Priventia ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services. It covers priventia.com, the Priventia Platform, and scan.priventia.com, where we provide the Priventia Compliance Scan.
We collect information that you provide directly to us, including:
Information may also be obtained from publicly accessible websites submitted to the Priventia Compliance Scan, as described in section 4.
We use the information we collect to:
Where these activities rely on our legitimate interests, including fraud prevention and network and information security, we carry out the required balancing of those interests against your rights and reasonable expectations.
Priventia provides the Priventia Compliance Scan, an automated service that reviews publicly accessible information about a submitted website and produces a Regulatory Intelligence Snapshot.
The Scan is designed to identify observable compliance-related signals and to indicate regulatory frameworks that may be relevant to what was observed. It does not access authenticated areas, bypass access controls or perform intrusive security testing.
When you submit a website for scanning, we may process:
A public website may contain names, business contact details or other personal data relating to individuals. Where the Scan encounters such information, the source is the publicly accessible website submitted for review. Priventia processes such information only where necessary to identify or evidence compliance-relevant website characteristics. The Scan is not designed to identify, profile or contact individuals appearing on the submitted website.
We process this information to provide the Compliance Scan and Regulatory Intelligence Snapshot requested by you; operate, secure and protect the Scan service; prevent abuse and excessive automated use; maintain the integrity and traceability of Scan evidence and results; investigate technical failures; and improve the reliability and quality of the service.
Depending on the circumstances, our legal basis is performance of a contract or steps taken at your request before entering into a contract where Article 6(1)(b) GDPR applies, or our legitimate interests under Article 6(1)(f) GDPR in providing the requested service to organisations, operating and securing Priventia, preventing misuse and maintaining reliable compliance intelligence. We may also process information where necessary to comply with a legal obligation under Article 6(1)(c) GDPR.
Where we rely on legitimate interests, we consider the nature of the information, the publicly accessible context in which relevant website information appears, the limited and compliance-focused purposes of the Scan, and the rights and reasonable expectations of affected individuals.
The Compliance Scan uses automated technical collection and analysis to produce evidence, observational signals and indications of regulatory frameworks that may be relevant.
A Scan result is not an automated decision about an individual and does not produce legal or similarly significant effects concerning an individual.
Where Priventia does not have sufficient information to determine jurisdiction, applicability or another relevant fact, the Snapshot may expressly identify that matter as undetermined rather than infer a conclusion.
A Regulatory Intelligence Snapshot may be made available through a unique capability URL generated for the Scan request. Possession of that URL may permit access to the corresponding Snapshot, so you should share it only with people whom you intend to have access.
The customer-facing Snapshot does not expose Priventia's internal diagnostic or failure information.
Scan requests, authority assertions, technical request records, collected evidence, generated signals and Snapshots are retained only for as long as necessary to provide and operate the Scan, maintain security and integrity, investigate failures, meet legitimate operational or evidential requirements, and comply with applicable legal obligations. They are then deleted, anonymised or otherwise handled in accordance with Priventia's retention practices.
Security and abuse-prevention records may be retained for a different period where reasonably necessary to investigate misuse or protect Priventia's systems.
Providing an email address with a scan is optional. Where you provide one, we use it to send you the link to your Regulatory Intelligence Snapshot when the scan completes, and to contact you about the scan and related Priventia services. We state these purposes at the point of collection. You can ask us to stop contacting you, or to delete the address, at any time by writing to hello@priventia.com. The email address is stored separately from the scan itself and is retained on the same criteria described above.
The public Compliance Scan does not currently require you to create a Priventia account.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. This includes encryption, access controls, and regular security assessments.
Depending on your jurisdiction, you may have the following rights:
To exercise any of these rights, write to hello@priventia.com. If you are in the European Union, you also have the right to lodge a complaint with your national supervisory authority. Priventia is established in the Netherlands, where that authority is the Autoriteit Persoonsgegevens.
Your information may be transferred to and processed in countries other than your country of residence. We maintain appropriate safeguards for such transfers in compliance with applicable data protection laws.
If you have questions about this Privacy Policy or our privacy practices, please contact us at hello@priventia.com.
Priventia. Registered in the Netherlands, Rotterdam. KVK 42143235. hello@priventia.com