Privacy Policy
Last updated: September 7, 2026
This page is provided for transparency. Generated scan results and templates are informational and not legal advice.
On this page
- 01Introduction & controller
- 02Our roles (controller & processor)
- 03Information we collect
- 04Lawful basis for processing
- 05How we use your information
- 06Cookies & similar technologies
- 07AI / automated report summaries
- 08Scanning, badges, plugins & APIs
- 09How we share information
- 10Third-party subprocessors & recipients
- 11International data transfers
- 12Data retention
- 13Security
- 14Your privacy rights
- 15Non-discrimination
- 16Children
- 17Changes to this policy
- 18Contact
1Introduction & controller
PrivBeacon ("we", "us", "our") is the product name for the privacy compliance platform at https://privbeacon.com. The service is owned and operated by Vassbrekke AS, a company registered in Norway. This Privacy Policy describes how we collect, use, store, share, and protect personal information when you use our website, APIs, plugins, on-prem agent, and related services (the "Services").
Controller: Vassbrekke AS Address: Stolevegen, 5514 Haugesund, Norway Country: Norway
Privacy & data protection contact: privacy@privbeacon.com (We have not appointed a separate formal DPO; privacy requests go to the same contact.) Support: support@privbeacon.com
2Our roles (controller & processor)
We act in different roles depending on the data:
Data controller — for account registration, authentication, billing, product usage, free public scans you run on our site, marketing conversion tags (with consent), security logs, and our own website operations.
Data processor — when you use PrivBeacon features that store personal data about your end users or other third parties on your instructions — in particular the in-product DSAR request tracker (requester emails and notes), site monitoring configurations (alert emails), and scan workspaces tied to your organization. In those cases you are the controller of that third-party data and must have a lawful basis to collect and process it; we process it only to provide the Services.
Independent operator on scanned websites — when our scanner fetches a public URL (or a URL you authorize), we process technical content of that site to produce a compliance report. You must only scan sites you own or are authorized to test.
3Information we collect
We may collect the following categories of personal information:
- Identifiers — name, email address, password hash (if you register with email/password), OAuth subject identifiers, profile name/image from Google, Microsoft, or GitHub if you choose those sign-in methods, API key prefixes/hashes, session tokens.
- Commercial information — plan tier, Stripe customer/subscription identifiers, subscription status, trial and billing period metadata (card numbers are handled by Stripe; we do not store full payment card data).
- Internet / technical activity — pages and features used on PrivBeacon, scan requests (including free public scans), device/browser type, approximate country derived locally from IP to select USD vs EUR pricing (IP Geolocation by DB-IP https://db-ip.com; not sent to a geolocation API), IP address and rate-limit keys (security and abuse prevention), consent preference flags.
- Professional / customer content — company or organization name, site names and URLs, optional repository URLs, compliance law selections, monitoring schedules, alert webhook URLs and alert email addresses you configure.
- Scan — derived data — scores, tracker inventories, consent findings, compliance gap labels, generated policy/banner/DSAR templates, report summaries, and limited HTML or text snippets needed to produce results. Scans may include personal data that appears on the scanned public pages.
- DSAR tool data (processor role) — emails and notes of individuals who submit access/deletion-style requests that you log in the product on behalf of your business.
- Communications — support and privacy emails you send us.
- Public verification data — badge certification status and related metadata shown on public verify/badge endpoints for sites you choose to certify.
4Lawful basis for processing
We process personal data on the following lawful bases (GDPR / UK GDPR):
- Consent — non-essential cookies and similar technologies (including Google Ads conversion measurement when you opt into marketing cookies); optional marketing communications where we ask separately.
- Contract — creating and securing your account; providing scans, dashboards, reports, badges, APIs, plugins, billing, and support you request.
- Legitimate interests — securing the Services, rate limiting and fraud/abuse prevention, selecting display and checkout currency from country (derived locally from IP), debugging, improving reliability and product quality, and limited self-certification of our own site — balanced against your rights.
- Legal obligation — retaining or disclosing information when required by applicable law, regulation, or valid legal process.
5How we use your information
- Provide privacy scans (including free public scans), dashboards, AI or template report summaries, generated policies/banners/DSAR workflows, evidence exports, and compliance badges.
- Authenticate users (email/password, Google/Microsoft/GitHub OAuth, or enterprise SSO when configured) and manage sessions and API keys.
- Process subscriptions and payments via Stripe and enforce plan limits.
- Run scheduled monitoring, send email/webhook alerts you configure, and support CI/CD or on-prem agent scan sync.
- Operate the customer DSAR tracker as your processor when you log third-party requests.
- Respond to support requests and data subject requests about PrivBeacon’s own processing.
- Measure ad conversions with Google Ads only after marketing cookie consent.
- Secure the platform (rate limits, logging, fraud prevention) and improve the product.
- Comply with legal obligations and enforce our Terms of Service.
7AI / automated report summaries
AI features may generate compliance report summaries and privacy policy drafts from scan metadata (for example site URL or name, score, tracker vendor names, and gap labels). Issue detection and scoring are rule-based and do not use a language model. Free public scans do not call an AI provider.
Production (privbeacon.com): authenticated scans send that scan metadata to xAI (Grok) in the United States unless you turn AI features off. We request that xAI does not store the prompt or response. We do not use OpenAI or a self-hosted Ollama instance for PrivBeacon production AI features.
You can turn AI features off at any time in Dashboard → Settings. When AI is off, we use template reports and policy drafts only and do not send scan metadata to xAI.
If the xAI request fails, we fall back to template-based text without calling another model provider. Do not submit secrets or unnecessary personal data into free-text fields when using AI-assisted features.
8Scanning, badges, plugins & APIs
Free public scans (no account): we process the URL you submit and your IP address (rate limiting / abuse prevention), fetch the target site, and return findings. A shareable report is stored as a random token for 14 days, then deleted. Tokens are unguessable and not indexed. Results are not attached to an account unless you later sign up and re-scan.
Authenticated scans: we store scan results and generated artifacts in your account for the retention periods below. You may delete scans from the dashboard (subject to product features).
Authorization: you must only scan websites you own or have permission to test. Scanning may contact third-party domains referenced by the target site as part of detection.
Plugins & agent: WordPress/Shopify embeds and the on-prem agent communicate with our APIs using credentials you configure; they process site identifiers and scan-related data needed to show badges or sync results.
Public badge / verify pages: if you enable certification, badge status and limited site compliance metadata may be publicly accessible via badge and verify URLs.
10Third-party subprocessors & recipients
We use the following vendors (subprocessors / recipients) for PrivBeacon at privbeacon.com:
| Vendor | Purpose | Region |
|---|---|---|
Stripe Payment | Payment processing, subscriptions, customer billing portal | US / EU (Stripe) |
Google (OAuth) Authentication | Optional Google sign-in on the login page | US / global |
GitHub (OAuth) Authentication | Optional GitHub sign-in on the login page | US / global |
Microsoft (OAuth) Authentication | Optional Microsoft sign-in on the login page | US / global |
Google Ads Advertising / conversion | Optional conversion measurement via gtag.js — loaded only after marketing cookie consent | US / global |
xAI AI / LLM | AI compliance report summaries and privacy policy drafts (Grok). Scan metadata such as URL, score, tracker names, and gap labels may be sent to xAI in the US. We request that xAI does not store the prompt or response | US |
Proton Mail (SMTP) Email | Primary transactional email: verification, monitoring alerts, and service notices | EU / Switzerland (Proton) |
Resend Email (optional) | Optional alternate transactional email provider | US |
Hosted infrastructure operated by Vassbrekke AS Infrastructure | Application hosting, PostgreSQL database, Redis (rate limiting / sessions support) | Norway / EU |
Customer-configured endpoints Customer integrations | Optional monitoring webhooks and alert emails you set on a site — we send scan/alert payloads to addresses or URLs you control | Customer-selected |
Stripe
PaymentPayment processing, subscriptions, customer billing portal
US / EU (Stripe)
Google (OAuth)
AuthenticationOptional Google sign-in on the login page
US / global
GitHub (OAuth)
AuthenticationOptional GitHub sign-in on the login page
US / global
Microsoft (OAuth)
AuthenticationOptional Microsoft sign-in on the login page
US / global
Google Ads
Advertising / conversionOptional conversion measurement via gtag.js — loaded only after marketing cookie consent
US / global
xAI
AI / LLMAI compliance report summaries and privacy policy drafts (Grok). Scan metadata such as URL, score, tracker names, and gap labels may be sent to xAI in the US. We request that xAI does not store the prompt or response
US
Proton Mail (SMTP)
EmailPrimary transactional email: verification, monitoring alerts, and service notices
EU / Switzerland (Proton)
Resend
Email (optional)Optional alternate transactional email provider
US
Hosted infrastructure operated by Vassbrekke AS
InfrastructureApplication hosting, PostgreSQL database, Redis (rate limiting / sessions support)
Norway / EU
Customer-configured endpoints
Customer integrationsOptional monitoring webhooks and alert emails you set on a site — we send scan/alert payloads to addresses or URLs you control
Customer-selected
11International data transfers
Primary application hosting is operated by Vassbrekke AS in Norway / EU. Personal data may also be processed in other countries where our subprocessors operate — including the United States for Stripe, Google (OAuth and, with consent, Ads conversion), Microsoft OAuth, GitHub OAuth, xAI (AI summaries and policy drafts), and any optional Resend usage.
Where required under GDPR/UK GDPR for transfers outside the UK/EEA/Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and UK addenda where applicable), vendor Data Processing Agreements, and transfer impact assessments as needed. You can contact us for more information about transfer mechanisms.
12Data retention
We retain personal data only as long as needed for the purposes above, unless a longer period is required by law:
- Account data — while your account is active, and up to 24 months after closure (or sooner if you validly request deletion and no legal hold applies).
- Scan results and generated artifacts — while associated with an active account; you may delete individual scans in-product. Closed accounts follow the account retention window unless you request earlier deletion.
- Free public scan inputs — processed to produce an immediate response. A shareable findings report (score, named issues, tracker vendors, host) is stored under a random token for 14 days, then deleted. Security logs (e.g. IP-based rate limits) may persist for shorter operational windows (typically up to 30–90 days).
- DSAR tool records you create — until you delete them or your account is closed/deleted under the account schedule (you remain controller of that content).
- Billing records — as required for tax, accounting, and dispute resolution (often longer than account closure).
- Cookie / consent choice — up to 12 months for the consent cookie, or until you clear site data.
- Google Ads / conversion data — subject to Google’s retention; we do not run a separate long-term ad-profile database.
- xAI prompts/responses — we request that xAI does not store conversation history. Generated summaries and drafts we save are retained with your scan/account records as above.
When retention ends, we delete or irreversibly anonymize data where feasible.
13Security
We implement technical and organizational measures appropriate to the risk, including TLS encryption in transit, LUKS on the Proxmox host that stores application volumes (guest VMs are not separately encrypted), access-controlled production systems limited to Vassbrekke AS operators, hashed passwords (for email/password accounts), hashed API keys, least-privilege operational access, tenant isolation in the product dashboard, dependency and infrastructure updates, and rate limiting / abuse controls. No method of transmission or storage is 100% secure; if you believe you have found a vulnerability, contact privacy@privbeacon.com or support@privbeacon.com.
14Your privacy rights
GDPR / UK GDPR: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent (where processing is consent-based). You may also lodge a complaint with your local supervisory authority (for example your EU/EEA data protection authority or the UK ICO).
CCPA / CPRA (California) and similar US state laws: right to know/access, delete, correct, and opt out of sale/sharing; non-discrimination for exercising rights. We do not sell personal information. Limited conversion measurement with Google after consent is described under “Sharing” above and can be controlled via cookie preferences.
Other regions (including LGPD, PIPEDA, POPIA, APPI, PDPA, PIPA, Privacy Act (Australia), FADP, and US state laws such as VCDPA, CPA, CTDPA): contact us to exercise access, correction, deletion, or portability rights that apply to you.
How to exercise: submit a request via our DSAR form at https://privbeacon.com/legal/dsar, or email privacy@privbeacon.com with your request type (access, deletion, correction, opt-out, etc.). We will verify your request as required by law and respond within applicable deadlines (for example up to 45 days under CCPA, subject to lawful extensions; without undue delay and within one month under GDPR where applicable). See also our Privacy Choices page.
Account deletion: submit a deletion request via the DSAR form or email privacy@privbeacon.com (or in-product controls when available). We will delete or anonymize personal data we control, subject to legal retention needs. Data you stored as controller (e.g. DSAR requester emails) is deleted with your account or earlier if you remove those records.
To exercise your rights, email privacy@privbeacon.com or visit Privacy Choices. Request your data (DSAR) · Privacy Choices.
15Non-discrimination
We will not discriminate against you for exercising your privacy rights under CCPA, CPRA, or other applicable laws.
16Children
PrivBeacon is a business/professional service and is not directed at children. We do not knowingly collect personal information from children under 16 (or under 13 where COPPA applies). If you believe a child has provided us personal data, contact privacy@privbeacon.com and we will take appropriate steps to delete it.
17Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of the policy will change when we do. Material changes will be highlighted on this page and, where appropriate, notified by email or in-product notice. Continued use of the Services after the effective date constitutes acceptance of the updated policy where permitted by law.
18Contact
Controller: Vassbrekke AS
Address: Stolevegen, 5514 Haugesund, Norway
Country: Norway
Privacy & data protection: privacy@privbeacon.com
Support: support@privbeacon.com
PrivBeacon provides automated privacy scans and document templates for informational purposes only. This is not legal advice. Consult qualified legal counsel before relying on generated policies or compliance scores for regulatory decisions.