1. Data controller
The data controller is
Maciej Zmitrukiewicz, a natural person operating the
CometWeb brand. There is no registered company yet (no KRS / NIP for CometWeb). Privacy contact:
rodo@cometweb.io.
2. Data we collect
We collect: e-mail (registration), company name (optional), scanned URLs, technical logs (IP, user-agent, timestamp). We do not collect third-party data beyond scanned public domains.
3. Purpose of processing
We process data under contract (Art. 6(1)(b) GDPR) — to provide the service: domain scanning, report generation, billing. On the marketing site we may process analytics data under consent (Art. 6(1)(a)) via Google Tag Manager, Google Analytics 4 and Microsoft Clarity. We do not use scan results, reports, or other product data for profiling, AI model training, or any purpose other than providing the service.
4. Retention
Technical logs — 30 days. Scan trend/archive windows — per plan (Free: current snapshot only, no trend archive; Growth: 30 days; Studio: 90 days; Scale: 365 days). Account data — until account deletion + 30 days grace.
5. Your rights
You have the right to access, rectify, erase, restrict processing, port data, and lodge a complaint with the President of UODO (PL). We respond to requests within 72 hours.
6. Transfers outside the EU
Application data is stored on EU servers (Hostinger — Frankfurt, DE). Transfers outside the EEA happen only when necessary — transactional e-mail via Resend Inc. (US) and, after consent, marketing-site analytics via Google LLC and Microsoft Clarity (US) — under Standard Contractual Clauses (SCC).
7. Sub-processors
Stripe (payments · IE), Hostinger (hosting · LT/DE), Resend (e-mail · US, SCC), Google LLC / Tag Manager & Analytics 4 and Microsoft Clarity (marketing-site analytics · US, SCC, after consent). Public DPA links are listed in the table on the
GDPR page.
8. Changes
Material changes are announced 30 days before taking effect — via email and an in-app banner. Minor edits (typos, formatting) — without notice. v4.3: controller named as a natural person (no registered company); EEA transfer summary aligned with SCC; privacy contact without a dedicated DPO placeholder.
Document version 4.3 · Effective from 2026-08-05