Data processing
Effective 6 August 2026
Who is what
Under UK and EU data protection law, the roles depend on which data you mean:
- Your account data — we are the controller. We decide what to collect to run the service, and the privacy policy governs it.
- Data inside the sites you audit — you are the controller and we are the processor. If a page you audit contains personal data, we process it only to produce your report and only on your instruction.
In practice the second category is small. We analyse a page and retain findings and extracted metadata, not the page itself.
What we process on your behalf
| Item | Detail |
|---|---|
| Subject matter | Automated analysis of web pages you nominate |
| Duration | For as long as your account is active, plus your plan's retention window |
| Nature and purpose | Fetching, analysing and scoring a page; generating a report |
| Categories of data | Whatever appears in the public page you audit. Typically none; possibly names, emails or images if published on that page. |
| Data subjects | Any individual whose information appears on an audited page |
Our commitments
- Process personal data only on your documented instructions.
- Ensure anyone with access is bound by an appropriate duty of confidentiality.
- Implement the technical and organisational measures described below.
- Not engage a new subprocessor without updating this page, giving you a reasonable opportunity to object.
- Assist you with data subject requests, impact assessments and regulator enquiries, so far as is reasonable.
- Delete or return the data at the end of the service, unless we are legally required to keep it.
- Notify you without undue delay on becoming aware of a personal data breach affecting your data.
Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Application hosting | United States / EU |
| Neon Inc. | Database hosting | Region you select |
| Clerk Inc. | Authentication | United States |
| Google LLC | PageSpeed Insights; optional AI summaries | United States |
| Anthropic PBC | Optional AI summaries | United States |
| Zoho Corporation | Transactional email | United States / EU |
The AI subprocessors are engaged only when an AI provider is configured. With none configured, report summaries are produced by our own rules engine and no audit content leaves our infrastructure.
International transfers
Where data is transferred outside the UK or EEA, we rely on the transfer mechanisms our subprocessors maintain — Standard Contractual Clauses, the UK Addendum, and the EU–US Data Privacy Framework where the recipient is certified.
Security measures
- All traffic encrypted in transit; data encrypted at rest by our hosting providers.
- Authentication delegated to a specialist provider; we never handle passwords.
- API keys stored as hashes; plaintext shown once at creation.
- IP addresses stored only as salted hashes.
- Strings resembling private credentials redacted before entering a report.
- Access to production data limited to the operator.
- Ownership enforced at the database layer, not only in the interface.
- Rate limiting and input validation on every endpoint.
Requesting a signed DPA
If your procurement process needs a countersigned agreement, email privacy@checkmysites.com with your entity name and the standard form you use. We can usually turn one around within five working days.