Last updated: September 2026
Davies Meyer GmbH Spielbudenplatz 24-25 20359 Hamburg Germany Phone: +49 (0)40 4309 32 30 Email: datenschutz@daviesmeyer.com Managing Director: Nikolaus Meyer
This privacy policy applies to the website and the SaaS platform "SiteGuard". SiteGuard is offered exclusively to businesses (entrepreneurs within the meaning of § 14 German Civil Code, BGB). Where we process personal data on behalf of our customers within the platform (e.g. data found on scanned websites), we do so under the Data Processing Agreement (DPA) pursuant to Art. 28 GDPR; the customer is the controller in that case.
a) Registration and customer account Name, email address, password (stored only as a hash), organisation, team role, selected plan. Purpose: providing the platform and performing the contract. Legal basis: Art. 6(1)(b) GDPR (contract or pre-contractual measures). b) Use of the platform Added websites, scan configurations, scan results, reports, API keys (hashed), settings. Legal basis: Art. 6(1)(b) GDPR. c) Server and security logs IP address, timestamp, requested URL, browser/device information, error messages; to prevent abuse, hashed identifiers for rate limiting. Purpose: operational security, abuse prevention and error analysis. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and stable operation). d) Billing and payment data Billing address, VAT ID, payment information (card data is processed exclusively by Stripe, not by us), invoices. Legal basis: Art. 6(1)(b) GDPR; invoices are retained under Art. 6(1)(c) GDPR in conjunction with § 147 German Fiscal Code (AO) and § 257 German Commercial Code (HGB). e) Contact requests Information from the contact form or by email (name, email address, company, message). Legal basis: Art. 6(1)(b) GDPR (pre-contractual request) or Art. 6(1)(f) GDPR (answering general enquiries).
For sign-up, verification of your email address, sign-in links ("magic link"), password resets and scan/account notifications we send transactional emails via the provider Resend. We process your email address, name and the content of the respective message. Legal basis: Art. 6(1)(b) GDPR. We do not send marketing newsletters.
You can optionally sign in with your Microsoft account (Microsoft Entra ID). You will be redirected to Microsoft; after successful sign-in Microsoft transmits your name, email address and a unique identifier to us. In this case no password is stored with us. Legal basis: Art. 6(1)(b) GDPR. Processing by Microsoft within your own Microsoft account is governed by the privacy terms of Microsoft or your organisation.
Paid plans are billed via Stripe Payments Europe Ltd. (Ireland). You enter payment data (e.g. card or bank details) directly with Stripe; we only receive information about the payment status, the subscription and the details required for invoicing. Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR for statutory retention obligations.
SiteGuard performs automated scans of the websites you add for monitoring. It collects publicly accessible content (HTML, CSS, JavaScript), cookies and trackers set, network requests and third-party connections, as well as performance and accessibility characteristics. The results are used exclusively to create your compliance and performance reports.
For AI reports we use Claude by Anthropic. Only aggregated scan data (scores, issues found, statistics, URL of the checked website) is transmitted — no account data and no personal data of visitors to the scanned websites. Legal basis: Art. 6(1)(b) GDPR.
We use the following service providers as processors. Agreements pursuant to Art. 28 GDPR are or will be concluded with all providers. Where data is transferred to third countries (in particular the USA), this is based on an adequacy decision (EU-US Data Privacy Framework, where the provider is certified) or the EU Standard Contractual Clauses.
| Provider | Purpose | Location | Transfer basis |
|---|---|---|---|
| Vercel Inc. | Hosting of the web application, website delivery, server logs | USA | EU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) |
| Supabase Inc. | Database (account, organisation and scan data) | Database region EU (Frankfurt, aws-eu-central-1) | Stored in the EU; for any access from the USA: EU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) |
| Inngest Inc. | Execution of background jobs (scheduled scans, reports, notifications) | USA | EU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) |
| Anthropic PBC | AI-assisted evaluation of aggregated scan results (AI reports) | USA | EU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) |
| Resend | Sending transactional emails (sign-in links, password reset, scan notifications) | USA | EU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) |
| Stripe Payments Europe Ltd. | Payment processing and subscription management | Ireland (EU); Stripe sub-processors possibly in the USA | Within the EU; for transfers to the USA: EU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) |
| Upstash, Inc. | Rate limiting to prevent abuse (only hashed identifiers are stored) | USA (provider) | EU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) |
| Microsoft (Entra ID) | Sign-in with a Microsoft account (single sign-on) – only if you use this option | EU/USA | EU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) |
• Scan data and reports: up to 12 months after the respective scan, after which they are deleted automatically. • Account and organisation data: for the duration of the contract; after termination or account deletion they are deleted unless statutory retention obligations apply. • Invoices and accounting records: 10 years (§ 147 AO, § 257 HGB). • Server and security logs: only as long as necessary for security and error analysis. • Contact requests: until fully handled, unless a contractual relationship arises.
SiteGuard only uses technically necessary cookies (§ 25(2) no. 2 TDDDG). We do not use tracking cookies, analytics tools or marketing pixels. • Session cookie (for sign-in) • Security token (protection against cross-site request forgery) • Language setting
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6(1)(f) GDPR (Art. 21). To exercise your rights, contact: datenschutz@daviesmeyer.com You also have the right to lodge a complaint with a data protection supervisory authority, e.g. the Hamburg Commissioner for Data Protection and Freedom of Information, which is responsible for us.
We implement appropriate technical and organisational measures, including: • Encrypted transmission (TLS) • Encryption at rest by the database provider (Supabase) • Row Level Security in the database (no access via public database keys) and tenant isolation at application level • Role-based access control and authentication • Restriction of access to authorised personnel
We update this privacy policy when processing activities or the legal situation change. The version published on this page applies.