digital scan

privacy & transparantie

Privacy policy

This page explains which personal data Marketing Scan processes, why, and which choices and rights you have.

Controller

Marketing Scan determines why and how data on this website is processed. For privacy questions or requests, use the contact address below or reply to an email you received from us.

Which data and why

  • Quick scan: domain, publicly accessible homepage content, technical headers, DNS and security signals. Purpose: provide the requested report. The scan is a snapshot and does not inspect protected systems.
  • Report request: name, business email, optional company and phone, domain, score and campaign data. Purpose: deliver and meaningfully follow up the report.
  • Contact and quote: messages, appointments, quote details and relevant contact history. Purpose: answer questions and prepare or provide requested services.
  • Site use: necessary technical data and, only after consent, analytics data through the selected measurement tools. Purpose: security and site improvement.
  • Business outreach: public company and professional contact details, scan result, sending status and objection status. Purpose: propose relevant B2B services. This relies on legitimate interests after a balancing test, not merely because data is public.

Service providers and transfers

We do not sell personal data. We only share what is necessary with hosting, database, email, analytics and scheduling providers working for us. This may currently include Vercel (hosting and cookieless visitor statistics), Supabase, Resend, Google Tag Manager/Analytics, Microsoft Clarity, the Meta pixel (Facebook and Instagram) and the OpenAI pixel; those two pixels measure which enquiries come from our ads. Analytics, Clarity and those pixels load only after consent. Some providers process data outside the EEA; in that case we rely on an adequacy decision or appropriate contractual safeguards.

Retention

IP addresses for report requests are removed within 30 days and for scans within 90 days. Anonymous visit events are kept for 180 days by default. Other report and contact data is kept for no more than 24 months after the last meaningful contact, unless a contract or legal duty requires longer. After an objection, only the minimum suppression record needed to prevent further outreach remains.

Your rights

You may request access, correction, deletion, restriction, portability or object, and may withdraw consent at any time. You can object to direct marketing free of charge at any time; we will stop that communication. You may also complain to the Belgian Data Protection Authority at dataprotectionauthority.be.

Last updated: 26 August 2026.