SiteTest.ai

Privacy Policy

Last updated: September 29, 2026

Controller

SiteTest.ai — Individual entrepreneur (FOP) Halyna Samoilenko
E-Mail: info@seoport.com.ua

The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR / DSGVO) is the seller listed above.

What data we collect

When you use SiteTest.ai we process the following data:

  • The URL you submit for analysis (and its publicly accessible content fetched by our crawler).
  • Your IP address (used for rate limiting and abuse prevention; truncated/anonymised after processing).
  • Your e-mail address — required to order a paid audit (to contact you about the order and payment); for a free audit, only if you voluntarily provide it to receive the report.
  • Standard server log data (timestamp, user agent, request path) for security and reliability.
  • Payment data — amount, currency, payment status and date, order number, and the masked card number and card type if the payment service passes them on. We never receive the full card number.

Purpose of processing

We process this data to deliver the audit service you requested (fetching, analysing and reporting on the submitted URL), to send you the report, to prevent abuse and overload of the service, and to operate and secure our infrastructure.

Legal basis

Processing is based on:

  • Art. 6 (1) (b) GDPR — performance of a contract (delivery of the requested audit).
  • Art. 6 (1) (f) GDPR — legitimate interest in operating, securing and improving the service (logs, abuse prevention, anonymous analytics).
  • Art. 11 of the Law of Ukraine “On Personal Data Protection” of 01.06.2010 No. 2297-VI — conclusion and performance of a transaction to which you are a party (item 3 of part 1) and compliance with an obligation imposed by law, in particular accounting for payments (item 5 of part 1).

Retention period

Free audit reports: 90 days after the audit is created we delete the report content and its identifiers — the URL, the domain, the page data, the AI-generated text and the details of every check. The report link stops working. What is left is a record holding only scores and a date; we do not claim it is fully anonymous data. Paid audit reports bought from 1 September 2026: the same clean-up 365 days after the audit is created, and the period is stated before payment. Reports bought earlier are not affected — we will not shorten access to something already sold without contacting the buyer first. The clean-up runs daily and has been in operation since 1 September 2026; it also covers free reports created before that date. E-mail addresses are kept until you unsubscribe or ask for deletion; an e-mail address in a payment record is kept for the period set for payment records (see below) and is not deleted earlier. Server logs are kept up to 30 days for security purposes. Database backups are removed by rotation; if a backup is ever restored, the clean-up is run again over the restored data.

Payment records (amount, currency, payment status and date, order number, the buyer’s e-mail, the masked card number if the payment service passed it on) are kept for the period set by accounting legislation.

Recipients / third-party processors

We use the following processors, each bound by a data processing agreement and serving European users on EU infrastructure where possible:

  • DeepSeek — AI analysis of publicly available page content (no personal data is intentionally sent).
  • Plausible Analytics — privacy-first, cookie-less aggregated analytics (no personal data, EU-hosted).
  • Hetzner Online GmbH (Germany) — hosting and infrastructure.
  • Cloudflare, Inc. (USA, with EU subprocessing) — CDN, DDoS protection, bot management. Cloudflare processes IP addresses and basic request metadata under DPA and SCCs. Cookies: __cf_bm, cf_clearance.

When you pay, your data is received by the payment service you pay through, which processes it under its own rules: WayForPay receives your e-mail address, the amount, the currency, the order number and the name of the service with the address of the audited site; monobank (through the payment gateway mono-pay) receives the amount, the currency and the order number. Card details are entered only on the payment service’s side; we receive from it the payment status and technical payment details (including the masked card number and card type, if the service passes them on).

The payment gateway mono-pay, through which we issue monobank invoices, acts as a processor of personal data on our behalf: it processes the amount, currency, order number and payment status.

We do not sell or share personal data with third parties for marketing.

Cookies and tracking

We do not use tracking or advertising cookies. We use minimal technical/functional storage (e.g. for language preference) and Cloudflare security cookies that are strictly necessary to operate the site. Plausible Analytics is cookie-less.

Your rights

Under the GDPR you have the following rights:

  • Right of access (Art. 15 GDPR) — to know what data we hold about you.
  • Right to rectification (Art. 16 GDPR).
  • Right to erasure / "right to be forgotten" (Art. 17 GDPR).
  • Right to restriction of processing (Art. 18 GDPR).
  • Right to data portability (Art. 20 GDPR).
  • Right to object (Art. 21 GDPR) and right to withdraw consent at any time.

To exercise any of these rights, contact us at info@seoport.com.ua.

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement.

Changes to this policy

We may update this privacy policy from time to time. The current version always applies and is published on this page.