Legal

Privacy notice

What RegInspector does with personal data, in plain language.

Version 1.0 In force from 2 August 2026
PrivacyCookiesTermsSecurity
One block to complete before you charge: replace the [bracketed] identity details below with your registered entity. Everything else on this page already describes exactly what the service does, and was written against the code.

This notice explains what RegInspector does with personal data. It is written to be read, not to be survived.

1. Who is responsible

The controller is [Legal entity name], [registered address], company number [number], VAT [VAT number]. For anything in this notice, or to exercise a right, write to privacy@reginspector.com.

2. What we process

The URL you submit and the resulting scan. We fetch the address you give us and store the technical evidence gathered — response headers, cookies set on first load, third-party scripts, published policy text, form structure and accessibility markup — together with the findings and score derived from it. Legal basis: performance of a contract (Art. 6(1)(b) GDPR) for paid reports, and our legitimate interest in providing a free tier (Art. 6(1)(f)).

Your IP address. Used only to apply the hourly scan limit and to prevent abuse. It is held in memory by the running server and is not written to the scan record. Legal basis: legitimate interest (Art. 6(1)(f)).

Billing details, if you buy a report. Name, email address, billing country and payment metadata. Card details never reach our servers — payment happens entirely on Stripe's own checkout page. Legal basis: contract (Art. 6(1)(b)) and our legal obligation to keep tax records (Art. 6(1)(c)).

Correspondence, if you email us. Legal basis: legitimate interest in replying (Art. 6(1)(f)).

We do not ask for an account, a name or an email address to run a scan.

3. When you scan a third party

A scan requests publicly available pages exactly as any visitor or search engine would, identifying itself as RegInspectorBot. It does not attempt to authenticate, does not submit forms, does not test for vulnerabilities and does not place unusual load on the target. Requests that resolve to private or internal addresses are refused outright.

The material retained is technical. If a scanned page happens to contain personal data in its public content, that may be captured as evidence — you can have any report deleted on request.

4. How long we keep it

5. Who else is involved

We do not sell personal data. We do not share scan results with anyone. We do not use your data, or the results of your scans, to train machine-learning models.

6. International transfers

Where a processor above operates outside the European Economic Area, the transfer relies on the European Commission's Standard Contractual Clauses with supplementary measures. Ask us at privacy@reginspector.com and we will send you a copy of the safeguards.

7. Your rights

You may request access to your personal data, its rectification or erasure, restriction of or objection to processing, and portability. Where we rely on consent you may withdraw it at any time, without affecting processing already carried out. Write to privacy@reginspector.com; we answer within one month.

You may also complain to your supervisory authority. In Spain that is the Agencia Española de Protección de Datos (aepd.es).

8. Cookies

RegInspector sets no cookies at all — none for analytics, advertising or profiling. See the cookie policy, and feel free to verify it by scanning us with our own tool.

9. Automated decision-making

The Compliance Score is produced automatically by a deterministic rule engine. It is an analytical indicator about a digital asset, not a decision producing legal effects concerning a person under Art. 22 GDPR. Every score traces back to the individual rules and evidence that produced it, and the report shows both.

10. Changes

Material changes update the version and date at the top of this page. Where we hold your email because you bought a report, we will also tell you directly.