1. Controller
The controller for data processing on gtm-audit.com is Commander & Architect, Simon Formanowski.
Contact and postal address for protection of the private address: c/o IP-Management #6945, Ludwig-Erhard-Strasse 18, 20459 Hamburg, Germany. Phone (management): +49 40 696328495.
Privacy contact: privacy@commander-architect.com. German-language privacy requests may also be sent to datenschutz@commander-architect.com.
General beta support requests should be sent to support@commander-architect.com.
2. Scope of this notice
This privacy notice describes the processing of personal data in connection with the GTM Audit beta.
The beta lets companies submit a publicly accessible website and have it analyzed automatically for what the public offer says to the outside.
3. Data we process
We process the details you send us, technical data for access and delivery, publicly readable content of the submitted website, and the analysis results created from that.
We do not ask for passwords. Sign-in happens through a confirmation link by email.
- business email address and email domain
- time and version of the accepted terms
- beta code and whether the code is valid, redeemed, or revoked
- submitted website address and the domain recognized from it
- optional details about market, goal, and maturity of the offer
- confirmation that you may have the website reviewed, plus a short explanation if email domain and website do not match
- technical website check results such as reachability, page title, text excerpts, and links
- texts and research results that we send to AI and research services where needed for the analysis
- technical logs such as IP address, browser type, time, and security events
- delivery status of the result email
- coarse usage states: access requested, audit started, analysis complete, result opened
- feedback, if you send any
- whether participation was accepted, declined, or ended
- storage and deletion status so we can remove or reduce data after the retention period
4. Publicly accessible website content
The beta analyzes the publicly accessible website URL submitted by the user. Content that the target website makes public may be processed.
If that website contains personal data, such as names, team pages, contact details, or quotes, such data may be processed as part of the analysis.
The user should submit only URLs that the user is authorized to have analyzed. Internal documents, non-public information, password-protected content, or confidential personal data should not be submitted.
5. Purposes and legal bases
We process data to provide the website and customer area, sign you in with a confirmation link, check the beta code, prevent misuse and unauthorized website reviews, run the audit, find errors, deliver the result, improve the beta, and meet legal duties.
Depending on the processing, the legal bases are Art. 6(1)(b) GDPR, Art. 6(1)(f) GDPR, and, where legal obligations are concerned, Art. 6(1)(c) GDPR.
Our legitimate interest is in particular the secure operation of the beta, preventing misuse, fixing errors, improving the offer, protecting against unauthorized reviews of other people’s websites and, where necessary, establishing, exercising or defending legal claims.
This is not marketing tracking and not a recording of your screen movements. We want to see whether invited companies get through sign-in, start, analysis, result, and feedback, and where it breaks.
If you allow us to use feedback as a testimonial, we store that permission and use the feedback only within the scope you allowed.
6. Browser storage and cookies
The beta stores in the browser what is needed for sign-in and continuation. After you click the confirmation link, the sign-in remains in the browser.
The form stores a short-lived continuation note in the browser so you do not have to start over after the email click. Email, beta code, and website address are not stored there as a filled-in form.
This storage for sign-in, continuation, and result access is necessary. The legal basis for access to your device is Section 25(2) TDDDG.
The interface may also remember locally whether you chose light or dark appearance. That is a display setting, not tracking.
We store usage states in our own system, not through marketing cookies. No unnecessary analytics, advertising, or tracking cookies are set.
If analytics or advertising cookies are later activated for GTM-Audit.com, we will update this notice and obtain consent where required.
7. Recipients and service providers
We use service providers that may process personal data on our behalf or as independent providers.
These currently include in particular: Supabase for database and sign-in, Railway for running the application, Cloudflare for name resolution and network, Resend for emails, Microsoft Azure in the EU for AI analysis, and Perplexity for research on the public web.
We use further AI or research services only where they are actually used for the respective function. We keep the list of recipients current. We describe material changes in this notice.
8. International transfers
Some providers may process data outside the EU or the EEA, in particular in the United States. Where required, we rely on recognized transfer tools such as an adequacy decision or standard contractual clauses.
We currently operate Microsoft Azure for the AI analysis in the EU.
Perplexity may process data outside the EU or the EEA depending on the contract.
9. No own training use
We do not use submitted beta data to train our own publicly available AI foundation models.
Providers may process data according to their respective contracts and privacy notices. Provider-specific training, retention, and security commitments apply only to the extent contractually or publicly documented for the respective service.
10. Retention
We store personal data only for as long as required for the beta, result provision, security, error analysis, legal obligations, or legitimate interests.
To evidence that and under which conditions a beta request was concluded, we retain a separate, data-minimised proof record until 31 December of the third calendar year following the year in which the beta request was accepted. It contains the case ID, pseudonymous account reference, time and version of acceptance, the authorization confirmation, and the time the beta request was completed, cancelled, or failed. During that period, we use this record only where necessary to establish, exercise or defend legal claims.
We keep technical logs such as IP addresses, browser and session data, security events, and coarse usage states for no more than 180 days. We retain a case-specific snapshot of the website content captured for the audit until 31 December of the third calendar year following the year in which the beta request was accepted. It includes captured Markdown, URL, capture time, content hash, and the structured website-evidence and analysis artifacts derived from it where generated for the completed audit. The snapshot serves result provision and, where necessary, traceability and the establishment, exercise or defence of legal claims. Prompts, model responses, tokens, debug logs, and other internal run traces are not part of this snapshot and are not retained for that purpose.
We retain feedback that you expressly allow us to use as a testimonial only while that consent remains in effect. After withdrawal, we delete or reduce it unless a legal duty or a specific, documented legal matter requires limited further retention.
After that, we delete or reduce the data unless legal duties or a specific, documented legal matter require limited further retention. The continuation note in the browser remains until the audit starts or until you delete browser data. Sign-in in the browser follows the session length of the sign-in service.
11. Automated decisions
The beta creates automated analyses and guidance. There is no solely automated decision within the meaning of Art. 22 GDPR that has legal effect on the user or similarly significantly affects the user.
The user makes business decisions based on the results independently.
12. Data subject rights
Under the GDPR, data subjects have rights including access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent.
Requests may be sent to privacy@commander-architect.com. German-language privacy requests may also be sent to datenschutz@commander-architect.com. We review and handle requests in accordance with statutory requirements.
13. Right to lodge a complaint and changes
Data subjects have the right to lodge a complaint with a data protection supervisory authority. Because the controller is seated in Leipzig, that is in particular the Saxon Commissioner for Data Protection and Transparency. The supervisory authority at the data subject’s place of residence may also be competent.
This privacy notice will be adjusted if the beta, providers used, data categories, tracking or analytics functions, or legal requirements change.