beaudited

Privacy

Controller: Gianmaria Palumbo, VAT IT11703831005. Address: via Flaminia 732/i, 00191 Roma. Contact: email.

What we collect

This site uses no cookies or tracking tools and loads no third-party resources. The only form on the site is the check request form, described below; other buttons open your email client. When you write to us we process the data in your email (name, address, site, details of your case) to reply and, if you ask, to deliver the service.

Legal basis and retention

Pre-contractual and contractual measures (art. 6.1.b GDPR). Requests that lead nowhere are deleted 12 months after the last contact; emails and reports of those who become clients are kept for 24 months after the relationship ends, except accounting documents kept for 10 years under tax law.

The request form

When you ask for your site’s measurement, the form sends your site address, your email and the chosen check to a function of ours hosted on Vercel. The function stores nothing: it forwards the request to our mailbox and sends you a confirmation, both through Resend on servers in Ireland. The legal basis is your request (art. 6.1.b GDPR). Site and email are necessary: without them we cannot reply. After the request you receive the result of the measurement and, where it makes sense, the offer of the fixed-price inspection; you receive nothing else, no newsletter and no promotions, unless you buy or ask us. If you did not ask for it, ignore the confirmation: we will do nothing further and will not write again.

The instant check

When you check a domain on the check page, that domain is sent to a function of ours on Vercel which queries public DNS records and answers straight away. We store neither the domain you type nor the result, and we ask for no email. Your IP address stays in the function’s memory for one minute, for the sole purpose of stopping anyone hammering the tool: the legal basis is our legitimate interest in keeping the service up (art. 6.1.f GDPR). You may object at the contact above, though in practice there is nothing to erase, because after a minute it no longer exists.

Checks on public sites

Checks analyse public pages and DNS records with automated tools: they collect no personal data about the analysed site's visitors.

Payments

Since 12 September 2026 the checks can be bought online. Payment happens on a page hosted by Stripe (checkout.stripe.com), not on this site: card details are handled by Stripe directly and we never see them. From Stripe we receive what we need to deliver the service and to invoice: email address, billing name and address, VAT number or tax code, Italian SDI recipient code or certified email, the check purchased, the site to inspect, the amount and the payment outcome. The legal basis is performance of the contract (art. 6.1.b GDPR) and, for the invoice, a legal obligation (art. 6.1.c). Billing data are kept for ten years as tax law requires; everything else follows the periods above. Stripe acts as a processor for carrying out the payment, under an agreement pursuant to art. 28 GDPR, and as an independent controller for fraud prevention and legal obligations; transfers to the United States rely on standard contractual clauses and the Data Privacy Framework.

Signing the clauses

Before payment you approve the one-sided clauses of the terms of sale with a code we email you, as Article 1341 of the Italian Civil Code requires. To send the code we use your email address through Resend, on servers in Ireland. Of the signature we record the email, the site given, date and time, terms version, clauses approved, cryptographic hash of their text, IP address and user agent: the record reaches our mailbox and, in copy, you. The legal basis is steps prior to and performance of the contract (art. 6.1.b GDPR) and our legitimate interest in proving the approval if it is disputed (art. 6.1.f). The record is kept for ten years, the ordinary limitation period. The code itself is not stored.

If we contacted you

Between 7 and 8 September 2026 we sent 45 emails to addresses published on European company websites, carrying the measurement of their site or DNS records. The address came from the site itself; no list was bought from a third party. That channel, towards recipients in the European Union, has been suspended since 8 September 2026: art. 130 of the Italian Privacy Code requires prior consent for commercial email, and legitimate interest does not replace it. Twenty-three already scheduled messages were cancelled before they went out. If you received one of those emails you can ask us to delete your address at the contact above: we act within 24 hours and keep only the note that marks you as excluded, so we never contact you again.

Since 11 September 2026 we write without prior contact only to companies based in the United States and to corporate subscribers in the United Kingdom that sell to European consumers, where local law allows commercial contact with an opt-out (CAN-SPAM Act; Privacy and Electronic Communications Regulations 2003, regulations 22 and 23). The address is the one the company publishes on its own site. Every message contains the measurement of the recipient’s site, our name, our postal address and a simple way to ask for no further messages. Legal basis: art. 6.1.f GDPR, our legitimate interest in offering a service relevant to the recipient’s business; this page is the information due under art. 14 GDPR. No more than two hundred messages a day, and never a second message to the same recipient without a reply. Anyone asking not to be contacted is excluded within 24 hours, and in any case within the ten business days of the CAN-SPAM Act, and stays on a list holding only the address and the date, kept without expiry because deleting it would restart contact. We do not write to sole traders, professionals or individuals, nor to any recipient in the European Union, without consent.

Providers

Domain, DNS and mailbox: Register.it, in Italy; since 11 September 2026 a copy of every email arriving at info@ is forwarded to a Gmail mailbox of the controller, so Google (United States) receives its content: it is a consumer service with no processor agreement, which is why we say so. Email delivery: Resend on Amazon SES, Ireland region, with no open or click tracking. Website hosting: Vercel, servers in the United States with European edge delivery, under standard contractual clauses; like any server, Vercel receives the IP address and page request of every visitor in order to respond, and keeps them in its own technical logs for a limited period; we run no analytics and do not read those logs except to investigate a fault or abuse. Payments: Stripe Payments Europe Ltd, Ireland, with processing also in the United States under standard contractual clauses and the Data Privacy Framework; agreement pursuant to art. 28 GDPR. Electronic invoicing: the document is transmitted to the Italian Revenue Agency through the Sistema di Interscambio, as the law requires. Assistance with drafting copy and building the tools: Anthropic (Claude), United States, on a consumer subscription and therefore without a processor agreement; what goes into the work with the assistant is the domain to be analysed and the site’s technical measurements, which are public data, and not names, email addresses or client correspondence.

Vulnerability analysis. When a customer activates this service, the engagement data, namely the targets authorised in writing, the vulnerabilities found and their technical evidence, are processed on the BountyOS platform, which Gianmaria Palumbo heads and runs. They are not shared with third parties, other than the licensed scanning tool and the security professional engaged for the analysis, both bound by confidentiality. They are kept for the duration of the engagement and for as long as legal obligations require, and do not concern the customer’s own end users beyond the minimum needed to demonstrate a vulnerability.

Artificial intelligence

We also sell checks on AI transparency duties, so it is worth saying where we stand. This site has no chat, assistant or automated system interacting with visitors: the notice duty under Article 50(1) of regulation (EU) 2024/1689 does not apply. The copy on the site, the guides and the study is drafted with the assistance of AI systems and published under the editorial responsibility of the controller, who checks and signs it. The checks we run on client sites use deterministic tools, namely axe-core for accessibility, DNS queries and header reading: no AI system decides anything about your site, and we take no automated decisions within the meaning of Article 22 GDPR. The full detail, activity by activity, is on the page How we use artificial intelligence.

Your rights

You may request access, rectification, erasure, restriction, portability and object to processing at the contact above: we reply within one month. You may lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).

Last updated: 13 September 2026.