Skip to content
seeking data labs
Sightline Sample report Consulting Documentation Sign in Contact Request an invitation

Legal · Data protection

Privacy Policy

Last updated: 3 October 2026

This Privacy Policy explains how Seeking Data Labs ("we", "us", "our") collects, uses, discloses, and protects personal data when you visit seekingdatalabs.com, create an account, use Sightline (our website audit service, its hosted report pages and its audit API), engage our research and consultancy services, or when we contact your organisation about Sightline.

We operate from Switzerland. Two data-protection regimes apply to us in parallel and this policy is written to satisfy both:

  • the Swiss Federal Act on Data Protection (revFADP / nFADP), in force since 1 September 2023, because we are established in Switzerland; and
  • the EU General Data Protection Regulation (GDPR, Reg. 2016/679), which applies under Art. 3(2) because we offer services to, and process the data of, individuals in the EU/EEA.

Where the two regimes differ, we apply the stricter standard. The legal bases below are stated under the GDPR and mapped to the corresponding Swiss justification.

1. Who is responsible (controller) and how to contact us

The controller responsible for your personal data is:

  • Matteo Assinnata, who operates Seeking Data Labs (trading name) in Zürich, Switzerland, until the company is incorporated
  • Privacy contact: [email protected]
  • To have a report about your organisation deleted, see Having a report deleted.

Please direct all privacy questions and all requests to exercise your rights to [email protected].

Data protection officer. We have not appointed a statutory data protection officer. The revFADP does not impose a general DPO requirement, and the GDPR Art. 37 triggers (large-scale processing of special-category data, or systematic large-scale monitoring as a core activity) are unlikely to be met by our processing. The privacy contact above handles all matters.

EU/UK representative. As a controller outside the EU that processes EU/EEA personal data, GDPR Art. 27 in principle requires an EU representative unless the Art. 27(2) exemption applies (processing that is occasional, does not involve large-scale special-category data, and is unlikely to risk individuals' rights). If we appoint an EU representative, we will name them here. Because we are established in Switzerland, the revFADP Art. 14 obligation to appoint a Swiss representative, which applies only to controllers based abroad, does not apply to us.

2. The personal data we process

We only process the categories of data our service actually involves:

  • Account identity. Your email address (email/password sign-up and Google sign-in). For Google sign-in we also receive, from the openid email profile scope, your Google account identifier, display name, and profile picture.
  • Authentication and security data. A password hash (argon2id; we never store plaintext passwords); if you turn on two-factor sign-in, the one-time-password secret and your recovery codes; the single-use links we email you to verify your address or reset your password, stored only as a hash; a signed session token held in an HttpOnly, Secure cookie; and, for login abuse-protection and rate-limiting, a record of sign-in attempts keyed by your email address and IP address.
  • Account and usage data. Your API key(s) (stored as a hash), your subscription plan, any one-off reports you buy, your credit balance, the domains you add and their DNS verification status, the audits you run and the reports they produce, your sharing settings, the service and consultancy requests or bookings you make (including the name, email address and topic you enter), request and usage logs, and timestamps.
  • Contact form messages. When you write to us through the contact form: your name, email address, the company or website you add, the topic you pick and your message, plus a short triage we compute from them (topic, urgency, likely spam, and whether it is a privacy or deletion request, which we handle first). We do not store your IP address with the message; to stop abuse we count submissions per email address and per connection, the connection held only as a one-way hash, and those counts are deleted after 30 days.
  • Payment data. If you pay in USDC on the Solana blockchain: the wallet address that sends the payment, the amount, the transaction signature and the payment reference (memo), plus our internal record of the credits and debits on your account. If a payment is settled off-platform, we record the amount, date and reference. Before a payment is credited, the sending wallet may be checked against official public sanctions lists; a match holds the payment, and the check and its outcome are kept with the payment records. On a public blockchain these records are pseudonymous but permanent, irreversible, and outside our control.
  • Nickname. An optional nickname you can set in your account. It is stored with your account; we do not publish public profile pages.
  • Technical and operational data. IP address, user-agent, and request metadata processed at our CDN/WAF edge and at the origin to deliver and protect the service.
  • Communications. The content of emails you send us, including replies to a message we sent you, and the delivery status of the emails we send (delivered, bounced, delayed, or marked as spam). We also record when a report link we sent is opened.
  • Content of the websites we audit. An audit reads the pages of the site being audited and keeps evidence for each finding (page addresses, short text excerpts, screenshots, timings). Public pages sometimes carry personal data, such as a name on a team page, and it can appear in that evidence incidentally. Findings describe the product, never the people.
  • Analytics data, collected only after you opt in (see section 11). We use Google Analytics 4 for privacy-respecting web analytics. It loads only after you grant consent through the banner, and until then no Google Analytics identifiers or _ga cookies are set.

We do not collect payment-card data, and we do not seek to collect special categories of data (health, biometrics, political opinions, etc.). Please do not send us such data.

Payments in USDC, and their on-chain footprint

Where a payment is made in USDC on the Solana blockchain, it is sent to our deposit address with a short payment reference in the transaction memo field, which tells us what the payment is for. We never hold your wallet's signing keys. Our systems read the public ledger, match the memo, and keep a payments ledger (transaction signature, amount, what it paid for, status, timestamp) linked to your account.

Important, irreversible consequence. Some payment references identify your account: the reference used to add credit to an account contains that account's id. Anything written into the memo is recorded on the public, permanent Solana ledger alongside the paying wallet address. This creates a permanent, public on-chain link between the reference and the wallet you pay from that we, and everyone, cannot delete, rectify, or geographically confine. If you do not want that link to exist, pay from a wallet you are comfortable associating with your account, and never place other personal data in a memo.

Reports you choose to share

A report is private to your account unless you share it. You can create a share link that anyone holding it can open, or share a report only with named registered users, in which case we store their email addresses on the share. Shared report pages are marked noindex so search engines are asked not to list them, and you can revoke a share at any time, after which the link stops working. We process this on the basis of contract (Art. 6(1)(b)), delivering the sharing feature you asked for.

If we contacted your organisation

We may write once to an organisation to ask whether it would like a free Sightline check of its website. For that we process:

  • the organisation's name and domain, and a role-based contact address (such as hello@ or info@) published on the organisation's own website, together with the page it was published on and the date we read it. We never infer, buy, or store a personal email address;
  • where the organisation publishes it (for example in its imprint or on its team page), the name, job title and public professional profile address of one person who runs it, with the page we read it on and the date, so that our message can be addressed to a person. Nothing else about that person is kept, and our first message says where we found the name;
  • the message we sent, the reply, and whether the answer was yes or no.

We send one message per organisation in any 12 months and no follow-ups; silence is treated as an answer. We audit the website and send a report only if the organisation says yes. Such an audit reads public pages only, signs in nowhere, and changes nothing on the site. A report page stays noindex until the organisation claims it. The legal basis is our legitimate interest (Art. 6(1)(f)) in offering a relevant business service to a business at an address it published for such enquiries.

Having a report deleted

To have a report about your site, and everything we hold about it, deleted, write to [email protected] and we will. We take down any report page at once and delete the records we hold about the organisation, including any named person, within 30 days. We delete everything except accounting records the law requires us to keep, and those exist only if you bought something (see section 7). The one thing we add is the bare domain, on a do-not-contact list, so that we never write again; it stops our outreach, not the domain's owner later buying an audit of its own verified domain. A named person may ask for their own data to be deleted without the organisation's agreement.

3. Why we process it, and the legal basis

For each purpose we state the GDPR Art. 6 legal basis. Under the revFADP, which relies on lawful processing plus a duty to inform rather than an enumerated list of bases, the same justification applies.

PurposeData usedLegal basis
Create your account and authenticate you Account identity, authentication data Contract, Art. 6(1)(b)
Provide, operate, and support Sightline audits, reports, and the audit API Account, usage metadata, technical data Contract, Art. 6(1)(b)
Send account and service emails (address verification, password reset, report notifications) Email address, account and report data, delivery status Contract, Art. 6(1)(b)
Process payments and keep billing records Payment data, billing metadata Contract, Art. 6(1)(b); legal obligation (accounting), Art. 6(1)(c)
Security, abuse/fraud prevention, and login rate-limiting IP address, email, request metadata Legitimate interests, Art. 6(1)(f): protecting the service and our users
Operate CDN, hosting, and WAF logs IP address, user-agent, request metadata Legitimate interests, Art. 6(1)(f); Contract, Art. 6(1)(b)
Respond to your emails and enquiries Communications, contact details Legitimate interests / pre-contractual steps, Art. 6(1)(f)/(b)
Contact an organisation once about Sightline, record its answer, and honour opt-outs and deletion Organisation name and domain, published role address, published name and title of one person who runs it, the message and reply Legitimate interests, Art. 6(1)(f)
Comply with legal, tax, accounting, and lawful-request obligations Billing records, relevant account data Legal obligation, Art. 6(1)(c)
Aggregate, non-identifying product and reliability statistics De-identified usage data Legitimate interests, Art. 6(1)(f)
Privacy-respecting web analytics (Google Analytics 4) Analytics identifiers, IP Consent, Art. 6(1)(a) (prior ePrivacy opt-in via the banner)

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms, and we have concluded the processing is limited to what is necessary. You have the right to object to legitimate-interest processing at any time (see section 9).

4. Our AI research pipelines, scope and limits

We describe ourselves as AI-driven research: automated agents run the Sightline audit, gather evidence from a target's public surfaces, and produce the report. To be clear about what this does and does not involve:

  • These AI/agent pipelines operate on the pages of the domain being audited (its public pages) and on the resulting report, not on your account data.
  • The AI models run on the platform of our hosting provider, which acts as our processor (see section 5). Page content, including any personal data a page happens to show, is processed there to produce findings.
  • We do not use your personal data, account contents, or the content of your reports to train or fine-tune AI or machine-learning models.
  • If we ever introduce a feature in which a third-party AI/LLM provider processes user-submitted content (for example, to assist with support), that provider would become a processor and we would disclose it here before doing so.

5. Who we share data with (processors and recipients)

We do not sell your personal data. We share it only with service providers who process it on our documented instructions under a data-processing agreement (GDPR Art. 28 / revFADP Art. 9), and where required by law.

RecipientRoleWhat it processes
Google (Google LLC, United States / Google Ireland) Processor, sign-in identity provider; hosted email (Google Workspace) for the hello@ alias; consent-gated web analytics (Google Analytics 4) Google sign-in (email, account id, name, picture); the content of emails you send us; GA4 analytics events and identifiers (only after opt-in)
Cloudflare, Inc. Processor, hosting of the website, API, and report pipeline; databases and file storage; AI model inference; CDN, edge/WAF, and DNS; inbound email routing Visitor IP, user-agent, request metadata; account data, billing metadata, usage logs, reports and audit evidence; inbound email in transit
Email delivery provider Processor, sends our account, service, and outreach emails and reports their delivery status Recipient address, message content, delivery events
Customer-relationship management (CRM) provider Processor, keeps our record of the organisations we are in contact with Organisation name and domain, published role address, the published name and title of one person who runs it, conversation status
Cloud compute provider (EU region) Processor, runs the security tests a site owner has asked us to perform on their own site The target site's responses to that test
The Solana public blockchain and its validators Recipient we cannot bind by contract On-chain transactions (wallet address, amount, signature, memo), public, permanent, pseudonymous

We may also disclose data to professional advisers, or to authorities and courts, where necessary to comply with the law, respond to lawful requests, or establish, exercise, or defend legal claims. If our business is reorganised or transferred, data may be disclosed to a successor under equivalent protections.

6. International transfers

Some recipients above are located in, or transfer data to, countries outside Switzerland and the EEA, in particular the United States. Where that happens, we rely on recognised safeguards:

  • the EU Standard Contractual Clauses (2021/914) for EEA-origin transfers, and the FDPIC-recognised SCCs with the Swiss addendum for Switzerland-origin transfers;
  • the EU–US and Swiss–US Data Privacy Framework where the recipient is certified (Google and Cloudflare are certified; for any provider that is not certified, we rely on the SCCs);
  • Switzerland's recognition of the EEA as providing adequate protection.

Our hosting provider holds the richest set of personal data we process (account data, billing metadata, usage logs, reports, and our databases) and may process it in more than one country. It is certified under the EU–US and Swiss–US Data Privacy Framework and additionally offers the Standard Contractual Clauses, on which we rely for any transfer of this data outside Switzerland and the EEA. The security tests described in section 5 run in the EU. You can request copies of the transfer safeguards by emailing [email protected].

On-chain payments are inherently international. The Solana blockchain is a globally distributed public ledger with no controllable transfer location; transactions on it cannot be erased or geographically confined. If you value the privacy of a wallet, do not use it to pay us, and do not place personal data on-chain.

7. How long we keep it

  • Account data, kept for the life of your account, then deleted or anonymised within 90 days of account closure or of an erasure request, except for the financial records described next.
  • Financial records (payments and the payment ledger, credits and debits, invoices, the record of what a payment bought, and sanctions-screening results), retained for 10 years, the period Swiss law sets for business records (Code of Obligations, Art. 958f). If you ask us to erase your account, we keep these records but restrict them: they are detached from your sign-in identity, stripped of anything not needed to evidence the transaction, excluded from every other use, and read only for bookkeeping, tax, audit, legal claims and sanctions compliance. They are deleted when the period ends. Everything else about the account is deleted as above.
  • Reports, findings and audit evidence, kept while your account is open, and deleted with the account or when you ask. When an organisation asks us to delete an audit or report about it, we delete it; no retention period applies to audit or outreach data.
  • Contact form messages, kept while we answer and follow up, and deleted within 24 months of your last message, or sooner when you ask. A privacy or deletion request is kept until we have finished handling it.
  • Sign-in attempt records (email address and IP address, for rate-limiting and abuse protection), deleted after 30 days; expired verification and password-reset tokens are deleted on the same schedule.
  • Records about an organisation we contacted: if it does not answer, we do not write again for at least 12 months. If it asks for deletion, we delete them within 30 days and keep only the bare domain on a do-not-contact list.
  • Operational, CDN/WAF, and security logs, a short rolling window of approximately 30 days.
  • On-chain USDC transactions (including the memo), permanent and outside our control; they cannot be deleted.
  • Analytics data (Google Analytics 4), retained only from the point of consent; the _ga cookies expire after roughly 13 months.

8. Security

We apply technical and organisational measures appropriate to the risk (GDPR Art. 32 / revFADP Art. 8), including:

  • TLS/HTTPS for all traffic;
  • passwords stored only as argon2id hashes, never in plaintext, and optional two-factor sign-in;
  • emailed verification and reset links that are single-use, expiring, and stored only as hashes;
  • the login session in an HttpOnly, Secure, SameSite=Lax cookie on the API host that page scripts cannot read (this "not exposed to page scripts" property describes that session cookie and the OAuth CSRF cookie, not every credential: a separate, script-readable bearer token may be stored in your browser's localStorage for direct API calls, as the Cookie Policy details);
  • login rate-limiting and protections against account enumeration and timing attacks;
  • a web application firewall in front of every service, and operator tools reachable only from restricted networks;
  • non-root containers for security testing, and least-privilege access;
  • a design in which we never hold your wallet's signing keys.

No method of transmission or storage is completely secure, but we work to protect your data and to review our measures.

9. Your rights

Under the GDPR and the revFADP you have the right to:

  • access the personal data we hold about you;
  • rectify inaccurate or incomplete data;
  • request erasure ("right to be forgotten"). We delete everything except the financial records we are legally required to keep (section 7), which we keep restricted for the statutory period, and which exist only if you bought something;
  • restrict or object to processing, including any processing based on our legitimate interests and any direct marketing;
  • receive your data in a portable format (data portability);
  • withdraw consent at any time for any processing based on consent (such as analytics), as easily as you gave it, without affecting the lawfulness of processing before withdrawal.

To exercise any right, email [email protected]. We respond without undue delay and within one month (extendable by two further months for complex requests, with notice). Requests are free unless manifestly unfounded or excessive. We may need to verify your identity before acting.

Right to complain. You may lodge a complaint with a supervisory authority:

  • in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern (edoeb.admin.ch); and
  • in the EU/EEA, the supervisory authority in your country of residence or workplace.

10. Automated decision-making and profiling

We do not make decisions that produce legal or similarly significant effects about you by solely automated means. The only automated logic we apply is operational: rate-limiting, abuse/fraud detection, plan gating (a request beyond your plan returns an upgrade prompt), and reading whether a reply to our outreach message says yes or no, where any unclear reply goes to a person and a no only stops further contact. These do not profile you.

Should any such control ever be treated as a significant automated decision within the meaning of GDPR Art. 22 or revFADP Art. 21, you have the right to obtain human review, to express your point of view, and to contest the decision, contact [email protected].

11. Cookies and analytics

The site uses strictly-necessary and functional cookies and local storage, plus consent-gated analytics, there is no advertising or third-party tracking. Our fonts are self-hosted, so your browser makes no request to Google Fonts. See our Cookie Policy for the full, itemised inventory.

For web analytics we use Google Analytics 4, and it loads and sets identifiers only after you give prior, informed opt-in consent through the consent banner. Nothing non-essential, no Google Tag Manager request and no _ga cookie, loads before you accept; rejecting is as easy as accepting, no boxes are pre-ticked, and you can change or withdraw your choice at any time via the "Cookie settings" control in the footer. IP addresses are handled under Google's EU/EEA data-processing measures (we set anonymize_ip). Analytics data is shared with Google LLC (United States) and processed there under the transfer safeguards in section 6 (the EU–US / Swiss–US Data Privacy Framework, the Standard Contractual Clauses, and the Swiss addendum).

12. Children

This is a professional developer and research service and is not directed to children. It is not intended for, and must not be used by, anyone under 16 (or a higher minimum age set by local law). We do not knowingly collect data from children; if you believe a child has provided us data, contact [email protected] and we will delete it.

13. Data breaches

If a personal-data breach occurs, we will comply with our notification duties: notifying the competent EU supervisory authority within 72 hours where required (GDPR Art. 33), notifying the FDPIC as soon as possible where a breach is likely to result in a high risk (revFADP Art. 24), and informing affected individuals where the law requires it (GDPR Art. 34).

14. Changes to this policy

We may update this policy. We will change the "last updated" date above and, for material changes, notify account holders by email and/or a prominent site notice. We will not apply materially adverse changes retroactively to data already collected without a lawful basis. Prior versions are available on request.

15. Contact

Seeking Data Labs, Switzerland, [email protected], or the contact form.

seeking data labs

Sightline reads live websites and reports what to fix, with evidence for each finding. We also take on engineering work.

[email protected]

Lab

Home Sightline Consulting Sample report Guides for agencies Contact

Product

Sign in Request an invitation Documentation For agencies For portfolios Status

Legal

Privacy How our crawler works Cookies

© 2026 Seeking Data Labs.

Cookies Essential ones keep the site working. Analytics only if you agree. Cookie policy

Cookie preferences

We use a first-party cookie for essential functions, keeping you signed in, remembering your theme, and storing this choice. With your consent we also load a traffic-measurement script; it loads only after you opt in. The cookie policy names the provider. You can change this anytime from Cookie settings in the footer.

Always on, required for the site to work (theme, login session, and this consent record). No tracking.

Anonymous traffic measurement. Off by default; loads only after you turn it on.

Cookie policy · Privacy