Skip to content
CheckMySites

Data processing

Effective 6 August 2026

Who is what

Under UK and EU data protection law, the roles depend on which data you mean:

  • Your account data — we are the controller. We decide what to collect to run the service, and the privacy policy governs it.
  • Data inside the sites you audit — you are the controller and we are the processor. If a page you audit contains personal data, we process it only to produce your report and only on your instruction.

In practice the second category is small. We analyse a page and retain findings and extracted metadata, not the page itself.

What we process on your behalf

ItemDetail
Subject matterAutomated analysis of web pages you nominate
DurationFor as long as your account is active, plus your plan's retention window
Nature and purposeFetching, analysing and scoring a page; generating a report
Categories of dataWhatever appears in the public page you audit. Typically none; possibly names, emails or images if published on that page.
Data subjectsAny individual whose information appears on an audited page

Our commitments

  • Process personal data only on your documented instructions.
  • Ensure anyone with access is bound by an appropriate duty of confidentiality.
  • Implement the technical and organisational measures described below.
  • Not engage a new subprocessor without updating this page, giving you a reasonable opportunity to object.
  • Assist you with data subject requests, impact assessments and regulator enquiries, so far as is reasonable.
  • Delete or return the data at the end of the service, unless we are legally required to keep it.
  • Notify you without undue delay on becoming aware of a personal data breach affecting your data.

Subprocessors

SubprocessorPurposeLocation
Vercel Inc.Application hostingUnited States / EU
Neon Inc.Database hostingRegion you select
Clerk Inc.AuthenticationUnited States
Google LLCPageSpeed Insights; optional AI summariesUnited States
Anthropic PBCOptional AI summariesUnited States
Zoho CorporationTransactional emailUnited States / EU

The AI subprocessors are engaged only when an AI provider is configured. With none configured, report summaries are produced by our own rules engine and no audit content leaves our infrastructure.

International transfers

Where data is transferred outside the UK or EEA, we rely on the transfer mechanisms our subprocessors maintain — Standard Contractual Clauses, the UK Addendum, and the EU–US Data Privacy Framework where the recipient is certified.

Security measures

  • All traffic encrypted in transit; data encrypted at rest by our hosting providers.
  • Authentication delegated to a specialist provider; we never handle passwords.
  • API keys stored as hashes; plaintext shown once at creation.
  • IP addresses stored only as salted hashes.
  • Strings resembling private credentials redacted before entering a report.
  • Access to production data limited to the operator.
  • Ownership enforced at the database layer, not only in the interface.
  • Rate limiting and input validation on every endpoint.

Requesting a signed DPA

If your procurement process needs a countersigned agreement, email privacy@checkmysites.com with your entity name and the standard form you use. We can usually turn one around within five working days.