Back to homepage

Privacy Policy

Last updated: September 2026

1. Data Controller

Davies Meyer GmbH Spielbudenplatz 24-25 20359 Hamburg Germany Phone: +49 (0)40 4309 32 30 Email: datenschutz@daviesmeyer.com Managing Director: Nikolaus Meyer

2. Scope

This privacy policy applies to the website and the SaaS platform "SiteGuard". SiteGuard is offered exclusively to businesses (entrepreneurs within the meaning of § 14 German Civil Code, BGB). Where we process personal data on behalf of our customers within the platform (e.g. data found on scanned websites), we do so under the Data Processing Agreement (DPA) pursuant to Art. 28 GDPR; the customer is the controller in that case.

3. Data we process and legal bases

a) Registration and customer account Name, email address, password (stored only as a hash), organisation, team role, selected plan. Purpose: providing the platform and performing the contract. Legal basis: Art. 6(1)(b) GDPR (contract or pre-contractual measures). b) Use of the platform Added websites, scan configurations, scan results, reports, API keys (hashed), settings. Legal basis: Art. 6(1)(b) GDPR. c) Server and security logs IP address, timestamp, requested URL, browser/device information, error messages; to prevent abuse, hashed identifiers for rate limiting. Purpose: operational security, abuse prevention and error analysis. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and stable operation). d) Billing and payment data Billing address, VAT ID, payment information (card data is processed exclusively by Stripe, not by us), invoices. Legal basis: Art. 6(1)(b) GDPR; invoices are retained under Art. 6(1)(c) GDPR in conjunction with § 147 German Fiscal Code (AO) and § 257 German Commercial Code (HGB). e) Contact requests Information from the contact form or by email (name, email address, company, message). Legal basis: Art. 6(1)(b) GDPR (pre-contractual request) or Art. 6(1)(f) GDPR (answering general enquiries).

4. Email verification and transactional emails

For sign-up, verification of your email address, sign-in links ("magic link"), password resets and scan/account notifications we send transactional emails via the provider Resend. We process your email address, name and the content of the respective message. Legal basis: Art. 6(1)(b) GDPR. We do not send marketing newsletters.

5. Sign-in with Microsoft (single sign-on)

You can optionally sign in with your Microsoft account (Microsoft Entra ID). You will be redirected to Microsoft; after successful sign-in Microsoft transmits your name, email address and a unique identifier to us. In this case no password is stored with us. Legal basis: Art. 6(1)(b) GDPR. Processing by Microsoft within your own Microsoft account is governed by the privacy terms of Microsoft or your organisation.

6. Payment processing via Stripe

Paid plans are billed via Stripe Payments Europe Ltd. (Ireland). You enter payment data (e.g. card or bank details) directly with Stripe; we only receive information about the payment status, the subscription and the details required for invoicing. Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR for statutory retention obligations.

7. Website scans

SiteGuard performs automated scans of the websites you add for monitoring. It collects publicly accessible content (HTML, CSS, JavaScript), cookies and trackers set, network requests and third-party connections, as well as performance and accessibility characteristics. The results are used exclusively to create your compliance and performance reports.

8. AI-assisted analysis

For AI reports we use Claude by Anthropic. Only aggregated scan data (scores, issues found, statistics, URL of the checked website) is transmitted — no account data and no personal data of visitors to the scanned websites. Legal basis: Art. 6(1)(b) GDPR.

9. Recipients and processors

We use the following service providers as processors. Agreements pursuant to Art. 28 GDPR are or will be concluded with all providers. Where data is transferred to third countries (in particular the USA), this is based on an adequacy decision (EU-US Data Privacy Framework, where the provider is certified) or the EU Standard Contractual Clauses.

ProviderPurposeLocationTransfer basis
Vercel Inc.Hosting of the web application, website delivery, server logsUSAEU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)
Supabase Inc.Database (account, organisation and scan data)Database region EU (Frankfurt, aws-eu-central-1)Stored in the EU; for any access from the USA: EU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)
Inngest Inc.Execution of background jobs (scheduled scans, reports, notifications)USAEU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)
Anthropic PBCAI-assisted evaluation of aggregated scan results (AI reports)USAEU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)
ResendSending transactional emails (sign-in links, password reset, scan notifications)USAEU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)
Stripe Payments Europe Ltd.Payment processing and subscription managementIreland (EU); Stripe sub-processors possibly in the USAWithin the EU; for transfers to the USA: EU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)
Upstash, Inc.Rate limiting to prevent abuse (only hashed identifiers are stored)USA (provider)EU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)
Microsoft (Entra ID)Sign-in with a Microsoft account (single sign-on) – only if you use this optionEU/USAEU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)

10. Storage periods

• Scan data and reports: up to 12 months after the respective scan, after which they are deleted automatically. • Account and organisation data: for the duration of the contract; after termination or account deletion they are deleted unless statutory retention obligations apply. • Invoices and accounting records: 10 years (§ 147 AO, § 257 HGB). • Server and security logs: only as long as necessary for security and error analysis. • Contact requests: until fully handled, unless a contractual relationship arises.

11. Cookies

SiteGuard only uses technically necessary cookies (§ 25(2) no. 2 TDDDG). We do not use tracking cookies, analytics tools or marketing pixels. • Session cookie (for sign-in) • Security token (protection against cross-site request forgery) • Language setting

12. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6(1)(f) GDPR (Art. 21). To exercise your rights, contact: datenschutz@daviesmeyer.com You also have the right to lodge a complaint with a data protection supervisory authority, e.g. the Hamburg Commissioner for Data Protection and Freedom of Information, which is responsible for us.

13. Data security

We implement appropriate technical and organisational measures, including: • Encrypted transmission (TLS) • Encryption at rest by the database provider (Supabase) • Row Level Security in the database (no access via public database keys) and tenant isolation at application level • Role-based access control and authentication • Restriction of access to authorised personnel

14. Changes

We update this privacy policy when processing activities or the legal situation change. The version published on this page applies.