WebGainer

Privacy policy

Courtesy translation. The German version is legally binding.

1. In short

You can have a website analysed without creating an account and without giving any personal data. Only when you want to unlock the full report do you provide a first name and an email address. We do not sell data and do not pass it to third parties for advertising purposes.

2. Controller

RAVARO SYSTEMS - FZCO
Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, United Arab Emirates
Email: service@ravaro.de

3. Hosting

This website is hosted by Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA). When you open the site, Vercel processes technically necessary access data (including IP address, time, requested address, browser type) in order to deliver and secure the page. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure and reliable provision). A data processing agreement is in place; transfers to the USA are based on the EU standard contractual clauses.

4. The website analysis

When you enter a website address and start the analysis, we process:

  • the address you entered and the domain name derived from it,
  • optionally the website goal you selected and the campaign source parameter (for example ?src=citicon),
  • the publicly accessible content of the page requested: visible text, technical header data and one screenshot each for desktop and mobile,
  • your IP address in truncated form, to limit abuse.

We open the website in question exactly the way any visitor does. We store the result so that you can look at it again later and so that the same address does not have to be evaluated again within 30 days. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures at your request) or Art. 6(1)(f) GDPR.

We take the screenshots ourselves: a browser without a screen (Chromium) runs on our server and opens the page exactly the way any visitor does. No external screenshot service is involved.

The screenshots are not stored. They are produced during the run, used for the assessment and then discarded. Only the result in text form is stored — the scores and the findings, not the image of your site.

Personal data on the analysed website

The website you enter may contain personal data of third parties, for example names and contact details in the legal notice or photos of staff. We did not collect this data from the data subjects themselves (Art. 14 GDPR); it is publicly accessible on the page requested. We evaluate it solely to produce the analysis requested, never use it for advertising and do not pass it on. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the assessment of his own website requested by the client).

We do not notify these individuals separately. We are not in a position to: we do not know them, do not collect their contact details, and do not store the screenshots on which they might appear. In such cases Art. 14(5)(b) GDPR allows the information to be provided publicly instead — which is what this policy does. Anyone who wants to know whether and what was processed about them can reach us at service@ravaro.de.

Processors used for the analysis

  • Anthropic PBC (San Francisco, USA) — assesses the screenshots and page text. Anthropic does not use content submitted via the API to train models.
  • Google Ireland Ltd. — PageSpeed Insights, measures loading time and layout stability of the analysed page.
  • Supabase Inc. — database and user accounts (hosted in the European Union).
  • Resend (Plus Five Five, Inc., USA) — sends our emails (sign-in link, result email, confirmations).

Data processing agreements under Art. 28 GDPR are in place with all providers. Where data is transferred to the USA, we rely on the European Commission’s adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework (Art. 45 GDPR), provided the respective provider is certified under it, and otherwise on the EU standard contractual clauses under Art. 46(2)(c) GDPR.

A copy of the respective safeguards — the standard contractual clauses or proof of certification — is available on request by email to service@ravaro.de.

5. Account and report

To get the full report you create an account. For this we process your first name and email address. Sign-in works without a password, via a one-time link we send you by email. We use the address to send you your report and to contact you about your analysis. The legal basis is Art. 6(1)(b) GDPR. You can have your account deleted at any time by informal email.

Do you have to provide this data? You are under no legal or contractual obligation to do so. You get the analysis and your score without providing anything. Only the full report requires a first name and email address — without them we cannot assign the report to an account or send it to you. That is the only consequence. The phone number on a draft request is optional; without it we get in touch by email.

6. Booking an appointment

For appointment booking we use Calendly (Calendly LLC, 271 17th St NW, Atlanta, GA 30363, USA). When you pick a time, a Calendly page opens. So that you do not have to type your details a second time, we pass on your name, your email address and — if you provided it — your phone number. Calendly’s own privacy policy additionally applies to the processing that happens there. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures at your request).

7. Marketing emails and your consent

You receive the report and messages about your analysis because you requested them — no separate consent is required for that. Anything beyond this, such as tips and suggestions, we only send if you explicitly ticked the box and then confirmed your consent via the link in our result email (double opt-in). Only after that confirmation will you receive such emails.

As evidence we store the exact wording you agreed to, the time of the request, the time of the confirmation and your IP address in truncated, non-reversible form. The legal basis is Art. 6(1)(a) GDPR in conjunction with Section 7(2)(2) of the German Act Against Unfair Competition (UWG). You may withdraw your consent at any time with effect for the future — by informal email or via the opt-out link in every such message. The lawfulness of processing carried out until then remains unaffected.

8. Browser storage

We do not use cookies for advertising or analytics and we embed no advertising or statistics services. As soon as you sign in, Supabase Auth sets a cookie that keeps your session open. It is strictly necessary for the service you requested and therefore exempt from consent under Section 25(2)(2) TDDDG.

9. Audience measurement

We count how often a page is opened. This creates no record about you: all we store is a counter per day, page and source — for example “home page, 17 August, from the ad: 12”. We store no IP address, no identifier, no timestamp and no history. Nobody can be picked out of those totals afterwards, ourselves included.

No third-party service is involved and nothing is stored on or read from your device — § 25 TDDDG is therefore not engaged and no consent is required. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is to know whether what we publish reaches anyone at all.

10. Automated assessment

The analysis assesses a website, not a person. There is no automated decision in an individual case that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR). We do not build a profile of you as a person.

11. Encryption

This site uses TLS encryption throughout. You can recognise this by the address bar of your browser starting with https://.

12. Retention

  • Analysis results: a stored result is reused for 30 days; after that a fresh measurement is taken on the next request. The analysis is deleted after 90 days at the latest — except for analyses you have sent us an enquiry about (we need those to handle it) and analyses of our own example sites.
  • Account and contact data: until the account is deleted.
  • Evidence of consent given: until withdrawal and thereafter for as long as we must still be able to prove it.
  • Server access data: according to the hosting provider’s policy, usually a few weeks.
  • Statutory retention obligations remain unaffected.

13. Your right to object

You have the right to object at any time to processing of your data based on a legitimate interest (Art. 21(1) GDPR). This concerns hosting access data, abuse prevention and the evaluation of personal data on an analysed website. If you object, we will stop processing that data unless we can demonstrate compelling legitimate grounds overriding your interests, or the processing serves to establish or defend legal claims.

You may object to marketing at any time without giving reasons (Art. 21(2) GDPR). After that we will send you no further marketing. The unsubscribe link in every marketing email is enough — one click, no questions — or an informal message to us.

An objection requires no particular form. An email to service@ravaro.de will do.

14. Your other rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You may withdraw consent at any time with effect for the future (Art. 7(3)); this does not affect the lawfulness of processing carried out beforehand. An email to service@ravaro.de is enough for any of these.

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). You may address the supervisory authority of your habitual residence, your place of work, or the place of the alleged infringement.