Privacy Policy
Effective 2026-09-24
This policy explains what personal data SecurityScan collects, why we collect it, how long we keep it, and what rights you have over it under the General Data Protection Regulation (EU) 2016/679 ("GDPR").
We sell a compliance product, so we hold ourselves to the standard we measure others against: we run no advertising trackers, we never load analytics inside your account, and we do not sell or share personal data with advertisers. Our public home page offers optional Google Analytics, which stays switched off until you accept it — see Cookies below.
1.Who is responsible for your data
The data controller is SIA "Villetta JZN", registration No. 40203469914, registered address Kazāru iela 4-34, Saurieši, Stopiņu pag., Ropažu nov., LV-2118, Latvia. VAT No. LV40203469914.
You can reach us about anything in this policy at [email protected].
We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Privacy requests are handled directly by the address above.
2.What we collect, why, and on what legal basis
We collect only what the service needs to function. The table below is the complete list.
| Data | Why we process it | Legal basis |
|---|---|---|
| Account details — your name, email address, and a hashed password. | To create and secure your account, authenticate you, and send service email such as password resets and report notifications. | Performance of a contract — Art. 6(1)(b) |
| Websites you add — the domain names you register for scanning. | To run the scans you asked for, on the schedule your plan provides. | Performance of a contract — Art. 6(1)(b) |
| Scan results — scores, findings, and the generated PDF reports. | To show you your compliance history and let you download reports. | Performance of a contract — Art. 6(1)(b) |
| Billing details — your Stripe customer and subscription identifiers, plan, subscription status, and billing period end. | To take payment, apply your plan limits, and keep accounting records. | Performance of a contract — Art. 6(1)(b); legal obligation for accounting records — Art. 6(1)(c) |
| Free scan requests — the domain and email address you submit, plus a keyed hash of your IP address. | To email you the report you requested and to enforce the abuse limit of three free scans per hour. | Consent — Art. 6(1)(a); legitimate interest in preventing abuse of a free endpoint — Art. 6(1)(f) |
| Follow-up emails after a free scan — only if you tick the box on the scan form: your email address, the scan result, when you consented and to which wording, and when you unsubscribed. | To send up to three short emails explaining the issues found and how to fix them; the last one describes our paid monitoring. | Consent — Art. 6(1)(a) |
| Technical logs — server and error logs, which may briefly contain IP addresses. | To keep the service running, diagnose faults, and detect attacks. | Legitimate interest in the security and availability of our service — Art. 6(1)(f) |
3.Payment card data
We never see or store your card number. Payments are processed by Stripe Payments Europe, Ltd., which collects your card details directly on its own systems. We store only the identifiers Stripe gives us — a customer ID and a subscription ID — plus your plan and subscription status.
4.The free website scan
If you request a free scan from our home page, we ask for a domain and an email address. We use the email address to send you that report. Submitting the form is your consent to that email; nothing else is sent unless you tick the box described below.
We do not return the result in the browser — it is only ever delivered by email — so that the endpoint cannot be used as an anonymous scanning proxy.
We do not store your IP address in readable form. We store a keyed HMAC-SHA-256 hash of it, which lets us count requests per source for the hourly rate limit but cannot be reversed back into an IP address.
Below the form there is an optional checkbox, unticked by default. Only if you tick it do we also send up to three short follow-up emails over the following nine days: what the most important issue means, how to fix it on your platform, and how our paid monitoring works. Every one of them carries a one-click unsubscribe link, and unsubscribing stops them for every scan you requested with that address. They also stop automatically if you create an account.
We keep a record of when you consented and to which wording, because the GDPR requires us to be able to show it (Art. 7(1)).
5.Cookies
We use two strictly necessary cookies and nothing else:
- A session cookie, which keeps you logged in.
- An XSRF-TOKEN cookie, which protects forms against cross-site request forgery.
Both are essential to deliver a service you have asked for, so under Article 5(3) of the ePrivacy Directive they do not require consent.
On our public home page only, we additionally offer Google Analytics, which sets its own cookies (_ga and a per-property _ga_… identifier) to count visits and see which parts of the page are read. This is optional and off by default: the Google tag is not loaded at all, and no analytics cookie exists, unless you press Accept on the banner. Rejecting is one click and carries no consequence — the site behaves identically.
The legal basis is your consent (Article 6(1)(a) GDPR and Article 5(3) ePrivacy). You can withdraw it at any time from the "Cookie settings" link in the footer of the home page, which is as easy as giving it and also deletes the analytics cookies already set. We record your choice in your browser's local storage, not in a cookie, so it never travels to our server.
Google Analytics is provided by Google Ireland Limited and involves a transfer of your IP address to Google, which may process it outside the EEA under the EU–US Data Privacy Framework and standard contractual clauses. We enable IP anonymisation. We set no advertising or profiling cookies, we run no ad-tech, and analytics is never loaded inside your account — only on the public home page.
Our pages load a web font from Bunny Fonts (BunnyWay d.o.o., Slovenia), a font host that sets no cookies and does not log visitor IP addresses.
6.Who we share data with
We do not sell personal data. We share it only with the service providers we need to operate, each of them bound by a data processing agreement under Article 28 GDPR:
- Stripe — payment processing and subscription management.
- Our email delivery provider — sending report notifications, account email, and the follow-up emails you asked for.
- Our hosting and object-storage providers — running the application and storing generated PDF reports.
We may also disclose data where the law requires it, or where it is necessary to establish, exercise, or defend legal claims.
7.Transfers outside the EU/EEA
Our infrastructure is hosted in the European Union. Some of our processors, including Stripe, may transfer data to the United States. Those transfers are covered by the European Commission’s Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework.
8.How long we keep data
- Account data, sites, and scan reports: for as long as your account exists. Delete your account and we erase them, except where accounting law requires us to keep records.
- Free scan records, including any follow-up consent and unsubscribe record: 12 months from the scan, then deleted automatically.
- Invoices and accounting records: 5 years, as required by Latvian accounting law.
- Server logs: up to 90 days.
9.How we protect your data
All traffic is served over TLS. Passwords are stored using a one-way bcrypt hash and are never recoverable. PDF reports live in private object storage and are reachable only through short-lived signed links tied to your account. Access to your sites and reports is enforced per user, so one customer cannot read another’s findings.
10.Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you (Art. 15).
- Have inaccurate data corrected (Art. 16).
- Have your data erased (Art. 17).
- Restrict how we process it (Art. 18).
- Receive your data in a portable, machine-readable format (Art. 20).
- Object to processing based on our legitimate interests (Art. 21).
- Withdraw consent at any time, without affecting processing already carried out (Art. 7(3)).
Write to [email protected] and we will respond within one month. You can also delete your account and all associated data yourself from the profile settings page.
If you believe we have handled your data unlawfully, you may lodge a complaint with the Latvian Data State Inspectorate (Datu valsts inspekcija), Elijas iela 17, Riga, LV-1050, [email protected], www.dvi.gov.lv — or with the supervisory authority in your own country of residence.
11.Data on the websites you scan
When we scan a website we collect technical information about it: cookies set, HTTP response headers, TLS certificate details, JavaScript libraries in use, and whether a consent banner and privacy policy are present. We do not harvest personal data from the pages we visit, and we do not retain page content beyond what the report needs.
You are responsible for ensuring you are entitled to have a site scanned. See the Terms of Service for the details.
12.Changes to this policy
If we make a material change we will email account holders before it takes effect. The effective date at the top of this page always reflects the current version.
13.Contact
Privacy questions and data-subject requests: [email protected]
General enquiries: [email protected]
SIA "Villetta JZN", Kazāru iela 4-34, Saurieši, Stopiņu pag., Ropažu nov., LV-2118, Latvia