Legal Information

Privacy Policy

This is a non-binding English translation provided for convenience. In case of any discrepancy or ambiguity, the German original version is legally binding.

Last updated: August 6, 2026. CERTavia is a product of Litzki Systems LLC.

Summary: CERTavia is a purely B2B service and collects personal data only to the extent necessary for operation and contract performance. The CERTavia Checker exclusively examines publicly accessible technical domain signals — no page content, no personal data, no profiling, and no automated decision-making (Art. 22 GDPR). Google Analytics 4 is loaded only after explicit consent; Cloudflare Web Analytics is cookie-free. Signed vault records are made available for 90 days, anonymized server logs are retained for a maximum of 14 days. Processors include Cloudflare, Hetzner, Stripe, Resend, and Calendly; businesses can access a DPA pursuant to Art. 28 GDPR. Detailed provisions for each processing activity follow below.

1. Data Controller

Litzki Systems LLC
7901 4th St N, #32272
St. Petersburg, FL 33702, USA
Represented by: Thorsten Litzki
Email: [email protected]

Data Processing Agreement (DPA): Businesses using CERTavia as part of their GDPR compliance documentation can retrieve the Data Processing Agreement pursuant to Art. 28 GDPR here and save it as a PDF. A countersigned copy is issued upon request.

2. Principles of Data Processing

CERTavia processes personal data exclusively within the scope of applicable data protection laws, in particular the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). Data is collected only to the extent necessary to provide the service.

CERTavia is directed exclusively at businesses within the meaning of Sec. 14 of the German Civil Code (BGB). No contracts are concluded with consumers.

3. Hosting and Infrastructure

This website is provided via Cloudflare Pages (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). As part of hosting, Cloudflare processes technical connection data (IP address, timestamp, requested URLs) to ensure operation and protect against abuse.

In addition, Cloudflare Web Analytics is used. This service collects exclusively aggregated, non-personal page-view statistics. No cookies are set and no local storage is used. Consent is not required. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in usage analysis in a privacy-compliant form).

The scan API and evaluation logic are operated on servers of Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany). Hetzner processes technical connection data on behalf of CERTavia. A data processing agreement (DPA) is in place.

Legal basis (hosting): Art. 6(1)(f) GDPR (legitimate interest in secure and stable website operation).

CERTavia additionally uses Cloudflare Turnstile on the contact form (certavia.org/kontakt). Turnstile is a CAPTCHA-like bot-protection service from Cloudflare that operates without cookies. To detect automated requests, Cloudflare processes technical browser signals (e.g., user agent, screen size, behavioral patterns). An IP address is processed but not permanently stored. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security of the contact form). Cloudflare privacy policy: cloudflare.com/privacypolicy.

Cloudflare is certified under the EU-US Data Privacy Framework. Further information: cloudflare.com/privacypolicy.

4. Contacting Us

4a. Direct Contact by Email

When contacting us via the contact form, the submitted data (name, email address, message content) is processed to handle the request.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) as well as Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries).

Retention period: The data is deleted after the communication has concluded, unless statutory retention obligations require otherwise.

4b. Contact Form

Inquiries can be submitted directly via the contact form on certavia.org.

Data processed: Name (required), email address (required), company (optional), phone number (optional), type of inquiry (optional), message content (required).

Purpose: Processing and responding to incoming inquiries.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) as well as Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries).

Transmission: Form data is forwarded to CERTavia as an email via Resend (see Section 7); the third-country safeguards named there (SCCs) apply. The data is not permanently stored in a database.

Retention period: The data is deleted after the communication has concluded, unless statutory retention obligations require otherwise.

Note: Storing contact inquiries in an internal CRM (Hetzner server) is planned for a future development stage. This privacy policy will be updated accordingly before activation.

5. Web Analytics – Google Analytics 4

This website uses Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) for anonymized evaluation of user behavior. Google Analytics 4 is activated only after your explicit consent.

Data processed: Anonymized usage data (page views, time on page, traffic source, browser and device information). IP addresses are truncated before transmission to Google (IP anonymization active).

Purpose: Optimization and further development of certavia.org based on anonymized usage statistics.

Legal basis: Art. 6(1)(a) GDPR (consent). Consent can be withdrawn at any time on the cookie settings page. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Third-country transfer: Data is processed on Google's servers (USA). Google LLC is certified under the EU-US Data Privacy Framework. Google's privacy policy: policies.google.com/privacy.

Opt-out: In addition to consent management via cookie settings, the Google Analytics Opt-out Browser Add-on is available.

6. Payment Processing (Stripe)

CERTavia uses Stripe (Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA; European entity: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland) to process payments.

Data processed: Email address, payment data (credit card data, IBAN, etc.), and the domain provided at purchase (as a technical reference ID, client_reference_id). The domain serves solely to identify the audit order and, for legal entities, does not constitute personal data.

Purpose: Contract performance – processing the purchase, issuing invoices, fraud prevention.

Legal basis: Art. 6(1)(b) GDPR (contract performance).

Retention period: Stripe stores payment data in accordance with statutory retention obligations and its own privacy policy.

Third-country transfer: Stripe, Inc. is certified under the EU-US Data Privacy Framework; Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR are in place between CERTavia and Stripe. Stripe's privacy policy: stripe.com/de/privacy.

CERTavia receives from Stripe only the information necessary to fulfill the order (payment confirmation, email address, domain). Complete payment data (e.g., card numbers) is processed exclusively by Stripe and is not transmitted to CERTavia.

7. Transactional Emails (Resend)

CERTavia uses Resend (Resend, Inc., 2261 Market St #5039, San Francisco, CA 94114, USA) to send transactional emails within the scope of existing contractual and usage relationships.

Types of emails sent and their purpose:

  • Order confirmation after payment — confirmation of the selected plan with its name and included re-scan capacity; legal basis: Art. 6(1)(b) GDPR.
  • Delivery of the audit report — transmission of the ordered infrastructure evidence after the scan is completed; legal basis: Art. 6(1)(b) GDPR.
  • Re-scan notification — information about the completion of an automatic or manually triggered re-scan; legal basis: Art. 6(1)(b) GDPR.
  • Quota exhaustion — notice when the last available re-scan quota of the subscription has been used; legal basis: Art. 6(1)(b) GDPR.
  • Vault expiration warning — reminder 14 days before the 90-day retention period of a vault record expires (for local archiving of the signed evidence); legal basis: Art. 6(1)(b) GDPR. Regarding processing of the email address in the vault record, see Section 10.
  • Subscription expiration warning — reminder 14 days before an active subscription expires; legal basis: Art. 6(1)(b) GDPR.
  • Cancellation confirmation — confirmation of contract termination after subscription cancellation; legal basis: Art. 6(1)(b) GDPR.

Data processed: Email address (from the Stripe purchase process or, for a free scan report, from the form consent pursuant to Section 8), domain name (as an order reference), plan- or scan-specific metadata (score, verdict, quota status, expiration date), timestamp of sending.

Legal basis: Art. 6(1)(b) GDPR (contract performance) for all types listed above.

Retention period: Email addresses of paying customers are stored for the duration of the contractual relationship and thereafter in accordance with statutory retention obligations. Resend stores sending data in accordance with its own privacy policy.

Third-country transfer: Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR are in place between CERTavia and Resend. Resend's privacy policy: resend.com/legal/privacy-policy.

8. Free Scan Reports and Benchmark Snapshots (Email on Request)

CERTavia offers a free EU AI Act compliance quick scan at certavia.org/scan and an industry benchmark snapshot at certavia.org/benchmarks. After the scan completes, or when retrieving the snapshot, a results report can be requested by email.

Scan snapshot (certavia.org/scan)

Data processed: Email address, domain name entered, selected sector (optional), overall CES score, assessment of the six compliance clusters, timestamp of the scan. Only data that is also visible to the user in the browser is transmitted; no internal weighting parameters or IP data.

Purpose: One-time delivery of the scan result to the provided email address (no contractual relationship, no automatic follow-up contact).

Legal basis: Art. 6(1)(a) GDPR (explicit consent via mandatory checkbox before sending). Consent relates to a one-time delivery; withdrawal is not applicable in the absence of repeated sending.

Benchmark snapshot (certavia.org/benchmarks)

Data processed: Email address, selected sector, aggregated benchmark metrics (avg. CES score, number of domains scanned, weakest cluster — aggregate data only, no individual domain data), timestamp.

Purpose: One-time delivery of the industry benchmark report to the provided email address.

Legal basis: Art. 6(1)(a) GDPR (explicit consent via mandatory checkbox before sending). One-time delivery; no withdrawal required.

Optional marketing communication (EU AI Act updates)

Anyone who additionally activates the optional checkbox agrees to receive occasional updates on the EU AI Act and EU AI regulation by email.

Legal basis: Art. 6(1)(a) GDPR (voluntary, separate consent). Consent can be withdrawn at any time by clicking the unsubscribe link in any such email or via the contact form. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Retention and deletion: Email addresses and associated scan data are stored in an internal lead database (scan_leads). Records without marketing consent are automatically deleted 30 days after the report is sent. Records with marketing consent are stored until withdrawal and deleted promptly thereafter.

Delivery via Resend: Report delivery also takes place via Resend (see Section 7); the same third-country safeguards (SCCs) apply.

9. Newsletter and Double Opt-in Procedure

CERTavia offers topic-specific email newsletters, including the Vorstand-Briefing (monthly, assessments of the EU AI Act, DORA, and NIS2 for decision-makers) and the Compliance-Barometer (bi-monthly, benchmark data and regulatory updates for compliance officers). Additional topic-specific newsletters may be added; the procedure described here applies in each case.

Data processed: Email address, selected newsletter type (newsletter_type), time of sign-up, time and IP address of confirmation (as proof of consent).

Double opt-in procedure: After signing up, you receive a confirmation email with an activation link. Newsletter delivery begins only after clicking this link. The confirmation link is valid for 48 hours; unconfirmed sign-ups are automatically deleted and no delivery takes place.

Purpose: Delivery of the selected newsletter content as well as proof of the consent given (double opt-in consent) in accordance with the documentation requirements established by case law.

Legal basis: Art. 6(1)(a) GDPR (consent).

Withdrawal: Consent can be withdrawn at any time via the unsubscribe link in any newsletter email or via the contact form. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Delivery: Confirmation and newsletter emails are sent via Resend (see Section 7); the same third-country safeguards (SCCs) apply.

Email tracking (open rate and click tracking): Newsletter emails contain an invisible tracking pixel (1×1 px image) that triggers a request to Resend's servers when the email is opened. This logs IP address, email client, operating system, and time of opening. In addition, contained links are routed via the domain track.litzki-systems.com (redirect to Resend); clicking captures the destination link along with IP address and timestamp. The purpose of this processing is statistical performance measurement of the newsletter (open rate, click rate). The legal basis is Art. 6(1)(f) GDPR (legitimate interest). You can prevent open tracking by disabling automatic display of external images in your email program.

Retention period: Email address and proof of confirmation are stored until consent is withdrawn and deleted promptly thereafter. Tracking events (opens, clicks) are deleted after 12 months.

10. Scan Service and Vault Records

Upon request, CERTavia carries out a technical audit of the specified domain. The data processed in this context and the retention period are as follows:

Domain name: The domain name entered when placing the order is processed as scan input. Domain names of legal entities generally do not constitute personal data within the meaning of the GDPR. For natural persons whose domain contains their name, the following applies: legal basis is Art. 6(1)(b) GDPR (contract performance).

Vault record: The audit result (score values, verdict, domain, timestamp) is stored in a cryptographically signed vault record and made available under a unique URL (vault.litzki-systems.org/{hash}) for 90 days. The record may contain an email address, used exclusively to send an expiration warning 14 days before the end of the 90-day period (see Section 7):

  • Subscription customers: The email address is automatically taken from the Stripe customer record when the vault record is created; legal basis: Art. 6(1)(b) GDPR (contract performance).
  • Basic customers: The email address is stored if, after the scan, the user submits the form at certavia.org/scan to receive the scan report and has thereby consented to the processing described in Section 8; legal basis: Art. 6(1)(a) GDPR (consent). Without form submission, the vault record contains no email address and no expiration warning is sent.

The email address is used exclusively for the expiration warning and is not shared with third parties. It is automatically deleted together with the vault record once the 90-day period expires.

PDF report: A PDF audit report is generated and made available for retrieval by the customer. The report contains domain name, score values, and recommendations – no personal contact data.

Purpose: Contract performance – creation and delivery of the ordered infrastructure evidence.

Legal basis: Art. 6(1)(b) GDPR (contract performance).

11. IP Addresses and Server Logs

When accessing certavia.org and using the scan API, technical connection data is processed. The last octet of the IP address is anonymized before logging and is not stored. Attribution to individual persons is thereby not possible.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security and abuse prevention).

Retention period: Anonymized log data is retained for a maximum of 14 days and then automatically deleted (daily rotation, compressed).

12. No Profiling, No Automated Decision-Making

CERTavia does not create user profiles and does not carry out automated decision-making within the meaning of Art. 22 GDPR. The CERTavia audit exclusively evaluates technical characteristics of a domain – not characteristics or behavior of a natural person.

Personal data is disclosed to third parties only within the scope of the processors named in this policy (Stripe, Resend, Cloudflare, Hetzner) and only to the extent necessary for contract performance.

13. Appointment Scheduling (Calendly)

CERTavia uses Calendly (Calendly LLC, 271 17th St NW, Atlanta, GA 30363, USA) to book initial consultations.

Data processed: Name, email address, selected appointment (date and time), time zone, and any further details entered in the booking form (e.g., company, topic of discussion).

Purpose: Coordination and confirmation of consultation appointments.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) as well as Art. 6(1)(f) GDPR (legitimate interest in efficient appointment management).

Third-country transfer: Calendly processes data on servers in the USA. Transfer is based on Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR. Calendly's privacy policy: calendly.com/privacy.

Retention period: Calendly stores booking data in accordance with its own privacy policy. CERTavia does not store separate copies of Calendly booking data.

14. Google Search Console

CERTavia uses Google Search Console (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to monitor visibility in Google Search. Integration is carried out exclusively via a DNS TXT record for domain verification. No user data from website visitors is collected or processed. Google's privacy policy: policies.google.com/privacy.

15. Cookies, Local Storage, and Consent Management

CERTavia uses technically necessary cookies (Cloudflare, always active), cookie-free page-view statistics via Cloudflare Web Analytics (no consent required, since no cookie or local storage is set), and, upon consent, analytics cookies (Google Analytics 4). The consent decision is stored in the browser's local storage (certavia_cookie_consent) – not as a cookie. A complete overview and the option to manage consent are available in the cookie policy and under cookie settings.

The CERTavia customer portal sets a session cookie (certavia_session) after successful magic-link authentication – httpOnly, secure, SameSite=None (required because certavia.org and the API domain are different origins), valid for 24 hours. The cookie is not readable by JavaScript and is used exclusively for session authentication. In addition, the backend checks the Origin header on all state-changing requests (CSRF protection). Legal basis: Art. 6(1)(b) GDPR (contract performance). See also the cookie policy.

16. Customer Portal (Magic-Link Login)

Access to the customer portal is provided for Annual Starter, Annual Subscription, and Enterprise (and on request for Basic, Pro, and Bulk). To log in, the purchase email address is sufficient; the system sends a time-limited login link (magic link).

Token storage: The login link (email address, token, usage status, creation and expiration time) is stored server-side. Used or expired tokens are automatically removed (cleanup at system startup and thereafter every six hours).

Session storage: After successful login, a session cookie is set – see Section 15.

IP addresses on portal access: The requesting IP address is not stored in plain text in the database. For rate limiting, it is temporarily held in memory and is lost on a server restart. Access to the portal interface is additionally logged (last IP octet removed) in the server access log and deleted after 14 days.

Security audit log: Failed login attempts, invalid sessions, and invalid magic-link verifications are additionally recorded in a separate log table – with a hashed data-subject reference (no plain-text email) and an anonymized IP address. Purpose: detection of abuse attempts. Retention period: 30 days, then automatic deletion. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in abuse detection).

Team invitations (Annual/Enterprise): Holders of an Annual or Enterprise access can invite additional persons to the customer portal by email address, confirming they are authorized to do so. Only the email address of the invited person is stored, no further information about them. The invitation email is itself the first notice to the data subject about this processing. Every invitation email contains a direct link through which the invited person can decline the invitation; the stored email address is then immediately removed, without any login or contact with support being necessary. Unaccepted invitations are automatically deleted no later than 30 days after being sent.

Legal basis: Art. 6(1)(b) GDPR (contract performance); for team invitations, additionally Art. 6(1)(f) GDPR (legitimate interest in the contractually provided team function).

17. Data Subject Rights

To the extent personal data is processed, the following rights apply:

  • Right to access processed data (Art. 15 GDPR)
  • Right to rectification of inaccurate data (Art. 16 GDPR)
  • Right to erasure of data (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing (Art. 21 GDPR)
  • Right to withdraw consent given (Art. 7(3) GDPR) – possible via cookie settings

Please direct requests to us via our contact form

18. Right to Lodge a Complaint

In case of complaints regarding data processing, there is a right to lodge a complaint with a data protection supervisory authority. The competent authority is determined by the data subject's place of residence or work, or the place of the alleged infringement.

19. Currency of This Policy

This privacy policy is updated whenever data processing practices change. The date of the current version is stated above. Material changes will be clearly indicated on the website.

20. CERTavia Checker (Technical Scanner)

CERTavia operates a technical scanner called the CERTavia Checker, which processes exclusively publicly accessible technical infrastructure parameters of domains: HTTP headers, DNS records, SSL configuration, structured data, link status values, and AI governance signals (e.g., /.well-known/ai-disclosure.json, /ai.txt).

Scans are initiated via the public validator at certavia.org/scan, by paying customers for their own domains or domains they are authorized to check, or as part of a vendor scan conducted by a commissioning company to assess a third-party provider under DORA Art. 28 or NIS2 — the latter also without the consent of the third-party provider being checked, since only publicly accessible parameters are processed.

Page content, user data, and personal information are not collected or stored in this process.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the quality assessment of public web infrastructure and in providing third-party risk assessments for regulated commissioning parties).

Website operators can exclude the CERTavia Checker at any time via robots.txt:

User-agent: CERTavia-Checker
Disallow: /

Further information, including the full list of parameters checked, is available on the CERTavia Checker reference page.

21. Use of Website Content as AI Training Data (Opt-out)

CERTavia objects to the use of certavia.org content for training generative AI models. This objection is recorded in a machine-readable form and communicated to compliant AI crawlers via the following signals:

  • /.well-known/content-signals.txt — sets ai-train=no (training prohibited) alongside ai-input=yes (use as context for responses permitted) and search=yes.
  • /robots.txt and /ai.txt — document the crawling and usage notices for AI systems.

Legal framework: The objection to text and data mining for training purposes is declared in machine-readable form pursuant to Art. 4(3) of Directive (EU) 2019/790 (DSM Directive). The EU AI Act refers, in Art. 53(1)(c), to the observance of such usage reservations by providers of general-purpose AI models; the data-quality requirements arise from Art. 10 of the EU AI Act.

If you, as a data subject, wish to object to the processing of your personal data submitted as part of an inquiry for AI-related purposes, or have an AI governance inquiry, please contact [email protected].