Your data, explained.

This notice covers ReiterWeb enquiries and the Tracking Scout browser audit. Updated 12 September 2026.

Who is responsible

ReiterWeb and Tracking Scout are operated by Artem Reiter, a sole trader registered in Poland. Registered business address: ul. Gdańska 141A lok. 186, 90-536 Łódź, Poland. NIP: 7272866266. REGON: 524361703.

For questions about your information or to exercise your rights, email artem@reiterweb.com or write to the registered business address.

When you make an enquiry

You can contact me directly by email. Include your website and what you need help with; your name and other context are optional. A contact link opened from Scout can prepare an email draft with the website and report link. You can review, edit or remove these details in your email app before sending. Please do not include passwords, access tokens, health information or other sensitive information.

I use this information to respond, understand your requirements and prepare a scope or quotation. The legal basis is taking steps at your request before a contract, Article 6(1)(b) GDPR. Where you enquire on behalf of an organisation, the basis is the legitimate interest in responding to business enquiries, Article 6(1)(f). Sending an enquiry does not subscribe you to marketing emails.

The current website does not submit enquiries to a website database. Opening an email draft does not send a message. Your email provider and the ReiterWeb business mailbox handle the message when you choose to send it.

When you run a browser audit

A public website address and a valid email address are required to request a Scout audit. Scout saves the request before confirming that it has started, continues after you close the page, and sends a report-ready or scan failure email. Your recipient address is stored in the private job queue and is excluded from public reports and JSON exports. Requesting an audit does not subscribe you to newsletters or marketing.

Tracking Scout records the public website address, scan time and observations used in the report: recognised tracking requests and tool identifiers, cookie names and attributes, storage keys, consent observations, browser failures and page screenshots. Raw cookie values and request payloads are not published. Detected sensitive values are redacted, but screenshots may contain visible content from the scanned page.

A separate automated browser visits the website and may use recognised cookie controls. It does not use your browser session. The target website and its providers may record that visit. Do not submit private pages or addresses with credentials, query strings or fragments.

Reports are accessible to anyone with their unlisted link. There is no public report directory. Reports and screenshots expire 24 hours after the scan finishes. Download the evidence if you need to keep it. The legal basis for providing the requested audit and its delivery email is taking steps at your request to provide the service, Article 6(1)(b) GDPR. Protecting the public audit against abuse is based on legitimate interest, Article 6(1)(f).

Cookies and measurement

The current website does not load third-party analytics or advertising tags and does not store advertising click identifiers or campaign attribution with enquiries. Essential server processing delivers pages, runs requested scans and limits abuse. Starting a scan or sending an email is not permission to receive marketing emails.

Hosting providers process technical request information to deliver and secure the service. Scout uses temporary network-based rate limits to protect the scanning service. The legal basis for security processing is legitimate interest, Article 6(1)(f).

How long information is kept

Scout reports, screenshots and private job records, including recipient addresses, are scheduled for automatic removal 24 hours after completion. Unfinished jobs expire 24 hours after submission. Hashed rate-limit records are retained for up to 24 hours. A report link in an email does not preserve an expired report. Download the report if you want to retain its evidence.

Resend retains email and delivery logs for 30 days on its standard plans, with backups persisting for 7 days. This provider retention is separate from Scout’s 24-hour report expiry. Emails already in your inbox and downloaded copies remain subject to your own provider and storage settings.

Correspondence in the business mailbox is kept for as long as it is needed to answer your enquiry, manage an agreed engagement or resolve a dispute. Report expiry does not delete email correspondence or downloaded copies. Applicable accounting and other legal retention duties can require longer storage for clients. You can request deletion of information that is no longer needed.

Providers and access

Vercel hosts the agency website. DigitalOcean hosts the browser scanner in Frankfurt, Germany. Resend sends Scout notifications and processes the recipient address, scanned domain, report score and report link. Google Workspace provides the business mailbox. Your own email provider also processes the notifications you request and messages you choose to send. Providers receive the information necessary for these services under their applicable data processing terms.

Resend stores message content and delivery logs in the United States; its EU sending region controls routing, not storage. Its published data processing terms provide standard contractual clauses for relevant transfers. Other provider support and infrastructure may also involve processing outside the European Economic Area. The Frankfurt scanner location does not mean that every provider processes all information only in the EU. Contact me for information about the safeguards relevant to your request.

Your enquiry is not sold. It is not used to make automated decisions with legal or similarly significant effects. The public scan score is a technical observation, not a legal compliance assessment.

Your choices and rights

Depending on the circumstances, you can request access, correction, erasure, restriction or portability, and object to processing based on legitimate interest. I may need information to verify that a request concerns your data. Rights can be limited where information must be kept to meet a legal obligation or establish, exercise or defend legal claims.

You can complain to the Polish supervisory authority, the President of the Personal Data Protection Office (UODO), or the supervisory authority in the country where you live or work. Information is available at uodo.gov.pl.