This Privacy Policy explains how RCS LT, UAB processes personal data through the free website scanner at scanner.pcrisk.com and the paid Trust Badge subscription service. It is written to meet Articles 12-14 of the EU General Data Protection Regulation (GDPR) and should be read together with our Terms of Service.
The controller responsible for your personal data is:
RCS LT, UAB publishes pcrisk.com and operates the scanner at scanner.pcrisk.com. We have not appointed a Data Protection Officer, because the mandatory triggers in Article 37(1) GDPR are not met: our automated monitoring targets websites and domains rather than individuals, we do not carry out large-scale special-category processing, and our scale is modest. We nonetheless designate support@pcrisk.com as the single point of contact for all privacy matters, and we will revisit this assessment if our monitoring footprint over individuals materially grows.
This policy covers two connected services:
We send two distinct kinds of email, which have different legal bases (see Section 4):
The scanner primarily processes information about websites, not about individuals. Two personal-data footprints must nonetheless be addressed:
Our legal basis for both processing and publishing this information is Article 6(1)(f) GDPR (legitimate interests) - namely website security, threat transparency and public-interest security information. We have weighed registrants' reasonable expectations (WHOIS is already a public register) against the value of this transparency. As a safeguard, if you are an individual identified in a report and wish to object, correct or remove that information, contact support@pcrisk.com or use the dispute form on the report page. A person will review your request. Reports are point-in-time automated assessments drawn from third-party sources and are not guarantees.
Because some of this data is not collected from the individual directly, Article 14 GDPR applies: the categories of data are registrant identity and contact details, and the sources are public domain registries and WHOIS data providers. We make this policy and the dispute route publicly available as our means of informing affected individuals.
The table below maps each processing purpose to the categories of personal data involved and the applicable Article 6 GDPR legal basis. We do not rely on a single blanket basis.
| Purpose | Personal data categories | Legal basis |
|---|---|---|
| Account creation, authentication, delivering the Trust Badge subscription, badge rendering, dashboard, API keys, and service & security emails to the customer (threat alerts and all-clear notices) | Verified email address; optional name; bcrypt password hash; Google/Apple OIDC identity (verified email, name, avatar URL); monitored domain names; SHA-256-hashed API keys | Art 6(1)(b) - performance of a contract |
| Optional weekly digest and any product / upsell email (direct marketing of our own similar services) | Account email address | Art 6(1)(a) - consent, or the ePrivacy Article 13(2) "soft opt-in" for our own similar services; you may unsubscribe at any time and doing so stops only these optional emails |
| Billing, invoicing and retention of billing / tax records | Account email and subscription / transaction records (payment card data is handled by Paddle and never stored on our servers) | Art 6(1)(c) - legal obligation (Lithuanian accounting / tax law). Paddle is merchant of record and a separate controller for the payment and tax leg. |
| Running the free scanner, abuse and fraud prevention, securing the platform, HMAC-signing webhooks, storing API keys only as SHA-256 hashes | Submitted URLs; technical / log data; registrant data described in Section 3 | Art 6(1)(f) - legitimate interest (network and information security; Recital 49) |
| Publishing scan reports as public-interest security information | WHOIS / DNS registrant data; screenshots; AI summaries | Art 6(1)(f) - legitimate interest, with the dispute / erasure safeguard in Section 3 |
| Usage analytics (Google Analytics GA4) and other non-essential cookies | Device / usage identifiers set only after you accept the cookie banner | Art 6(1)(a) - consent (with the ePrivacy consent gate applied first) |
We keep a documented Legitimate Interests Assessment on file for the scanner and publication processing, following EDPB Guidelines 1/2024 (purpose, necessity and balancing tests). We never rely on Article 6(1)(b) or 6(1)(f) to justify analytics or optional marketing email.
Providing a verified email address is a contractual requirement: it is necessary to create an account and to deliver the Trust Badge subscription (authentication, dashboard access, badge rendering and security notices). If you do not provide it, we cannot enter into or perform the contract with you. A name is optional. Where you subscribe to a paid plan, providing the billing details requested by our payment provider Paddle is necessary to complete the purchase and for us to meet our statutory accounting and tax obligations. Consent to optional marketing email is entirely voluntary and refusing it has no effect on your account or subscription.
Our trust score is generated automatically from third-party security signals. It assesses websites, not individuals, and does not by itself produce legal or similarly significant effects on any natural person. Every score can be reviewed by a person through our dispute channel, so it is not a solely automated decision for anyone who contests it. For a Trust Badge customer, the badge showing or hiding at the 70/100 threshold is contract performance affecting a business relationship, not a legal or similarly significant effect on a natural person. We therefore do not use the trust score to make solely automated decisions about you within the meaning of Article 22 GDPR, and we maintain the human-review dispute channel as the backstop.
We share personal data only with the service providers needed to run the platform. Categories and named recipients are:
| Recipient | Role |
|---|---|
| Paddle.com | Payments, billing, invoicing and tax as merchant of record (effectively its own controller for the sale; card data never reaches us) |
| Zoho ZeptoMail | Transactional email delivery (processor) |
| Google Analytics (GA4) | Usage analytics (processor), loaded under Google Consent Mode v2 - denied until you accept the cookie banner |
| Cloudflare | CDN / reverse proxy (processor) |
| Disqus | Comments widget on public report pages - an independent controller for the cookies it sets; loaded only after consent (see Section 10) |
External scan data sources - VirusTotal, Quttera, WHOIS providers, Tranco and OpenPageRank / Keywords Everywhere - receive only the scanned domain name, never customer personal data.
Some of the providers above (Paddle, Google, Zoho ZeptoMail and Cloudflare) may process personal data outside the European Economic Area. Where they do, we rely on a European Commission adequacy decision - including the EU-US Data Privacy Framework where the provider is certified - or on the Commission's Standard Contractual Clauses (2021/914) together with a transfer impact assessment and supplementary safeguards. You can request a copy of the relevant safeguards at support@pcrisk.com.
We verify each provider's current Data Privacy Framework certification or Standard Contractual Clause coverage before relying on it, and keep that assessment under review.
Subject to the conditions in the GDPR, you have the right to: access (Art 15); rectification (Art 16); erasure (Art 17); restriction (Art 18); data portability (Art 20, for account data processed on the basis of contract or consent); object (Art 21, in particular to the legitimate-interest scanning and publication processing); withdraw consent at any time (Art 7(3), for analytics cookies and optional marketing email) without affecting prior processing; and rights regarding automated decision-making (Art 22).
To exercise any right, email support@pcrisk.com, or delete your account yourself in Settings (this performs a GDPR erasure cascade). We respond within one month (Art 12(3)), and exercising your rights is free of charge (Art 12(5)).
You have the right to lodge a complaint with a data protection supervisory authority. Our lead authority is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI), L. Sapiegos str. 17, LT-10312 Vilnius, Lithuania, https://vdai.lrv.lt/en/. You may also complain to the supervisory authority in your own EU country of residence or work.
We distinguish strictly necessary cookies from cookies that require your consent. This section forms our cookie notice. Only the strictly-necessary badge_session cookie is set without consent; every other cookie below is non-essential and set only after you give prior consent through the cookie banner (Article 5(3) ePrivacy).
| Cookie / provider | Purpose | Category | Consent |
|---|---|---|---|
badge_session (RCS LT) | Keeps you signed in to the dashboard (HttpOnly, 7 days) | Strictly necessary | Not required |
| Google Analytics (GA4) | Measures usage of the site | Analytics | Required - set only after you accept the banner (Consent Mode v2) |
| Disqus | Comment widget on public report pages; Disqus sets its own third-party cookies | Third-party | Required - the Disqus widget loads and sets cookies on report pages only after you accept non-essential cookies in the banner |
Consent is the ePrivacy gate for non-essential cookies, and Article 6(1)(a) is the GDPR basis for the resulting processing. The banner offers Accept and Reject with equal prominence, sets nothing non-essential before you choose, treats closing the banner as a refusal, and lets you withdraw consent through the persistent cookie-settings control as easily as you gave it.
We may update this policy from time to time. The "Last updated" date above always reflects the current version. For material changes, we will notify account holders by email. We keep this policy behind a persistent footer link on both scanner.pcrisk.com and the Trust Badge dashboard so it is always easy to find. The same controller identity, contact and processor list are used consistently across this policy, our cookie notice and our Terms of Service.
For any question about this policy or your personal data, contact RCS LT, UAB, 18 I. Kanto str., 44296 Kaunas, Lithuania, at support@pcrisk.com.