Privacy policy
Last updated: [DATE]
DRAFT — requires legal review before publication. Text in [SQUARE BRACKETS] must be completed by the site operator. This draft is not legal advice.
1. Controller
The controller responsible for this website under the EU General Data Protection Regulation (GDPR) is:
[COMPANY / FULL NAME]
[STREET AND NUMBER]
[POSTCODE, CITY], [COUNTRY]
E-mail: [CONTACT EMAIL]
[If applicable: Data protection officer: NAME, CONTACT]
2. Summary
- We do not require accounts and use no analytics. Some tool pages show Google AdSense ads, which may use cookies only after you give consent. Ads are never shown on the password generator, the home page or the e-mail header analyzer.
- Passwords made with the password generator are created in your browser and are never transmitted to us.
- E-mail headers you paste are processed in memory to show you the analysis and are then discarded. They are not stored, logged or cached.
- Domain names, IP addresses and URLs you ask us to check are used to perform that check and may be kept for up to 15 minutes in a short-term result cache.
3. Data processed when you visit the site
Server log files. Our hosting provider, [HOSTING PROVIDER NAME, ADDRESS], automatically records technical data for each request: IP address, date and time, requested URL, referring URL, browser user agent, HTTP status and amount of data transferred. This is needed to deliver the website and to keep it secure (Art. 6(1)(f) GDPR — legitimate interest in secure and stable operation). Log files are retained for [NUMBER] days and then deleted [CONFIRM WITH HOSTING PROVIDER]. Note: for tools that use a web address (GET request), the value you entered is part of the requested URL and therefore appears in these logs. The e-mail header analyzer uses POST requests, so headers do not appear in URLs or access logs.
We have a data processing agreement with our hosting provider under Art. 28 GDPR [CONFIRM].
4. Using the tools
4.1 Password generator
Passwords are generated locally by JavaScript in your browser. No password, and no setting you choose, is sent to our server or stored on your device.
4.2 DNS, e-mail and web lookup tools
When you submit a domain name, IP address, URL or DKIM selector, our server uses it to perform the requested check (Art. 6(1)(b) GDPR — providing the service you request; and Art. 6(1)(f) GDPR). This involves sending queries containing that input to third parties:
- Public DNS resolvers: Cloudflare, Inc.; Google LLC (Google Public DNS); Quad9 Foundation; Cisco Systems, Inc. (OpenDNS); AdGuard Software Ltd. Some of these providers are located outside the EU/EEA. [LEGAL REVIEW: assess transfer mechanism / whether queries about the entered domain constitute personal data in your context.]
- The authoritative name servers of the domain you look up.
- For the blacklist checker: the DNS blocklist operators listed on the blocklist sources page receive the IP address being checked.
- For the SSL, HTTP header and redirect checkers: the web server you ask us to check receives a connection from our server (not from your device).
Your own IP address is not passed to these third parties by us.
Result cache. To avoid repeated queries, results may be stored for between 30 seconds and 15 minutes in a database on our server. Entries are looked up by a keyed hash of the input and deleted when they expire.
4.3 E-mail header analyzer
Headers you paste may contain personal data of you and others (names, e-mail addresses, IP addresses, subject lines). They are transmitted over an encrypted connection, processed in memory to produce the result page and then discarded. They are not written to a database, cache or log file by our application. Please only submit headers you are entitled to share.
5. Abuse protection (rate limiting)
To protect the service from abuse, we count requests per network. We do not store your IP address for this: we store a keyed hash of your network prefix (IPv4 /24 or IPv6 /64) together with a request counter. The hash key changes every day, so entries cannot be linked across days, and entries are deleted after at most 24 hours (Art. 6(1)(f) GDPR).
6. Usage statistics
We count how often each tool is used per day. These counters contain no IP addresses, inputs or other personal data.
7. Cookies and similar technologies
Our own application sets no cookies and does not read or write browser storage.
7.1 Advertising (Google AdSense)
DNS, e-mail and web tool pages, the tool directory and the information pages display ads from Google AdSense, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). When such a page loads, your browser connects to Google's servers, which receive your IP address, browser information and the address of the page (which, on a result page, can include the domain, IP address or URL you checked). Before any cookies or similar technologies are used for advertising, Google's certified consent message asks for your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). If you do not consent, Google may still show non-personalised or limited ads, which use cookies only as far as strictly necessary or permitted. You can change or withdraw your consent at any time via the privacy/consent link shown by the consent message [CONFIRM LINK LOCATION]. Data may be transferred to Google LLC in the USA; Google is certified under the EU–U.S. Data Privacy Framework [LEGAL REVIEW: confirm current status]. More information: How Google uses information from sites that use its services and Google's privacy policy.
Pages without ads: the home page, the password generator and the e-mail header analyzer never load advertising scripts, so no third party can see generated passwords or pasted headers. Legal pages and error pages are also ad-free.
8. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21 GDPR). Because we do not keep lookup inputs beyond the short cache period and do not link requests to persons, we will usually be unable to identify data relating to you. You also have the right to lodge a complaint with a supervisory authority, for example [COMPETENT AUTHORITY, e.g. Der Hessische Beauftragte für Datenschutz und Informationsfreiheit].
9. Changes
We will update this policy when our processing changes. The date at the top shows the latest version.