
Privacy notice
Contents
This page, observed in your browser
This page sets no cookies and asks no other website for anything. It keeps only your lamp and currency choice in your browser, and only if you used those controls.
- Cookies set by this page
- 0
- Requests to other sites
- 0
- Kept in your browser
- nothing yet
| What | Why | Lawful basis | How long |
|---|---|---|---|
| Server logs for this website and the app: IP address, date and time, page requested, browser details | Keep the service running, find faults, stop abuse | Legitimate interests | Held by render.com for the short rolling period of our hosting plan. We keep no copy. |
| Your lamp and currency choice on this website | Remember a setting you picked | Needed for the setting you chose | In your own browser until you clear it. Never sent to us. |
| Your account: email, name, picture, LinkedIn handle, password hash, Google sign-in link | Run your account and sign you in | Contract | While your account is open. Removed 14 days after you ask us to delete the account. |
| App cookies for sign-in and form protection | Keep you signed in and protect forms from forgery | Contract | Sign-in up to 2 weeks, form protection up to 1 year. |
| Company details, websites to scan, members, roles and invitations | Run the company's workspace | Contract | While the company has a workspace with us. A manager can ask us to delete it. |
| Scans, findings and evidence, including personal data that was visible on a scanned public page | Produce the company's reports and keep their history | Contract with the company; legitimate interests for what appears incidentally | While the company has a workspace. For a company that was scanned as a sample and never joined: 12 months after the scan. |
| Sample report access codes (email address, LinkedIn handle or email domain) and the invitation email | Let a named person open a sample report about their company | Legitimate interests | Until the sample is withdrawn or expires, and no longer than 12 months after the invitation. If you object, only your address stays, on a do-not-contact list. |
| Billing: billing name, email and country, Stripe references, card brand, last four digits and expiry, payments | Take payment and keep accounts | Contract; legal obligation | Payment records for as long as tax and accounting law requires. Card details for display until you remove the card. |
| Audit log of key actions (roles, payments, sharing, report access), with IP address | Security and a record of who did what | Legitimate interests | As long as the record it describes. IP addresses are removed after 12 months. |
| Failed attempts to open a sample report | Slow down guessing | Legitimate interests | 1 hour per IP address, 24 hours per browser session. |
| Emails you send to hello@ or privacy@ | Answer you | Legitimate interests, or contract if you are a customer | 2 years after the conversation ends. |
PeekWell runs the website at peekwell.org and the app at app.peekwell.org. In this notice, “the service” means both, and “we” and “us” mean PeekWell.
For the personal data this notice describes, PeekWell is the controller: we decide why and how it is used. PeekWell operates under Greek and EU law.
- Operator
- PeekWell
- General questions: hello@peekwell.org
- Questions about your personal data, requests to use your rights, and our data protection officer contact: privacy@peekwell.org
This notice covers everyone whose personal data we handle: visitors to this website, people with an account in the app, people invited to see a sample report, and people whose details appear on public web pages we scan.
peekwell.org is a static website. It sets no cookies. It runs no analytics, advertising or tracking code. It loads nothing from other websites: its fonts, images and scripts all come from peekwell.org. That is why it shows no cookie banner: there is nothing to ask your consent for.
Two settings can be stored in your browser’s local storage, and only if you use the control that sets them:
pw-themeholds your lamp choice (light or dark), set when you press the lamp switch.pw-currencyholds your currency on the pricing page, set when you pick one.
These stay in your browser. They are never sent to us, and you can clear them in your browser’s settings at any time.
Server logs. The company that hosts this website, render.com, records the requests your browser makes, as any web server does. A log entry can include your IP address, the date and time, the page requested, the response, the page you came from and your browser’s user agent. We use these logs only to keep the website running and secure. We do not combine them with other data or use them to build a profile of you.
Email. If you write to us, we receive your email address and what you write.
Your account
Your email address, a hash of your password (never the password itself), your full name, a profile picture if you add one, your LinkedIn handle if you give it, how you joined (on your own, from an invitation or from a sample report) and when you saw the welcome slideshow.
If you sign in with Google, Google sends us your name, email address and profile picture, and we keep the Google account identifier that links your sign-in to your account. We ask Google for nothing else.
Your company
The company’s name, legal name, description, logo, main website, country of headquarters, size band and sector, and facts that decide which checks apply (for example whether the website is aimed at children or sells subscriptions). The websites and jurisdictions you ask us to scan. The company’s members, their roles, and invitations, which hold the invited person’s email address.
Payments
Your billing account’s name, billing email and country; the references Stripe gives us for your customer record, cards, payments, subscriptions and invoices; and, for display, each card’s brand, last four digits and expiry date. Card numbers go straight to Stripe. We never see or store them.
Scans, findings and evidence
Scan requests, scans, findings, scores and the evidence behind each finding: network requests, cookies, page code and text, response headers and screenshots, recorded while visiting public web pages. Comments and responses that members add to findings.
Evidence is an observation of public web pages, as any visitor’s browser would see them. Those pages sometimes show personal data, such as a name and photo in a testimonial, a manager’s name in a legal notice, or a contact email. When they do, that data can appear in a finding or a screenshot. We do not look for it, we do not use it to identify or profile anyone, and we use it only in the report it belongs to.
Sample reports and access codes
A company member, or PeekWell staff, can share a sample report about a company’s public website with named people. To let a person open it, they enter an access code: that person’s email address, their LinkedIn handle, or an email domain. When an email address is added, we send that person one email inviting them to view the sample. We record when the invitation was sent, how often a code was used, when it was first and last used, and whether the person later joined.
When you open a sample report, you type your email address or LinkedIn handle. We compare it with the access codes and remember in your browser session that you got through.
Using the app
The app sets cookies that keep you signed in and protect its forms from forgery. It sets no analytics or advertising cookies.
The app keeps an audit log of important actions, such as role changes, payments, sharing and opening a shared report, with the account that acted and its IP address. To slow down guessing, it counts failed attempts to open a sample report per browser session and per IP address. render.com keeps server logs for the app, as it does for this website.
Messages
We send account emails (such as address confirmation and password resets), invitations to join a company, invitations to view a sample report, and messages about payments and your subscription. Emails you send to hello@ or privacy@ arrive in our mailboxes at Zoho.
GDPR and UK GDPR, Article 14
Some of this data does not come from you: a colleague may have invited you, a sample report may have been addressed to you, or your details may have appeared on a public page we scanned. You have the same right to this information as someone who gave us their data directly. When we use your email address to contact you, we give you this information at the latest in that first message (Article 14(3)(b)).
We use personal data only for the purposes below. Each has a lawful basis under Article 6(1) of the GDPR and of the UK GDPR.
- Running the service you signed up for. Your account, your company’s workspace, scans, reports, the accreditation page and badge, and the emails that go with them. Basis: contract (Article 6(1)(b)).
- Signing you in with Google. Only if you choose it. Basis: contract (Article 6(1)(b)).
- Taking payment. Basis: contract (Article 6(1)(b)).
- Keeping accounting and tax records. Basis: legal obligation (Article 6(1)(c)).
- Scanning public web pages. Visiting a website’s public pages and recording what they do, including personal data that happens to be visible on them. Basis: legitimate interests (Article 6(1)(f)): ours and our customer’s interest in a report on how a public website behaves. We keep the impact on people small: we only visit public pages, we never sign in or submit forms, and incidental personal data stays inside the report.
- Sending a sample report to someone at a company that has not asked for one. We may tell a person at a company what we observed on that company’s public website, and offer the full report. Basis: legitimate interests (Article 6(1)(f)): our interest in offering the service, and the company’s interest in hearing what its public website shows. We keep it narrow: one invitation, sent to a work address or professional profile, about that person’s own company’s public website, with a plain way to say no.
- Security and preventing abuse. Server logs, the audit log and the limit on failed attempts. Basis: legitimate interests (Article 6(1)(f)) in keeping the service and its users safe.
- Answering you. Basis: legitimate interests (Article 6(1)(f)), or contract when you are a customer.
- Legal claims and requests from authorities. Basis: legal obligation (Article 6(1)(c)) or legitimate interests (Article 6(1)(f)) in establishing or defending legal claims.
We do not rely on consent for anything today. If we ever ask for it, you can withdraw it at any time, and withdrawing does not affect what we did before (Article 7(3)).
GDPR and UK GDPR, Article 21
Your right to object. Where we rely on legitimate interests, you can object at any time on grounds relating to your situation, and we stop unless we have compelling grounds or need the data for a legal claim (Article 21(1)). Where we use your data for direct marketing, including an invitation to a sample report you did not ask for, you can object at any time and we stop, with no reason needed (Article 21(2) and (3)).
We use these providers to run the service. Each one handles personal data on our instructions, under its data processing terms, and only for the job listed. Google is the exception: it runs your Google account itself and only tells us who you are when you choose to sign in with it.
| Provider | What it does for us | Where |
|---|---|---|
| render.com | Hosts this website and the app; keeps server logs | App in Frankfurt, Germany. The website is delivered through render.com’s network. render.com is based in the United States. |
| Supabase | Database and file storage: accounts, companies, scans, findings, evidence files, logos and pictures | Frankfurt, Germany |
| Stripe | Payments, cards, subscriptions, invoices and tax calculation | European Union and United States |
| Resend | Sends the app’s emails | Sends from Ireland. Resend is based in the United States. |
| Zoho | Our mailboxes at hello@ and privacy@ | European Union or United States, depending on the data centre of our account |
| Sign-in with Google, only if you use it | United States and elsewhere | |
| Anthropic | Language models that help write findings, read policy text and, for our staff, fill in public company details | United States |
Other people see some of this data because of how the service works. Members of a company see that company’s workspace and reports. A person with a valid access code sees that sample report. A published accreditation page is public: it shows the company’s name, scan dates and scores, and never findings.
We may also share personal data with professional advisers under a duty of confidence, with authorities when the law requires it, and with a buyer if PeekWell’s business is sold, who would then be bound by this notice.
GDPR and UK GDPR, Article 28
A provider that handles personal data for us is a processor. It may use the data only on our instructions and under a contract that sets out what it does with it.
The app, its database and its files are hosted in the European Union, in Frankfurt. Some providers in section 5 are in the United States or can access data from there.
When personal data leaves the European Economic Area or the UK for a country that does not have an adequacy decision, the transfer relies on one of these safeguards:
- the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795), for providers certified under it, and for data from the UK, the UK Extension to it (recognised by the Data Protection (Adequacy) (United States of America) Regulations 2023);
- the standard contractual clauses adopted by the European Commission (Commission Implementing Decision (EU) 2021/914), with the clauses approved for UK transfers where UK data is involved.
You can ask us at privacy@peekwell.org which safeguard covers a provider, and for a copy of it.
GDPR and UK GDPR, Articles 45 and 46
Transfers outside the EEA or the UK need either an adequacy decision for the destination (Article 45) or appropriate safeguards, such as standard data protection clauses (Article 46(2)(c)).
The table “What we keep, why, how long” near the top of this notice gives the period for each kind of data. These rules apply across it:
- When you ask us to delete your account, we wait 14 days in case you change your mind. Then we remove your email address, name, picture, LinkedIn handle, password and Google sign-in link. Records of actions you took, such as a comment on a finding, stay, attributed to an anonymous account.
- A published report is never edited afterwards, so it can be relied on later. It is kept while the company has a workspace with us. A manager of the company can ask us to delete the workspace and its reports.
- When a period ends, we delete the data or make it anonymous. Copies in backups are overwritten as the backups roll over.
- We keep data longer only when the law requires it or when we need it for a legal claim, and only for that purpose.
You have the right to:
- access your personal data and get a copy (Article 15);
- have inaccurate data corrected (Article 16);
- have your data erased (Article 17);
- restrict how we use it (Article 18);
- receive the data you gave us in a portable format, or have it sent to someone else (portability, Article 20);
- object to our use of it based on legitimate interests, and to direct marketing at any time (Article 21);
- withdraw consent where we rely on it (Article 7(3));
- not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you (Article 22).
How to use them. Write to privacy@peekwell.org. You can also delete your account from your account page in the app. We may ask you to confirm who you are before we act. Using your rights is free.
We answer within one month of receiving your request. If a request is complex, or you send several, we can extend that by two further months, and we will tell you within the first month why we need longer.
GDPR Article 12(3); UK GDPR Articles 12 and 12A
The controller must act on a request without undue delay and within one month. The period can be extended by two further months where needed, taking into account the complexity and number of requests.
If you are unhappy with how we handle your personal data, tell us at privacy@peekwell.org. We acknowledge your complaint within 30 days, look into it, and tell you the outcome without undue delay.
You can also complain to a data protection authority at any time, without coming to us first:
- Greece: the Hellenic Data Protection Authority, Kifisias 1-3, 115 23 Athens, www.dpa.gr.
- Anywhere in the EU or EEA: the authority in the country where you live, where you work, or where you think the problem happened. The European Data Protection Board lists them at edpb.europa.eu.
- United Kingdom: the Information Commission (the ICO), at ico.org.uk.
GDPR Article 77; UK Data Protection Act 2018, sections 164A and 165
In the EU, you can complain to a supervisory authority, in particular in the member state where you live, work or where the problem happened (Article 77 GDPR). In the UK, you can complain to the controller, which must acknowledge your complaint within 30 days (section 164A), and to the Information Commission (section 165).
California’s Consumer Privacy Act and the privacy laws of other US states give residents rights over their personal information. We give these rights to everyone in the United States, whether or not a particular law applies to a business our size:
- to know what personal information we collect, use and disclose, and to get a copy (California Civil Code section 1798.110);
- to have it deleted (section 1798.105);
- to have inaccurate information corrected (section 1798.106);
- to opt out of the sale or sharing of personal information (section 1798.120);
- not to be treated differently for using these rights (section 1798.125).
We do not sell or share personal information. We do not give it to anyone for money or other value, and we do not disclose it for cross-context behavioural advertising. We do not use sensitive personal information to infer things about you.
Global Privacy Control. We treat an opt-out preference signal, such as Global Privacy Control, as a request to opt out of sale and sharing. This website tracks nothing, so it has nothing to switch off, and neither does the app.
The categories of personal information we collect are those in sections 2 and 3: identifiers (such as name, email address, IP address and account identifiers), commercial information (plans and payments), internet activity on our service (server logs and the audit log), and professional information (your company and role). We collect them for the purposes in section 4, and disclose them only to the providers in section 5 and as section 5 describes.
How to use your rights. Write to privacy@peekwell.org. You can use an authorised agent, who must show that you authorised them. We confirm that we received your request within 10 business days and answer within 45 days. If we need more time, we tell you why, and take at most 45 more. If we decline a request, we explain why, and you can ask us to look at it again.
The service is for businesses and is not directed at children. You must be at least 16 to have an account. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to privacy@peekwell.org and we will delete it.
A scan is automated. A browser visits a website’s public pages and records what happens, and code decides most outcomes from that evidence. A language model, Anthropic’s Claude, reads policy text, sorts unclear labels, and helps write each finding, its plain-words summary and its suggested fix. A finding that rests on the model’s judgement is marked as such, with how confident it is. PeekWell staff review each scan before it is published. When staff prepare a sample scan, a language model can also fill in public details about the company.
Whether the accreditation badge shows is decided by fixed rules applied to a company’s scans and subscription. That decision is about a company’s website, not about a person.
We make no decision about a person based solely on automated processing that has legal or similarly significant effects on them.
GDPR and UK GDPR, Article 22
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. We make no such decisions.
We protect personal data with measures that fit the risk:
- every connection to the website and the app is encrypted (HTTPS, with HSTS);
- passwords are stored only as hashes;
- evidence files are kept in private storage and opened through short-lived signed links;
- access to a company’s data depends on each person’s role in that company, and sensitive actions are recorded in the audit log;
- card data stays with Stripe.
No system is perfectly secure. If a personal data breach puts your rights at risk, we notify the competent authority within 72 hours of becoming aware of it where the law requires, and we tell you without undue delay when the law requires that too.
- Personal data and your rights: privacy@peekwell.org
- Everything else: hello@peekwell.org
- Operator
- PeekWell


