Version 0.3 (pre-launch draft) — last updated 2026-08-10
The controller is HostingBrain ApS, CVR 46679091, Denmark. Write to [email protected] about anything on this page. Full details are in section 9.
| What we hold | Why | Lawful basis | How long |
|---|---|---|---|
| Access-key record — email, organisation, plan, the address you signed up from | Give you access and apply your plan's limits | Contract, Art. 6(1)(b); abuse prevention, Art. 6(1)(f) | Life of the account plus 12 months |
| Contact-form request — work email, organisation, role, plan of interest, your question | Reply to you and arrange a walkthrough | Pre-contract steps, Art. 6(1)(b) | 24 months from our last exchange |
| Product request log — key hash, organisation, which query ran, the parameters, timing | Run the service, apply limits, prevent abuse | Contract, Art. 6(1)(b); abuse prevention, Art. 6(1)(f) | 90 days at parameter level |
| Feedback — your message and what it refers to | Fix a wrong or missing answer | Legitimate interest, Art. 6(1)(f) | 24 months |
| Web server log — time, IP address, country, page, referring page, browser string | Security, and a daily count of visits | Legitimate interest, Art. 6(1)(f) | 90 days |
| Observational data — public infrastructure signals at domain level | The market analysis the product performs | Legitimate interest, Art. 6(1)(f) | Kept as the historical record |
The outside parties involved are listed in section 5, retention in section 6, and your rights in section 7.
We process (a) account data about you as a user, and (b) observational data about public internet infrastructure, which is what the product analyses.
The service is sold to organisations and their professional advisers. It is not directed at children, and we do not knowingly hold data about anyone under 16. We do not ask for special-category data — health, beliefs, biometrics and the rest of Art. 9 — and you should not send it to us.
Account data reaches us at the five points below. Each one is listed with what it holds and why we may hold it under the GDPR.
You can sign in with Google or ask for a key by email. Google sign-in gives us your Google account identifier, your email address and the name on the account; the sign-in itself happens at Google, and we never see your password. The email form gives us your email address, your organisation if you type one, and the IP address the form was sent from — we keep that address to cap automated signups.
The key record itself holds your organisation, your email address, the plan you are on, whether the key is active or revoked, the date it was created and — once billing is live — the payment-provider customer reference. The key is stored only as a one-way hash; we cannot read it back to you.
Both routes record which version of the Terms and this policy you accepted, when you accepted it, and whether you asked for product updates. Basis: performing the contract you are entering (Art. 6(1)(b)), and legitimate interest in preventing abuse (Art. 6(1)(f)).
If you connect through an assistant rather than a header, we also hold the connection tokens that stand in for your key. Access tokens expire after 90 days and refresh tokens after a year; both can be revoked at any time from our side.
The contact form sends your work email, your organisation, your role, the plan you asked about, the question you want answered and an optional market or operator. Those six fields are the whole form; nothing else on the page is collected, and there is no hidden field.
We store those fields with the IP address the request came from, and a status we use to track whether we have replied. So that a request is not missed, a founder's phone is alerted that one has arrived; the alert says only that, and carries nothing about you. Basis: steps taken at your request before a contract (Art. 6(1)(b)).
Requests are read by us and answered by email. They are not passed to a sales tool, a CRM or an advertising platform, because we run none.
Every call to the product records the hash of your access key, your organisation, which query ran, the parameters you passed, how many rows came back, how long it took, whether it succeeded, and the name and version of the client software. We do not store the answers themselves, and calls are not recorded against your IP address. Purpose: running the service, applying the usage limits your plan sets, preventing abuse and improving the product. Basis: performing our contract with you (Art. 6(1)(b)), and legitimate interest in preventing abuse (Art. 6(1)(f)).
The parameters stay inside that store. They are not sent to any outside party, not used to train a model, and never visible to another customer — the boundary is built into the system, not a promise about how we behave. We also count calls per key per day, which is how a plan's limits are applied.
Parameters are reduced to theme-level aggregates after 90 days, for research confidentiality. We do not sell account or usage data.
The product has a feedback channel for reporting a wrong number or a missing answer. It stores your message, what it refers to, the version of the data you were on, your organisation, your key hash and the client you sent it from. The channel only takes messages in — nothing written to it is served back through the product. We read it to fix the product. Basis: legitimate interest in improving a service you use (Art. 6(1)(f)).
Our web server keeps a standard access log with one line per request: the time, your IP address, the country the request came from, the page requested, the referring page and the browser string. Basis: legitimate interest in keeping the service secure and knowing whether anyone is reading it (Art. 6(1)(f)).
Once a day we read that log to produce a summary: how many page views, how many distinct visitors, the top few countries, pages and referring sites. The summary is counts only — it names no visitor and carries no address. Nothing else reads the log.
The site sets no cookies of its own and carries no advertising or analytics trackers. There is no third-party script on any page of this site, so no outside party learns that you visited. The security service in front of the site may set a cookie of its own to tell visitors from automated traffic.
Our dataset is derived from publicly available internet infrastructure signals (DNS configuration, certificates, web server responses) at domain level. Where a domain belongs to a sole proprietor, some of this may constitute personal data under GDPR. We process it under legitimate interest (Art. 6(1)(f)): market research on aggregate infrastructure, with data minimisation — no consumer profiling, no marketing to data subjects, aggregate-level reporting by default.
Your rights: if a domain concerns you, you may request access, correction or objection at [email protected]. Objections are honoured by excluding the domain from analytical output.
The service runs on our own EU-located hardware. These outside parties are involved, and no others:
Transfers outside the EU. These three are US-headquartered. Where they process account data outside the EU, the transfer rests on the European Commission's standard contractual clauses in their data-processing terms. We ask for EU data residency where a service offers it.
We may also disclose account data if a Danish or EU authority lawfully requires it. Beyond that, account data does not leave the service described on this page.
An IP address stored alongside a signup or a contact request is deleted with that record, on the period above. If you ask us to delete something sooner, we do — see the next section.
Under the GDPR you may ask us to:
Where a use rests on your consent — product updates by email — you may withdraw that consent at any time, and withdrawing it does not affect what came before.
Write to [email protected]. We answer within one month, and we do not charge for it. If we need to be sure it is you, we ask from the address on the account rather than for a document.
On request we delete your access key, your sign-in record and the requests you have sent us, and we remove the identifiers that tie usage records to you. What is left is counts that name nobody.
If you think we have handled your data wrongly, you may complain to your national supervisory authority. In Denmark that is Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby — datatilsynet.dk.
This page carries a version and a date at the top, and both change when the substance does. When a change is material we ask you to accept the new version the next time you sign in, and we record which version you accepted.
Controller: HostingBrain ApS, CVR 46679091, VAT DK46679091, Store Kannikestræde 10, 1169 København K, Denmark — [email protected]. We have not appointed a data protection officer; the founder answers privacy mail directly.