Privacy Policy
Last updated: January 21, 2026
Effective date: January 21, 2026
1. Who We Are
GDPR Scanner ("we", "us", "our") is a privacy compliance scanning service operated by:
GDPR Scanner
Finland
Business ID: 1803004-8
VAT ID: FI1803004-8
Data Protection Contact: contact@gdprscanner.eu
2. What This Policy Covers
This Privacy Policy explains how we collect, use, store, and protect your personal data when you:
- Visit our website
- Use our scanning service
- Create an account
- Subscribe to VIP plans
- Contact us
3. Data We Collect
3.1 All Visitors (No Account Required)
| Data | Purpose | Collected When |
|---|---|---|
| IP address | Rate limiting, abuse prevention, security | Every visit |
| URLs submitted | Provide scanning service | When you scan |
| Scan results | Display results to you | When you scan |
| Timestamp | Service logs | Every request |
| Browser type | Compatibility, debugging | Every visit |
3.2 Registered Users (Free Account)
In addition to the above:
| Data | Purpose | Collected When |
|---|---|---|
| Email address | Account login, notifications | Registration |
| Password | Account security (stored hashed) | Registration |
| Display name | Personalization (optional) | Registration |
| Scan history | Your dashboard, history feature | When you scan |
| Account settings | Your preferences | When you change settings |
3.3 VIP Subscribers
In addition to the above:
| Data | Purpose | Collected When |
|---|---|---|
| Payment method | Process subscription | Checkout |
| Billing address | Invoices, tax compliance | Checkout |
| Subscription status | Access control | Subscription changes |
| Invoice history | Your records, legal compliance | Each payment |
| Country | VAT calculation | Checkout |
3.4 Data We Do NOT Collect
- ❌ Full credit card numbers (handled by Stripe)
- ❌ Government ID or passport
- ❌ Precise location / GPS
- ❌ Contacts or address book
- ❌ Data from scanned websites (only metadata)
4. How We Use Your Data
4.1 To Provide the Service
- Process your scan requests
- Display scan results
- Maintain your account
- Process payments
- Send transactional emails (receipts, password resets)
4.2 To Protect the Service
- Prevent abuse and fraud
- Enforce rate limits
- Detect and block malicious activity
- Maintain security
4.3 To Improve the Service
- Analyze usage patterns (anonymized)
- Fix bugs and errors
- Develop new features
4.4 To Communicate With You
- Respond to support requests
- Send service announcements
- Send marketing emails (only with your consent)
5. Legal Basis for Processing
Under GDPR, we process your data based on:
| Data Type | Legal Basis | GDPR Article |
|---|---|---|
| IP address, scan logs | Legitimate interest | Art. 6(1)(f) |
| Account data (email, password) | Contract performance | Art. 6(1)(b) |
| Payment and billing data | Contract + Legal obligation | Art. 6(1)(b), 6(1)(c) |
| Invoice retention (7 years) | Legal obligation | Art. 6(1)(c) |
| Marketing emails | Consent | Art. 6(1)(a) |
Legitimate Interest Assessment
For data processed under legitimate interest, we have balanced our interests against your rights:
- Our interest: Operating a secure, abuse-free service
- Your rights: Privacy, data minimization
- Balance: We collect minimal data, retain it briefly, and anonymize where possible
6. Data Sharing
6.1 We Do NOT Sell Your Data
We never sell, rent, or trade your personal data to third parties for marketing purposes.
6.2 Service Providers
We share data with these processors who help us operate:
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Stripe | Payment processing | Email, billing address, payment method | USA (GDPR compliant) |
| Railway | Server hosting | All service data | EU (Germany) |
| SMTP2GO | Transactional emails | Email address | EU |
All processors are bound by Data Processing Agreements (DPAs) and are GDPR compliant.
6.3 Legal Requirements
We may disclose data if required by:
- Court order or legal process
- Law enforcement request
- Protection of our legal rights
- Emergency situations involving safety
We will notify you unless legally prohibited.
7. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| IP addresses | 14 days | Abuse prevention |
| Anonymous scan logs | 12 months | Service improvement |
| Scan history (logged-in) | Until account deletion | User feature |
| Account data | Until account deletion | Service provision |
| Payment records | 7 years | Tax/legal requirement |
| Support conversations | 2 years | Service quality |
| Marketing consent | Until withdrawn | Compliance record |
After retention periods, data is permanently deleted or irreversibly anonymized.
8. Data Security
We protect your data with:
Technical Measures
- ✅ HTTPS encryption for all connections
- ✅ Password hashing (bcrypt)
- ✅ Database encryption at rest
- ✅ Regular security updates
- ✅ Firewall and intrusion detection
- ✅ Regular backups (encrypted)
Organizational Measures
- ✅ Limited staff access to data
- ✅ Security training
- ✅ Incident response procedures
Data Breach Notification
If a breach occurs that risks your rights:
- We notify the supervisory authority within 72 hours
- We notify affected users without undue delay
- We document the breach and our response
9. Your Rights
Under GDPR, you have these rights:
9.1 Right to Access (Art. 15)
Request a copy of your personal data.
9.2 Right to Rectification (Art. 16)
Correct inaccurate or incomplete data.
9.3 Right to Erasure (Art. 17)
Request deletion of your data ("right to be forgotten").
Note: Some data must be retained for legal reasons (e.g., invoices).
9.4 Right to Restrict Processing (Art. 18)
Limit how we use your data while disputes are resolved.
9.5 Right to Data Portability (Art. 20)
Receive your data in a machine-readable format (JSON/CSV).
9.6 Right to Object (Art. 21)
Object to processing based on legitimate interest.
9.7 Right to Withdraw Consent (Art. 7)
Withdraw consent for marketing emails anytime.
9.8 Right to Complain
Lodge a complaint with your supervisory authority:
- Finland: Tietosuojavaltuutetun toimisto (tietosuoja.fi)
- EU: Your local Data Protection Authority
How to Exercise Your Rights
Option 1: Account Settings → Privacy → Manage My Data
Option 2: Email contact@gdprscanner.eu with:
- Your request
- Email address for verification
- Any relevant details
Response time: Within 30 days (extendable by 60 days for complex requests)
Cost: Free (unless requests are excessive or unfounded)
10. Account Deletion
How to Delete
- Go to Settings → Account → Delete Account
- Confirm deletion
- Account is scheduled for deletion
What Happens
| Data | Action |
|---|---|
| Profile (email, name) | Deleted within 30 days |
| Scan history | Deleted or anonymized |
| Active subscription | Cancelled immediately |
| Payment records | Retained 7 years (legal) |
| Support tickets | Anonymized |
Reactivation
Once deleted, your account cannot be recovered. You may create a new account with the same email after deletion completes.
11. Payment Processing
Payment Provider
We use Stripe to process payments. When you subscribe:
- Card details go directly to Stripe (we never see full card numbers)
- Stripe stores payment methods securely
- We receive only: last 4 digits, expiry, card type
Stripe's Privacy Policy: https://stripe.com/privacy
What We Store
- Subscription status (active/cancelled/expired)
- Plan type (monthly/yearly)
- Billing address (for invoices)
- Invoice history
PCI Compliance
We do not store, process, or transmit credit card data directly. Stripe handles all payment data under PCI-DSS Level 1 compliance.
12. Emails We Send
Transactional (Cannot Opt Out)
These are required for the service:
- Account verification
- Password reset
- Payment receipts and invoices
- Subscription changes (renewal, expiry, cancellation)
- Security alerts (suspicious login)
- Important service announcements
Marketing (Opt-In Only)
These require your consent:
- Product updates and new features
- Tips and tutorials
- Promotional offers
To unsubscribe:
- Click "Unsubscribe" in any marketing email
- Or: Settings → Notifications → Email Preferences
13. Cookies
What Are Cookies
Cookies are small files stored on your device that help websites function.
Cookies We Use
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
| session | Essential | Keep you logged in | Session |
| csrf_token | Essential | Security (prevent attacks) | Session |
| cookie_consent | Essential | Remember your cookie choice | 1 year |
Cookies We Do NOT Use
- ❌ Analytics cookies (Google Analytics, etc.)
- ❌ Advertising cookies
- ❌ Third-party tracking cookies
- ❌ Social media cookies
Cookie Banner
Because we only use essential cookies, no consent banner is required. However, we inform you here about our cookie use.
Managing Cookies
You can delete or block cookies in your browser settings. Note that blocking essential cookies may break the service.
14. International Data Transfers
Where Data Is Stored
Our primary servers are located in the European Union (Germany).
Transfers Outside EU
Some processors may transfer data outside the EU:
| Provider | Location | Safeguard |
|---|---|---|
| Stripe | USA | EU-US Data Privacy Framework |
We ensure all transfers have appropriate safeguards under GDPR Chapter V.
15. Children's Privacy
Our service is not intended for children under 16 years of age.
We do not knowingly collect data from children. If you believe a child has provided us data, contact us immediately and we will delete it.
16. Third-Party Links
Our service may contain links to other websites (e.g., scanned websites, documentation).
We are not responsible for the privacy practices of other sites. Please review their privacy policies.
17. Changes to This Policy
We may update this Privacy Policy periodically.
How We Notify You
- Minor changes: Updated on this page
- Major changes: Email notification to registered users
Your Continued Use
Continued use after changes constitutes acceptance. If you disagree with changes, you may delete your account.
Version History
| Version | Date | Changes |
|---|---|---|
| 1.0 | January 21, 2026 | Initial version |
18. Contact Us
General Inquiries
contact@gdprscanner.eu
Privacy Requests
contact@gdprscanner.eu
Mailing Address
GDPR Scanner
Finland
Response Time
We aim to respond within 2 business days, and fulfill data requests within 30 days.
19. Supervisory Authority
If you are unsatisfied with our response, you may complain to:
Finland:
Office of the Data Protection Ombudsman
(Tietosuojavaltuutetun toimisto)
PO Box 800, 00531 Helsinki
tietosuoja.fi
Other EU countries: Contact your local Data Protection Authority.
This Privacy Policy was last updated on January 21, 2026.