Privacy Policy
Last updated: 2026-09-09 · This English version is the binding version of this document.
This Privacy Policy explains how FixRamp ("we", "us") processes personal data when you use fixramp.zalize.com and its scanning services (the "Service"). We designed the Service to collect as little personal data as possible.
1. Data we process
- URLs you submit for scanning. We fetch and analyse the public page(s) at the URL you provide. Scan results (violation metadata, scores, a page screenshot) are stored for up to 30 days so that your PDF audit links keep working, then deleted.
- Email address — only if you voluntarily join the early-access / waitlist or contact us. We store it with a timestamp and the context in which you provided it. We use it solely to respond to you and to inform you about the Service. We do not sell or share it.
- Local browser storage. Your scan history and language preference are stored in your own browser (localStorage), not on our servers. You can clear them at any time via your browser settings.
- Technical logs. Our hosting provider (Cloudflare) processes IP addresses and request metadata to deliver and protect the Service (legitimate interest, Art. 6(1)(f) GDPR).
2. What we do not do
- No advertising or cross-site tracking, no analytics cookies, no fingerprinting.
- We do not sell personal data.
- We do not scan pages behind authentication.
3. Legal bases
We process data to perform the Service you request (Art. 6(1)(b) GDPR), based on your consent where you provide your email (Art. 6(1)(a)), and based on our legitimate interest in operating and securing the Service (Art. 6(1)(f)).
4. Processors and transfers
The Service runs on Cloudflare (edge hosting, storage). AI fix suggestions are generated by a large-language-model API processor that receives only the failing HTML snippet and rule context — never your email or identity. Processors are bound by data-processing agreements; where data leaves the EEA, standard contractual clauses apply.
5. Retention
- Scan results and reports: 30 days.
- Waitlist / contact emails: until you ask us to delete them or the purpose ends.
6. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict or object to the processing of your personal data, the right to data portability, and the right to lodge a complaint with a supervisory authority. To exercise any right, contact us via the contact page.