Guides Create account 🇬🇧 🇩🇪
  • Guides
  • Create account
  • Sign in
  • 🇬🇧 🇩🇪
  • Privacy Policy

    Last updated: 1 October 2026

    Privacy at a Glance

    General Notes

    The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally. Detailed information on data protection can be found in our privacy policy listed below.

    Data Collection on This Website

    Who is responsible for data collection on this website?

    Data processing on this website is carried out by the website operator. You can find the operator's contact details in the section "Information on the Data Controller" in this privacy policy.

    How do we collect your data?

    Your data is collected partly because you provide it to us. This may, for example, include data that you enter into a contact form.

    Other data is collected automatically or with your consent when you visit the website by our IT systems. This is mainly technical data (e.g. internet browser, operating system or time of page request). The collection of this data takes place automatically as soon as you enter this website.

    What do we use your data for?

    Some of the data is collected in order to ensure error-free provision of the website and to protect it against abuse.

    What rights do you have regarding your data?

    You have the right to obtain information free of charge at any time about the origin, recipient and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. You also have the right to request the restriction of the processing of your personal data under certain circumstances. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.

    Data Controller

    The data controller responsible for the processing of personal data on this website is:

    Erseni Ltd
    Archiepiskopou Makariou III, 59
    MOUYIAS TOWER, 3rd floor, Flat/Office 301
    6017 Larnaca
    Cyprus
    Phone: +43 664 4367523
    Email: contact@erseni.com

    The data controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.

    Hosting

    We operate our website on our own servers, hosted by the following infrastructure provider:

    Hetzner Online GmbH

    Infrastructure provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen

    We have full control over the servers and the data stored on them. The infrastructure provider only supplies the hardware and the network connection.

    When you visit our website, information is automatically saved on our servers in server log files, which your browser transmits to us.

    Details on the infrastructure provider's privacy policy: https://www.hetzner.com/legal/privacy-policy/

    A data processing agreement pursuant to Art. 28 GDPR exists with the infrastructure provider.

    The use of the server infrastructure is based on Art. 6 (1) (f) GDPR. We have a legitimate interest in a reliable and secure provision of our website.

    Server Log Files

    Our web server automatically saves information in so-called server log files, which your browser automatically transmits to us. These are:

    • Browser type and version
    • Operating system used
    • Referrer URL
    • address requested, status code and volume of data transferred; access tokens and email addresses in the address are replaced by a placeholder before storage
    • Time of the server request
    • IP address, truncated before storage (without the last octet for IPv4, without the trailing part for IPv6); stored for a maximum of 90 days for abuse prevention on the basis of Art. 6 (1) (f) GDPR

    This data is not merged with other data sources.

    Server log files are stored for a maximum of 90 days and then automatically deleted, unless a specific security incident requires longer retention. This period serves security, abuse prevention and error analysis: attack patterns, cases of abuse and errors are often only noticed weeks after the request in question.

    The collection of this data is based on Art. 6 (1) (f) GDPR. We have a legitimate interest in the technically error-free presentation and optimisation of our website – for this purpose, the server log files must be collected.

    SSL/TLS Encryption

    This website uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or enquiries you send to us as the site operator. You can recognise an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.

    If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

    Cookies

    Our website exclusively uses technically necessary cookies. These cookies are required for the operation of the website and enable basic functions.

    Session Cookie

    The session cookie is used exclusively to maintain your session and does not contain any personal data. It is valid for a maximum of 9 hours and becomes invalid afterwards.

    The storage of this cookie is based on Art. 6 (1) (f) GDPR and Article 99 (5) of the Cypriot Regulation of Electronic Communications and Postal Services Law (Law 112(I)/2004), because the cookie is strictly necessary for the service you requested. We have a legitimate interest in the technically error-free provision of our website.

    You can set your browser to inform you about the setting of cookies or to generally reject cookies. If cookies are disabled, the functionality of this website may be limited.

    Processing by the Browser Extension

    Our scanner has an optional browser extension that you install yourself and can remove at any time. Without that installation, none of the processing described here takes place.

    Categories of Data Processed

    Once the extension is installed and set up, we process the following data:

    • The origin of the page you are visiting, meaning the scheme and host name, for example https://example.com. It is sent to our service to start a scan of that host or to fetch an existing result.
    • The API token of your account, which the extension uses to identify itself. It is held locally in your browser only and is never synchronised between your devices.
    • The scan result for that host, which the extension caches locally in your browser so that further pages of the same host do not trigger another scan.

    What is Never Transmitted

    The extension deliberately transmits less than it technically could:

    • Neither the path nor the query string nor the fragment of the page you are reading. https://example.com/account/invoice?id=4711 is reduced to https://example.com and nothing else.
    • No page content, no form input, no cookies and no credentials from the pages you visit.
    • Nothing from local or private addresses. Hosts such as localhost, addresses under .local or .internal, IP addresses and single-label host names never leave the browser. You can also block hosts of your own in the extension settings.

    Retention Period

    A scan triggered through the extension is stored with us like a scan started by hand and can be viewed and deleted through your account. The cache in your browser sits on your device alone; you can clear it in the extension settings at any time, and uninstalling the extension removes it entirely.

    Legal Basis

    The legal basis is Art. 6 (1) (b) GDPR, as the processing serves to deliver the scanning service you have commissioned. Where the extension additionally contributes to improving the service, we rely on Art. 6 (1) (f) GDPR.

    Your Control

    Every stage is yours to decide. Without a token the extension does nothing. Automatic scanning can be switched off, leaving it to scan only when you click. Individual hosts can be blocked permanently. And uninstalling it in the browser ends all processing immediately.

    Customer and Invoicing Data

    In order to initiate, perform and invoice contracts, we process the master data of our customers and of the contact persons named by them.

    Categories of Data Processed

    • company name as well as first and last name of the contact persons
    • address and billing address
    • email address and telephone number
    • VAT identification number and tax number
    • quotation, contract and service data
    • invoicing, payment and bank data

    Purposes of Processing

    We process this data in order to prepare quotations, to conclude and perform contracts, to invoice services and to handle payments. It also serves to fulfil our obligations under commercial and tax law, in particular proper bookkeeping and accounting.

    Legal Bases

    Processing for the initiation and performance of a contract takes place on the basis of Art. 6 (1) (b) GDPR.

    Invoices and accounting records are retained on the basis of Art. 6 (1) (c) GDPR in conjunction with the retention obligations under commercial and tax law to which we are subject.

    Retention Period

    We retain invoices, accounting records and the associated master data for the duration of the statutory retention periods under commercial and tax law. We cannot delete them before those periods expire.

    Data not subject to a retention obligation is deleted as soon as the purpose of its processing no longer applies and no outstanding claims remain.

    Recipients

    Data is only passed on to third parties where this is necessary for the performance of the contract or where we are legally obliged to do so.

    Payment processing

    We bill paid plans through the payment service provider Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.

    In this context, your name, email address, billing address, VAT identification number where applicable, payment data such as card details or bank details, and information on plan, term and payment status are processed. You enter card and bank details on the payment page of the payment service provider; they do not reach our servers.

    Stripe Payments Europe, Ltd. processes this data for payment processing, fraud prevention and the fulfilment of its own legal obligations as a controller in its own right. We receive the information required to perform the contract, such as the payment status and the invoices.

    The legal basis is Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (c) GDPR for the statutory retention obligations.

    The payment service provider may also process data in the USA. The transfer is based on the European Commission's adequacy decision on the EU-US Data Privacy Framework, under which its US parent company is certified, and in the alternative on the standard contractual clauses of the European Commission.

    Privacy information of the payment service provider: https://stripe.com/privacy

    Your Rights

    Right of Access

    You have the right to obtain information free of charge at any time about the personal data stored about you, its origin and recipients, and the purpose of the data processing (Art. 15 GDPR).

    Right to Rectification

    You have the right to request the correction of inaccurate personal data (Art. 16 GDPR).

    Right to Restriction of Processing

    You have the right under certain circumstances to request the restriction of the processing of your personal data (Art. 18 GDPR).

    Right to Erasure

    You have the right to request the deletion of your personal data, unless statutory retention obligations conflict with this (Art. 17 GDPR).

    Right to Data Portability

    You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format (Art. 20 GDPR).

    Right to Object

    You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Art. 6 (1) (e) or (f) GDPR. You may also object at any time, without giving reasons, to the processing of your data for direct marketing purposes (Art. 21 GDPR).

    Right to Lodge a Complaint with the Supervisory Authority

    You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data (Art. 77 GDPR).

    In our case (registered office in the Republic of Cyprus), the competent supervisory authority is:
    Office of the Commissioner for Personal Data Protection
    Iasonos 1, 1082 Nicosia, Cyprus
    www.dataprotection.gov.cy

    Automated Decision-Making

    Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place on this website.

    Recent scans Guides Local leagues Pricing Methodology For hosters API Data protection Imprint Accessibility Terms Cancel contracts here © 2026 Erseni