PRIVACY POLICY · UPDATED 1 OCTOBER 2026

Privacy policy

This notice covers the GDPRFix website at gdprfix.org, accounts, contact enquiries and automated website reports.

On this page

Privacy contact · Make a privacy complaint · Complain to the ICO

Who is responsible

Alex Player, trading as Nexus Websites operates GDPRFix and is responsible for the personal information described here. Contact: hello@gdprfix.org. Telephone: 07404 022848. Address: 18 Lower Marsh Lane, London, KT1 3FE.

Information you provide

We process submitted public website addresses, account email addresses, scan requests, report-sharing choices, answers to owner questionnaires and remediation scope requests. Do not put passwords or sensitive personal information in scan URLs, questionnaires or general notes. Temporary website access may be supplied only through the dedicated access form after payment. Account email is needed for email sign-in; a public website address is needed to run a scan.

Contact form messages

The contact form collects your name, reply email, topic and message and sends the enquiry to hello@gdprfix.org. We use it to respond, not to add you to a marketing list. Messages waiting for delivery are encrypted in our mail queue and retried for up to 24 hours; their queued content is removed after provider acceptance or expiry. The delivered enquiry remains in our business mailbox so we can handle your request. Please do not send passwords, card details or unnecessary sensitive information.

Preventing spam and excessive requests

We allow one accepted scan every five minutes and one accepted contact message every two minutes per IP address. People sharing an internet connection share these limits. We store a keyed hash of the IP address and the next permitted submission time; the cooldown record does not contain the raw IP address. Expired cooldown records are cleared by our background worker after 24 hours. These records support service security and do not identify you for advertising.

Contact form security check

Where enabled, the contact form uses Google reCAPTCHA to help prevent automated spam. Google is contacted only after you select Load security check. The check can send Google your IP address, browser and device information, and information about your interaction with the check, and can use cookies. Our server sends the resulting verification token to Google to confirm the check. Your name, email and message are not included in that verification request. If you prefer not to load the check, you can email us directly. Google explains its processing in its privacy notice and terms.

Google privacy notice ↗ · Google terms ↗

Website-fixing records

We store your request, authority confirmation, page count, platform, answers, proposed scope, approval, payment status, preparation details, work date, completion report and sign-off. Fix orders retain snapshots of relevant scan findings and retest findings so they remain understandable after a normal scan expires. Temporary access details are encrypted separately and visible only to the owning account and authorised operators. Access viewing is logged without recording the secret. Stored access expires after seven days and is removed at completion, cancellation or your request. This does not revoke an account on your website: you must remove that temporary access there too. Order, payment and evidence retention arrangements must be finalised before launch.

Country and currency

Where supported by our hosting provider, we use its IP-derived country code to suggest a display currency. You can change the currency manually. Reference exchange rates are fetched by our server from Frankfurter; that rate request does not send your IP address or account details. Converted website prices are estimates. Stripe handles checkout currency, payment details and its own exchange rates under its privacy notice.

Stripe privacy notice ↗

Information from scans

The scanner visits public pages and records page addresses, titles, text excerpts, technology and storage names, storage activity, network destinations, selected consent controls, timestamps and screenshots. Public page content may include personal information about people who did not request the scan. Cookie values are excluded, URL query values are redacted and input fields are masked in screenshots. These precautions cannot remove every piece of personal information from a public page.

Why we use information

We use the information to deliver requested scans and reports, maintain account access, prevent abuse, investigate faults and handle enquiries and privacy requests. The proposed bases for the public service are contract for requested account and report services, legitimate interests for service security and proportionate public-page technical assessment, and legal obligation where a specific law requires processing. The operator must approve the purpose-to-basis mapping and legitimate-interest assessment before launch; these draft bases do not replace that decision.

Storage and retention

Reports expire 30 days after creation. An active worker removes expired scan records and evidence; access checks reject expired reports. Sign-in links expire after 15 minutes, account sessions after seven days and guest-report cookies after 30 days. The worker also clears rate-limit records older than 24 hours. Account records, audit logs, email delivery metadata, deletion requests and any future payment, complaint or backup records need a documented retention schedule before public launch; this build does not promise automatic deletion for those records.

Who can access information

Reports require the owning guest browser or account, unless the owner enables link sharing. Anyone holding an enabled sharing link can view that report and its evidence, so treat it as confidential. Authorised operators may access records to run and support the service. The architecture supports hosting and database providers, private evidence storage, Resend sign-in email and Stripe-hosted checkout. The final provider list, locations and any international-transfer safeguards must be confirmed for the chosen production hosting. Live payments and email require separate configuration.

Sign-in email records

When production email is enabled, sign-in messages are queued for delivery through Resend. The queued message content is encrypted and has a 15-minute expiry. The worker clears that content after the provider accepts the message or after expiry; recipient and delivery-status records remain. A queued message or provider acceptance does not prove arrival in your inbox. Development mailbox previews are local and do not represent an email sent to you.

Accounts and deletion

Signed-in users can use Account & privacy to export account information, review sessions and request account deletion. A deletion request is saved for operator review; it does not immediately erase the account or evidence. You can cancel a pending request. We may need to clarify scope or retain information where there is a lawful reason, and will explain the outcome. If you cannot sign in or the information concerns a public scan about you, email hello@gdprfix.org.

Open Account & privacy ↗

Your choices and rights

Depending on the circumstances, you may request access, correction, deletion, restriction or portability, and object to processing based on legitimate interests. Rights are not absolute. If we rely on consent for a future optional use, you can withdraw it without affecting earlier lawful processing. Use the contact details on the Contact page to make a request. We may need proportionate identity checks. You can also raise a data-protection complaint with us and complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint/.

Your right to object

You can object to processing based on legitimate interests, including public-page assessment involving your personal information. Email hello@gdprfix.org, identify the relevant page or report and explain your concern. We will assess the request and any grounds for continued processing; this right is not limited to account holders.

Automated decisions and AI

Versioned technical rules generate scan findings. The current product does not send scan evidence to a generative AI service, provide an AI chatbot or make decisions with legal or similarly significant effects about individuals. A report is a technical observation, not a regulatory decision.

Changes to this notice

We will update this notice when processing changes, including before migration, new analytics, live payments or a change of service providers. This draft must be completed against the final operating arrangements before accepting public customers.

Official guidance: Privacy information · Complaint handling · Cookies and storage