Privacy Policy
1. Introduction
Welcome to FortifyNet. We are committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR). This privacy policy explains how we collect, use, share, and protect your personal information when you use our service at fortifynet.com.
2. Data Controller
FortifyNet is the data controller for the processing of your personal data.
Contact:
Daniel Faegnell
Email: daniel@fortifynet.com
Website: https://fortifynet.com
3. What personal data do we collect?
We collect the following categories of personal data:
• Contact information: name, email address
• Account data: encrypted password
• Subscription data: chosen plan, payment status
• Domain data: domains you add for security analysis
• Audit data: results from security scans
• Newsletter: email address if you subscribe (with explicit consent)
• Technical data: IP address, browser type, device information, cookie identifiers
• Communication data: messages you send via contact forms
• Payment data: processed directly and securely by Stripe – we do not store card details
4. How do we use your personal data?
We use your personal data to:
• Provide, operate, and maintain our service
• Manage your account and subscription
• Perform security analyses of domains you register
• Send transactional communications (receipts, alerts, system notifications)
• Send newsletters and offers – only with your consent
• Analyse and improve our service via aggregated statistics
• Prevent fraud, misuse, and security threats
• Comply with legal obligations
5. Legal basis for processing
We process your personal data based on:
• Contract performance (Art. 6.1b GDPR): to deliver the service you signed up for
• Legitimate interest (Art. 6.1f GDPR): security monitoring, fraud prevention, service improvement
• Consent (Art. 6.1a GDPR): newsletters, marketing communications, and analytics cookies – can be withdrawn at any time
• Legal obligation (Art. 6.1c GDPR): accounting and VAT compliance
6. Third-party services and data transfers
We use the following third-party services that may process personal data:
**Stripe (Payment Processing)**
Company: Stripe, Inc. / Stripe Payments Europe, Limited
Purpose: Processing payments and subscriptions
Data categories: Card details, billing address, email
Privacy policy: https://stripe.com/privacy
**Google Analytics (Web Analytics)**
Company: Google LLC
Purpose: Analysis of website traffic and user behaviour
Data categories: IP address (anonymised), page views, device information, cookie identifiers
Legal basis: Consent (analytics cookies)
Privacy policy: https://policies.google.com/privacy
Opt-out: https://tools.google.com/dlpage/gaoptout
**Google PageSpeed Insights / Google APIs**
Company: Google LLC
Purpose: Performance measurement of websites being analysed
Data categories: Domain name, technical metrics (no personal data of end users)
Privacy policy: https://policies.google.com/privacy
**SSL Labs (Qualys)**
Company: Qualys, Inc.
Purpose: SSL/TLS certificate analysis
Data categories: Domain name, IP address of the analysed website
Privacy policy: https://www.qualys.com/privacy
**HaveIBeenPwned (HIBP)**
Company: Troy Hunt (individual operator)
Purpose: Checking email accounts against known data breaches (dark web search)
Data categories: Email addresses submitted by the user for checking
Privacy policy: https://haveibeenpwned.com/Privacy
**Base44 (Platform Infrastructure)**
Purpose: Hosting, database, authentication, and backend services
Data categories: All personal data stored in the app
Data storage: EU region
Privacy policy: https://base44.com/privacy
We never sell your personal data to third parties.
7. International transfers
Some data may be processed outside the EU/EEA by providers such as Google and Stripe. We ensure such transfers are lawful through EU Standard Contractual Clauses (SCCs) or the EU-U.S. Data Privacy Framework (DPF).
8. Retention periods
• Account data: retained until you close your account, then deleted within 90 days
• Payment data: 7 years (accounting requirements)
• Security audit results: deleted when you remove the domain
• Newsletter subscription: until you unsubscribe
• Analytics data (Google Analytics): 26 months
• Audit and system logs: 12 months
9. Your rights (GDPR)
You have the following rights:
• Right of access (Art. 15): request a copy of your data
• Right to rectification (Art. 16): correct inaccurate data
• Right to erasure (Art. 17): request deletion ('right to be forgotten')
• Right to restriction (Art. 18): limit processing
• Right to data portability (Art. 20): export your data
• Right to object (Art. 21): to processing based on legitimate interest
• Right to withdraw consent (Art. 7.3): at any time without negative consequences
Contact us: Daniel Faegnell – daniel@fortifynet.com
You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY): imy.se
10. Security
We apply technical and organisational security measures: TLS encryption for all data transport, encrypted passwords, least-privilege access control, regular security audits, and incident response procedures. In the event of a breach that risks your rights, we will notify IMY within 72 hours and affected users without undue delay.
11. Cookies
We use cookies for functionality, security, and analytics. Analytics cookies (including Google Analytics) are only activated with your consent. See our Cookie Policy for full details.
12. Children
Our service is not directed at children under 16. We do not knowingly collect data about minors. If you suspect a child has registered, please contact us immediately.
13. Changes
We may update this policy. For significant changes we will notify you via email or a clear notice in the service at least 14 days in advance.
14. Contact and complaints
Daniel Faegnell
Email: daniel@fortifynet.com
Supervisory authority:
Swedish Authority for Privacy Protection (IMY)
Box 8114, 104 20 Stockholm
https://www.imy.se