Last updated: September 1, 2026
1. Data Controller
Battal Fatih
Individual entrepreneur (EI)
Trading name: DataCore
SIREN: 934 166 174
Strasbourg
France
Email: contact@verifixscan.com
This policy describes only the processing activities actually implemented by the VeriFixScan service as it operates on the date of the last update indicated above.
2. Data Collected
Account and profile. Email address, full name when provided, interface language, internal account identifier, creation and update dates, as well as any account suspension status and the reason for such suspension when an administrative measure is taken.
Authentication. Credentials and sessions are managed by our authentication provider. Passwords are never stored in plain text by VeriFixScan and are not accessible to the publisher. A verified email address, last login date, and session tokens are processed to enable login.
Google Sign-In (optional). When you choose “Continue with Google,” we receive from Google the basic profile information provided during authentication: email address, displayed name when provided, and Google account identifier. No other data from your Google account is requested.
Subscriptions and payments. Subscribed plan, subscription status, current billing period end date, scheduled cancellation, Stripe technical identifiers (customer, subscription, checkout session, invoice), amounts, currency, AI credit purchases and individual audit purchases, as well as payment events received from Stripe. No full bank card number, security code, or expiration date is received or stored by VeriFixScan.
AI credits and usage. AI credit balance, usage per period, usage counters (scans performed, AI requests), and AI request logs (operation type, model, tokens consumed, status).
Websites and analyses. Websites you add, analyzed URLs, scan settings, analysis results, detected issues and their technical evidence, crawled pages, scores, generated reports, scan history, comparisons between scans, conversations with the AI assistant associated with an issue, shared reports when you create a sharing link, and website intelligence data (detected technologies, publicly available business identification information retrieved from public registers).
Screenshots. When the feature is used, a screenshot of the analyzed page is generated by a specialized provider and stored in private storage, together with the page URL, display format, and generation status.
Integrations and APIs. If you connect a third-party service or create an API key, we store the connection data required, integration events, webhook deliveries, and API request logs (timestamp, route, status).
Security and abuse prevention. For scans launched without an account, the IP address is not stored in plain text: it is transformed into an irreversible fingerprint (hash) used for rate limiting, IP reputation, and temporary blocking. We also record abuse events, rate-limiting counters, and, for administrators, an administration activity log. IP addresses authorized to bypass maintenance mode are stored in plain text: they are voluntarily entered by the service administrator and do not concern ordinary users.
Support. Messages sent through the contact form (name, email address, subject, and message content) are processed in order to respond to you.
We do not use any audience measurement or advertising tools: no Google Analytics, Meta Pixel, Hotjar, or equivalent.
3. Purposes and Legal Bases
- Account creation and management, authentication (including through Google), provision of the service, execution of scans, report generation, AI credit management, and support: performance of the contract (Terms of Use accepted upon registration).
- Subscription management, payment processing and monitoring, invoice management, and cancellations: performance of the contract, and legal obligation for the retention of accounting records.
- Service security, rate limiting, abuse and fraud prevention, maintenance, and technical reliability: the publisher’s legitimate interest in protecting the service and its users.
- Google Sign-In: use of this authentication method results from your choice, within the framework of performance of the contract.
- Responding to legal requests and complaints: legal obligation or legitimate interest, as applicable.
No processing currently relies on consent within the meaning of the GDPR, since no non-essential cookies or trackers are deployed and no marketing newsletter is sent.
4. Data from Analyzed Websites
When you request an analysis of a website, VeriFixScan makes requests to that website in a manner similar to a browser or indexing crawler, and processes elements that are technically accessible to the public: URLs, response headers, DNS, TLS and email configuration, HTML code of crawled pages, linked resources, cookies set by the website, and accessibility or performance elements measured.
VeriFixScan does not retain a complete copy of your website. The following are recorded: the list of crawled pages, results and scores, detected issues and limited evidence excerpts (for example, a code fragment, header, or URL) necessary to substantiate each finding, as well as screenshots when requested.
If the analyzed website contains publicly accessible personal data, such data may incidentally appear in the collected evidence. You must have the necessary rights or authorizations to request an analysis of a website where required, and you remain responsible for the URLs you submit.
5. Payments
Payments are processed by Stripe. You are redirected to a payment page hosted by Stripe: bank card details are entered directly with Stripe and do not pass through VeriFixScan, which does not store them.
VeriFixScan receives from Stripe the information necessary to monitor the transaction and subscription: customer and subscription identifiers, billing email address, payment status, amount, currency, billing period, invoices, and related events (renewal, payment failure, cancellation, refund). This data is used to activate the plan, manage renewals and cancellations, maintain billing history, and allocate purchased AI credits.
Stripe acts as an independent data controller for its own regulatory and anti-fraud obligations.
6. Google Authentication
Google Sign-In is offered as an optional feature. If you use it, Google authenticates you and provides us with basic profile information (email address, displayed name when provided, and account identifier). This information is used solely to create or retrieve your VeriFixScan account. We do not access any other service or content from your Google account.
7. Artificial Intelligence
Certain features (explanation of an issue, prioritization of fixes, executive summary of a report, correction assistant) rely on AI models provided by external providers:
- Anthropic (Claude models) — generation of analyses and assistant responses.
The data transmitted is limited to the context necessary for the request: scan findings, technical evidence excerpts from the analyzed website, scores, the relevant URL and, for the assistant, your question. No billing data is transmitted. Your email address is not necessary for these processes and is not sent.
These providers are established in the United States or may process data there: a transfer outside the European Union is therefore possible for AI features (see Section 9).
8. Recipients and Processors
- Vercel Inc. — application hosting and delivery.
- Supabase — database, authentication, private screenshot storage, and authentication email delivery (email verification, password reset).
- Stripe — payments, subscriptions, and billing.
- Anthropic — AI features.
- ScreenshotOne — generation of screenshots of analyzed pages.
- Technical services queried during a scan, without transmission of account data: public DNS resolvers (Cloudflare), public business registries (Recherche d'entreprises / INSEE API in France, VIES for intra-EU VAT), and public web archives when the corresponding check is performed.
- Third-party services that you voluntarily connect through integrations or your own webhooks, solely for the data you choose to send to them.
Your data is neither sold, rented, nor used for advertising purposes.
9. Transfers Outside the European Union
Some providers are established in the United States or may process data there: Vercel, Stripe, Anthropic, ScreenshotOne and, depending on the infrastructure region, Supabase. Transfers outside the European Union are therefore possible.
These transfers rely on mechanisms provided for under the GDPR, including the European Commission’s Standard Contractual Clauses and, where applicable, the provider’s certification under the EU–U.S. Data Privacy Framework, supplemented by technical measures such as encryption in transit and data minimization.
10. Data Retention Periods
The retention periods actually configured, or, where applicable, the retention criteria applied, are set out below.
- Account, profile, websites, scans, reports, history, and AI conversations: retained for as long as the account exists. No automatic deletion is currently scheduled; these data are deleted when the account is deleted (see Section 13) or upon request.
- Scans performed without an account: each anonymous scan has a technical expiration date (including the hashed IP identifier), after which it is no longer used or accessible.
- IP reputation and temporary blocks: retained for a maximum of 7 days from the last event, in the form of an irreversible fingerprint.
- Subscriptions, payments, invoices, and credit purchases: retained for the duration of the contractual relationship, followed by the legally required retention period for accounting records (10 years in France). Stripe retains its own records separately.
- Screenshots: retained in private storage for as long as the associated scan is retained.
- Technical and security logs (API requests, abuse events, administration logs): retained for as long as necessary for security, usage billing, and evidentiary purposes, and then purged during maintenance operations.
- Support messages: retained for as long as necessary to process the request and manage any potential dispute.
For full transparency: apart from the expiration of anonymous scans and IP reputation data, the service does not currently perform scheduled automatic purging of account data. Deletion takes place upon request or when your account is deleted.
11. Cookies and Local Storage
VeriFixScan does not use audience measurement or advertising cookies. Only strictly necessary or convenience-related elements are used:
- the authentication session, which is necessary to remain logged in;
- an interface cookie that remembers whether the sidebar menu is open or collapsed;
- local storage that remembers your theme (light/dark), language, and a delay between two free scans, with a local technical identifier used solely to limit abuse;
- a technical cookie for bypassing maintenance mode, reserved for service administration.
See also the Cookie Policy.
12. Security
Appropriate technical and organizational measures are implemented to protect data: encryption of communications, account-based access segregation, database-level access controls, server-side storage of secrets only, rate limiting, and logging of sensitive operations. As no system is infallible, we cannot guarantee absolute security.
13. Your Rights
Under the GDPR, you have the rights of access, rectification, erasure, restriction, and data portability, as well as the right to object to processing based on legitimate interests. Where processing is based on your consent, you may withdraw it at any time.
To exercise your rights, write to contact@verifixscan.com, specifying your request and the email address associated with your account. You will receive a response within one month, which may be extended in the event of a complex request. Proof of identity may be requested where there is reasonable doubt about your identity.
You may also lodge a complaint with the CNIL (3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr).
14. Account Deletion
You can delete your account from your dashboard settings. Deletion is permanent and requires explicit confirmation.
The following are then deleted: your authentication account, profile, websites, scans and analyzed pages, detected issues and reports, conversations with the AI assistant, screenshots, integrations, API keys, webhooks, and subscription and credit status on the VeriFixScan side.
Certain data may need to be retained after deletion: accounting records and payment documentation retained to comply with legal obligations, as well as information strictly necessary to establish or defend a legal claim. Records held by Stripe are subject to its own retention policy.
Deleting your account does not automatically cancel an active subscription: cancel your subscription before deleting your account to avoid further renewals. After deletion, your reports and history cannot be recovered.
15. Changes to This Policy
This policy may be updated, particularly in the event of changes to the service, the processing activities carried out, the providers used, or applicable legal requirements. The date of the last update is shown at the top of this page.
