Privacy Policy
Last updated: 22 February 2026
1. Data Controller
We are FixGDPR, the data controller responsible for processing your personal data through the website fixgdpr.com. FixGDPR is operated by FixGDPR Ltd.
2. Contact Information
If you have questions about this privacy policy or wish to contact us about your personal data, you can reach our privacy team at:
Our Data Protection Officer can be reached at the email address above. The privacy team handles all data protection inquiries.
3. What Data We Collect and Purpose of Processing
We collect and use your personal data for the following purposes:
- Account data: When you sign up, we collect your email address, name, and password hash to provide and manage your account.
- Scan data: When you submit a URL for scanning, we collect the URL and your IP address to perform the GDPR compliance audit.
- Payment data: When you subscribe to a paid plan, payment information is collected and processed directly by Stripe (our payment processor). We do not store your card details.
- Email communications: When you subscribe to receive a report, we use your email to send the compliance report via Resend (our email service provider).
- Session cookies: We use a session cookie to keep you logged in. This is an essential cookie required for the service to function.
We use your data to provide the GDPR compliance scanning service, process payments, send transactional emails, and improve our service.
4. Legal Basis for Processing
We process your personal data on the following legal bases under GDPR Article 6:
- Consent: When you voluntarily submit your website URL for a scan or provide your email for a report, you consent to the processing of that data for the stated purpose. You may withdraw consent at any time.
- Contract: Processing is necessary for the performance of the contract when you create an account or subscribe to a paid plan.
- Legitimate interest: We rely on legitimate interest for essential cookies required for website functionality and for basic security measures such as rate limiting.
5. Third-Party Sharing and Service Providers
We do not sell your personal data. We may share your data with third parties only as described below. The following third-party service providers (processors) process data on our behalf:
- Stripe: Payment processing. Stripe acts as a data processor for payment transactions. See Stripe's privacy policy.
- Resend: Transactional email delivery. Resend processes email addresses to deliver account verification, password reset, and report emails.
- Playwright/Headless browser: Used server-side to perform website compliance scans. No personal data is shared; only the submitted URL is accessed.
All processors are bound by data processing agreements and process data only as instructed by us. We do not transfer personal data outside the European Economic Area.
6. Data Retention
We retain your personal data only for as long as necessary for the purposes described above:
- Account data: Retained for as long as your account is active. If you delete your account, we will delete your personal data within 30 days.
- Scan results: Retained for 12 months, then automatically deleted.
- Session data: Session cookies expire after 30 days of inactivity.
- Subscriber emails: Retained until you unsubscribe or request deletion.
You can request that we delete your data at any time by contacting us at [email protected]. We will process deletion requests within 30 days.
7. Your Rights
Under GDPR Articles 15–21, you have the following rights regarding your personal data:
- Right to access: You can request a copy of all personal data we hold about you (Article 15).
- Right to rectification: You can request correction of inaccurate personal data (Article 16).
- Right to erasure: You can request deletion of your personal data when it is no longer necessary for the purposes for which it was collected (Article 17).
- Right to restrict processing: You can request that we limit how we use your data (Article 18).
- Right to data portability: You can request your personal data in a structured, machine-readable format (Article 20).
- Right to object: You can object to processing based on legitimate interest (Article 21).
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.
8. Cookies
We use only essential cookies required for the website to function:
- Session cookie (
connect.sid): An essential cookie used to maintain your login session. This cookie is strictly necessary and does not require consent under GDPR.
We do not use analytics cookies, advertising cookies, or third-party tracking cookies. If this changes in the future, we will update this policy and request your consent before setting any non-essential cookies.
9. Changes to This Policy
We may update this privacy policy from time to time. When we make significant changes, we will notify you by posting a notice on our website. The "Last updated" date at the top of this page indicates when this policy was last revised.