BFSG Check / Privacy
Privacy notice
For an automated scan, we store the submitted public URL, tested pages, technical findings and minimal evidence snippets. To prevent abuse, the submitter IP address is stored only as a salted hash. We do not visit private pages, sign in or submit forms.
Technical findings are prioritized on our infrastructure. Scan data is not sent to external AI models for this purpose. Stripe and Brevo process payments and report delivery as described below.
A technically necessary session protects forms against misuse. A cookie stores the selected language for one year. For scan limits we store an HMAC hash of the IP address, rather than the address in the scan record. Server logs may briefly contain the IP address for operations and security diagnostics.
After a purchase, Stripe processes payment data and sends us payment status and email address. Brevo sends the PDF report as a transactional email. We do not store card data. The report is available through a random, hard-to-guess link. Share this link only with authorized people.
Scan data and PDFs are deleted after 180 days by default; the period can be configured. Payment records may be kept for applicable legal retention periods. For controller details, data subject rights and contact information, also read the Egidijus Girčys privacy policy. BFSG Check specific processing is described here.