Legal

Privacy notice

We collect little, we sell nothing, and this page tells you everything: what data we process, on what legal basis, who touches it, how long we keep it, and how to exercise your rights.

Last updated: July 19, 2026.

1. Who is responsible

The data controller is Jivaseva OÜ, registry code 12142627, Lootuse tn 1-6, Kiili alev, 75401 Harju maakond, Estonia, operating as AuditRush. For anything in this notice, use the contact form and pick the data request topic; we answer in writing. We are an EU company and apply the GDPR to everyone we serve, wherever you are. Our processing does not require a data protection officer; the controller answers data questions directly.

2. What we process, why, and on what legal basis

This website sets no cookies and carries no advertising, no third-party trackers, and no third-party fonts. Measurement is limited to the cookieless aggregate counting described above. We do not sell personal data, and we make no automated decisions about people that have legal or similarly significant effects.

Providing the order data is necessary to deliver the audit: without an email address and a site URL there is nothing to deliver. None of our processing relies on consent, so there is no consent to withdraw. For everything we base on legitimate interest we have documented the balancing test; you can request a summary through the contact form.

Sensitive and children's data: we never seek either, but an audited page can incidentally show them. The two cases are legally distinct, with the same practical outcome. Special categories of personal data (GDPR art 9, for example a staff biography mentioning disability): where the person manifestly made the information public themselves, art 9(2)(e) applies, and in every other case we redact it from the audit artifacts as soon as we become aware of it or on request. Children's data (for example pupils shown on a school site) is not an art 9 category, but children are vulnerable data subjects whose interests weigh heavier in our legitimate interest balancing, so we apply the same redaction on awareness or on request. Redaction never weakens a finding: findings concern the page's markup, not the people shown on it.

3. Who processes data for us

We use a small set of service providers, each only for what it says:

4. International transfers

Some of these providers process data in the United States, and the named reviewer may work from outside the EEA. Provider transfers rely on the EU-US Data Privacy Framework or on the European Commission's Standard Contractual Clauses, per each provider's data processing agreement; the reviewer's written confidentiality obligations include data protection duties. You can request details of the applicable safeguards through the contact form.

5. How long we keep things

6. Confidentiality

Customer identities, orders, and report contents are confidential, as the terms state: no marketing use of customer audits, no publishing customer names, disclosure only where law or a binding order requires it. Many customers are in active legal disputes and we treat everything accordingly.

7. Your rights

You can ask for access to the personal data we hold about you, have it corrected or deleted, restrict or object to processing based on legitimate interest, and receive data you gave us in a portable format. Send the request through the contact form; we respond within a month. If you think we handle personal data unlawfully, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or to the supervisory authority of your own country.

If you are not our customer but personal data about you is visible on pages we audited, the same rights apply to the audit artifacts. The source of that data is the audited website itself, where it was publicly visible; we collected it as part of the page evidence, not from you. Contact us and we will respond the same way.

8. Security

The site and all delivery channels run over TLS, we collect the minimum the service needs, access to audit data is limited to the people producing the audit, and secrets are not stored in the website's code. If a personal data breach ever occurs, we notify the supervisory authority within 72 hours of becoming aware of it where the GDPR requires notification, and we tell you without undue delay when the breach is likely to put you at high risk.

9. Changes to this notice

The date at the top tells you the current version. If we change what we process or who processes it, we update this page before the change takes effect; the version that applies to an order is the one published when you ordered.