SiteGuard
Privacy policy
Last updated: 2 September 2026
This privacy policy explains how personal data is processed when you visit the public SiteGuard website and use the early-access registration offered there. It describes the functions currently intended for production use; merely registering for early access does not start monitoring, scanning or a SiteGuard agent.
Controller
SmartBit.Services
Kevin Reiter
Im Altengarten 44
54528 Salmtal
Deutschland
E-Mail: info@smartbit.services
Telephone:
+49 (0) 6578 / 2149977
1. Scope and principles of processing
We process personal data only to the extent necessary to operate the public website securely, handle an early-access registration requested by you, verify your email address, provide the requested access, communicate with you or protect the service against misuse.
Depending on the processing activity, we rely in particular on Art. 6(1)(b) GDPR for pre-contractual steps or the handling of a service requested by you and on Art. 6(1)(f) GDPR for secure, stable and abuse-resistant operation. We rely on consent under Art. 6(1)(a) GDPR only where an optional processing activity is expressly based on consent.
2. Hosting and server log files
The public SiteGuard website is hosted by Mittwald CM Service GmbH & Co. KG, Königsberger Straße 4–6, 32339 Espelkamp, Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with Mittwald.
Technically necessary server and error logs are generated when the website is accessed. According to Mittwald's published information, access logs include information such as the time, requested page, protocol, status code, amount of data, referrer, user agent and hostname; IP addresses are anonymised in archived access logs. According to Mittwald, anonymised access logs are retained for 60 days. Error logs may include error messages, the accessing IP address and the requested page and are deleted after seven days according to Mittwald.
This processing serves technical delivery, troubleshooting, stability and security of the website. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is to provide a secure and functional online service.
3. Technically necessary cookies and session data
SiteGuard does not use analytics, marketing or advertising trackers on the public website. Short-lived session information and cookies may be used for technically necessary functions, in particular form protection, CSRF protection and short-lived status or error messages after a form submission.
Where information is stored on or accessed from your device for these purposes, no consent is required under Section 25(2) no. 2 TDDDG where the storage or access is strictly necessary to provide a digital service expressly requested by you. Where personal data is processed in this context, the legal basis is Art. 6(1)(f) GDPR for security and proper operation.
4. Early-access registration
When you register for SiteGuard early access, we process in particular the website or system URL you provide, your email address, the selected audience type, language and status, time and version information relating to registration and verification.
To protect against abusive or automated registrations, an HMAC-SHA256 verification value is additionally generated from the IP address detected for the request using a secret application key. The IP address itself is not stored as a plain-text value in the early-access registration for this purpose.
Registration data is processed to handle your request, verify the supplied email address and later provide the access requested by you on the basis of Art. 6(1)(b) GDPR. The IP verification value and comparable security information are processed on the basis of Art. 6(1)(f) GDPR; our legitimate interest is preventing misuse and protecting the application.
The required confirmation in the form is not consent to a newsletter or advertising. It documents the request initiated by you and your acknowledgement of the related privacy information.
5. Email verification and service-related messages
After an early-access registration, SiteGuard may send a verification email containing a time-limited confirmation link. After successful confirmation, further messages may be sent where they directly relate to registration, confirmation, provision of the requested access or another SiteGuard service requested by you.
These messages are not newsletters and are not used to send general advertising. Sending requires processing in particular the email address, sender and recipient information and technically necessary transmission and delivery information. Where the message is required to handle your request, the legal basis is Art. 6(1)(b) GDPR; security- and delivery-related technical processing may additionally be based on Art. 6(1)(f) GDPR.
6. Contact by email
If you contact us by email, we process your email address, the content you send and the technical metadata required for communication in order to handle and respond to your request.
If the contact relates to a contract or pre-contractual steps, the legal basis is Art. 6(1)(b) GDPR. Other enquiries are processed on the basis of Art. 6(1)(f) GDPR; our legitimate interest is the proper handling of incoming enquiries.
7. Recipients and processors
Personal data is made available only to recipients that need it for the relevant purpose. These may include authorised persons internally and technical service providers for hosting, infrastructure and email transport.
Mittwald is used as a processor for hosting. Further service providers are used only where necessary for operation and where the applicable data-protection requirements are met. If the production mail infrastructure is moved to another external provider in the future, this privacy policy will be updated before or when that provider is used.
8. Retention periods
We retain personal data only for as long as it is necessary for the relevant purpose or for as long as statutory retention obligations apply. Data is then deleted or, where deletion is not yet possible, its processing is restricted.
Unverified early-access registrations are deleted once they are no longer necessary to carry out verification, handle the request and provide appropriate protection against misuse. Verified early-access data is retained during the early-access phase and, where applicable, the subsequent access-provision phase and is deleted when the request is no longer pursued and there are no contractual, statutory or evidentiary reasons for further retention. Necessity is reviewed regularly.
The retention periods stated in section 2 apply to server logs maintained by the hosting provider. Correspondence is generally retained until the relevant matter has been fully handled; statutory retention obligations and retention required to establish, exercise or defend legal claims remain unaffected.
9. Transfers to third countries
A transfer of personal data to countries outside the European Union or the European Economic Area is not intended for the core functions described in this policy.
If a service requiring a third-country transfer is used in the future, the legal requirements, including any required adequacy decision or appropriate safeguards, will be assessed before or when the service is introduced and this privacy policy will be updated accordingly.
10. Requirement to provide data
For early-access registration you must provide the information marked as required in the form. Without this information we cannot process the registration, verification and later provision of the requested access.
There is no statutory obligation to register for early access or to provide this information to us.
11. Automated decision-making and profiling
No automated decision-making within the meaning of Art. 22 GDPR takes place in connection with the public website and early-access registration described here. We also do not carry out personal advertising profiling.
12. Your data protection rights
Subject to the statutory requirements, you have in particular the right of access under Art. 15 GDPR, rectification under Art. 16, erasure under Art. 17, restriction of processing under Art. 18 and data portability under Art. 20 GDPR.
Where processing is based on your consent, you may withdraw that consent at any time with effect for the future under Art. 7(3) GDPR. The lawfulness of processing carried out before withdrawal remains unaffected.
You can exercise your rights using the contact details provided in the “Controller” section.
13. Right to object under Art. 21 GDPR
Where we process personal data on the basis of Art. 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation.
We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing is required to establish, exercise or defend legal claims.
14. Right to lodge a complaint
Under Art. 77 GDPR you have the right to lodge a complaint with a data protection supervisory authority. For SmartBit.Services in Rhineland-Palatinate, the State Commissioner for Data Protection and Freedom of Information Rhineland-Palatinate is in particular competent: Hintere Bleiche 34, 55116 Mainz, Germany; email: poststelle@datenschutz.rlp.de; telephone: +49 (0) 6131 8920-0.
You may also contact another supervisory authority competent under Art. 77 GDPR, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement.
15. Data security
We take appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access and unauthorised disclosure. The public SiteGuard website is provided over encrypted HTTPS connections in production.
16. External links
Where our website contains links to external services, the privacy information of the respective provider applies to processing on the destination website. As a rule, data is transferred to the destination website only when you open such a link.
17. Changes to this privacy policy
We update this privacy policy when functions, service providers or the legal framework change. The version published on this website with the date stated above is the current version.