Privacy policy
Last updated: 26 July 2026
This is a translation. In case of ambiguity or conflict, the German version prevails.
1. Controller and dual role
The controller within the meaning of the General Data Protection Regulation (GDPR) for the processing of personal data in connection with the website percelia.eu, the dashboard and the services provided to our customers is:
Timon Filipovic, sole proprietor
trading as “Percelia”
In der Breite 54, 79224 Umkirch, Germany
Email: hello@percelia.eu
Phone: +49 163 4427640
Dual role. Percelia is the controller for the data of website visitors, of prospects (free scan, contact requests) and for the account, contract and billing data of our customers. For personal data arising when we audit a customer website, that is screenshots, markup excerpts and content visible on the audited pages, the customer is the controller. In that respect Percelia acts as a processor under Art. 28 GDPR on the basis of the Data Processing Agreement (DPA).
2. Data protection officer
Percelia is not required to appoint a data protection officer under § 38(1) of the German Federal Data Protection Act, as fewer than 20 people are permanently engaged in the automated processing of personal data. Please direct data protection questions to hello@percelia.eu.
3. Supervisory authorities and right to lodge a complaint
Competent German supervisory authority:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW)
Königstraße 10a, 70173 Stuttgart, Germany
www.baden-wuerttemberg.datenschutz.de
For our Croatian market:
Agencija za zaštitu osobnih podataka (AZOP)
Selska cesta 136, 10000 Zagreb, Croatia
www.azop.hr
Under Art. 77 GDPR you have the right to lodge a complaint with a supervisory authority in the member state of your habitual residence, place of work or the place of the alleged infringement.
4. Purposes, data categories and legal bases
- Providing the website and server logs. IP address, date and time, user agent, referrer, requested URL. Purpose: technical provision, stability, abuse prevention. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and stable operation). These logs arise at our infrastructure providers (Vercel, Fly.io, Supabase) and are processed there under their standard retention. Percelia keeps no persistent log store of its own and does not analyse logs for profiling.
- Free scan. The website address you enter, your email address, optionally your name or company, the selected language and the headline result figures (number and severity of findings). Purpose: running the scan, emailing you the result and contacting you about a full audit. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measure taken at your request) and, for the subsequent business contact, Art. 6(1)(f) GDPR (legitimate interest in business-to-business outreach). You can object to that contact at any time. Your IP address is processed in memory only, to limit the number of requests, and is not stored.
- Contacting us. Name, email address, content of your message. Purpose: handling the enquiry. Legal basis: Art. 6(1)(b) GDPR (steps prior to a contract) or Art. 6(1)(f) GDPR (legitimate interest in communication).
- Account and authentication. Name, email address, password hash, role, membership of the customer account. Purpose: access to the dashboard, attribution of audits and sign-offs. Legal basis: Art. 6(1)(b) GDPR.
- Carrying out a commissioned audit. Addresses of the audited pages, screenshots, markup and accessibility-tree excerpts, the findings derived from them and the suggested fixes. These contain personal data only where the audited page itself displays personal data (for example names inside a test account). Percelia acts as the customer's processor here; the legal basis towards the data subjects lies with the customer.
- Test credentials for gated areas. Username and password of a test account provided by the customer. Purpose: auditing pages behind a login (checkout, account). Legal basis: Art. 6(1)(b) GDPR in the relationship with the customer. Credentials are stored encrypted, used only to log in inside the browser and are never returned through any interface.
- Sending email. Email address and message content. Purpose: sending scan results, reports and system notifications. Legal basis: Art. 6(1)(b) GDPR or processing on behalf of the customer.
- Error monitoring. Error stacks, browser and device information, possibly the IP address. Purpose: stability and security of the service. Legal basis: Art. 6(1)(f) GDPR. Monitoring is configured in the EU region and personal data is minimised.
- Invoicing and accounting. Name, address, VAT ID, service and payment data. Purpose: performance of the contract and statutory retention. Legal basis: Art. 6(1)(b) and (c) GDPR.
5. What a scan does, and what it never does
A Percelia scan loads the page under test in our own browser, the way a visitor would see it, and evaluates the result on our side. What matters for transparency towards you and your users is what is technically ruled out:
- We never inject code into your website. Percelia is not an overlay and not a widget; nothing is embedded in your site and nothing is changed there.
- The check that triggers forms blocks the submission and aborts every writing request. No data is written into your systems and no real orders, sign-ups or messages are created.
- Suggested fixes are verified against our own copy of the page only, never against your live system.
- Screenshots capture the state of the page our browser saw. When gated areas are audited, the content of the test account can be visible on them. That is why we ask for test accounts holding test data, not real customer accounts.
6. Use of AI, the EU AI Act and automated decisions
For part of the audit Percelia uses an AI language model provided by Anthropic. Screenshots and markup excerpts of the audited page are sent to that model to answer questions a rule-based check cannot decide, such as whether an alternative text conveys what the image actually shows. Under the provider's contractual commitments, the transmitted content is not used to train models.
No automated decisions about people. The AI evaluates web pages, not humans. There is no automated decision within the meaning of Art. 22 GDPR producing legal effects concerning a person. Uncertain findings are not finalised automatically; they are routed to human review before they enter a report or a conformance statement.
7. Recipients and subprocessors
We use carefully selected providers who support us as processors under Art. 28 GDPR. Data processing agreements are in place with all of them and, where required, the EU Standard Contractual Clauses (SCC).
| Provider | Purpose | Region / transfer |
|---|---|---|
| Vercel Inc., USA | Hosting of the website and dashboard | USA with EU edge; DPF + SCC |
| Supabase Inc., USA | Database, authentication, screenshot storage | Data location EU (Frankfurt); SCC |
| Fly.io, Inc., USA | Scan worker (headless browser loading the audited page) | Executed in the Frankfurt region (fra); SCC |
| Upstash, Inc., USA (über Fly.io) | Scan job queue (Redis) | EU region (Frankfurt); DPF + SCC |
| Anthropic PBC, USA | AI analysis of screenshots and markup excerpts of the audited page | USA; SCC, no use for model training |
| Resend Inc., USA | Transactional email (scan result, system notifications) | Sent from the EU region (eu-west-1); DPF + SCC |
| Functional Software, Inc. (Sentry), USA | Error monitoring | EU region (de.sentry.io); DPF + SCC |
| Cloudflare, Inc., USA | DNS for percelia.eu | global; DPF + SCC |
| Zoho Corporation B.V. | Mailboxes (messages sent to us) | EU data centre (Netherlands/Ireland) |
There is currently no payment service provider in the chain; invoices are settled by bank transfer. Should that change, we will add it to the table in advance.
8. Transfers to third countries
Where data is transferred to the USA or other third countries, this is based either on the European Commission's adequacy decision of 10 July 2023 (EU-US Data Privacy Framework, Implementing Decision (EU) 2023/1795), where the recipient is on the DPF list, or on the Standard Contractual Clauses under Implementing Decision (EU) 2021/914, supplemented by appropriate additional measures (encryption, data minimisation, EU processing regions).
The material third-country transfer concerns the AI analysis at Anthropic (USA). Standard Contractual Clauses are in place for that transfer. What is transmitted are screenshots and markup excerpts of the audited page, that is the content any visitor of the page sees, plus, for gated areas, the content of the test account.
9. Retention periods
- Server log files: within the retention of our infrastructure providers; no persistent log store of our own.
- Free-scan enquiries: up to 24 months after the last contact, then deleted. On objection we delete without undue delay.
- Audit data (screenshots, findings, reports): for the term of the contract. After it ends we provide an export for 30 days and then delete in line with the DPA.
- Test credentials: until the respective engagement is completed or they are revoked.
- Account and invoicing data: term of the contract plus the statutory retention periods (up to 10 years under German tax and commercial law).
- Contact enquiries: until the enquiry has been dealt with.
10. Your rights
You have the right to:
- access (Art. 15 GDPR)
- rectification (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- object to processing based on legitimate interests (Art. 21 GDPR)
- withdraw consent with effect for the future (Art. 7(3) GDPR)
- lodge a complaint with a supervisory authority (Art. 77 GDPR)
A message to hello@percelia.eu is enough to exercise them. If your request concerns data that was visible on the website of one of our customers, please address it to that customer first; we forward such requests without undue delay and support them in meeting their obligations.
11. Cookies and local storage (§ 25 TDDDG)
On percelia.eu we use strictly necessary cookies and local storage only, in particular for the dashboard login session and for the selected appearance (light or dark mode). These are strictly necessary under § 25(2)(2) TDDDG, so no consent is required. We use no tracking, analytics or marketing cookies and no third-party pixels. Should that change, we will obtain your consent beforehand.
12. Data security
Transmission is encrypted (TLS) and data is stored encrypted. Access to customer data is separated at database level by row-level security, screenshots are held in storage that is not publicly readable and can only be retrieved through time-limited, authenticated links. Test credentials are stored encrypted and never returned through an interface. Administrative access is protected by multi-factor authentication.
13. Changes to this policy
We adapt this privacy policy when features, subprocessors or the legal situation change. The version published at percelia.eu/en/datenschutz applies.