Privacy Policy
Last updated: September 29, 2026
This policy explains what personal data we process when you visit our website, use SiteUpward, run a check, buy an audit or subscription, receive our e-mails or contact us, and what rights you have. We serve customers worldwide. Because we are established in the European Union, we apply the standards of the EU General Data Protection Regulation (GDPR) to everyone, wherever they live; this policy also covers the UK GDPR, the Swiss Federal Act on Data Protection (FADP), US state privacy laws and the privacy laws of other countries. It also explains what we process about websites that are audited with SiteUpward.
1. Controller
The controller of your personal data is SIA "MICRON", registration no. 42103081578, VAT number LV42103081578, Aldaru iela 36/38–21, Liepāja, LV-3401, Latvia (“we”, “us”, “our”).
For any privacy question or to exercise your rights, write to privacy@siteupward.com. We are not required to appoint a data protection officer; messages to this address reach the people responsible for data protection at our company.
2. Scope
This policy covers our website, the SiteUpward application, our e-mails and our support, for users anywhere in the world. Section 14 explains what we process about audited websites and about people whose information appears on them.
Where a business customer uses SiteUpward to audit websites for its own clients, we may process some personal data on that customer's behalf. That processing is governed by our Data Processing Agreement.
Your rights depend on where you live: section 9 covers the EU/EEA, the UK and Switzerland, sections 10 and 11 the United States, and section 12 other countries. If the law of your country gives you more rights than this policy describes, we respect them.
3. Personal data we process
| Category | What it includes | Source |
|---|---|---|
| Account data | E-mail address, optional name, preferred language, marketing preference, and the dates your account was created, your e-mail address was confirmed and you last signed in. | You |
| Sign-in and session data | Single-use sign-in links (stored only in hashed form) with their expiry and the page you wanted to open; the IP address from which a link was requested; session records with a hashed token, expiry, last activity, IP address and browser user agent. | You, automatically |
| Audit data | Website addresses you submit, the resulting reports and scores, the IP address from which a check was started, an e-mail address entered in “e-mail me this report”, share links you create, and a hashed browser token for checks run without an account. | You, automatically |
| Public website content | Page addresses, titles, headings, short text excerpts and technical measurements of public pages fetched for an audit. These can include personal data that a website publishes, such as names or business contact details. | Public websites |
| Purchase and billing data | Products bought, amounts, taxes, currency, payment, subscription and refund status, credits, and the payment processor's customer and payment references. The payment processor collects your name, billing address, tax ID such as a VAT number (if any) and payment details; we can access them in its systems when needed for billing, tax or support. We never store card numbers. | You, payment processor |
| Communications | Messages you send us and our replies. | You |
| Technical and security data | Server logs with IP address, date and time, requested page (without query parameters), response status, referring page, browser user agent and a request identifier; short-lived rate-limit counters based on IP address, network or e-mail address; the result of the human-verification check. | Automatically |
| Device storage | Cookies and local storage as described in our Cookie Policy. | Automatically |
You are not obliged to give us personal data. Without an e-mail address, however, we cannot create an account, send sign-in links or deliver paid audits, and without billing details we cannot process a purchase.
4. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and managing your account, sending sign-in links, running audits, showing reports, adding credits and sending service e-mails such as report-ready notices and receipts | Performance of a contract or steps taken at your request before entering into one – Art. 6(1)(b) |
| Running free checks without an account and linking them to your browser | Art. 6(1)(b); our legitimate interest in offering a free trial – Art. 6(1)(f) |
| Confirming an address entered in “e-mail me this report” before we send anything to it | Art. 6(1)(b); our legitimate interest in not e-mailing people who did not ask for it – Art. 6(1)(f) |
| Processing payments, issuing invoices, calculating and reporting taxes, handling refunds and payment disputes, keeping accounting records | Art. 6(1)(b); legal obligations under Latvian accounting and tax law and, where we must collect tax in another country, its tax law – Art. 6(1)(c) |
| Protecting the Service and audited websites: security, fraud and abuse prevention, rate limits, free-check limits, human verification, logs and backups | Our legitimate interest in a secure and reliable service – Art. 6(1)(f) |
| Internal notifications to our team about new accounts, purchases, subscription changes, refunds, payment disputes and failed audits, so we can support customers and react to problems quickly | Our legitimate interest in running and supporting the Service – Art. 6(1)(f) |
| Crawling and analysing public websites that users ask us to audit | The legitimate interests of our users and us in analysing public websites – Art. 6(1)(f) |
| Answering your questions and support requests | Art. 6(1)(b) or our legitimate interest in answering enquiries – Art. 6(1)(f) |
| Sending product news by e-mail, only if you opted in | Consent – Art. 6(1)(a). You can withdraw it at any time in your account settings or by e-mailing us. |
| Improving the Service with aggregated statistics | Our legitimate interest in improving the Service – Art. 6(1)(f) |
| Establishing, exercising or defending legal claims and responding to lawful requests from authorities | Art. 6(1)(c) and Art. 6(1)(f) |
Where we rely on legitimate interests, we have weighed them against your interests and rights; you can ask us for details and object at any time (section 9). We do not sell personal data, do not use it for advertising and do not share it with data brokers.
The UK GDPR provides the same legal bases. Where the law of another country applies, we rely on the equivalent grounds it provides.
5. Recipients
We use carefully selected service providers that process personal data on our behalf under data processing agreements and only on our instructions. We list them by category below; a current list of providers is available on request at privacy@siteupward.com.
| Category | Purpose | Data | Location |
|---|---|---|---|
| Hosting provider | Servers, database and backups of the Service | All data described in section 3 | European Union |
| Backup storage provider | Off-site copies of our database backups | Data stored in our database | European Union |
| AI analysis provider | AI-assisted analysis of audited pages | Public page content only (page address, title and text) – never your account or billing data | May be outside the EEA (section 6) |
| Payment processor | Checkout, payments, invoices, tax calculation, billing portal and fraud prevention | Name, e-mail address, billing address, tax ID (such as a VAT number), payment details and purchase details | EEA; may transfer data outside the EEA (section 6) |
| E-mail delivery provider | Sending sign-in links, report notifications and receipts | E-mail address and the content of the e-mail | May be outside the EEA (section 6) |
| Bot-protection provider | Human verification on the free-check and sign-in forms | IP address and technical browser and device signals | May be outside the EEA (section 6) |
| Internal team messaging | Operational notifications to our team | E-mail address, product, plan and amount of purchases, subscription events, a tax ID (such as a VAT number) that could not be verified automatically, audited domain names | May be outside the EEA (section 6) |
For some purposes, such as fraud prevention and its own legal obligations, the payment processor acts as an independent controller under its own privacy notice, which is linked on its checkout page.
If we use further providers to monitor errors in our software or to deliver and protect network traffic to our website, they receive only technical data, such as IP addresses, request details and error reports, under the same contractual and transfer safeguards.
We may also disclose personal data to professional advisers bound by confidentiality (such as accountants, auditors and lawyers), to authorities where we are legally required to, and to a successor in a merger or acquisition, which must respect this policy. Anyone who has a share link that you created can view the report behind it.
6. International transfers
Our database and backups are stored in the European Union. If you use the Service from outside the EU, your personal data is transferred to the EU and protected there by the GDPR. Some of the providers listed in section 5 may process data outside the European Economic Area (EEA). Where the destination country is not covered by an adequacy decision of the European Commission, we rely on the European Commission's Standard Contractual Clauses, with additional safeguards where needed. For providers certified under the EU–U.S. Data Privacy Framework, transfers rely on the corresponding adequacy decision.
For personal data of people in the United Kingdom, we rely on UK adequacy regulations or on the Standard Contractual Clauses together with the UK International Data Transfer Addendum. For personal data of people in Switzerland, we rely on adequacy decisions of the Swiss Federal Council or on the Standard Contractual Clauses with the adjustments required by the FADP.
You can request information about these safeguards, or a copy of them, at privacy@siteupward.com.
7. How long we keep data
| Data | Retention |
|---|---|
| Account data | As long as your account exists. When you ask us to close your account, we delete or anonymise your data within 30 days, except data we must keep by law. |
| Sign-in links | Valid for 20 minutes (sign-in), 1 hour (purchase links) or 24 hours (address confirmation links); deleted 7 days after use or expiry. |
| Sessions | 30 days or until you sign out, whichever comes first; then deleted. |
| Reports in your account | As long as your account exists, or until you ask us to delete them. For free checks, the detailed page analysis (AI assessments, text excerpts and page measurements) is deleted after 30 days; the score, findings and page titles remain. |
| Free checks run without an account | Detailed page analysis deleted after 30 days; the whole check deleted after 12 months. |
| IP address stored with a check | Cleared automatically 30 days after the check was started. |
| “E-mail me this report” address stored with a check | As long as the check itself is kept (see above). |
| Purchase and billing records | As long as your account exists and afterwards for as long as Latvian accounting and tax law requires – generally 5 years after the end of the financial year of the transaction, or longer where the tax law of another country that applies to the sale requires it. |
| Rate-limit counters | Up to 24 hours. |
| Server logs | Up to 30 days. |
| Internal team notifications | Deleted when no longer needed, at the latest after 12 months. |
| Support correspondence | Up to 3 years after your request has been closed, to handle follow-up questions and legal claims. |
| Backups | Kept on a rolling basis and overwritten, normally within 30 days. Data deleted from the live system disappears from backups when they expire. |
When a retention period ends, we delete the data or anonymise it so that it no longer identifies you.
8. Security
We protect personal data with technical and organisational measures appropriate to the risk, including: encryption in transit for all connections; session, sign-in and browser tokens stored only as keyed hashes; single-use, short-lived sign-in links; strict access control, with access to production systems limited to authorised personnel; network separation so that our databases are not reachable from the internet; rate limiting and bot protection; removal of query parameters from logs; regular, integrity-checked backups; and prompt security updates.
No method of transmission or storage is completely secure. If a personal data breach is likely to result in a risk to your rights, we will inform the supervisory authority and, where required, you, as the law requires.
9. Your rights in the EU/EEA, the UK and Switzerland
If you live in the European Union or the European Economic Area, you have the following rights under the GDPR. If you live in the United Kingdom, you have the same rights under the UK GDPR, and if you live in Switzerland, comparable rights under the FADP. You have the right to:
- access your personal data and receive a copy of it;
- have inaccurate data corrected;
- have your data erased, for example when it is no longer needed or you withdraw consent;
- restrict the processing of your data in certain circumstances;
- receive data you provided to us in a structured, commonly used, machine-readable format and have it transmitted to another controller (data portability);
- object at any time to processing based on legitimate interests, on grounds relating to your particular situation, and to direct marketing without giving any reason;
- withdraw your consent at any time, without affecting the lawfulness of processing before the withdrawal.
You can change your name, language and e-mail preferences yourself in your account settings. For any other request, e-mail privacy@siteupward.com from the address linked to your account, or tell us how we can verify your identity. We respond within one month; for complex requests this can be extended by two further months, in which case we tell you why. Exercising your rights is free of charge unless requests are manifestly unfounded or excessive.
You also have the right to lodge a complaint with a data protection authority. Our lead supervisory authority is the Data State Inspectorate of Latvia (Datu valsts inspekcija), Elijas iela 17, Rīga, LV-1050, www.dvi.gov.lv. You may also complain to the authority in your own country, in particular where you live or work or where the alleged infringement took place – for example the Information Commissioner's Office in the United Kingdom or the Federal Data Protection and Information Commissioner in Switzerland. We would appreciate the chance to address your concern first.
10. Additional information for United States residents
This section applies to residents of California and of other US states with comprehensive consumer privacy laws, such as Colorado, Connecticut, Delaware, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Utah and Virginia. It supplements the rest of this policy and is our notice at collection under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA). We honour the requests described in section 11 from residents of every US state.
In the last 12 months, we have collected the following categories of personal information. Section 3 describes the data in detail, section 4 the purposes, section 5 the categories of recipients and section 7 how long we keep each category.
| Category | What we collect | Sources | Business purposes |
|---|---|---|---|
| Identifiers | E-mail address, optional name, IP address, account and session identifiers, and the payment processor's customer references | You; automatically | Providing your account and the Service, sign-in, service e-mails, security and fraud prevention |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Name, billing address and payment details, collected by our payment processor; we never store card numbers | You, through the payment processor | Processing payments, issuing invoices and calculating taxes |
| Commercial information | Products bought, amounts, taxes, credits, subscriptions and refunds | You; the payment processor | Providing what you bought, billing, accounting and customer support |
| Internet or other electronic network activity | Website addresses you submit for checks, sign-in and session records, server logs with browser user agent and requested pages, and human-verification signals | You; automatically | Providing and securing the Service, preventing abuse and fixing errors |
| Approximate location | Your country or region, derived from your billing address or IP address; we do not collect precise geolocation | You; automatically | Calculating taxes, security |
| Professional information | Names, job titles and business contact details that appear on public websites audited with the Service | Public websites | Producing the reports that users request (section 14) |
| Sensitive personal information | Payment card details, entered only on the payment processor's checkout pages | You, through the payment processor | Processing payments only; never to infer characteristics about you |
We do not create profiles or draw inferences about you, and we do not collect biometric, health or precise geolocation data.
We disclose personal information for business purposes only to the categories of service providers and contractors listed in section 5, to professional advisers bound by confidentiality, and to authorities where the law requires it.
We do not sell or share personal information, and we do not use it for targeted advertising or for profiling that produces legal or similarly significant effects. In the last 12 months, we have not sold personal information or shared it for cross-context behavioral advertising, including personal information of consumers under 16.
11. Your privacy rights in the United States
Depending on the state where you live, you have the right to:
- know what personal information we have collected about you, including the categories and specific pieces of information, their sources, the purposes for collecting them and the categories of recipients, and receive a copy in a portable format;
- have personal information that we collected from you deleted, subject to exceptions allowed by law, for example records we must keep for tax purposes;
- have inaccurate personal information corrected;
- opt out of the sale or sharing of personal information, of targeted advertising and of profiling that produces legal or similarly significant effects – we do none of these, so there is nothing to opt out of;
- limit the use of sensitive personal information – we already use it only to process payments;
- not be discriminated against for exercising your rights: we will not deny you the Service, charge you different prices or give you a different quality of service because you exercised them.
To exercise your rights, e-mail privacy@siteupward.com. We verify your request by matching it with information we already hold, usually by asking you to write from, or confirm through, the e-mail address linked to your account. We confirm receipt within 10 business days and respond within 45 days; if we need more time, up to a further 45 days, we tell you why.
You may use an authorised agent to make a request on your behalf. We ask the agent for proof of your signed permission and may ask you to verify your identity directly with us, unless the agent holds a valid power of attorney.
If we decline your request, you may appeal by replying to our decision. We tell you the outcome of your appeal and the reasons for it within the period set by the law of your state; if you disagree, you can contact the attorney general of your state.
Global Privacy Control: because we do not sell or share personal information or use it for targeted advertising, there is nothing to opt out of. If your browser sends a Global Privacy Control signal, we nevertheless treat it as a valid request to opt out of the sale and sharing of personal information linked to that browser.
California residents may also ask us once a year whether we have disclosed personal information to third parties for their own direct marketing purposes (Cal. Civ. Code § 1798.83). We do not make such disclosures.
12. Other countries
If you live in another country – for example Canada, Australia, New Zealand, Brazil, Japan, South Korea, Singapore, India or South Africa – we protect your personal data to the same standard described in this policy. You can ask us to give you access to your personal data, correct it or delete it, to stop using it for a particular purpose, or to withdraw your consent, as described in section 9. Where the law of your country gives you further rights, we respect them.
Your personal data is processed in the European Union and, through our service providers, in other countries as described in section 6.
To make a request, e-mail privacy@siteupward.com. You may also complain to the data protection or privacy authority of your country; we would appreciate the chance to address your concern first.
13. Automated decision-making
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, and we do not profile individuals. Our audits assess websites, not people.
Automated protective measures – such as rate limits, free-check limits and human verification – can temporarily block a request. If you believe you were blocked by mistake, contact us and a member of our team will review it.
14. Website owners and people named on audited websites
SiteUpward audits publicly accessible websites at the request of its users, including websites that the user does not own. For an audit, our crawler fetches the website's robots.txt, sitemaps and a limited number of public pages, as described on our crawler page.
We store the page addresses, titles, headings, short excerpts used as evidence, technical measurements and the resulting findings. If public pages contain personal data – for example an author's name or a business contact – it can appear in this data. We process it on the basis of legitimate interests (Art. 6(1)(f) GDPR) only to produce the requested report, keep it as described in section 7, and do not use it to contact, profile or track anyone or to train AI models.
Website owners can block our crawler through robots.txt or ask us to exclude their domain from future audits. Anyone can object to this processing or ask us to remove data about them from reports by writing to privacy@siteupward.com with the page address concerned.
15. Children and minimum age
The Service is intended for business and professional use and is not directed at children. If you live in the European Union or the European Economic Area, you must be at least 16 years old to use it, unless the law of your country sets a lower age for consenting to online services (which is never below 13). Elsewhere, you must be at least 13 years old. To buy products, you must be old enough to enter into a binding contract where you live.
We do not knowingly collect personal data from children below these ages. If you believe that a child has given us personal data, please contact privacy@siteupward.com and we will delete it.
16. Changes to this policy
We may update this policy when our Service, our providers or legal requirements change. We will inform registered users of material changes by e-mail or in the Service before they take effect. The date at the top of this page shows the current version.
17. Contact
SIA "MICRON", Aldaru iela 36/38–21, Liepāja, LV-3401, Latvia. Privacy and data protection: privacy@siteupward.com. Other questions: support@siteupward.com.