Sitewarden

Privacy Policy

Effective from 1 September 2026. This policy explains what personal data we collect when you use Sitewarden, why we collect it, and what you can do about it.

1. Controller

The data controller is NIKITA MESHCHERIAKOV PR BEOGRAD, Dobropoljska 56/5, 11000 Belgrade, PIB 114281750. Contact us about anything in this policy at legal@aicour.site. We have not appointed a Data Protection Officer, as we are not required to.

2. What we collect

DataWhyLegal basis (GDPR Art. 6)
Email address, optional name, hashed passwordTo create and secure your account and to send service messagesPerformance of a contract
Domains and URLs you audit, and the resulting reportsTo deliver the product and keep your audit historyPerformance of a contract
Subscription status, plan, Paddle customer and subscription identifiersTo grant the right level of access and handle renewalsPerformance of a contract
Server logs: IP address, user agent, timestamp, requested pathSecurity, abuse prevention and debuggingLegitimate interests
Support correspondenceTo answer you and to keep a record of what was agreedLegitimate interests

We never see or store your card details. Payment data is collected directly by Paddle.com Market Ltd at checkout and never passes through our servers.

3. What we do not do

  • We do not sell or rent personal data.
  • We do not run advertising or third-party analytics trackers on this site.
  • We do not build profiles of you, and we take no automated decisions with legal effect.
  • We do not email you marketing unless you opt in, and every such email has an unsubscribe link.

4. Data about third-party websites

When you audit a domain, we fetch publicly available information about it: DNS records, the TLS certificate, HTTP response headers and the page markup. That data is stored in your account as part of the report. It is generally not personal data, but if a page you audit happens to contain personal data in its markup, it will be present in the stored report. Deleting the report deletes it.

5. Who we share data with

ProcessorPurposeLocation
Paddle.com Market LtdPayment processing, invoicing, tax remittance, billing supportUnited Kingdom / EU
Our hosting providerRunning the application and storing its databaseEuropean Union
Our transactional email providerAccount and billing notification emailsEuropean Union

Where a processor is outside the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses or an adequacy decision. We may also disclose data where we are legally required to, and we will tell you unless we are prohibited from doing so.

6. Retention

  • Account data: for as long as the account exists, then 30 days.
  • Audit reports: until you delete them, or 30 days after the account is closed.
  • Server logs: 90 days.
  • Invoices and tax records: as long as Serbian tax law requires, currently 10 years.

7. Your rights

Under the GDPR and the Serbian Law on Personal Data Protection you can request access to your data, correction, erasure, restriction of processing, portability in a machine-readable format, and you can object to processing based on legitimate interests. Where processing rests on consent, you can withdraw it at any time without affecting past processing.

Email legal@aicour.site and we will respond within 30 days. We never charge for a first request. If you are unhappy with our response you may complain to your national supervisory authority, or in Serbia to the Commissioner for Information of Public Importance and Personal Data Protection.

8. Security

Traffic is encrypted with TLS. Passwords are stored as bcrypt hashes and are never recoverable in plain text. Access to production data is limited to those who need it. We will notify you and the relevant authority within 72 hours of becoming aware of a breach that is likely to result in a risk to your rights.

9. Cookies

We use only what is strictly necessary to keep you signed in. The detail is in our Cookie Policy.

10. Children

Sitewarden is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe we have, tell us and we will delete it.

11. Changes

We will post any update here and, if the change is material, email account holders before it takes effect.