DSGVO Konform
Back to home

Privacy Policy

Last updated: 16 August 2026

1. Who we are

DSGVO Konform is a GDPR compliance audit tool for SMEs. This policy explains how we process your personal data when you use our website and services.

2. Data we collect

We only collect what is necessary for the service: (a) audit quiz answers (data you provide about your company); (b) your email when you request the PDF report or create an account; (c) technical browsing data (cookies, IP address) for security and improvements.

3. Legal basis (GDPR Art. 6)

We process your data based on: consent (Art. 6.1.a) — when you opt in to receive the report; contract performance (Art. 6.1.b) — when you subscribe to a paid plan; legal obligation (Art. 6.1.c) — when required by law; and legitimate interests (Art. 6.1.f) — for security and fraud prevention.

4. How we use your data

We use your data exclusively to: generate your compliance score and diagnosis, send the requested report, process payments, manage your account and subscription, and improve the product in aggregate, anonymous form. We never sell your data.

5. Cookies

We use strictly necessary cookies (session, language preference) and, only with your consent, aggregate analytics cookies. You can manage or block cookies in your browser settings.

6. Sharing

We share data only with processors essential to the service (hosting, Stripe payments, Resend email), all bound by data processing agreements (DPA) and subject to the GDPR. We do not share data with third parties for marketing.

7. Retention

We keep your data only as long as needed: audit answers and reports while your account exists; billing data for the legally required period (usually 5 years). You can request deletion at any time.

8. Your rights (GDPR Arts. 15–22)

You have the right to: access your data, correct it, request deletion ('right to be forgotten'), portability, restriction of processing, objection and withdrawal of consent. To exercise any right, contact us — we respond within 30 days.

9. Security

We apply appropriate technical and organisational measures: encryption in transit (TLS) and at rest, restricted access control, and periodic reviews. Your payment data is processed directly by Stripe, which is PCI DSS certified.

10. Contact and Data Protection Officer (DPO)

For any question about this policy or your data, contact us via the Contact page or at [email protected]. As a company based in the EU, we are the controller of your data.