Privacy Policy

In short

This site collects nothing about you. No cookies, no analytics, no trackers, no counters, no pixels. Not a single request to a third-party domain when the page loads.

We audit other people’s sites for exactly these things. It would be strange to behave otherwise ourselves.

And you can verify it. Open your developer tools, go to the “Network” tab, reload the page. Every request goes only to gdpru.eu. Fonts and scripts sit on our own server, not on Google Fonts or a CDN.

Who is responsible for the site

The gdpru.eu project, Estonia. Contact for any data-related questions: contact@gdpru.eu

What happens when you open a page

Your IP address is processed at the moment the page is delivered — without it your browser physically cannot receive data over the network. It is not stored anywhere.

The hosting logs contain no personal data: they record only the request method, host name, duration, response size and status code. No IP, no user-agent. Logs are kept for no more than 7 days, after which they are deleted.

The legal basis is legitimate interest in the operation and security of the site, Art. 6(1)(f) GDPR. No consent is required here: nothing is stored on or read from your device.

Who the data goes to

Hosting: statichost.eu (Sweden) — a processor under Art. 28 GDPR, with a data processing agreement signed by both parties. Sub-processors: Actually engaged sub-processor: Hetzner Online GmbH (Germany). The site is served only from their servers — confirmed in writing by the hosting operator.

Approved but not engaged: BunnyWay d.o.o. (Slovenia) — CDN. It is listed among the approved sub-processors and may be enabled in the future; at present no data passes through it.

All within the EU/EEA. There are no transfers to third countries.

Beyond that — no one. We have no ad networks, analytics systems or partners.

About the audit archive

We publish site audits, the texts of privacy policies and the results of technical measurements. These materials may contain personal data — for example, the name and work email of the person responsible for data protection, which the company itself listed in its public policy.

We do this as journalistic and research work: the subject is how companies and public authorities handle people’s data, and that is a matter of public interest. The legal bases are set out below, in “Legal bases in detail”.

How we limit ourselves:

If you are mentioned in an audit and believe your rights are affected disproportionately, write to contact@gdpru.eu. We will look into it on the merits.

Your rights

You have the right to request access to your data, its correction or deletion, and to object to processing. Write to contact@gdpru.eu.

A practical caveat: since we do not store visitors’ data, for an ordinary visit to the site we simply have nothing to hand over or delete.

If our response does not satisfy you, you can lodge a complaint with Estonia’s supervisory authority — Andmekaitse Inspektsioon (AKI), aki.ee.

This section is for lawyers, regulators and anyone who wants to check us the same way we check others. It is all the same, but with the exact provisions.

These are two different processing operations, and they must not be confused

The first — site visitors. The second — personal data that ends up in the audit archive. They have different bases, different retention periods and different rights. We address them separately.

1. Site visitors

What is processed. Only the IP address, and only at the moment the page is delivered. We acknowledge outright: an IP address is personal data — established by the Court of Justice of the EU in the Breyer case (C-582/14). We do not try to hide behind the wording “technical data”, as many of the sites we audit do.

ePrivacy, Art. 5(3). We do not need consent to store information on the user’s device or access it — because we store nothing and access nothing. No cookies, no localStorage, no fingerprinting. The provision simply does not apply to us: there is nothing to apply it to.

GDPR, Art. 6(1)(f) — legitimate interest. We pass the test from Recital 47 in three steps:

Logs. Contain no personal data: request method, host name, duration, response size, status code. No IP, no user-agent. Retention — up to 7 days.

Processor and sub-processors. statichost.eu (Sweden) — a processor under Art. 28 GDPR, with a data processing agreement signed by both parties. Sub-processors: Hetzner Online GmbH (Germany). All within the EU/EEA; Chapter V (transfers to third countries) is not engaged at all.

2. The audit archive

What ends up in the archive. The texts of audited sites’ privacy policies, HAR measurement files, correspondence with companies and regulators. They contain personal data — above all the names and work contacts of those responsible for data protection (DPOs).

The first basis — Art. 85 GDPR, implemented in Estonia through IKS § 4 (processing for journalistic purposes) and § 5 (academic expression). § 4 permits processing without consent where three conditions are met together, and we address each:

The second basis — Art. 6(1)(f) for the part not covered by the journalistic exemption.

About DPO contacts specifically. Publishing them is not an intrusion: under Art. 37(7) GDPR a company is obliged to publish its DPO’s contacts and communicate them to the supervisory authority. This is a professional contact, disclosed by the company itself and intended precisely for data-related enquiries. We do not obtain this information — we quote what is already published.

How we limit ourselves (safeguards under Art. 89(1)):

Why we do not notify everyone mentioned (Art. 14). The data is obtained not from the subject but from public sources and our own network measurements. Art. 14(5)(b) exempts from notification where it is impossible or would require a disproportionate effort — in particular for processing for archiving purposes in the public interest and scientific research, subject to the safeguards of Art. 89(1).

Ours is exactly such a case. We do not collect people’s contacts — we record the text an organisation has published itself, together with everything in it. Personal data ends up in the archive as part of the quoted document, not as an aim. Individually notifying every person mentioned in someone else’s public policies would require an effort disproportionate both to the volume of processing and to its negligible impact on those people’s rights: these are work contacts disclosed by the organisations themselves precisely for data-related enquiries.

In place of notification we apply an alternative measure expressly provided for by Art. 14(5)(b) — public disclosure. This policy is publicly available, the methodology is published, all measurements are reproducible, and you can contact us at any time: contact@gdpru.eu.

Retention periods

Site visitors: zero. There is nothing to keep.

The archive: indefinitely — and this is not carelessness but the point.

The purpose of the archive is to record what an organisation stated on a specific date. To delete a snapshot is to destroy the evidence itself and strip the project of its meaning. Art. 5(1)(e) expressly permits longer storage where data is processed solely for archiving purposes in the public interest, scientific or historical research, or statistical purposes — subject to the safeguards of Art. 89(1). This is the regime we operate in.

Your rights — and where they are limited

We will not pretend that Art. 85 imposes no obligations on us, nor will we pretend it does not exist.

For site visitors the rights work fully — there is simply nothing to apply them to: we store nothing.

For the archive, Art. 85 allows Member States to derogate from chapters of the GDPR, including Chapter III (data subject rights), in order to reconcile data protection with freedom of expression and information. Estonia has exercised this right in IKS § 4.

What this means in practice. We do not refuse automatically by citing the exemption. Every request is considered on the merits:

We respond within 30 days (Art. 12(3)) — the very deadline whose observance we check in others.

What we do not do

Changes

If the policy changes, a new date will appear here. Previous versions are preserved in the project’s repository history — like everything else.

Updated: 12 July 2026.