Privacy Policy
Last updated: 15 August 2026. Document under review by Spanish legal counsel.
1. Data controller
PAIQ RAAS, S.L., tax ID (NIF) B27677392, C/ Poeta Francisco Coronado y Delicado nº 6, 3A, 29011 Málaga. Privacy contact: hello@paiq.io.
PAIQ acts as data controller for account and purchase data (email address and payment details). It does not process personal data on behalf of its customers, including Agency subscribers — scanned content is processed transiently and not retained — so no data processing agreement under Art. 28 GDPR is required.
2. Data we process
- Purchase data: buyer email and payment data, processed by Stripe (we do not store card data).
- Scan usage data: the URLs submitted for analysis and the audit result. Reports are generated on demand and are not stored on our servers. The content of the analysed page, which may include third parties' personal data, is processed only transiently to generate the report and is not retained. By submitting a URL, you warrant that you are authorised to submit it for analysis.
- Report delivery by email: If you choose to receive a report by email, the address you enter and the attached report are used solely for that delivery and are not stored by PAIQ; they pass through our email provider (Resend), which retains delivery data, including message content, for up to 30 days under its own terms.
- Technical records: IP address and connection data in server logs, for security and abuse prevention.
- Browser local storage: holds only your language preference, your theme preference (light or dark) and your unlock code, on your device. We use no tracking cookies and no third-party analytics.
3. Purposes and legal bases
- Providing the Service and delivering the report and unlock code: performance of a contract (art. 6.1.b GDPR).
- Security, fraud and abuse prevention: legitimate interest (art. 6.1.f GDPR).
- Tax and accounting obligations on purchases: legal obligation (art. 6.1.c GDPR).
4. Recipients and processors
We use providers acting as data processors: Stripe (payments), Resend (transactional email) and Hostinger (application hosting). The application and its server logs are hosted in Frankfurt, Germany (European Union); the hosting provider, Hostinger International Ltd., is established in Cyprus (European Union) and engages its own sub-processors, some of which are outside the European Union. Some providers process data in the United States; those international transfers rely on EU Standard Contractual Clauses. We do not use third-party analytics, and server logs are not sent to any external logging or monitoring service. We do not sell data to third parties.
5. Retention periods
Purchase and billing data: for the legally required tax periods. Unlock codes: while valid and for the period needed for support. Technical logs: for a limited security period. Scanned URLs and results: not retained beyond report generation.
6. Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to hello@paiq.io. If you believe processing breaches the law, you may complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos (aepd.es).
7. Security
We apply proportionate technical and organisational measures: encrypted communication (HTTPS), signature verification on payment webhooks and data minimisation by design.
8. Changes
This policy may be updated. The current version is always the one published on this page.