Privacy policy
This notice describes what this website and the testing service actually do — not what such texts usually say. Every retention period named here is configured in the system and enforced automatically, every hour.
Privacy policy
As at 25 August 2026
Controller
The controller for data processing on this website and in the testing service is:
Ingo Christ, sole proprietorship (brand picjoy)
Luisenstraße 15
44787 Bochum
Germany
ingo.christ@picjoy.de
Data protection officer
No data protection officer has been appointed, and none is required: under § 38 (1) of the German Federal Data Protection Act the obligation only applies where at least 20 people are constantly engaged in the automated processing of personal data. This business has no employees. Data protection questions are answered by the controller in person.
What data we process
The following data arises when you visit and use this website:
- Connection data: the website is delivered via Cloudflare. This involves the IP address, date and time, the address requested, the volume of data transferred, the referring address and the browser and operating system identifier. The legal basis is Art. 6 (1) (f) GDPR — legitimate interest in the operation and security of the website.
- The website address you enter when you start a test. It is processed in order to carry out the test and display the result. The legal basis is Art. 6 (1) (b) GDPR.
- A pseudonym of your IP address when you start a test or request a report. We do not store the IP itself but a SHA-256 hash salted with a secret random value; without that value the IP cannot be recovered from it. The sole purpose is rate limiting and abuse prevention. The legal basis is Art. 6 (1) (f) GDPR.
- Your email address when you request the full report — together with the time and IP address of the request and of the confirmation, as evidence of the double opt-in. The legal basis is Art. 6 (1) (b) GDPR, and for the evidence Art. 6 (1) (c) in conjunction with Art. 7 (1) GDPR.
- Your consent to marketing, if you ticked the relevant box. The legal basis is Art. 6 (1) (a) GDPR.
The report and marketing are kept separate
You receive the test report regardless of whether you consent to marketing. Consent is voluntary and is not a condition for the report (prohibition of coupling, Art. 7 (4) GDPR). Report and marketing are two separate entries in our consent record.
Your email address is confirmed by double opt-in: you first receive a confirmation email, which itself contains no advertising; only after you click the link it contains do we send the report and — if you consented — further messages. If the click does not come, the request is deleted in full after 72 hours.
As evidence we store, for each purpose: the time and IP address of the request, the time and IP address of the confirmation, the browser identifier, the source and the version of the consent wording. This is required by the accountability duty in Art. 7 (1) GDPR; a hash would be worthless as evidence.
You can withdraw consent at any time with effect for the future — informally by email or via the unsubscribe link in every message, which also works as a one-click unsubscribe under RFC 8058. Withdrawal blocks marketing; you can still request test reports. A marketing box once withdrawn is not re-activated by the next form. The lawfulness of processing up to the withdrawal is unaffected.
Delivery, bounces and the suppression list
Undeliverable messages and complaints about unwanted mail are evaluated. The addresses concerned go onto an internal suppression list and are never written to again. The legal basis is Art. 6 (1) (f) GDPR — the legitimate interest in not writing to anyone against their will, and the requirements of our sending provider.
If you request erasure of your data, such a suppression entry remains; only its details are removed. Deleting it as well would remove precisely the instruction never to write to that address again.
No third-party tools
This website loads no fonts, scripts or styles from external servers and embeds no analytics services, advertising networks or social networks. No cookies are set for analytics or advertising and no profiles are built. No payment provider is currently integrated; before one is, this notice will be updated.
Processors and recipients
We use two service providers, in each case on the basis of a data processing agreement under Art. 28 GDPR:
- Cloudflare (Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA) delivers the website, protects it against overload and provides the encrypted connection between the website and our test server. Connection data including the IP address is processed in doing so.
- Amazon Simple Email Service (Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg) sends the confirmation and report emails. It processes the email address, the content and the delivery status of the message; sending runs through the Frankfurt am Main region (eu-central-1).
Both providers belong to groups headquartered in the USA, so access from a third country cannot be ruled out. Any transfer is based on the European Commission's adequacy decision on the EU-US Data Privacy Framework (Art. 45 GDPR) and, in addition, on the standard contractual clauses (Art. 46 (2) (c) GDPR).
The test run itself and the database run on our own hardware in Germany. Neither test results nor address lists are held by a cloud provider.
Retention periods
We keep every item of data only as long as its purpose lasts. A program enforces the periods automatically, every hour:
- Rate-limiting counters (pseudonymised IP): 24 hours — the purpose ends with the time window.
- Pseudonymised IP on the test job: 7 days — long enough to follow up abuse.
- Unconfirmed report request (address and IP): 72 hours — without confirmation there is no consent, so there is no reason to store it.
- Test results and reports: 90 days — long enough for queries, short enough that no permanent file is built on other people's websites. Exception: results referenced publicly by an active test seal — they are the evidence behind the public test page and remain for as long as the seal is carried.
- Consent given, including the evidencing IP: for as long as the consent applies (accountability, Art. 7 (1) GDPR).
- Evidence after withdrawal: 3 years — the standard limitation period under § 195 of the German Civil Code.
- Marketing consent left unused: after 24 months without contact it is treated as lapsed and is no longer used.
- Details of undeliverable messages (diagnostic text, message identifier): 12 months.
- Suppression entry after a permanently undeliverable address: indefinite. It is the instruction “never write to this address again” and does not become wrong over time; only the address and a note are stored.
Your rights
Under the General Data Protection Regulation you have the following rights:
- Access to the data stored about you (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Objection to processing based on legitimate interests (Art. 21)
- Withdrawal of consent given (Art. 7 (3))
An informal email to ingo.christ@picjoy.de is enough for access and erasure. Both are implemented here as a defined procedure and are not pieced together by hand.
You may also lodge a complaint with a supervisory authority — the one where you habitually reside or the one responsible for the controller. For us that is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
Testing other people's websites
When you enter an address to be tested, our system requests the pages concerned like an ordinary browser and analyses the delivered source code technically. Personal data on the tested website is not deliberately collected; what is stored is the technical result, not the page itself.
Our system identifies itself as Scanready in the browser identifier and respects access barriers rather than circumventing them. Cookie banners are not clicked away automatically, because that would be a declaration of intent in someone else's name. The same address is re-tested at most once an hour — which also protects the websites being tested.