Skip to content
IsMyENVPublic

Legal

Privacy policy

We designed IsMyENVPublic to process as little personal data as possible. This policy explains what we process, why, and for how long.

Last updated

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Leon Spingler – LSP Virtual Services
c/o Online-Impressum#9730, Europaring 90, 53757 St. Augustin, Deutschland
Email: [email protected]

2. Summary

  • No user accounts, no cookies, no analytics, no advertising and no third-party trackers.
  • Fonts and all other assets are served by us. No third-party scripts, fonts or tracking services are loaded.
  • Contents of checked files are analyzed in memory only and are never stored, logged or shown, including secrets they may contain.
  • Verification data is deleted automatically after it expires.

3. Hosting and server log files

When you visit the website, the web server and the reverse proxy in front of it technically need to process your IP address, the date and time of the request, the requested URL, the HTTP status, the transferred data volume, the referrer and your browser's user agent. This is necessary to deliver the website and to protect it against attacks. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the secure and stable operation of the service.

Hosting provider: netcup GmbH, Karlsruhe, Deutschland. A data processing agreement under Art. 28 GDPR is in place. Server log files are deleted after 14 days.

Content delivery network

Requests to this website are routed through the network of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. The provider protects the website against attacks and delivers it efficiently. For this purpose it processes your IP address and technical request data such as the requested URL, the time of the request and your browser's user agent. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the secure and reliable operation of the service. The provider acts as our processor under a data processing agreement (Art. 28 GDPR). Data may be processed outside the EU/EEA, in particular in the USA. Such transfers are based on the EU–U.S. Data Privacy Framework adequacy decision, where the provider is certified, and on the EU standard contractual clauses.

4. Running a check

When you use the checker, we process:

  • The domain name you enter, to validate it, resolve it in DNS and create a verification token.
  • The verification token and the session identifier (random values without any personal reference) in the server's memory. They are deleted automatically when they expire, at the latest about two hours after creation. In your browser, the session identifier is kept in session storage so that a page reload doesn't interrupt the verification. It is deleted when you close the tab. This storage is strictly necessary to provide the service you requested (§ 25 (2) no. 2 TDDDG).
  • Responses from the checked website (at most 64 KB per request). They are inspected in memory and discarded immediately. We do not store them.
  • Operational logs containing the hostname, the verification method, the result classification (safe, exposed, inconclusive), error codes and timings. IP addresses are not written to these logs unless the operator enables it, and then only in truncated form.
  • Rate-limiting counters keyed by a hash of your IP address, held in memory for at most two hours.

The legal basis is Art. 6 (1) (b) GDPR (providing the service you requested) and Art. 6 (1) (f) GDPR (our legitimate interest in preventing misuse of the checker, for example against websites you are not authorized to test). There is no public list of checked domains, and results are not shared with anyone.

If a domain name identifies a natural person, the owner of that domain is also affected. The check only runs after control of the domain has been proven, so it is always carried out on the owner's behalf.

5. DNS lookups

To validate domains and verify TXT records, our server sends DNS queries. Address lookups use the resolver of our hosting environment; TXT lookups for verification are sent to the public resolvers 1.1.1.1, 1.0.0.1. These queries contain the domain name, not your IP address.

6. Recipients and transfers to third countries

Apart from the hosting provider and the content delivery network named above, we don't share personal data with other recipients. Transfers to countries outside the EU/EEA only take place through the content delivery network as described in section 3.

7. Your rights

Under the GDPR, you have the right to:

  • access your personal data (Art. 15 GDPR),
  • rectification (Art. 16 GDPR) and erasure (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR),
  • object to processing based on Art. 6 (1) (f) GDPR, on grounds relating to your particular situation (Art. 21 GDPR),
  • lodge a complaint with a supervisory authority (Art. 77 GDPR), for example the authority responsible for our registered office: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg.

Because we keep almost no data, and none of it for long, we often can't link a request to earlier processing. Contact us anyway and we will help as far as possible.

8. Automated decision-making

We don't use automated decision-making or profiling within the meaning of Art. 22 GDPR.

9. Security

The website is only available over encrypted HTTPS connections. See the security page for how the checker is protected against misuse.

10. Changes

We update this policy when the service or the legal requirements change. The current version is always available on this page.