quality
Marketing consentUntil withdrawnCompliance record

After retention periods, data is permanently deleted or irreversibly anonymized.


8. Data Security

We protect your data with:

Technical Measures

  • ✅ HTTPS encryption for all connections
  • ✅ Password hashing (bcrypt)
  • ✅ Database encryption at rest
  • ✅ Regular security updates
  • ✅ Firewall and intrusion detection
  • ✅ Regular backups (encrypted)

Organizational Measures

  • ✅ Limited staff access to data
  • ✅ Security training
  • ✅ Incident response procedures

Data Breach Notification

If a breach occurs that risks your rights:

  • We notify the supervisory authority within 72 hours
  • We notify affected users without undue delay
  • We document the breach and our response

9. Your Rights

Under GDPR, you have these rights:

9.1 Right to Access (Art. 15)

Request a copy of your personal data.

9.2 Right to Rectification (Art. 16)

Correct inaccurate or incomplete data.

9.3 Right to Erasure (Art. 17)

Request deletion of your data ("right to be forgotten").

Note: Some data must be retained for legal reasons (e.g., invoices).

9.4 Right to Restrict Processing (Art. 18)

Limit how we use your data while disputes are resolved.

9.5 Right to Data Portability (Art. 20)

Receive your data in a machine-readable format (JSON/CSV).

9.6 Right to Object (Art. 21)

Object to processing based on legitimate interest.

9.7 Right to Withdraw Consent (Art. 7)

Withdraw consent for marketing emails anytime.

9.8 Right to Complain

Lodge a complaint with your supervisory authority:

  • Finland: Tietosuojavaltuutetun toimisto (tietosuoja.fi)
  • EU: Your local Data Protection Authority

How to Exercise Your Rights

Option 1: Account Settings → Privacy → Manage My Data

Option 2: Email contact@gdprscanner.eu with:

  • Your request
  • Email address for verification
  • Any relevant details

Response time: Within 30 days (extendable by 60 days for complex requests)

Cost: Free (unless requests are excessive or unfounded)


10. Account Deletion

How to Delete

  1. Go to Settings → Account → Delete Account
  2. Confirm deletion
  3. Account is scheduled for deletion

What Happens

DataAction
Profile (email, name)Deleted within 30 days
Scan historyDeleted or anonymized
Active subscriptionCancelled immediately
Payment recordsRetained 7 years (legal)
Support ticketsAnonymized

Reactivation

Once deleted, your account cannot be recovered. You may create a new account with the same email after deletion completes.


11. Payment Processing

Payment Provider

We use Stripe to process payments. When you subscribe:

  • Card details go directly to Stripe (we never see full card numbers)
  • Stripe stores payment methods securely
  • We receive only: last 4 digits, expiry, card type

Stripe's Privacy Policy: https://stripe.com/privacy

What We Store

  • Subscription status (active/cancelled/expired)
  • Plan type (monthly/yearly)
  • Billing address (for invoices)
  • Invoice history

PCI Compliance

We do not store, process, or transmit credit card data directly. Stripe handles all payment data under PCI-DSS Level 1 compliance.


12. Emails We Send

Transactional (Cannot Opt Out)

These are required for the service:

  • Account verification
  • Password reset
  • Payment receipts and invoices
  • Subscription changes (renewal, expiry, cancellation)
  • Security alerts (suspicious login)
  • Important service announcements

Marketing (Opt-In Only)

These require your consent:

  • Product updates and new features
  • Tips and tutorials
  • Promotional offers

To unsubscribe:

  • Click "Unsubscribe" in any marketing email
  • Or: Settings → Notifications → Email Preferences

13. Cookies

What Are Cookies

Cookies are small files stored on your device that help websites function.

Cookies We Use

CookieTypePurposeDuration
sessionEssentialKeep you logged inSession
csrf_tokenEssentialSecurity (prevent attacks)Session
cookie_consentEssentialRemember your cookie choice1 year

Cookies We Do NOT Use

  • ❌ Analytics cookies (Google Analytics, etc.)
  • ❌ Advertising cookies
  • ❌ Third-party tracking cookies
  • ❌ Social media cookies

Cookie Banner

Because we only use essential cookies, no consent banner is required. However, we inform you here about our cookie use.

Managing Cookies

You can delete or block cookies in your browser settings. Note that blocking essential cookies may break the service.


14. International Data Transfers

Where Data Is Stored

Our primary servers are located in the European Union (Germany).

Transfers Outside EU

Some processors may transfer data outside the EU:

ProviderLocationSafeguard
StripeUSAEU-US Data Privacy Framework

We ensure all transfers have appropriate safeguards under GDPR Chapter V.


15. Children's Privacy

Our service is not intended for children under 16 years of age.

We do not knowingly collect data from children. If you believe a child has provided us data, contact us immediately and we will delete it.


16. Third-Party Links

Our service may contain links to other websites (e.g., scanned websites, documentation).

We are not responsible for the privacy practices of other sites. Please review their privacy policies.


17. Changes to This Policy

We may update this Privacy Policy periodically.

How We Notify You

  • Minor changes: Updated on this page
  • Major changes: Email notification to registered users

Your Continued Use

Continued use after changes constitutes acceptance. If you disagree with changes, you may delete your account.

Version History

VersionDateChanges
1.0January 21, 2026Initial version

18. Contact Us

General Inquiries

contact@gdprscanner.eu

Privacy Requests

contact@gdprscanner.eu

Mailing Address

GDPR Scanner
Finland

Response Time

We aim to respond within 2 business days, and fulfill data requests within 30 days.


19. Supervisory Authority

If you are unsatisfied with our response, you may complain to:

Finland:

Office of the Data Protection Ombudsman
(Tietosuojavaltuutetun toimisto)
PO Box 800, 00531 Helsinki
tietosuoja.fi

Other EU countries: Contact your local Data Protection Authority.


This Privacy Policy was last updated on January 21, 2026.