Security & Compliance
Your data, our posture
PrivScan processes the inputs you submit for analysis. This page states, plainly, what we handle and what we do not claim.
What we handle
website/app URLs and data-practice descriptions you submit for GDPR gap screening.
Data handling commitments
- Submissions run the product pipeline and are retained only as long as needed for your audit log (paid tiers) or until you delete the run.
- We apply access controls consistent with GDPR Art. 32 (security of processing) where personal data is processed.
- BYOK keys (Enterprise), when offered, are stored server-side only and never exposed to the browser.
Honesty rule: PrivScan is decision-support, not a law firm. We do not guarantee GDPR compliance, 100% coverage of trackers, or that you will never miss a gap. We do not claim guarantee / 100% / never miss.
Our compliance posture
- PrivScan is decision-support, not a law firm, clinic, or certified auditor.
- For binding advice, consult a qualified professional in the relevant domain.
Subprocessors & payments
refs: GDPR Art. 6 (lawfulness) · GDPR Art. 7 (consent) · GDPR Art. 32 (security of processing)