Privacy policy

This page loads no fonts, scripts, maps, tracking pixels or videos from third parties. It sets no third-party cookie. This is a translation; the German version is binding.

Controller

Immanuel Schranz, Josef Bierenz-Gasse 10b/4/50, 2700 Wiener Neustadt, Austria.
hallo@konformia.at, +43 660 8591793.

What we process

1. Server logs. When you open this site, our server logs IP address, time, requested address, status code and user agent, to run the service and fend off abuse (Art. 6(1)(f) GDPR). Kept for 14 days, then deleted automatically.

2. The checked address and the report. When you enter a shop address, we open that site and store the result under a random, unguessable address. The report is excluded from search engines and only reachable via its link. It describes the checked website. Legal basis Art. 6(1)(f) GDPR, our interest in providing the service. Kept for 12 months or until you ask us to delete it, whichever comes first.

3. Sending the report and signing up for monitoring. If you enter an email address, we store it, the report it refers to, time and IP address of the sign-up, the wording of the consent shown to you, and time and IP address of your confirmation. Without a click on the confirmation link we send nothing. Legal basis is your consent under Art. 6(1)(a) GDPR and § 174 TKG 2021. We must be able to prove that consent and keep the record until three years after you withdraw it. You can withdraw any time, informally to hallo@konformia.at or via the unsubscribe link in every email.

4. Plans and billing. If you buy a plan, Mollie B.V., Amsterdam, processes the payment. We never see payment details. From Mollie we receive your email address, customer and subscription number and the payment status. We also store which shops you added for monitoring and when we last checked them. Legal basis Art. 6(1)(b) GDPR. Kept for up to seven years after the contract ends, as far as § 132 BAO requires.

5. Your messages to us. We process your message and sender address to answer it (Art. 6(1)(b) and (f) GDPR), as long as the correspondence has a purpose, at most until statutory retention periods end.

6. Measuring our Google ads. If you come through one of our Google ads, Google adds a click ID (gclid) to the address. If you then start a check, we store that ID with the time and send it to Google Ireland Limited, so Google Ads can count how many ad clicks led to a check. We set no cookie for this and load no script from Google. We do not send the shop address, your email address or your IP address. Legal basis Art. 6(1)(f) GDPR. You can object any time under Art. 21 GDPR by writing to us. Kept for 90 days.

7. Sign-in cookie. After you click a sign-in link, we set one cookie that holds only your plan number and an expiry date, signed, with no tracking. It is strictly necessary to keep you signed in and expires after 30 days, or when you click “Sign out”.

8. Shopify app. If you install our app, Shopify gives us the shop address and an access key with the single right to read the shop's policies (read_legal_policies). We store shop address, access key, installation time and the plan status Shopify reports. We have no access to your shop's customers, orders or products. Shopify handles billing. Legal basis Art. 6(1)(b) GDPR. Access key and shop entry are deleted on uninstall and on Shopify's deletion request.

9. Page language. This site exists in German and English. Which one you see first we derive from your browser language and the country of your IP address; the country comes from a table on our own server, the address is not sent anywhere and the country is not stored. If you click “English” or “Deutsch”, we set the cookie lang, which holds only that choice. It is necessary for the service you asked for (Art. 5(3) Directive 2002/58/EC). Kept for one year, or until you delete it in your browser.

Recipients and processors

ServicePurposeLocation
Hetzner Online GmbHHosting, data centre HelsinkiGermany, DC Finland
ImprovMXForwarding of email sent to usUSA
Email inbox providerReceiving and reading email sent to usUSA
Google Ireland LimitedMeasuring our ads (see 6)Ireland, USA
Sinch Email (Mailjet)Sending confirmation and change emailsFrance
Mollie B.V.Payment processingNetherlands
Shopify International Ltd.Only with the Shopify app: installation and billing (see 8)Ireland, Canada
Mistral AILanguage model to classify text on checked websites (cookie banner buttons, checkout notes)France

For transfers to the USA we rely on the EU-US Data Privacy Framework or on standard contractual clauses under Art. 46(2)(c) GDPR. Mistral only receives public text of the checked website, never your email address, IP address or other personal data.

Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21 GDPR). An informal message to hallo@konformia.at is enough.

You may also complain to the supervisory authority: Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, dsb.gv.at.

What we do not do

No third-party cookies, scripts or pixels, no audience measurement, no passing on or selling of addresses, no advertising to addresses that have not confirmed it, and no automated decisions with legal effect under Art. 22 GDPR.

As of 10 October 2026.