VitalSite

Privacy Notice

Version 1.0 · Effective 2026-09-18

This is a template drafted for VitalSite's launch and has not been reviewed by DACH counsel. Insert the real controller identity and registered address below, and obtain a qualified legal review (GDPR/TTDSG) before relying on it.

1. Controller

VitalSite [legal entity name, address — placeholder] is the controller for the personal data described below. Contact: privacy@vitalsite.example (placeholder).

2. Data we process about you

We process the following categories of personal data, with the legal basis noted for each:

  • Account data (email address, name, login events) — to provide the Service and secure your account (contract performance, Art. 6(1)(b) GDPR).
  • Organization data (organization name, member roles, invitations) — contract performance.
  • Billing data (handled by our payment processor; we store plan tier and subscription status, not card numbers) — contract performance and legal retention obligations (Art. 6(1)(c)).
  • Website configuration and scan results for sites you add — contract performance. Scan results may incidentally include technical data exposed by websites you scan (e.g. detected cookie names, tracker domains, HTTP headers); this is processed on your instruction as part of the scanning service.
  • Support and compliance requests (e.g. DPA requests) — legitimate interest in administering the Service (Art. 6(1)(f)).

3. Recipients and subprocessors

We share personal data with the infrastructure and service providers described on our Subprocessors page (hosting, database, object storage, email delivery, payment processing, error monitoring), each under a data-processing agreement.

4. International transfers

Where a subprocessor is located outside the EEA, transfers are made under an adequacy decision or Standard Contractual Clauses, as listed on the Subprocessors page.

5. Retention

Account, organization, and scan data are retained for as long as your organization is active. If you delete your organization, we delete this data on a rolling basis, except billing and audit-log records, which are retained only as long as legally required (typically tax/commercial retention periods).

6. Your rights

Subject to applicable law, you have the right to access, rectify, erase, or restrict processing of your personal data, to receive it in a portable format, and to object to processing based on legitimate interest. You can export or delete your organization's data yourself from Organization Settings, or contact us at the address in Section 1. You also have the right to lodge a complaint with your local data protection supervisory authority.

7. Cookies on vitalsite.example

We use a small number of strictly necessary cookies to operate the Service: a session cookie (vs_session) that keeps you signed in, and short-lived cookies used only during Google sign-in to prevent request forgery. We do not use advertising or analytics cookies on VitalSite itself.

8. Automated decision-making

Health scores and findings are automated technical observations, not automated decisions with legal or similarly significant effects on you within the meaning of Art. 22 GDPR.

9. Changes to this notice

We will post material changes here with an updated version and effective date, and notify organization owners by email in advance of changes that materially affect how we process your data.

10. Contact

privacy@vitalsite.example (placeholder — update once a support mailbox and, if required, a DPO exist).