Privacy Policy
Last updated: 2026-06-14
Data Controller
GDPRChecker is operated by QIN ZHANYA, the data controller for personal data processed in connection with your account, billing, support, and use of our marketing website.
Controller identity: QIN ZHANYA, 51, Mais 1, Triq il-Molletta, Is-Swieqi, Malta.
Privacy contact: legal@gdprchecker.online.
For privacy, data protection, or legal requests, please contact us at legal@gdprchecker.online.
Legal name: QIN ZHANYA
Title: Founder & Product Builder
Postal address: 51, Mais 1, Triq il-Molletta, Is-Swieqi, Malta
Country: Malta
Email: legal@gdprchecker.online
Contact page: https://www.gdprchecker.online/contact
Data Protection Officer
We have not appointed a Data Protection Officer. Privacy requests can be sent to the contact above.
When We Act as Processor
When you use GDPRChecker to manage consent, block trackers, log consent events, or otherwise process data relating to visitors to your websites, we process that end-user data on your instructions and you remain the data controller.
Our Data Processing Agreement (https://www.gdprchecker.online/dpa) applies to that processing and is incorporated into your use of the Service by reference. The current Sub-processor list is published at https://www.gdprchecker.online/dpa/subprocessors.
Processing Overview (Article 13)
The table below summarizes how we process personal data when you use GDPRChecker as a controller for account and service data. Retention periods are indicative and may vary based on legal obligations, security needs, plan settings, and backup cycles.
| Processing purpose | Data categories | Legal basis | Retention |
|---|---|---|---|
| Account creation and authentication | Account identifiers, name, email, authentication metadata, session tokens | Contract; legitimate interests (security, fraud prevention) | While your account is active, plus a reasonable period after closure for security, disputes, and legal obligations |
| Billing and subscription management | Billing identifiers, subscription status, invoice metadata, payment status (not full card numbers) | Contract; legal obligation (tax and accounting where applicable) | For the subscription term and periods required by tax, accounting, and dispute rules |
| Compliance scans | Submitted URL or domain, scan results, detected signals, timestamps, diagnostic metadata | Contract; legitimate interests (service delivery and abuse prevention) | According to plan limits, product settings, and operational needs |
| Managed site configuration | Domain names, site IDs, ownership verification records, setup progress, CMP and runtime settings | Contract | While your account and managed sites remain active, then per the DPA and backup schedules |
| Consent logs / runtime telemetry | Consent choices, timestamps, browser or runtime telemetry, IP-derived technical data if collected | Contract (when processing end-user data on your behalf); legitimate interests (service operation and troubleshooting) | According to your configuration, plan limits, and the DPA |
| Support communications | Name, email, message content, attachments, and related ticket metadata | Contract; legitimate interests (support and quality improvement) | As needed to resolve inquiries and maintain reasonable support records |
| Security and fraud prevention | IP addresses, device or browser signals, access logs, abuse indicators | Legitimate interests; legal obligation where applicable | For operational security periods consistent with risk and legal requirements |
| Marketing communications (if applicable) | Email address, communication preferences, campaign interaction data | Consent where required; legitimate interests for permitted B2B outreach where applicable | Until you opt out, withdraw consent, or we no longer need the data for the stated purpose |
| Product analytics (if applicable) | Usage events, page views, and similar telemetry on our properties when enabled | Consent where required; legitimate interests where permitted | According to analytics configuration and provider retention settings |
Data Retention
We retain personal data only as long as necessary for the purposes described above, to provide the Service, resolve disputes, meet legal obligations, and maintain security logs.
Scan records, consent logs, and backups may persist for limited periods after deletion requests because of backup cycles or legal retention requirements.
The typical retention ranges below are indicative — not fixed guarantees. We may retain data longer where required by law, security needs, or backup schedules.
| Data type | Typical retention |
|---|---|
| Account data | For your account lifetime, plus a reasonable period after closure (typically up to 24 months) for security, disputes, and legal obligations unless a longer period is required by law |
| Billing metadata | For the subscription term and statutory accounting or tax periods required under applicable law (often several years where tax records apply) |
| Scan reports | According to plan limits and product settings until deleted by you or upon account closure, subject to backup cycles |
| Consent logs (when we act as processor) | According to your configuration, plan limits, and the DPA |
| Support communications | As needed to resolve the request, then typically up to 24 months unless a longer period is required by law |
| Security and fraud-prevention logs | Typically up to 12 months unless investigation or legal obligations require longer retention |
Service Providers
We use infrastructure and service providers to operate the Service. We do not sell personal information.
The table below describes the main providers and typical purposes. Actual processing depends on the features you use (for example, Google sign-in, checkout, or AI-assisted review if enabled).
| Provider | Purpose |
|---|---|
| Vercel | Application hosting and deployment |
| Supabase | Account authentication, database, and storage |
| Stripe | Payment processing and subscription management |
| Google OAuth | Optional login and authentication when you choose Google sign-in |
| Resend | Transactional email delivery |
| Cloudflare | DNS, security, caching, and network services where configured |
| AI model providers (e.g. OpenAI) | AI-assisted document or risk review features if you use them when available |
Sub-processors
We use infrastructure and service providers such as hosting (Vercel), database and authentication (Supabase), payments (Stripe), email delivery (Resend), and security or DNS providers where configured.
When we process end-user data on your behalf, Sub-processors are listed at https://www.gdprchecker.online/dpa/subprocessors and in our DPA (https://www.gdprchecker.online/dpa).
International Transfers
Some providers may process or store data outside the European Economic Area or United Kingdom.
Where required, we use Standard Contractual Clauses or equivalent safeguards.
Where UK GDPR applies, we use the UK International Data Transfer Addendum or another lawful UK transfer mechanism where required.
Your Rights
Depending on your location, you may have the right to request access, rectification, erasure, restriction of processing, objection, data portability, and withdrawal of consent where processing is based on consent.
To exercise these rights, contact us at legal@gdprchecker.online. We normally respond within the time required by applicable law. We may need to verify your identity before fulfilling a request.
You may lodge a complaint with a supervisory authority. As we are established in Malta, the Malta Information and Data Protection Commissioner (IDPC) is our lead supervisory authority. You may also contact your local supervisory authority if you are in another country.
Security
We apply administrative, technical, and organizational measures appropriate to the risk, including access controls, encryption in transit, and monitoring. No method of transmission or storage is completely secure.
Children
The Service is not directed to children under 16 and we do not knowingly collect their personal data.
Changes
We may update this Privacy Policy. The latest version is posted here with date 2026-06-14.
Contact
For privacy, data protection, or legal requests, please contact us at legal@gdprchecker.online.
Legal name: QIN ZHANYA
Title: Founder & Product Builder
Postal address: 51, Mais 1, Triq il-Molletta, Is-Swieqi, Malta
Country: Malta
Email: legal@gdprchecker.online
Contact page: https://www.gdprchecker.online/contact