Privacy Policy
Our privacy policy and how we use your data
Effective date: September 4, 2026
This Privacy Policy explains how MB Evelaina (trading as RemedyProof) processes personal data when you visit remedyproof.com, create an account, use the service, or purchase a subscription. Questions can be sent to support@remedyproof.com.
1. Controller
The data controller is MB Evelaina (trading as RemedyProof), a company established in Lithuania. Questions about the controller can be sent to support@remedyproof.com.
- Contact: support@remedyproof.com
2. Information we process
Depending on how you interact with RemedyProof, we may process the following categories of personal data:
- Account and service data: your email address, name if provided, authentication details, account and workspace information, approved properties, service configuration, scan results, evidence records, and records of how you use the service.
- Billing and subscription data: customer and subscription references, plan, currency, transaction identifier, invoices, and payment status. Stripe handles card details; we do not store your full card number.
- Online identifiers and campaign data: your consent status, Google Analytics identifiers, Google and Meta click identifiers such as gclid and fbclid, UTM parameters, attribution data, device and browser information received by our providers, and conversion information associated with a subscription.
- Property and business information: domains, hosts, ownership or authorization records, technical observations returned by an approved read-only check, remediation notes, and contact or business information you choose to place in a workspace. You must have authority to submit a property for checking.
3. Purposes of processing
We use personal data for the following purposes:
- Site analytics: to understand how the website and service are used and improve their performance, where you have consented to optional analytics.
- Paid-campaign attribution: to identify which consented campaign or advertisement led to a visit or subscription.
- Conversion measurement: to measure completed subscriptions and report campaign results, where the relevant consent has been given.
- Campaign optimization: to help Google and Meta evaluate and optimize advertising campaigns where you have consented.
- Service delivery, fraud, security, and operational monitoring: to deliver authorized checks and evidence, prevent abuse and fraud, protect accounts and the service, diagnose errors, and monitor operational reliability.
4. Legal bases
We rely on the following legal bases under the GDPR where it applies:
- Analytics: consent. Analytics storage and related processing are optional and remain off until you allow them.
- Advertising and conversion measurement: consent. This includes Google advertising storage, the Meta browser Pixel, and related campaign attribution or conversion processing.
- Account, checks, and Stripe checkout: performance of the contract and strict necessity to provide the service or payment and subscription functionality you request.
- Security and error monitoring: our separately assessed legitimate interest in protecting the service, users, and systems and keeping the service reliable, subject to applicable law.
5. Processors, recipients, and international transfers
Core service providers currently include Stripe (payments), Vercel (hosting and delivery), and Supabase (database and authentication). Google (optional analytics and advertising measurement) and Meta (optional browser Pixel and campaign measurement) are used only after the relevant consent and feature configuration. When AI Defensive Brief is configured, OpenAI receives a compact normalized finding, the authorized canonical hostname, reviewed remediation fields, and a hashed or pseudonymous user identifier where applicable for on-demand guidance; direct account identity or contact data, raw page content, response bodies, credentials, secrets, private notes, and event reasons are excluded. Transactional email delivery and application error monitoring are optional integrations; no Resend or Sentry processing occurs unless a deployment explicitly enables and establishes that provider. We do not share personal data with third parties for their own unrelated marketing.
For customer workspace processing terms and the current provider inventory, see our Data Processing Addendum and Subprocessors.
Some providers may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, the EU Standard Contractual Clauses, or another lawful transfer mechanism, together with appropriate supplementary safeguards. Provider information is available in their privacy notices:
6. Retention
We retain account, service, evidence, and billing records for as long as needed to provide the service, meet legal and accounting obligations, resolve disputes, and enforce agreements. Routine monitoring history and operational records may be purged under the applicable plan and operational retention schedule. Immutable evidence ledgers and the minimum audit links needed to interpret or verify an issued ledger are not promised to be deleted merely because a property or account is removed; they may be retained for integrity, legal, accounting, dispute, or security purposes. The consent cookie ld_consent is retained for six months and the attribution cookie ld_attr is retained for 90 days. Provider-held records follow the applicable provider settings and policies.
7. Your rights and complaints
Subject to the GDPR, you may request access to, correction of, deletion of, or restriction of processing of your personal data; object to processing based on legitimate interests; request data portability; and withdraw consent at any time. Contact support@remedyproof.com. We will respond within the time required by law.
You can withdraw or change optional consent using the persistent Cookie settings control on the website. Withdrawal does not affect processing that was lawfully carried out before withdrawal.
If you represent a business or property owner and want information associated with your request removed, contact us and see our data removal page for the information we hold and how removal works.
You also have the right to lodge a complaint with the Lithuanian supervisory authority, Valstybinė duomenų apsaugos inspekcija (VDAI), through www.vdai.lrv.lt, or with another competent supervisory authority in the EEA.
8. Cookies and similar technologies
We use necessary storage and, only with your consent, analytics and advertising technologies. Our Cookie Policy describes the categories, providers, purposes, durations, and triggers in detail.
9. Sale of personal data
We do not sell your personal data.
10. Security
Data is encrypted in transit and stored with reputable providers. RemedyProof uses bounded, read-only checks against properties submitted with authorization; it is not a guarantee that a property is secure or free from vulnerabilities. No transmission or storage method is completely secure, but we take reasonable technical and organizational measures to protect personal data.
11. Children
The service is intended for business users aged 18 or over and is not directed at children.
12. Changes and contact
We may update this policy and will update the effective date above. Material changes may also be communicated by email or in the service. For privacy questions, contact support@remedyproof.com.