Privacy Policy
This policy explains what data WebAssure processes and why.
Last updated: January 3, 2026
Overview
WebAssure is a monitoring service that helps you detect compliance drift on your websites over time. To provide the service, we process account data and store monitoring artifacts you generate (such as scan results and evidence exports).
This Privacy Policy is informational and not legal advice. If you need a specific compliance interpretation, consult a qualified professional.
Data we collect
- Account data: email address, authentication identifiers, and basic profile details required to sign in and operate the app.
- Customer configuration: the websites you add, scan schedules, and monitoring preferences.
- Monitoring artifacts: scan results you initiate or schedule (for example: detected scripts, cookies, headers, page snapshots, diffs, and generated reports).
- Operational telemetry: logs and diagnostics needed for reliability and security (for example: job status, error logs, performance metrics).
How we use data
- Provide and operate the service (scans, comparisons, alerts, exports).
- Secure the product (fraud prevention, abuse detection, auditing).
- Improve reliability and performance (debugging, monitoring, capacity planning).
- Communicate with you about important service events (for example: alerts and verification emails).
Legal bases (EEA/UK)
Where applicable under GDPR/UK GDPR, our typical legal bases are:
- Contract: to provide the service you request.
- Legitimate interests: to secure and operate the service and prevent abuse.
- Consent: where required for optional analytics cookies (if enabled).
Subprocessors and providers
WebAssure relies on vetted infrastructure providers to host the application, store artifacts, and deliver emails. These providers may process data on our behalf under appropriate agreements.
Retention
We retain account data and monitoring artifacts for as long as needed to provide the service, comply with legal obligations, and resolve disputes. You can delete sites and artifacts within the product; deletion may take time to propagate to backups.
Security
We use administrative, technical, and organizational safeguards designed to protect data. No system can be guaranteed 100% secure, but we work to reduce risk through access controls, encryption in transit, and careful operational practices.
For more, see Security.
Your rights
Depending on your location, you may have rights such as access, correction, deletion, portability, or objection to processing. To make a request, contact us at support@webassure.app.