Back to homepage

Privacy Policy

Last updated: March 2026

1. Data Controller

Davies Meyer GmbH Musterstraße 1 20095 Hamburg Germany Email: datenschutz@daviesmeyer.com Managing Director: Nick Meyer

2. Collection and Processing of Personal Data

We process personal data only to the extent necessary to provide our platform and services. Processing is based on Art. 6(1) GDPR. When using SiteGuard, the following data is processed: • Email address (for login and account management) • Name and organization (for multi-tenant management) • IP address and browser information (for security and error analysis) • Usage data (features used, scan results)

3. Website Scans and Data Processing

SiteGuard performs automated scans of websites you add for monitoring. The following data is collected and processed: • Publicly accessible website content (HTML, CSS, JavaScript) • Cookies and trackers on scanned websites • Network requests and third-party connections • Performance metrics and accessibility information This data is used exclusively for generating compliance and performance reports. Scanned website data is stored for a maximum of 12 months.

4. Hosting and Infrastructure

Our platform is hosted with the following service providers: • Vercel Inc. (frontend hosting, USA — with EU Standard Contractual Clauses) • Supabase Inc. (database, region: EU Frankfurt — aws-eu-central-1) • Inngest Inc. (background jobs, USA — with EU Standard Contractual Clauses) All data transfers to third countries comply with GDPR requirements, in particular through EU Standard Contractual Clauses.

5. AI-Powered Analysis

SiteGuard uses artificial intelligence (Anthropic Claude) to analyze scan results and generate reports. Only aggregated scan data (scores, issues found, statistics) is transmitted to the AI service — no personal data from your website visitors. Anthropic processes data according to their privacy policy and does not permanently store transmitted data.

6. Cookies and Tracking

SiteGuard uses only technically necessary cookies for authentication and session management. We do not use tracking cookies, analytics tools, or marketing pixels on our own platform. Technically necessary cookies: • Session cookie (for login) • CSRF token (for security) • Language setting (for internationalization)

7. Your Rights

You have the following rights regarding your personal data: • Right of access (Art. 15 GDPR) • Right to rectification (Art. 16 GDPR) • Right to erasure (Art. 17 GDPR) • Right to restriction of processing (Art. 18 GDPR) • Right to data portability (Art. 20 GDPR) • Right to object (Art. 21 GDPR) To exercise your rights, please contact: datenschutz@daviesmeyer.com You also have the right to lodge a complaint with a data protection supervisory authority.

8. Data Security

We implement appropriate technical and organizational measures to protect your data: • Encrypted data transmission (TLS/SSL) • Access control and authentication • Regular security audits • Encrypted data storage • Restriction of data access to authorized personnel

9. Changes to this Privacy Policy

We reserve the right to update this privacy policy as needed. The current version is always available on this page.