Privacy Policy
Last updated: 1 September 2026
1. Controller
Konform is the data controller. Contact: [email protected]. This policy describes how we process personal data under the EU General Data Protection Regulation (GDPR).
2. Data we process
- Account data: email address, hashed password, plan, language preference (legal basis: contract performance, Art. 6(1)(b) GDPR).
- Scan data: URLs you submit, crawled page URLs, accessibility findings including HTML snippets of affected elements (contract performance). Only scan websites you are authorized to test.
- Free check: the URL you submit and your IP address for rate limiting (legitimate interest, Art. 6(1)(f) GDPR — abuse prevention).
- Alert emails: your email address and alert content (contract performance).
3. Processors and recipients
We use the following categories of processors under data processing agreements: hosting infrastructure, transactional email delivery, and — for paid plans — a merchant of record that processes payments as an independent controller. We do not sell personal data. Current provider list available on request at [email protected].
4. Retention
Account and scan data are retained while your account exists and deleted within 30 days of account deletion. Rate-limiting IP data is retained for a maximum of 24 hours. Backups roll off within 35 days.
5. Your rights
You have the right to access, rectify, erase, restrict and port your personal data, to object to processing based on legitimate interests, and to lodge a complaint with a supervisory authority. Contact [email protected] to exercise these rights.
6. International transfers
Where data is processed outside the EU/EEA, we rely on adequacy decisions or Standard Contractual Clauses.
7. Cookies
We use only technically necessary cookies: a session cookie for authentication and a cookie storing your language preference. No advertising or tracking cookies are set.