Skip to content
SiteUpward

Privacy Policy

Last updated: September 29, 2026

This policy explains what personal data we process when you visit our website, use SiteUpward, run a check, buy an audit or subscription, receive our e-mails or contact us, and what rights you have. We serve customers worldwide. Because we are established in the European Union, we apply the standards of the EU General Data Protection Regulation (GDPR) to everyone, wherever they live; this policy also covers the UK GDPR, the Swiss Federal Act on Data Protection (FADP), US state privacy laws and the privacy laws of other countries. It also explains what we process about websites that are audited with SiteUpward.

1. Controller

The controller of your personal data is SIA "MICRON", registration no. 42103081578, VAT number LV42103081578, Aldaru iela 36/38–21, Liepāja, LV-3401, Latvia (“we”, “us”, “our”).

For any privacy question or to exercise your rights, write to privacy@siteupward.com. We are not required to appoint a data protection officer; messages to this address reach the people responsible for data protection at our company.

2. Scope

This policy covers our website, the SiteUpward application, our e-mails and our support, for users anywhere in the world. Section 14 explains what we process about audited websites and about people whose information appears on them.

Where a business customer uses SiteUpward to audit websites for its own clients, we may process some personal data on that customer's behalf. That processing is governed by our Data Processing Agreement.

Your rights depend on where you live: section 9 covers the EU/EEA, the UK and Switzerland, sections 10 and 11 the United States, and section 12 other countries. If the law of your country gives you more rights than this policy describes, we respect them.

3. Personal data we process

CategoryWhat it includesSource
Account dataE-mail address, optional name, preferred language, marketing preference, and the dates your account was created, your e-mail address was confirmed and you last signed in.You
Sign-in and session dataSingle-use sign-in links (stored only in hashed form) with their expiry and the page you wanted to open; the IP address from which a link was requested; session records with a hashed token, expiry, last activity, IP address and browser user agent.You, automatically
Audit dataWebsite addresses you submit, the resulting reports and scores, the IP address from which a check was started, an e-mail address entered in “e-mail me this report”, share links you create, and a hashed browser token for checks run without an account.You, automatically
Public website contentPage addresses, titles, headings, short text excerpts and technical measurements of public pages fetched for an audit. These can include personal data that a website publishes, such as names or business contact details.Public websites
Purchase and billing dataProducts bought, amounts, taxes, currency, payment, subscription and refund status, credits, and the payment processor's customer and payment references. The payment processor collects your name, billing address, tax ID such as a VAT number (if any) and payment details; we can access them in its systems when needed for billing, tax or support. We never store card numbers.You, payment processor
CommunicationsMessages you send us and our replies.You
Technical and security dataServer logs with IP address, date and time, requested page (without query parameters), response status, referring page, browser user agent and a request identifier; short-lived rate-limit counters based on IP address, network or e-mail address; the result of the human-verification check.Automatically
Device storageCookies and local storage as described in our Cookie Policy.Automatically

You are not obliged to give us personal data. Without an e-mail address, however, we cannot create an account, send sign-in links or deliver paid audits, and without billing details we cannot process a purchase.

5. Recipients

We use carefully selected service providers that process personal data on our behalf under data processing agreements and only on our instructions. We list them by category below; a current list of providers is available on request at privacy@siteupward.com.

CategoryPurposeDataLocation
Hosting providerServers, database and backups of the ServiceAll data described in section 3European Union
Backup storage providerOff-site copies of our database backupsData stored in our databaseEuropean Union
AI analysis providerAI-assisted analysis of audited pagesPublic page content only (page address, title and text) – never your account or billing dataMay be outside the EEA (section 6)
Payment processorCheckout, payments, invoices, tax calculation, billing portal and fraud preventionName, e-mail address, billing address, tax ID (such as a VAT number), payment details and purchase detailsEEA; may transfer data outside the EEA (section 6)
E-mail delivery providerSending sign-in links, report notifications and receiptsE-mail address and the content of the e-mailMay be outside the EEA (section 6)
Bot-protection providerHuman verification on the free-check and sign-in formsIP address and technical browser and device signalsMay be outside the EEA (section 6)
Internal team messagingOperational notifications to our teamE-mail address, product, plan and amount of purchases, subscription events, a tax ID (such as a VAT number) that could not be verified automatically, audited domain namesMay be outside the EEA (section 6)

For some purposes, such as fraud prevention and its own legal obligations, the payment processor acts as an independent controller under its own privacy notice, which is linked on its checkout page.

If we use further providers to monitor errors in our software or to deliver and protect network traffic to our website, they receive only technical data, such as IP addresses, request details and error reports, under the same contractual and transfer safeguards.

We may also disclose personal data to professional advisers bound by confidentiality (such as accountants, auditors and lawyers), to authorities where we are legally required to, and to a successor in a merger or acquisition, which must respect this policy. Anyone who has a share link that you created can view the report behind it.

6. International transfers

Our database and backups are stored in the European Union. If you use the Service from outside the EU, your personal data is transferred to the EU and protected there by the GDPR. Some of the providers listed in section 5 may process data outside the European Economic Area (EEA). Where the destination country is not covered by an adequacy decision of the European Commission, we rely on the European Commission's Standard Contractual Clauses, with additional safeguards where needed. For providers certified under the EU–U.S. Data Privacy Framework, transfers rely on the corresponding adequacy decision.

For personal data of people in the United Kingdom, we rely on UK adequacy regulations or on the Standard Contractual Clauses together with the UK International Data Transfer Addendum. For personal data of people in Switzerland, we rely on adequacy decisions of the Swiss Federal Council or on the Standard Contractual Clauses with the adjustments required by the FADP.

You can request information about these safeguards, or a copy of them, at privacy@siteupward.com.

7. How long we keep data

DataRetention
Account dataAs long as your account exists. When you ask us to close your account, we delete or anonymise your data within 30 days, except data we must keep by law.
Sign-in linksValid for 20 minutes (sign-in), 1 hour (purchase links) or 24 hours (address confirmation links); deleted 7 days after use or expiry.
Sessions30 days or until you sign out, whichever comes first; then deleted.
Reports in your accountAs long as your account exists, or until you ask us to delete them. For free checks, the detailed page analysis (AI assessments, text excerpts and page measurements) is deleted after 30 days; the score, findings and page titles remain.
Free checks run without an accountDetailed page analysis deleted after 30 days; the whole check deleted after 12 months.
IP address stored with a checkCleared automatically 30 days after the check was started.
“E-mail me this report” address stored with a checkAs long as the check itself is kept (see above).
Purchase and billing recordsAs long as your account exists and afterwards for as long as Latvian accounting and tax law requires – generally 5 years after the end of the financial year of the transaction, or longer where the tax law of another country that applies to the sale requires it.
Rate-limit countersUp to 24 hours.
Server logsUp to 30 days.
Internal team notificationsDeleted when no longer needed, at the latest after 12 months.
Support correspondenceUp to 3 years after your request has been closed, to handle follow-up questions and legal claims.
BackupsKept on a rolling basis and overwritten, normally within 30 days. Data deleted from the live system disappears from backups when they expire.

When a retention period ends, we delete the data or anonymise it so that it no longer identifies you.

8. Security

We protect personal data with technical and organisational measures appropriate to the risk, including: encryption in transit for all connections; session, sign-in and browser tokens stored only as keyed hashes; single-use, short-lived sign-in links; strict access control, with access to production systems limited to authorised personnel; network separation so that our databases are not reachable from the internet; rate limiting and bot protection; removal of query parameters from logs; regular, integrity-checked backups; and prompt security updates.

No method of transmission or storage is completely secure. If a personal data breach is likely to result in a risk to your rights, we will inform the supervisory authority and, where required, you, as the law requires.

9. Your rights in the EU/EEA, the UK and Switzerland

If you live in the European Union or the European Economic Area, you have the following rights under the GDPR. If you live in the United Kingdom, you have the same rights under the UK GDPR, and if you live in Switzerland, comparable rights under the FADP. You have the right to:

  • access your personal data and receive a copy of it;
  • have inaccurate data corrected;
  • have your data erased, for example when it is no longer needed or you withdraw consent;
  • restrict the processing of your data in certain circumstances;
  • receive data you provided to us in a structured, commonly used, machine-readable format and have it transmitted to another controller (data portability);
  • object at any time to processing based on legitimate interests, on grounds relating to your particular situation, and to direct marketing without giving any reason;
  • withdraw your consent at any time, without affecting the lawfulness of processing before the withdrawal.

You can change your name, language and e-mail preferences yourself in your account settings. For any other request, e-mail privacy@siteupward.com from the address linked to your account, or tell us how we can verify your identity. We respond within one month; for complex requests this can be extended by two further months, in which case we tell you why. Exercising your rights is free of charge unless requests are manifestly unfounded or excessive.

You also have the right to lodge a complaint with a data protection authority. Our lead supervisory authority is the Data State Inspectorate of Latvia (Datu valsts inspekcija), Elijas iela 17, Rīga, LV-1050, www.dvi.gov.lv. You may also complain to the authority in your own country, in particular where you live or work or where the alleged infringement took place – for example the Information Commissioner's Office in the United Kingdom or the Federal Data Protection and Information Commissioner in Switzerland. We would appreciate the chance to address your concern first.

10. Additional information for United States residents

This section applies to residents of California and of other US states with comprehensive consumer privacy laws, such as Colorado, Connecticut, Delaware, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Utah and Virginia. It supplements the rest of this policy and is our notice at collection under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA). We honour the requests described in section 11 from residents of every US state.

In the last 12 months, we have collected the following categories of personal information. Section 3 describes the data in detail, section 4 the purposes, section 5 the categories of recipients and section 7 how long we keep each category.

CategoryWhat we collectSourcesBusiness purposes
IdentifiersE-mail address, optional name, IP address, account and session identifiers, and the payment processor's customer referencesYou; automaticallyProviding your account and the Service, sign-in, service e-mails, security and fraud prevention
Customer records (Cal. Civ. Code § 1798.80(e))Name, billing address and payment details, collected by our payment processor; we never store card numbersYou, through the payment processorProcessing payments, issuing invoices and calculating taxes
Commercial informationProducts bought, amounts, taxes, credits, subscriptions and refundsYou; the payment processorProviding what you bought, billing, accounting and customer support
Internet or other electronic network activityWebsite addresses you submit for checks, sign-in and session records, server logs with browser user agent and requested pages, and human-verification signalsYou; automaticallyProviding and securing the Service, preventing abuse and fixing errors
Approximate locationYour country or region, derived from your billing address or IP address; we do not collect precise geolocationYou; automaticallyCalculating taxes, security
Professional informationNames, job titles and business contact details that appear on public websites audited with the ServicePublic websitesProducing the reports that users request (section 14)
Sensitive personal informationPayment card details, entered only on the payment processor's checkout pagesYou, through the payment processorProcessing payments only; never to infer characteristics about you

We do not create profiles or draw inferences about you, and we do not collect biometric, health or precise geolocation data.

We disclose personal information for business purposes only to the categories of service providers and contractors listed in section 5, to professional advisers bound by confidentiality, and to authorities where the law requires it.

We do not sell or share personal information, and we do not use it for targeted advertising or for profiling that produces legal or similarly significant effects. In the last 12 months, we have not sold personal information or shared it for cross-context behavioral advertising, including personal information of consumers under 16.

11. Your privacy rights in the United States

Depending on the state where you live, you have the right to:

  • know what personal information we have collected about you, including the categories and specific pieces of information, their sources, the purposes for collecting them and the categories of recipients, and receive a copy in a portable format;
  • have personal information that we collected from you deleted, subject to exceptions allowed by law, for example records we must keep for tax purposes;
  • have inaccurate personal information corrected;
  • opt out of the sale or sharing of personal information, of targeted advertising and of profiling that produces legal or similarly significant effects – we do none of these, so there is nothing to opt out of;
  • limit the use of sensitive personal information – we already use it only to process payments;
  • not be discriminated against for exercising your rights: we will not deny you the Service, charge you different prices or give you a different quality of service because you exercised them.

To exercise your rights, e-mail privacy@siteupward.com. We verify your request by matching it with information we already hold, usually by asking you to write from, or confirm through, the e-mail address linked to your account. We confirm receipt within 10 business days and respond within 45 days; if we need more time, up to a further 45 days, we tell you why.

You may use an authorised agent to make a request on your behalf. We ask the agent for proof of your signed permission and may ask you to verify your identity directly with us, unless the agent holds a valid power of attorney.

If we decline your request, you may appeal by replying to our decision. We tell you the outcome of your appeal and the reasons for it within the period set by the law of your state; if you disagree, you can contact the attorney general of your state.

Global Privacy Control: because we do not sell or share personal information or use it for targeted advertising, there is nothing to opt out of. If your browser sends a Global Privacy Control signal, we nevertheless treat it as a valid request to opt out of the sale and sharing of personal information linked to that browser.

California residents may also ask us once a year whether we have disclosed personal information to third parties for their own direct marketing purposes (Cal. Civ. Code § 1798.83). We do not make such disclosures.

12. Other countries

If you live in another country – for example Canada, Australia, New Zealand, Brazil, Japan, South Korea, Singapore, India or South Africa – we protect your personal data to the same standard described in this policy. You can ask us to give you access to your personal data, correct it or delete it, to stop using it for a particular purpose, or to withdraw your consent, as described in section 9. Where the law of your country gives you further rights, we respect them.

Your personal data is processed in the European Union and, through our service providers, in other countries as described in section 6.

To make a request, e-mail privacy@siteupward.com. You may also complain to the data protection or privacy authority of your country; we would appreciate the chance to address your concern first.

13. Automated decision-making

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, and we do not profile individuals. Our audits assess websites, not people.

Automated protective measures – such as rate limits, free-check limits and human verification – can temporarily block a request. If you believe you were blocked by mistake, contact us and a member of our team will review it.

14. Website owners and people named on audited websites

SiteUpward audits publicly accessible websites at the request of its users, including websites that the user does not own. For an audit, our crawler fetches the website's robots.txt, sitemaps and a limited number of public pages, as described on our crawler page.

We store the page addresses, titles, headings, short excerpts used as evidence, technical measurements and the resulting findings. If public pages contain personal data – for example an author's name or a business contact – it can appear in this data. We process it on the basis of legitimate interests (Art. 6(1)(f) GDPR) only to produce the requested report, keep it as described in section 7, and do not use it to contact, profile or track anyone or to train AI models.

Website owners can block our crawler through robots.txt or ask us to exclude their domain from future audits. Anyone can object to this processing or ask us to remove data about them from reports by writing to privacy@siteupward.com with the page address concerned.

15. Children and minimum age

The Service is intended for business and professional use and is not directed at children. If you live in the European Union or the European Economic Area, you must be at least 16 years old to use it, unless the law of your country sets a lower age for consenting to online services (which is never below 13). Elsewhere, you must be at least 13 years old. To buy products, you must be old enough to enter into a binding contract where you live.

We do not knowingly collect personal data from children below these ages. If you believe that a child has given us personal data, please contact privacy@siteupward.com and we will delete it.

16. Changes to this policy

We may update this policy when our Service, our providers or legal requirements change. We will inform registered users of material changes by e-mail or in the Service before they take effect. The date at the top of this page shows the current version.

17. Contact

SIA "MICRON", Aldaru iela 36/38–21, Liepāja, LV-3401, Latvia. Privacy and data protection: privacy@siteupward.com. Other questions: support@siteupward.com.