This Privacy Policy explains how Tesoniq collects, uses, stores, shares, and protects personal data when you visit the website, create an account, submit a domain or URL for scanning, use reports, verify a domain, use monitored-domain features, contact us, purchase a plan, or otherwise interact with the Service.
Effective date: This policy applies when posted.
Last updated: 2026-07-06
Version: 1.0
Related legal documents: Terms of Service, Acceptable Use Policy, Cookie Policy, Data Processing Addendum, Report Disclaimer, and the Legal Hub.
By accessing or using Tesoniq, you acknowledge that personal data will be handled as described in this Privacy Policy.
Who we are
Tesoniq is currently operated as a website and online service under the Tesoniq name. Tesoniq is not presented as a registered company, and this policy does not list a physical address, phone number, VAT number, or company registration number.
If the operating entity changes, we will update this Privacy Policy and the Legal Hub. For privacy questions, data subject requests, or data protection concerns, contact [email protected] or use the Privacy Request category on the Contact page.
Our roles under data protection laws
Depending on the context, Tesoniq may act as:
- Controller for public/free scans when we decide why and how public scan data, public report access, cache controls, abuse controls, and related service data are processed.
- Controller for account, billing, support, and security operations when we manage account administration, billing, fraud prevention, abuse prevention, security, service operation, product analytics, marketing communications, and legal compliance.
- Processor for private reports, monitored domains, customer workflows, and other customer-controlled processing when we process personal data on behalf of a customer under an applicable agreement and customer instructions.
- Controller for abuse and security logs when we retain and use logs needed to protect the Service, users, and third parties.
Where Tesoniq acts as a processor, the Data Processing Addendum may apply.
Related role summary
When we act as a controller, we decide the purposes and means of processing for our own service operations.
When we act as a processor, the customer decides the purposes and means, and Tesoniq processes data under the customer's instructions and the applicable agreement.
Personal data we collect
Account and profile data
We may collect name, email address, company or organisation name, role, plan, organisation membership, workspace settings, authentication details, account status, user permissions, and related account metadata.
Scan and report data
We may collect submitted domains, URLs, scan configuration, scan timestamps, scan status, report identifiers, scan results, evidence, screenshots, extracted page text, metadata, scoring outputs, monitored-domain settings, verification status, report history, export activity, and related workflow data.
Website and content data
When a website, page, or URL is submitted, Tesoniq may process public page content, metadata, screenshots, headers, cookies, technical signals, search-readiness signals, trust signals, page text, and other publicly available or submitted content. This content may include personal data appearing on the submitted website.
Third-party personal data visible on scanned sites
Pages that you submit may contain personal data about visitors, staff, customers, authors, contractors, or other third parties. We may process that data as part of the scan, report, evidence, or export you requested.
Technical and usage data
We may collect IP addresses, device data, browser data, operating system data, approximate location derived from technical signals, log data, event data, error data, performance data, security data, abuse-prevention identifiers, cookie identifiers, and usage metrics.
IP addresses used for abuse prevention may be hashed, truncated, or retained where necessary to protect the Service.
Contact and support data
We may collect contact form submissions, support messages, privacy requests, security disclosures, abuse reports, billing inquiries, attachments, screenshots, and related correspondence.
Billing data
Payment processing is handled by third-party payment providers. Tesoniq may receive billing metadata such as plan type, subscription status, payment status, tax details, invoice identifiers, and customer identifiers. Tesoniq does not intentionally store full payment card numbers.
How we collect personal data
We collect personal data when you:
- Visit the website.
- Create or use an account.
- Submit a domain, page, URL, screenshot, or website content.
- Start, view, export, or share a report.
- Verify a domain.
- Use monitored domains or scheduled scans.
- Contact support, sales, privacy, security, or abuse channels.
- Purchase, renew, cancel, or change a plan.
- Interact with service emails or product notifications.
Our systems also generate technical logs for security, reliability, fraud prevention, abuse prevention, and service operation.
Why we use personal data
We use personal data for the following purposes:
- Public scans and public reports: to provide the scan you requested, manage cache and reuse behaviour, prevent abuse, rate-limit misuse, and operate the public report flow. Legal basis: contract performance, legitimate interests, and, where applicable, consent for non-essential cookies or similar technologies.
- Private reports, monitored domains, and customer workflows: to provide customer-controlled reporting, exports, monitored-domain features, scheduled scans, and account workspace functionality. Legal basis: contract performance, customer instructions, legitimate interests, and the Data Processing Addendum where Tesoniq acts as processor.
- Account and profile administration: to create, secure, support, and manage accounts and organisation workspaces. Legal basis: contract performance and legitimate interests.
- Billing and taxes: to process subscriptions, invoices, payment status, and accounting records. Legal basis: contract performance and legal obligation.
- Support and communications: to respond to questions, troubleshoot issues, and send service notices. Legal basis: contract performance, legitimate interests, or legal obligation.
- Abuse prevention and security: to detect, investigate, prevent, and respond to fraud, misuse, attacks, suspicious activity, and service abuse. Legal basis: legitimate interests and legal obligation.
- Product analytics and improvement: to understand how the Service is used and to improve reliability, usability, and quality. Legal basis: legitimate interests or consent where required.
- Marketing: to send optional product updates, campaigns, or related communications. Legal basis: consent or legitimate interests where permitted by law.
- Legal compliance: to comply with law, enforce our policies, preserve records, respond to lawful requests, and resolve disputes. Legal basis: legal obligation or legitimate interests.
- Cookies and similar technologies: to manage sessions, preferences, security, analytics, and consent records. Legal basis: consent for non-essential cookies where required and legitimate interests for strictly necessary cookies.
Where we rely on legitimate interests, our interests include providing, securing, improving, enforcing, and protecting Tesoniq, users, customers, and third parties.
Lawful-basis notes
For GDPR, UK GDPR, and Swiss privacy law, the following general mapping applies:
- Public scans: contract performance and legitimate interests.
- Private reports and customer workflows: contract performance, legitimate interests, and processor instructions under the DPA where applicable.
- Account management: contract performance and legitimate interests.
- Billing: contract performance and legal obligation.
- Abuse prevention and security logs: legitimate interests and legal obligation.
- Analytics: legitimate interests or consent where required.
- Marketing: consent or legitimate interests where permitted.
- Support: contract performance, legitimate interests, or legal obligation.
- Legal compliance: legal obligation and legitimate interests.
Customer responsibility for submitted websites and third-party data
If you submit a domain, URL, page, screenshot, report request, or website content containing personal data about website visitors, staff, customers, authors, contractors, or other third parties, you are responsible for ensuring that you have the authority, lawful basis, notices, permissions, and rights required to submit that material to Tesoniq.
Tesoniq does not control the content of websites submitted by users and is not responsible for a user's failure to obtain required authorisation, notice, consent, or legal basis.
Public and private reports
Tesoniq may offer public and private report modes.
- Public or free reports may be accessible through a report link, served from cache, reused for the same domain, rate-limited, marked as unverified or limited, or visible to others where disclosed in the product flow. Public or free scans are not intended for confidential use.
- Private reports are intended for authorised account or organisation users, subject to plan limits, access controls, workspace configuration, and product settings.
The product flow should indicate whether a report is public or private before submission. You are responsible for choosing the appropriate report mode and sharing report links responsibly.
Domain verification
Certain features may require domain verification, including monitored domains, scheduled scans, private domain workspaces, history, or exports. Verification methods may include DNS TXT records, hosted files, meta tags, or similar methods.
Domain verification helps reduce unauthorised monitoring but does not guarantee legal ownership or resolve all ownership disputes. Tesoniq may suspend, revoke, or re-check verification if needed for security, abuse prevention, legal compliance, or ownership concerns.
AI and automated analysis
Some Tesoniq features may use automated analysis, artificial intelligence assisted classification, screenshot processing, page text extraction, similarity analysis, content-quality diagnostics, trust scoring, or third-party analysis providers.
Depending on your plan and settings, this may involve processing public page screenshots, extracted page text, website metadata, technical scan results, report evidence, and scoring outputs.
Unless expressly stated otherwise in an order form, product setting, or provider notice, Tesoniq does not permit third-party artificial intelligence providers to use Customer Content submitted through Tesoniq to train their foundation models.
Tesoniq's outputs are informational website-signal findings only. They are not legal decisions, compliance certification, penetration-test results, or security guarantees.
Tesoniq does not make significant automated decisions about individuals based solely on personal data processed through the Service.
You should not submit sensitive, confidential, private, or regulated information for artificial intelligence assisted analysis unless you have a lawful basis, proper authorisation, and appropriate safeguards.
Cookies and similar technologies
Tesoniq uses cookies and similar technologies to keep the Service secure, maintain sessions, remember preferences, store consent choices, prevent abuse, measure performance, support billing, and improve the product.
Cookie and similar technology categories may include:
- Necessary cookies for login, session management, security, and consent records.
- Security and abuse-prevention cookies or similar identifiers for rate limiting, fraud detection, and service protection.
- Preferences cookies for language, region, dashboard, and interface settings where implemented.
- Analytics and performance cookies where permitted and, if required, after consent.
- Marketing cookies only if and when used, and only where permitted by law.
Where required by law, non-essential cookies are used only after valid consent. Tesoniq may honour Do Not Track or Global Privacy Control signals where required by law and technically feasible. See the Cookie Policy for details.
Sharing personal data
We may share personal data with:
- Hosting, infrastructure, and content delivery providers.
- Database, storage, and backup providers.
- Authentication and email providers.
- Payment and billing providers.
- Analytics, error monitoring, and performance providers.
- Artificial intelligence, page analysis, screenshot, search, or content-analysis providers where features require them.
- Security, fraud, abuse-prevention, and rate-limiting providers.
- Customer support and communication providers.
- Professional advisers, auditors, insurers, accountants, and legal advisers.
- Authorities, courts, regulators, or third parties where legally required or reasonably necessary to protect rights, safety, security, users, third parties, or the Service.
- Business successors in connection with a merger, acquisition, financing, reorganisation, sale of assets, or similar transaction.
We do not sell personal data to third parties for their own marketing.
Subprocessors and providers
Tesoniq may use subprocessors and service providers to operate the Service. Where we use subprocessors for processor services, we require written data-protection obligations that are substantially similar to the Data Processing Addendum where required by law.
Specific provider names are not published in this policy unless already listed elsewhere in the product. A current subprocessor or provider list may be made available through the DPA, legal hub, account area, order form, or on request. If a dedicated public list is added later, we will link it from the Legal Hub.
International transfers
Personal data may be processed in countries other than your country of residence. Where personal data is transferred outside the European Economic Area, United Kingdom, Switzerland, or another protected jurisdiction, Tesoniq will use appropriate safeguards where required, such as adequacy decisions, Standard Contractual Clauses, transfer impact assessments, or equivalent lawful mechanisms.
You may request information about applicable transfer safeguards by contacting [email protected].
Retention
We keep personal data only as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
- Account data: while the account is active, then for a limited closure period for recovery, support, dispute handling, abuse prevention, and legal recordkeeping.
- Free or public reports: limited cache or public-access retention, until refreshed, deleted, or no longer needed for abuse, security, or operational reasons.
- Private reports: for the customer account or plan term, with limited backup retention and any additional retention needed for legal, billing, security, or dispute purposes.
- Scan and job logs: for a limited operational period needed for reliability, abuse prevention, security, and troubleshooting.
- Abuse-prevention and security records: for a limited period needed to protect the Service, investigate misuse, enforce terms, and prevent repeat abuse.
- Contact and support data: for as long as needed to resolve the request, maintain business records, and meet legal obligations.
- Billing metadata: for the legal, tax, accounting, audit, and fraud-prevention period required by law or internal controls.
- Backups: through rolling backup cycles and then overwritten or deleted according to backup procedures.
Retention may be extended where necessary for security, abuse prevention, legal claims, dispute resolution, regulatory compliance, accounting, tax, or law enforcement requests.
Your privacy rights
Depending on your location and applicable law, you may have rights to:
- Access personal data we hold about you.
- Correct inaccurate personal data.
- Delete personal data.
- Restrict processing.
- Object to processing based on legitimate interests or direct marketing.
- Receive data in a portable format.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with a data protection supervisory authority.
To exercise rights, contact [email protected] or use the Privacy Request category on the Contact page. We may need to verify your identity before fulfilling certain requests.
Where applicable, you may also request export or deletion of account data, private reports, monitored domains, report history, and related workspace data, subject to legal, security, billing, backup, and technical limits.
Some rights may be limited where data is needed for legal obligations, security, abuse prevention, dispute handling, billing records, freedom of expression, or the rights of others.
We aim to respond to rights requests within the period required by law and, where applicable, generally within 30 days.
Breach notification
If a personal data breach affects your rights or risks them, Tesoniq will notify affected users and regulators as required by law.
Where GDPR applies and authority notification is required, Tesoniq will notify the competent authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach.
Security
Tesoniq uses appropriate technical and organisational measures designed to protect personal data, including access controls, authentication, encryption in transit, audit logging, least-privilege practices, monitoring, backup procedures, and vulnerability management.
No online service can guarantee absolute security. You are responsible for maintaining account security, managing authorised users, using strong authentication, and limiting access to reports and exports.
Jurisdiction-specific notes
GDPR, UK GDPR, and Swiss privacy law
Where these laws apply, Tesoniq relies on the lawful bases described above, uses transfer safeguards where required, and supports rights requests and complaints as described in this Policy.
Canada and PIPEDA
Where PIPEDA or similar Canadian privacy law applies, Tesoniq uses personal information for identified purposes, provides access and correction rights where required, and relies on consent or comparable legal authority where needed.
California and other US state privacy laws
Where US state privacy laws apply, Tesoniq provides the rights and notices required by those laws. Tesoniq does not sell personal data. If a law gives you a right to opt out of certain sharing or targeted advertising practices, we will honour that right where it applies and where the Service uses the relevant practice.
Children
Tesoniq is intended for business and professional use. It is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided personal data to Tesoniq, contact [email protected] so we can review and take appropriate action.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If changes are material, we will take reasonable steps to notify users, such as posting a notice, updating the legal hub, sending an email, or presenting an in-product notice.
Continued use of Tesoniq after an updated Privacy Policy becomes effective means the updated policy applies to your use from that point forward.
Contact
For privacy questions, rights requests, or data protection concerns, contact [email protected] or use the Privacy Request category on the Contact page.
We aim to respond to most inquiries within 3 business days.