Privacy Policy
Effective from 1 September 2026. This policy explains what personal data we collect when you use Sitewarden, why we collect it, and what you can do about it.
1. Controller
The data controller is NIKITA MESHCHERIAKOV PR BEOGRAD, Dobropoljska 56/5, 11000 Belgrade, PIB 114281750. Contact us about anything in this policy at legal@aicour.site. We have not appointed a Data Protection Officer, as we are not required to.
2. What we collect
| Data | Why | Legal basis (GDPR Art. 6) |
|---|---|---|
| Email address, optional name, hashed password | To create and secure your account and to send service messages | Performance of a contract |
| Domains and URLs you audit, and the resulting reports | To deliver the product and keep your audit history | Performance of a contract |
| Subscription status, plan, Paddle customer and subscription identifiers | To grant the right level of access and handle renewals | Performance of a contract |
| Server logs: IP address, user agent, timestamp, requested path | Security, abuse prevention and debugging | Legitimate interests |
| Support correspondence | To answer you and to keep a record of what was agreed | Legitimate interests |
We never see or store your card details. Payment data is collected directly by Paddle.com Market Ltd at checkout and never passes through our servers.
3. What we do not do
- We do not sell or rent personal data.
- We do not run advertising or third-party analytics trackers on this site.
- We do not build profiles of you, and we take no automated decisions with legal effect.
- We do not email you marketing unless you opt in, and every such email has an unsubscribe link.
4. Data about third-party websites
When you audit a domain, we fetch publicly available information about it: DNS records, the TLS certificate, HTTP response headers and the page markup. That data is stored in your account as part of the report. It is generally not personal data, but if a page you audit happens to contain personal data in its markup, it will be present in the stored report. Deleting the report deletes it.
5. Who we share data with
| Processor | Purpose | Location |
|---|---|---|
| Paddle.com Market Ltd | Payment processing, invoicing, tax remittance, billing support | United Kingdom / EU |
| Our hosting provider | Running the application and storing its database | European Union |
| Our transactional email provider | Account and billing notification emails | European Union |
Where a processor is outside the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses or an adequacy decision. We may also disclose data where we are legally required to, and we will tell you unless we are prohibited from doing so.
6. Retention
- Account data: for as long as the account exists, then 30 days.
- Audit reports: until you delete them, or 30 days after the account is closed.
- Server logs: 90 days.
- Invoices and tax records: as long as Serbian tax law requires, currently 10 years.
7. Your rights
Under the GDPR and the Serbian Law on Personal Data Protection you can request access to your data, correction, erasure, restriction of processing, portability in a machine-readable format, and you can object to processing based on legitimate interests. Where processing rests on consent, you can withdraw it at any time without affecting past processing.
Email legal@aicour.site and we will respond within 30 days. We never charge for a first request. If you are unhappy with our response you may complain to your national supervisory authority, or in Serbia to the Commissioner for Information of Public Importance and Personal Data Protection.
8. Security
Traffic is encrypted with TLS. Passwords are stored as bcrypt hashes and are never recoverable in plain text. Access to production data is limited to those who need it. We will notify you and the relevant authority within 72 hours of becoming aware of a breach that is likely to result in a risk to your rights.
9. Cookies
We use only what is strictly necessary to keep you signed in. The detail is in our Cookie Policy.
10. Children
Sitewarden is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe we have, tell us and we will delete it.
11. Changes
We will post any update here and, if the change is material, email account holders before it takes effect.