Last updated: 1 October 2026
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally. Detailed information on data protection can be found in our privacy policy listed below.
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find the operator's contact details in the section "Information on the Data Controller" in this privacy policy.
How do we collect your data?
Your data is collected partly because you provide it to us. This may, for example, include data that you enter into a contact form.
Other data is collected automatically or with your consent when you visit the website by our IT systems. This is mainly technical data (e.g. internet browser, operating system or time of page request). The collection of this data takes place automatically as soon as you enter this website.
What do we use your data for?
Some of the data is collected in order to ensure error-free provision of the website and to protect it against abuse.
What rights do you have regarding your data?
You have the right to obtain information free of charge at any time about the origin, recipient and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. You also have the right to request the restriction of the processing of your personal data under certain circumstances. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
The data controller responsible for the processing of personal data on this website is:
Erseni LtdThe data controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
We operate our website on our own servers, hosted by the following infrastructure provider:
Infrastructure provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen
We have full control over the servers and the data stored on them. The infrastructure provider only supplies the hardware and the network connection.
When you visit our website, information is automatically saved on our servers in server log files, which your browser transmits to us.
Details on the infrastructure provider's privacy policy: https://www.hetzner.com/legal/privacy-policy/
A data processing agreement pursuant to Art. 28 GDPR exists with the infrastructure provider.
The use of the server infrastructure is based on Art. 6 (1) (f) GDPR. We have a legitimate interest in a reliable and secure provision of our website.
Our web server automatically saves information in so-called server log files, which your browser automatically transmits to us. These are:
This data is not merged with other data sources.
Server log files are stored for a maximum of 90 days and then automatically deleted, unless a specific security incident requires longer retention. This period serves security, abuse prevention and error analysis: attack patterns, cases of abuse and errors are often only noticed weeks after the request in question.
The collection of this data is based on Art. 6 (1) (f) GDPR. We have a legitimate interest in the technically error-free presentation and optimisation of our website – for this purpose, the server log files must be collected.
This website uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or enquiries you send to us as the site operator. You can recognise an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.
If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Our website exclusively uses technically necessary cookies. These cookies are required for the operation of the website and enable basic functions.
The session cookie is used exclusively to maintain your session and does not contain any personal data. It is valid for a maximum of 9 hours and becomes invalid afterwards.
The storage of this cookie is based on Art. 6 (1) (f) GDPR and Article 99 (5) of the Cypriot Regulation of Electronic Communications and Postal Services Law (Law 112(I)/2004), because the cookie is strictly necessary for the service you requested. We have a legitimate interest in the technically error-free provision of our website.
You can set your browser to inform you about the setting of cookies or to generally reject cookies. If cookies are disabled, the functionality of this website may be limited.
Our scanner has an optional browser extension that you install yourself and can remove at any time. Without that installation, none of the processing described here takes place.
Once the extension is installed and set up, we process the following data:
The extension deliberately transmits less than it technically could:
A scan triggered through the extension is stored with us like a scan started by hand and can be viewed and deleted through your account. The cache in your browser sits on your device alone; you can clear it in the extension settings at any time, and uninstalling the extension removes it entirely.
The legal basis is Art. 6 (1) (b) GDPR, as the processing serves to deliver the scanning service you have commissioned. Where the extension additionally contributes to improving the service, we rely on Art. 6 (1) (f) GDPR.
Every stage is yours to decide. Without a token the extension does nothing. Automatic scanning can be switched off, leaving it to scan only when you click. Individual hosts can be blocked permanently. And uninstalling it in the browser ends all processing immediately.
In order to initiate, perform and invoice contracts, we process the master data of our customers and of the contact persons named by them.
We process this data in order to prepare quotations, to conclude and perform contracts, to invoice services and to handle payments. It also serves to fulfil our obligations under commercial and tax law, in particular proper bookkeeping and accounting.
Processing for the initiation and performance of a contract takes place on the basis of Art. 6 (1) (b) GDPR.
Invoices and accounting records are retained on the basis of Art. 6 (1) (c) GDPR in conjunction with the retention obligations under commercial and tax law to which we are subject.
We retain invoices, accounting records and the associated master data for the duration of the statutory retention periods under commercial and tax law. We cannot delete them before those periods expire.
Data not subject to a retention obligation is deleted as soon as the purpose of its processing no longer applies and no outstanding claims remain.
Data is only passed on to third parties where this is necessary for the performance of the contract or where we are legally obliged to do so.
We bill paid plans through the payment service provider Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
In this context, your name, email address, billing address, VAT identification number where applicable, payment data such as card details or bank details, and information on plan, term and payment status are processed. You enter card and bank details on the payment page of the payment service provider; they do not reach our servers.
Stripe Payments Europe, Ltd. processes this data for payment processing, fraud prevention and the fulfilment of its own legal obligations as a controller in its own right. We receive the information required to perform the contract, such as the payment status and the invoices.
The legal basis is Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (c) GDPR for the statutory retention obligations.
The payment service provider may also process data in the USA. The transfer is based on the European Commission's adequacy decision on the EU-US Data Privacy Framework, under which its US parent company is certified, and in the alternative on the standard contractual clauses of the European Commission.
Privacy information of the payment service provider: https://stripe.com/privacy
You have the right to obtain information free of charge at any time about the personal data stored about you, its origin and recipients, and the purpose of the data processing (Art. 15 GDPR).
You have the right to request the correction of inaccurate personal data (Art. 16 GDPR).
You have the right under certain circumstances to request the restriction of the processing of your personal data (Art. 18 GDPR).
You have the right to request the deletion of your personal data, unless statutory retention obligations conflict with this (Art. 17 GDPR).
You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format (Art. 20 GDPR).
You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Art. 6 (1) (e) or (f) GDPR. You may also object at any time, without giving reasons, to the processing of your data for direct marketing purposes (Art. 21 GDPR).
You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data (Art. 77 GDPR).
In our case (registered office in the Republic of Cyprus), the competent supervisory authority is:
Office of the Commissioner for Personal Data Protection
Iasonos 1, 1082 Nicosia, Cyprus
www.dataprotection.gov.cy
Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place on this website.