GDPR Compliance

Last updated: June 4, 2026

On this page

1. Our Commitment to GDPR

ADAGuard is committed to complying with the General Data Protection Regulation (EU) 2016/679 (“GDPR”). This page explains how we handle personal data of EU and EEA residents, what rights you have, and how to exercise them.

Data Controller: ADAGuard is the data controller for personal data collected through our platform.
Contact: privacy@adaguard.io

3. Your Rights Under GDPR

As an EU/EEA resident, you have the following rights:

Right of Access (Art. 15)
Request a copy of the personal data we hold about you.
Right to Rectification (Art. 16)
Ask us to correct inaccurate or incomplete personal data.
Right to Erasure (Art. 17)
Request deletion of your personal data where no longer necessary ("right to be forgotten").
Right to Restriction (Art. 18)
Ask us to restrict processing of your data in certain circumstances.
Right to Data Portability (Art. 20)
Receive your personal data in a structured, machine-readable format.
Right to Object (Art. 21)
Object to processing based on legitimate interests or for direct marketing.
Right to Withdraw Consent (Art. 7)
Withdraw consent for consent-based processing at any time without affecting prior processing.

To exercise any right, email privacy@adaguard.io. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority.

4. Data We Collect

We collect only the data necessary to deliver the service:

  • Account information: name, email address, hashed password
  • Billing details: passed directly to our payment processor (Dodo Payments); we store only the last-four digits and card type
  • Usage data: scanned URLs, scan results, and settings configured in the dashboard
  • Log data: IP address, browser type, and timestamps retained for security purposes (max 90 days)
  • Cookie data: see our Cookie Policy

5. International Data Transfers & Sub-processors

ADAGuard is hosted in the United States. When we transfer personal data from the EU/EEA to the US, we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission, and/or service providers that participate in recognised adequacy frameworks. This is the canonical list of our sub-processors — our Privacy Policy and Cookie Policy both link here rather than keeping separate copies.

Sub-processorPurposeData processed
MongoDB AtlasPrimary databaseAccount data, scan results, encrypted authentication sessions
RailwayBackend hosting + Redis (rate limiting, scan locks, caching)All data in transit through the API
VercelFrontend hosting + Vercel AnalyticsStatic assets; cookieless page-view analytics
CloudflareCDN, DNS, DDoS protectionTraffic routing; no persistent storage of personal data
Dodo PaymentsPayment processing and billingBilling details (we store only the last four digits and card type)
ResendTransactional email deliveryEmail address, message content
Google Analytics (GA4)Site analyticsPage views, browser/device info (cookie-based, opt-in)
Google OAuth"Sign in with Google"Name, email address (only if you use this sign-in method)
Steel.devBrowser automation for authenticated accessibility scansSession cookies from the login you perform in its remote browser, used only to scan your own site (ADAGuard never receives your password); ADAGuard stores the captured session encrypted at rest

We will give at least 30 days’ advance notice by email to your account address before adding or replacing a sub-processor.

6. Data Retention

We retain personal data for as long as your account is active, plus a further period required by law (7 years for billing records, per financial record-keeping requirements). Scan results are retained according to your plan limits: at the end of that period each scan’s detailed findings are deleted, while a short summary (date, URL, score, and issue counts) is kept so your score history remains available. Deleting your account removes both. The full per-plan schedule is on our Privacy Policy — that page is the canonical source for retention periods, so this section stays in step with it rather than restating the numbers. You may request earlier deletion via the rights process in Section 3.

7. Data Processing Agreement (DPA)

If you use ADAGuard to process personal data on behalf of your users (e.g., scanning pages that contain user data), ADAGuard acts as a data processor and you are the controller. A Data Processing Agreement is available to customers on any paid plan — this is not restricted by tier. To request a DPA, email privacy@adaguard.io.

8. Security

We implement technical and organisational measures appropriate to the risk, including TLS encryption in transit, encryption at rest, role-based access controls, and regular security assessments. In the event of a personal data breach affecting EU/EEA residents, we will notify the relevant supervisory authority within 72 hours where required.

10. Changes to This Page

We may update this GDPR compliance page when our practices change or when required by law. Material changes will be notified by email or a prominent notice on our site at least 30 days before they take effect, consistent with our Privacy Policy.

11. Contact

For all privacy-related enquiries including GDPR rights requests:

ADAGuard Privacy Team
privacy@adaguard.io