WE4

PRIVACY_POLICY

Privacy policy

Concretely and without legalese: what we collect, why, how long we keep it, and what you can do about it.

UPDATED 2026-08-24


Who we are

The data controller is WE4. You can reach us by replying to any email you received from us, or through the contact form on the site.

We use no processors beyond ordinary infrastructure suppliers (hosting, database, email delivery, the language model that writes the diagnosis), and we never sell data.

Website diagnosis — what happens to the address you enter

The address is used so our system can open and read the site the same way an ordinary visitor or a search engine does. We read publicly available data only: page HTML, server headers, the TLS certificate, public DNS records, and certificate transparency logs.

We never actively test anything. No login attempts, no port scanning, no probing for vulnerabilities, and we never read the contents of exposed files. For paths that are openly reachable from the internet, we report only that the address responds.

We respect robots.txt. If a site disallows automated crawling, we do not fetch the page.

We store the result so it can be shown and shared again, and so a repeat visit to the same domain does not trigger another run unnecessarily.

Email and phone

You provide your email voluntarily in exchange for the full diagnosis. We use it to deliver the report and for what you agreed to — typically follow-up about the result. The legal basis is your consent.

The phone number and the description of your goals are entirely optional and are offered only after you already have the report. Everything works the same without them.

You can withdraw consent at any time by replying to any of our emails. Withdrawal does not affect processing that already took place.

IP address

We do not store IP addresses in readable form. They become a one-way fingerprint (a salted hash) used solely to limit how many diagnoses can run from one network per hour. The IP address cannot be recovered from it.

The legal basis is our legitimate interest in protecting the service from abuse.

How long we keep data

Diagnosis results and contact details are kept for the duration of the business relationship, and at most three years from the last contact. After that we delete them.

If you want them deleted sooner, write to us — we will delete them without undue delay.

Diagnosed a site you do not manage?

The diagnosis works exclusively with publicly available data, so no access to anything non-public is ever created. Even so: if someone approached you with a report about a domain you manage and you do not want us holding it, write to us and we will delete it.

A shared result link never contains security findings — those are available only to whoever entered the email.

Your rights

You have the right to access your data, to rectification, erasure, restriction of processing, portability, and the right to object. Just write to us.

If you believe we process your data unlawfully, you may lodge a complaint with the Czech Office for Personal Data Protection (uoou.cz).

Cookies

The site uses only strictly necessary cookies: sign-in to the internal area, and one cookie remembering that you unlocked a particular diagnosis so it stays available after a page reload.

We deploy no advertising or third-party tracking cookies.