Privacy policy
Last updated: 2026-10-10 (draft)
1. Who is responsible
The seller named in the imprint is the controller for the personal data described here.
2. Data you enter in the tool
The Security Overview builder and the kit run in your browser. What you type (company name, contact, answers) is stored in your browser's local storage on your device. It is not sent to us or to anyone else. You can delete it by clearing site data in your browser.
3. Payments
When you buy, PayPal processes your payment and shares with us the details needed to fulfil and account for the order: order ID, name, email address, country, amount, and the optional company name and VAT ID you enter. Legal basis: performance of the contract and legal obligations (tax records). We keep order records as long as German tax law requires, up to 10 years. PayPal's own privacy statement applies to PayPal's processing.
4. Statistics
We count visits and a few named events (for example "free tool used" and "checkout started") to learn what works. We use no cookies for this and store no IP addresses or personal profiles ourselves. Counting uses a public counter service (abacus.jasoncameron.dev) and, if enabled, GoatCounter. These services receive a request from your browser, so they can see your IP address and browser details as part of normal web traffic. Legal basis: legitimate interest in basic, privacy-friendly statistics. Your browser stores small markers in local storage so that a visit is counted once per day.
5. Hosting
The site is hosted on GitHub Pages (GitHub, Inc.). GitHub may log technical data such as IP addresses for security. See GitHub's privacy statement.
6. Your rights
You can ask for access to, correction of or deletion of your personal data, and object to processing, by emailing the address in the imprint. You can complain to the data protection authority of Lower Saxony, Germany (Die Landesbeauftragte für den Datenschutz Niedersachsen) or your local authority.
7. International transfers
PayPal, GitHub and the counter services may process data outside the EU. Where they do, they rely on their own transfer mechanisms (for example the EU-US Data Privacy Framework or Standard Contractual Clauses).