Privacy Policy

Last updated: April 1, 2026

1. Data Controller

Akhene Studio (SIREN: 848 694 683), a company registered in France, is the data controller for the personal data collected through SiteWatch.

2. Data We Collect

Account data

When you create an account, we collect:

  • Email address
  • Agency/company name
  • Password (stored hashed, never in plain text)

Billing data

Payment processing is handled by Stripe. We do not store credit card numbers. Stripe provides us with a customer ID, subscription status, and payment history.

Monitoring data

When you add a site to monitor, we collect technical data from that site:

  • HTTP response codes and headers
  • SSL certificate information
  • DNS records
  • Page content (HTML, for SEO analysis)
  • Performance metrics (via Google PageSpeed API)

This data relates to the websites you monitor, not to your personal data.

Usage data

We use Google Analytics to understand how the Service is used. This includes pages visited, browser type, and device information. You can opt out using a browser extension or ad blocker.

3. How We Use Your Data

  • To provide and operate the monitoring service
  • To send you alerts when issues are detected
  • To process payments and manage your subscription
  • To send service-related emails (trial expiration, payment issues)
  • To improve the Service

We do not sell your data. We do not use your data for advertising.

4. Legal Basis (GDPR)

  • Contract performance: processing necessary to provide the Service you subscribed to
  • Legitimate interest: analytics to improve the Service, security monitoring
  • Legal obligation: invoicing, tax records

5. Data Sharing

We share data only with service providers necessary to operate SiteWatch:

  • Stripe — payment processing (USA, EU data processing)
  • Hetzner — server hosting (Germany)
  • Google — PageSpeed API and Analytics (USA)

All providers are bound by data processing agreements compliant with GDPR.

6. Data Retention

  • Account data: retained while your account is active, deleted within 30 days of account deletion
  • Monitoring data: check results are retained for the duration of your subscription. After account deletion, all monitoring data is permanently removed within 30 days
  • Billing data: invoices and payment records retained for 10 years as required by French tax law

7. Your Rights (GDPR)

If you are in the European Economic Area, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Delete your account and data
  • Export your data in a portable format
  • Object to processing based on legitimate interest
  • Restrict processing in certain circumstances

To exercise these rights, contact us through the application. We will respond within 30 days.

You also have the right to lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés), the French data protection authority.

8. Security

We use industry-standard security measures including encrypted connections (TLS), hashed passwords, and server-level firewalls. Access to production data is restricted to authorized personnel.

9. International Transfers

Some service providers (Stripe, Google) may process data in the United States. These transfers are covered by Standard Contractual Clauses or equivalent safeguards as required by GDPR.

10. Changes

We may update this Privacy Policy from time to time. Material changes will be communicated via email at least 30 days before taking effect.