Privacy policy
Courtesy translation. The German version is legally binding.
1. In short
You can have a website analysed without creating an account and without giving any personal data. Only when you want to unlock the full report do you provide a first name and an email address. We do not sell data and do not pass it to third parties for advertising purposes.
2. Controller
RAVARO® by Ralph A. Appel
Wacholderweg 3, 85049 Ingolstadt, Germany
Email: service@ravaro.de
3. Hosting
This website is hosted by Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA). When you open the site, Vercel processes technically necessary access data (including IP address, time, requested address, browser type) in order to deliver and secure the page. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure and reliable provision). A data processing agreement is in place; transfers to the USA are based on the EU standard contractual clauses.
4. The website analysis
When you enter a website address and start the analysis, we process:
- the address you entered and the domain name derived from it,
- optionally the website goal you selected and the campaign source parameter (for example
?src=citicon), - the publicly accessible content of the page requested: visible text, technical header data and one screenshot each for desktop and mobile,
- your IP address in truncated form, to limit abuse.
We open the website in question exactly the way any visitor does. We store the result so that you can look at it again later and so that the same address does not have to be evaluated again within 30 days. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures at your request) or Art. 6(1)(f) GDPR.
We take the screenshots ourselves: a browser without a screen (Chromium) runs on our server and opens the page exactly the way any visitor does. No external screenshot service is involved.
Personal data on the analysed website
The website you enter may contain personal data of third parties, for example names and contact details in the legal notice or photos of staff. We did not collect this data from the data subjects themselves (Art. 14 GDPR); it is publicly accessible on the page requested. We evaluate it solely to produce the analysis requested, never use it for advertising and do not pass it on. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the assessment of his own website requested by the client).
Processors used for the analysis
- Anthropic PBC (San Francisco, USA) — assesses the screenshots and page text. Anthropic does not use content submitted via the API to train models.
- Google Ireland Ltd. — PageSpeed Insights, measures loading time and layout stability of the analysed page.
- Supabase Inc. — database and user accounts (hosted in the European Union).
- Resend (Plus Five Five, Inc., USA) — sends our emails (sign-in link, result email, confirmations).
Data processing agreements under Art. 28 GDPR are in place with all providers. Where data is transferred to the USA, we rely on the European Commission’s adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework (Art. 45 GDPR), provided the respective provider is certified under it, and otherwise on the EU standard contractual clauses under Art. 46(2)(c) GDPR.
5. Account and report
To get the full report you create an account. For this we process your first name and email address. Sign-in works without a password, via a one-time link we send you by email. We use the address to send you your report and to contact you about your analysis. The legal basis is Art. 6(1)(b) GDPR. You can have your account deleted at any time by informal email.
6. Booking an appointment
For appointment booking we use Calendly (Calendly LLC, 271 17th St NW, Atlanta, GA 30363, USA). When you pick a time, a Calendly page opens. So that you do not have to type your details a second time, we pass on your name, your email address and — if you provided it — your phone number. Calendly’s own privacy policy additionally applies to the processing that happens there. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures at your request).
7. Marketing emails and your consent
You receive the report and messages about your analysis because you requested them — no separate consent is required for that. Anything beyond this, such as tips and suggestions, we only send if you explicitly ticked the box and then confirmed your consent via the link in our result email (double opt-in). Only after that confirmation will you receive such emails.
As evidence we store the exact wording you agreed to, the time of the request, the time of the confirmation and your IP address in truncated, non-reversible form. The legal basis is Art. 6(1)(a) GDPR in conjunction with Section 7(2)(2) of the German Act Against Unfair Competition (UWG). You may withdraw your consent at any time with effect for the future — by informal email or via the opt-out link in every such message. The lawfulness of processing carried out until then remains unaffected.
8. Browser storage
We do not use cookies for advertising or analytics and we embed no advertising or statistics services. As soon as you sign in, Supabase Auth sets a cookie that keeps your session open. It is strictly necessary for the service you requested and therefore exempt from consent under Section 25(2)(2) TDDDG.
9. Automated assessment
The analysis assesses a website, not a person. There is no automated decision in an individual case that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR). We do not build a profile of you as a person.
10. Encryption
This site uses TLS encryption throughout. You can recognise this by the address bar of your browser starting with https://.
11. Retention
- Analysis results: 30 days, afterwards only in your account for as long as it exists.
- Account and contact data: until the account is deleted.
- Evidence of consent given: until withdrawal and thereafter for as long as we must still be able to prove it.
- Server access data: according to the hosting provider’s policy, usually a few weeks.
- Statutory retention obligations remain unaffected.
12. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on a legitimate interest (Art. 21). You may withdraw consent at any time with effect for the future (Art. 7(3)). An email to service@ravaro.de is enough for any of these.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, Promenade 27, 91522 Ansbach, Germany). You may equally contact the authority where you live.