Dieses Dokument ist nur auf Englisch verfügbar
Der Rest dieser Website ist in Ihrer Sprache verfügbar, aber unsere rechtlichen Dokumente werden auf Englisch veröffentlicht. Der englische Text ist die rechtsverbindliche Version.

Privacy Policy - PCrisk Website Scanner & Trust Badge

Effective date: 8 July 2026 · Last updated: 24 August 2026

This Privacy Policy explains how RCS LT, UAB processes personal data through the free website scanner at scanner.pcrisk.com and the paid Trust Badge subscription service. It is written to meet Articles 12-14 of the EU General Data Protection Regulation (GDPR) and should be read together with our Terms of Service.

1. Who we are (controller & contact)

The controller responsible for your personal data is:

RCS LT, UAB
18 I. Kanto str., 44296 Kaunas, Lithuania, European Union
Contact: support@pcrisk.com

RCS LT, UAB publishes pcrisk.com and operates the scanner at scanner.pcrisk.com. We have not appointed a Data Protection Officer, because the mandatory triggers in Article 37(1) GDPR are not met: our automated monitoring targets websites and domains rather than individuals, we do not carry out large-scale special-category processing, and our scale is modest. We nonetheless designate support@pcrisk.com as the single point of contact for all privacy matters, and we will revisit this assessment if our monitoring footprint over individuals materially grows.

2. Scope of this policy

This policy covers two connected services:

Service communications vs marketing

We send two distinct kinds of email:

3. The free scanner & public reports

The scanner processes information about websites, not about individuals. A public report shows, from WHOIS/DNS data, only the registrar's name, the domain's registration and expiry dates, its nameserver, DNSSEC status and hosting provider - we do not publish domain registrants' names, email addresses, postal addresses or phone numbers, and our scans retain only those same curated technical fields from WHOIS responses. Two personal-data footprints nonetheless remain:

Our legal basis for scanning and for publishing reports is Article 6(1)(f) GDPR (legitimate interests) - website security, threat transparency and public-interest security information - and we keep a documented Legitimate Interests Assessment on file for it. As a safeguard, if you are an individual affected by content in a report and wish to object, correct or remove it, contact support@pcrisk.com or use the dispute form on the report page. A person will review your request. Reports are point-in-time automated assessments drawn from third-party sources and are not guarantees.

Where report content relates to individuals whose data was not collected from them directly (for example personal data visible on a scanned page), Article 14 GDPR applies. We rely on Article 14(5)(b): individually notifying every person who might appear in scanned public web content would involve disproportionate effort (there is no reliable contact route at that scale), so - as the appropriate measures that provision requires - we make this policy, the categories and sources of the data, and the dispute/objection route permanently and publicly available on every report page. Categories: content visible on scanned public pages and curated technical WHOIS fields; sources: the scanned website itself, public domain registries and WHOIS data providers.

4. What data we process, why, and on what legal basis

The table below maps each processing purpose to the categories of personal data involved and the applicable Article 6 GDPR legal basis. We do not rely on a single blanket basis.

PurposePersonal data categoriesLegal basis
Account creation, authentication, delivering the Trust Badge subscription, badge rendering, dashboard, API keys, service & security emails (threat alerts, all-clear notices, contract and cancellation confirmations, the monitoring digest) Verified email address; optional name; bcrypt password hash; Google/Apple OIDC identity (verified email, name and - for Google - avatar URL); language preference; monitored domain names; SHA-256-hashed API keys; recorded Terms acceptance (version + time) and, where given, the immediate-performance consent from checkout Art 6(1)(b) - performance of a contract
Billing, invoicing and retention of billing / tax records Account email and subscription / transaction records (payment data is handled by Paddle and never stored on our servers) Art 6(1)(c) - legal obligation (Lithuanian accounting / tax law). Paddle is merchant of record and a separate controller for the payment and tax leg.
Displaying prices in your local currency on marketing and checkout pages Your country code (derived by our CDN, Cloudflare) or - only when no country header is available - your IP address, passed to Paddle's price API, which geolocates it to pick the currency Art 6(1)(f) - legitimate interest (showing the price you would actually pay); also Art 6(1)(b) pre-contractual steps at checkout
Sales attribution and conversion accounting (understanding which marketing channel led to a subscription) First-touch attribution captured at your first pageview and frozen at checkout: landing path, referrer host, utm parameters, an optional "how did you hear about us" answer, page language, first-seen time, and - where analytics consent was given - the GA client/session ids Art 6(1)(f) - legitimate interest (sales accounting); the GA-id leg only alongside your analytics consent. Attribution identifiers (GA ids, free-text answer) are removed on account erasure.
Handling disputes, objections and data-subject requests about public reports The submitter's email (verified by an emailed link), optional name, dispute reason and free-text details, page language, and IP address (abuse limiting) Art 6(1)(f) - legitimate interest (operating the human-review safeguard for public reports); Art 6(1)(c) where the request exercises a GDPR right
Handling statutory withdrawal and cancellation requests Name, account email, the content of your withdrawal statement, and the related correspondence Art 6(1)(c) - legal obligation (Consumer Rights Directive withdrawal duties); Art 6(1)(b) contract administration
Running the free scanner, abuse and fraud prevention, securing the platform, HMAC-signing webhooks, storing API keys only as SHA-256 hashes Submitted URLs; technical / log data (IP addresses, user agents); curated technical WHOIS fields described in Section 3 Art 6(1)(f) - legitimate interest (network and information security; Recital 49)
Publishing scan reports as public-interest security information Screenshots and AI summaries (which can incidentally contain personal data shown on the scanned page); curated technical WHOIS fields Art 6(1)(f) - legitimate interest, with the dispute / erasure safeguard in Section 3
Usage analytics (Google Analytics GA4) and other non-essential cookies Device / usage identifiers set only after you accept the cookie banner Art 6(1)(a) - consent (with the ePrivacy consent gate applied first)

We keep a documented Legitimate Interests Assessment on file for the scanner and publication processing, following EDPB Guidelines 1/2024 (purpose, necessity and balancing tests). Cookie-based analytics runs only on Article 6(1)(a) consent; the server-side attribution ledger above is the one analytics-adjacent processing that rests on Article 6(1)(f), and it is disclosed and scoped in its own row.

Categories of personal data at a glance

Is providing your data required?

Providing a verified email address is a contractual requirement: it is necessary to create an account and to deliver the Trust Badge subscription (authentication, dashboard access, badge rendering and security notices). If you do not provide it, we cannot enter into or perform the contract with you. A name is optional. Where you subscribe to a paid plan, providing the billing details requested by our payment provider Paddle is necessary to complete the purchase and for us to meet our statutory accounting and tax obligations. Consent to analytics cookies is entirely voluntary and refusing it has no effect on your use of the scanner or your subscription.

5. The automated trust score (Article 22 GDPR)

Our trust score is generated automatically from third-party security signals and assesses websites, not individuals. To the extent the automated showing or hiding of a customer's badge at the 70/100 threshold could constitute a decision with significant effects for a customer who is a natural person (for example a sole trader), that processing is necessary for entering into and performing the Trust Badge contract the customer purchased - Article 22(2)(a) GDPR. As the safeguards Article 22(3) requires, you may at any time obtain human intervention, express your point of view and contest a score through the dispute channel available on every report page; a person reviews every contested score.

6. Recipients & processors

We share personal data only with the service providers needed to run the platform. Categories and named recipients are:

RecipientRole
PaddlePayments, billing, invoicing and tax as merchant of record (its own controller for the sale; payment details never reach us). Paddle's price API also receives your country code or IP address for local-currency price display (Section 4).
Zoho ZeptoMailTransactional email delivery (processor)
Google Analytics (GA4)Usage analytics (processor), loaded under Google Consent Mode v2 - denied until you accept the cookie banner
CloudflareCDN / reverse proxy, bot protection (Turnstile on the scan and form endpoints), and the screenshot worker (processor)
OpenAIAI report summaries and report translations (processor): receives page screenshots, page title/metadata and scan signals of scanned websites - content that can incidentally include personal data the scanned page displays. API terms without training on our data.
AnthropicFallback AI provider for the same summarisation/translation processing (processor), same data and terms posture as OpenAI
Bright DataPage-retrieval infrastructure (proxy / web unlocker) used to fetch scanned pages (processor): receives target URLs and the fetched public page content
ScreenshotOneFallback screenshot capture (processor): receives the target URL and returns the page image
DisqusComments widget on public report pages - an independent controller for the cookies it sets; it loads only after you accept non-essential cookies, or when you click "Show comments" (see Section 10)

External security data sources - VirusTotal, Quttera, Google Safe Browsing, OpenPhish, PhishTank, WHOIS/registrar data providers, Tranco and Keywords Everywhere - receive only the scanned domain or URL, never customer personal data. The page-retrieval, screenshot and AI providers above additionally handle the publicly visible content of scanned pages, as described in their rows.

7. International transfers

Some providers process personal data outside the European Economic Area. We rely on a lawful transfer mechanism per provider, not on one blanket claim:

You can request a copy of the relevant safeguards at support@pcrisk.com. We verify each provider's certification or clause coverage before relying on it and keep the assessment under review.

8. How long we keep data (retention)

9. Your rights and how to exercise them

Subject to the conditions in the GDPR, you have the right to: access (Art 15); rectification (Art 16); erasure (Art 17); restriction (Art 18); data portability (Art 20, for account data processed on the basis of contract or consent); object (Art 21, in particular to the legitimate-interest scanning and publication processing); withdraw consent at any time (Art 7(3), for analytics cookies) without affecting prior processing; and rights regarding automated decision-making (Art 22, see Section 5).

To exercise any right, email support@pcrisk.com, or delete your account yourself in Settings (after cancelling any active subscription - this performs a GDPR erasure). We respond within one month (Art 12(3)); where a request is complex or requests are numerous, this may be extended by two further months, and we will tell you about any extension within the first month, with reasons. Exercising your rights is free of charge (Art 12(5)).

Complaints to a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority. Our lead authority is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI), L. Sapiegos str. 17, LT-10312 Vilnius, Lithuania, https://vdai.lrv.lt/en/. You may also complain to the supervisory authority in your own EU country of residence or work.

10. Cookies and similar storage

This section is our cookie notice. For visitors in the EEA, UK and Switzerland, non-essential cookies are set only after you accept them in the cookie banner (Article 5(3) ePrivacy); outside those regions, where no consent requirement applies, analytics runs without a banner. The banner offers Accept and Reject with equal prominence; rejecting (or ignoring) it keeps analytics denied, and your choice - either way - is remembered in a cookie. You can change your choice at any time: deleting this site's cookies in your browser clears the stored choice, the banner appears again on your next visit, and analytics stays denied until you accept anew (Art 7(3)).

Cookie / storagePurposeCategoryConsent
badge_session (RCS LT)Keeps you signed in to the dashboard (HttpOnly; 7 days from last activity, rolling)Strictly necessaryNot required
cookieconsent_dismissed / cookieconsent_choice (RCS LT)Remembers your Accept (366 days; shared with www.pcrisk.com at the .pcrisk.com scope) or Reject (182 days) choiceStrictly necessary (consent state)Not required
pcr_oauth (RCS LT)Protects Google/Apple sign-in against cross-site request forgery (10 minutes, during sign-in only)Strictly necessaryNot required
Cloudflare (incl. Turnstile)Security and bot protection on the scan and form endpoints (e.g. __cf_bm)Strictly necessaryNot required
Paddle checkoutCookies set by Paddle.js during checkout on the account page, needed to process the paymentStrictly necessary (checkout only)Not required
pcr_origin (sessionStorage)First-touch attribution note (landing path, referrer host, utm tags) kept in your browser's sessionStorage for the session and read only if you subscribeFunctional, session-onlyNot required (no tracking identifier; disclosed here for transparency)
Google Analytics (GA4) - _ga, _ga_*Measures usage of the siteAnalyticsRequired - set only after you accept the banner (Consent Mode v2, denied by default)
DisqusComment widget on public report pages; Disqus sets its own third-party cookiesThird-partyRequired - the widget loads only after you accept non-essential cookies, or when you click the "Show comments" control (which is your consent for this embed)

Consent is the ePrivacy gate for non-essential cookies, and Article 6(1)(a) is the GDPR basis for the resulting processing. Nothing non-essential is set before you choose, and clearing the stored choice returns analytics to denied.

11. Changes to this policy

We may update this policy from time to time. The "Last updated" date above always reflects the current version. For material changes, we will notify account holders by email. We keep this policy behind a persistent footer link on scanner.pcrisk.com and in the Trust Badge dashboard so it is always easy to find. The same controller identity, contact and processor list are used consistently across this policy, our cookie notice and our Terms of Service.

12. Contact

For any question about this policy or your personal data, contact RCS LT, UAB, 18 I. Kanto str., 44296 Kaunas, Lithuania, at support@pcrisk.com.